Co-op Cloud Recipe CI · Weekly Edition
The Recipe Report
Week of September 4, 2026report.ci.commoninternet.net2026-09-04 03:28 UTC
A clean sweep: of the 20 recipes considered, the run extended eight open upgrade PRs and every one re-verified !testme GREEN — no failures, no stale tests, and nothing new this week carries a CVE. What needs attention is older: gitea (26 CVEs, five high) and keycloak (22 security fixes) have sat green and unmerged since Aug 31 on the forge and identity tiers, with mattermost-lts's ESR move (13 CVEs, off a line whose support expired Aug 15) and lasuite-meet's nginx high batch + redis security release (4) behind them. The table is ordered by what to address first — work it top-down.
The full wire — every recipe, in priority order
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| gitea | 1.27.2-rootless → 1.27.3-rootless | GREEN | 26 | build 1306 ✓ | #8 | … | The git forge itself: 26-CVE security release, five high (Actions approval bypasses, restricted-user leaks, registry/token scopes); count is a floor (CVE-2025-68939 unjudged). postgres 15 held. Green and unmerged since 08-31 — merge, then release -z. Unrelated fix PR #4 (writable app.ini) also open, green. |
| keycloak | 26.7.2 → 26.7.3 | GREEN | 22 | build 1307 ✓ | #8 | … | Identity provider: 22 security fixes — unsigned signed-JWT assertion bypass, LDAP cert hostname verification, redirect_uri/FGAP authz bypasses, PII disclosure. Deploying from ≤26.7.1 also lands critical CVE-2026-18963 (fixed in 26.7.2, already in main). No migrations; mariadb held. Green and unmerged since 08-31. |
| lasuite-meet | v1.21.0 → v1.30.0 | GREEN | 4 | build 1320 ✓ | #9 | … | Extended to v1.30.0 + nginx 1.31.5 this week. The PR crosses nginx 1.31.2→1.31.5 (three high fixed in 1.31.3: CVE-2026-42533/56434/60005) and redis 8.10.1 (CVE-2026-62356 heap OOB — a floor, more unnamed fixes); livekit v1.13.6 rides along. Recordings now finalize via LiveKit webhook only — recipe already configured for it. |
| mattermost-lts | 10.11.22 → 11.7.10 | GREEN | 13 | build 1323 ✓ | #2 | … | ESR move off 10.11 (EOL expired 2026-08-15) onto 11.7 (EOL 2027-05-15); 13 CVEs, all medium/low. Re-verified green this week — 11.7.10 is still the newest ESR patch; 11.8–11.10 are innovation releases, deliberately not taken. postgres 15 held; release is a major (-x). Fold decision with fix PR #1 still pending. |
| discourse | 2026.7.1 → 2026.7.2 | GREEN | none | build 1305 ✓ | #9 | … | Security patch on the 2026.7 ESR line: eight vendor security-fix groups / 18 SECURITY commits, but upstream publishes no CVE IDs — the none here means no identified CVEs, not no security content. Migrations auto-run on boot. Green and unmerged since 08-31 (1303; duplicate trigger 1305 also green). |
| custom-html | 1.31.3 → 1.31.5 | GREEN | none | build 1315 ✓ | #7 | … | nginx mainline 1.31.4 + 1.31.5 — no security entries in either (the last CVE batch was fixed in the pinned 1.31.3); the 1.31.5 HTTP/2-proxying use-after-free fix is proactive hardening. Static-file serving unaffected by the 1.31.4 :authority change. One-line diff; ready to merge. |
| ghost | 6.60.0-alpine → 6.62.0-alpine | GREEN | none | build 1316 ✓ | #7 | … | 6.61 gift subscriptions + 6.62 React tag-details screen and member-facing fixes (wrong-member unsubscribe links, private-site landing page). No breaking changes; mysql deliberately held at 8.4 — Ghost supports MySQL 8 only. Ready to merge. |
| lasuite-docs | v5.4.1 → v5.6.0 | GREEN | none | build 1318 ✓ | #8 | … | impress v5.5/v5.6 (math + diagram blocks, find-and-replace, word count, anchor links; whitenoise removed — recipe unaffected) + nginx 1.31.5. AUTO_MIGRATIONS ran clean. The scan's 51 contested nginx CVEs were adjudicated historical (fixed at/below the pin) — 0. Ready to merge. |
| lasuite-drive | v0.21.0 → v0.21.2 | GREEN | none | 1317 flake → build 1319 ✓ | #7 | … | App quartet stays at the 08-31-verified v0.21.2; this pass adds mailcatcher v0.11.0 (rack/sinatra/thin security dep bumps — no CVE IDs named) + nginx 1.31.5. Run 1 was RED on a warm-keycloak dep provisioning flake; the re-test is fully green. collabora/minio/onlyoffice held (26.04 redesign, Docker Hub cap, 9.4.1.2 newest). |
| matrix-synapse | v1.159.0 → v1.160.0 | GREEN | none | build 1321 ✓ | #5 | … | synapse v1.160.0 + MAS 1.24.0 + nginx 1.31.5. No numbered CVEs, but advisory fixes ride along: rustls-webpki (GHSA-82j2-j2ch-gfr8) and pyo3 (two GHSAs) in synapse, h2 (RUSTSEC-2026-0258) in MAS. Telegram bridge carried; DB majors held (bridge dump/restore is an operator step). Ready to merge. |
| n8n | 2.34.4 → 2.38.3 | GREEN | none | build 1322 ✓ | #7 | … | 2.38.x expression-engine hardening (copy-on-write writes, shared time budgets), new model providers, worker-cleanup fix. No breaking config; TypeORM auto-migrates. 2.38.x is still pre-release upstream — tracking the newest tag is the standing precedent. CVE-2026-73088 adjudicated NOT-FIXED here (see Addendum). Ready to merge. |
| hedgedoc | db 16-alpine → 18-alpine | GREEN | none | build 1302 ✓ | #3 | … | pgautoupgrade in-place DB major; app already latest at 1.12.0. Carry-over, green since 08-22 — merge-ready. |
| wordpress | 7.0.4 → 7.1.0 | GREEN | none | build 1301 ✓ | #1 | … | Carry-over, green since 08-21 — merge-ready; nothing new this run. |
| custom-html-tiny | 2.43.0 → 2.44.0 | GREEN | none | build 1159 ✓ | #9 | … | static-web-server 2.44.0 + alpine/git v2.54.0. Main still pins 2.43.0/v2.52.0 — the run's 'up-to-date' quotes the PR's targets (see Addendum). Green carry-over — merge-ready. |
| mailu | — | GREEN | none | build 483 ✓ | #3 | … | A feature, not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). App up-to-date at 2024.06.58. |
| plausible | clickhouse → 23.4.6.25-alpine | GREEN | none | build 1286 ✓ | #5 | … | 23.4 LTS patch. External (maintained elsewhere) — the mirror PR is green but nobody here merges it; see Addendum. |
| bluesky-pds | — | UPTODATE | none | pending · no CI run | #4 | … | App up-to-date (pds 0.4.5027). Routing-fix PR #4 (app→pds rename so caddy resolves this stack on the shared proxy) still has no !testme verdict — flagged last week, still untested. |
| immich | — | UPTODATE | none | build 1211 ✓ · overtaken by main | #4 | … | Up-to-date: upstream main now pins v3.1.0 itself — PR #4's head is byte-identical to main (verified for this report). The PR is an empty artifact and can be closed; see Addendum. |
| cryptpad | — | UPTODATE | none | | | | Up-to-date at 2026.5.1 (direct registry check — abra can't parse the version-… tag). |
| drone | — | UPTODATE | none | | | | Up-to-date at 2.28.2. |
| mumble | — | UPTODATE | none | | | | Up-to-date at v1.6.870-0. |
Addendum
- The warm gitea dep stack (the shared CI dependency, not the recipe) has crash-looped since 2026-08-11 — 0/1 replicas, Gitea failing to write its JWT secret to a read-only /etc/gitea config volume with an empty app.ini. Pre-existing and it doesn't block !testme, but gitea's open PR #4 ('seed app.ini into a writable config volume', green at build 1250) is aimed at exactly that failure mode — merging it, and seeding the warm stack the same way, is the likely cure. Worth an operator look.
- Two 'up-to-date' rows in the run's skip table don't match the mirrors. custom-html-tiny's main still pins static-web-server 2.43.0 / alpine/git v2.52.0 — the 2.44.0/v2.54.0 figures it quotes are green PR #9's targets, so the recipe is really 'covered by an open merge-ready PR'. And immich's 'open PR #4 covers v3.1.0' is now an empty artifact: upstream landed v3.1.0 on main itself and PR #4's head compose is byte-identical to main (verified for this report) — it can be closed, and the run's '0 merged-upstream PRs to close' sweep missed it.
- lasuite-drive's first !testme run (build 1317) was RED on test_oidc_password_grant_against_dep_keycloak — a 404 against the shared warm-keycloak dep's OIDC discovery, i.e. the per-run realm hadn't provisioned in time. All ten other tests passed and the unchanged re-run was green (1319). With last week's keycloak rerun, that is two consecutive runs where the warm-keycloak dep was intermittently slow to provision per-run realms and burned a CI re-run — worth tightening the provisioning wait.
- Two recipes still hold PR pairs to reconcile: gitea (#8 the 26-CVE upgrade, #4 the app.ini fix — both green; either order works, decide deliberately) and mattermost-lts (#2 the ESR upgrade, #1 the standalone pg-restore fix whose content is already cherry-picked into #2 — close #1 once #2 merges).
- bluesky-pds PR #4 (rename the main service app→pds so caddy resolves this stack on the shared proxy) remains the only open PR in the fleet with no CI verdict at all — flagged last week, still never !testme'd. Now that CI starts cleanly it deserves a run before any merge decision.
- plausible is classified external ('maintained elsewhere'), yet its mirror still carries open green PR #5 (clickhouse 23.4.6.25-alpine, build 1286) — the merge-or-close decision flagged last week is still open, and until it's made the mirror drifts from whatever the external maintainer ships.
- n8n's advisory scan surfaced CVE-2026-73088 (browserslist); the fix (1.123.76, upstream PR #37579) landed only on the 1.x maintenance line — neither the 2.38.3 tag nor any 2.37/2.38 release carries it, so it is adjudicated NOT-FIXED by this upgrade. It's a build-time transitive dependency of the frontend bundle, likely not runtime-exploitable, but clearing it on the 2.x line the recipe tracks is an upstream n8n question, not ours.
- The deployed tests snapshot on the CI host lags the server repo's main — tests/wordpress exists in the repo but not in the deployed copy. It didn't affect this run (wordpress is covered by its open green PR), but the deployed copy should be refreshed before a wordpress !testme is trusted to run the real suite.
- The stray 281-byte untracked main.go still sits at the cc-ci repo root — flagged last week; the accompanying .env.public Gitea-URL fix was since committed, but the file remains.
Security Bulletin
🔒 Critical CVE upgrades
gitea 1.27.3 — 26-CVE security batch incl. Actions approval bypasses (high) · the git forge itself, green and unmerged since Aug 31
1.27.2-rootless → 1.27.3-rootless fixes 26 CVEs — the deterministic scan's 24, plus CVE-2026-62925 (adjudicated FIXED from the vendor's patch note) and CVE-2026-70406 (named in the vendor security post, not yet in GHSA). Five are rated high per the vendor, four with GHSA advisories so far: CVE-2026-60010, -66877, -68957, -71184 — fork-PR Actions approval bypasses (code execution where self-hosted runners are enabled), restricted-user data leaks, package-registry access control and token-scope enforcement. The count is a floor: sidecar advisory CVE-2025-68939 could not be judged and is unmeasured, not unaffected. postgres is deliberately held at 15 (a DB-major bump needs an operator dump/restore). !testme GREEN at build 1306 and unmerged for a week — the forge itself runs 1.27.2 until this lands. Merge, then abra recipe release
gitea -z.
keycloak 26.7.3 — 22 security fixes on the identity provider (high) · green and unmerged since Aug 31
26.7.2 → 26.7.3 closes 22 CVEs named in the vendor changelog: an unsigned signed-JWT assertion bypass (CVE-2026-16093), LDAP certificate hostname verification (CVE-2026-35563), an incomplete redirect_uri fix (CVE-2026-18209), FGAP/role authorization bypasses (CVE-2026-16105, -16106, -18570, -18571), user PII disclosure in GET /roles/{role}/users (CVE-2026-17059), raw reCAPTCHA secret exposure (CVE-2026-16104), and an incomplete path-traversal fix (CVE-2026-19729), among others. Operators deploying from ≤26.7.1 additionally land critical CVE-2026-18963 (unauthenticated account takeover via reset-credentials bypass, fixed in 26.7.2 — already carried in main). Known 26.7.x watch-items, not blockers: admin-API cost growth with many realms (#51554) and post-upgrade high CPU (#51523). No migrations; mariadb 12.3 held. !testme GREEN at build 1307, awaiting merge since Aug 31.
lasuite-meet — nginx 1.31.3 high batch + redis 8.10.1 security release (high) · extended to v1.30.0 this week
The v1.21.0 → v1.30.0 PR crosses nginx 1.31.2 → 1.31.5, picking up the three high nginx CVEs fixed in 1.31.3 (CVE-2026-42533, -56434, -60005), plus redis 8.8.0 → 8.10.1 — a SECURITY release fixing CVE-2026-62356 (heap out-of-bounds write in CMSketch RDB loading) and several further flaws the vendor names without CVE ranges, so the count of 4 is a floor. livekit v1.13.6 rides along (its only default change is the H.264 baseline codec leaving the enabled list — standard clients unaffected). This week's extension to v1.30.0 adds the Voxtral realtime agent engine and Spanish i18n, and changes recording finalization to LiveKit's egress_ended webhook only — the recipe's livekit config already points there. AUTO_MIGRATIONS handled the database. !testme GREEN at build 1320.
discourse 2026.7.2 — eight vendor security-fix groups, severities undisclosed · internet-facing, green and unmerged since Aug 31
The 2026.7.1 → 2026.7.2 patch on the 2026.7 ESR line carries eight security-fix groups (18 SECURITY-tagged commits): stored XSS in video placeholders and email video titles, iframe allowlist / userinfo / wildcard fixes, embed-URL escaping in the footer, LIKE-metachar escaping on upload paths, hidden-post-revision reconstruction blocking, anonymous-cache-key partitioning, and more. Upstream publishes no CVE IDs for this release (advisory scan: 0; the one candidate, CVE-2025-53016, predates the window and was adjudicated already-fixed in 2026.7.1) — so the table's none means 'no identified CVEs', not 'no security content'. Rails migrations auto-run on boot; no config changes. !testme GREEN at build 1303 (a duplicate trigger also resolved green at 1305) — internet-facing and unmerged since Aug 31.
What changed
1.27.2-rootless → 1.27.3-rootless, a pure security patch: 26 CVEs, five high (see the bulletin) — fork-PR Actions approval bypasses, restricted-user data leaks, package-registry access and token-scope fixes. No config or migration changes; postgres deliberately held at 15 (16/17/18 is an operator dump/restore step). Green and unmerged since 08-31; after merge, abra recipe release
gitea -z. The separate app.ini fix PR #4 (green at build 1250) awaits its own decision — and likely also cures the warm-dep crash-loop (see Addendum).
26.7.2 → 26.7.3: 22 security fixes — unsigned signed-JWT assertion bypass, LDAP certificate hostname verification, redirect_uri and FGAP authz bypasses, PII disclosure, reCAPTCHA secret exposure (see the bulletin). No migrations, no KC_* env changes; mariadb 12.3 held. Green and unmerged since 08-31. Watch-items: admin-API cost growth with many realms (#51554), post-upgrade CPU spikes (#51523). Release: abra recipe release
keycloak -z.
v1.21.0 → v1.30.0 (app/backend/celery) — this week's extension adds v1.30.0 (Voxtral realtime agent engine, Spanish i18n, publish-permissions exposure) and nginx 1.31.4 → 1.31.5 on top of the PR's existing v1.29.0 tail, redis 8.10.1 (security release) and livekit v1.13.6. One behavioural change to know: recordings now finalize only via LiveKit's egress_ended webhook — the recipe's livekit config already points there, and the removed S3 storage-event envs were never set here. AUTO_MIGRATIONS ran clean; !testme GREEN at build 1320.
10.11.22 → 11.7.10, re-verified this week: 11.7.10 (released 2026-08-26) is still the newest 11.7 ESR patch — the 11.8/11.9/11.10 tags abra offers are innovation releases with weeks-left EOLs, deliberately not taken; the 11.7 ESR line runs to 2027-05-15. A vendor-supported ESR→ESR move off the 10.11 line that expired 2026-08-15, with DB migrations on boot; 13 CVEs (all medium/low) land with it. postgres 15-alpine held as a separate operator step. The pg_backup restore fix is folded into this PR — close #1 after it merges. Release: abra recipe release
mattermost-lts -x (major).
2026.7.1 → 2026.7.2, a security patch on the 2026.7 ESR line — eight vendor security-fix groups, 18 SECURITY-tagged commits (stored XSS, iframe allowlist, embed-URL escaping — see the bulletin), plus one optional livestream_allowed_hosts site setting and a reviewables performance index. No config changes; Rails db:migrate runs automatically on boot. Green since 08-31 (builds 1303 and 1305). Release: abra recipe release
discourse -z.
nginx 1.31.3 → 1.31.5, two mainline releases: 1.31.4 (PROXY-protocol v2 in stream/mail, the :authority/Host backend-header change) and 1.31.5 (control API, predicate locations, json module, client_body_early_read, plus a use-after-free fix in buffered HTTP/2 proxying). Neither carries a security entry — the last CVE batch was fixed in the already-pinned 1.31.3 — so this is proactive hardening; static-file serving is unaffected by the header change. One-line diff; !testme GREEN at build 1315.
6.60.0-alpine → 6.62.0-alpine: 6.61.0's emailable gift subscriptions + 6.62.0's React tag-details screen and a batch of member-facing fixes (wrong-member unsubscribe links, private-site landing page, stale sidebar selections). No breaking changes, no required migrations; the slow first-boot MySQL schema migration is covered by the recipe's 15m start_period. mysql deliberately held at 8.4 — Ghost supports MySQL 8 only (abra's 9.x/26.x candidates are false positives). !testme GREEN at build 1316.
impress v5.4.1 → v5.6.0 across app/backend/celery/y-provider, plus nginx 1.31.4 → 1.31.5. v5.5.0 adds presenter slide links and new i18n locales (cn_CN renamed zh_CN — only matters if explicitly configured); v5.6.0 adds math + diagram blocks, find-and-replace, word count and anchor links, and removes whitenoise (the recipe uses Django's default staticfiles backend — unaffected). AUTO_MIGRATIONS ran clean; the scan's 51 contested nginx CVEs were adjudicated historical (fixed at/below the pin). !testme GREEN at build 1318.
PR #7's evolving tail: the app quartet stays at v0.21.2 (verified green 08-31); this pass adds mailcatcher v0.10.0 → v0.11.0 (rack/sinatra/thin security dependency bumps — no CVE IDs named; ruby 3.4 base) and nginx 1.31.4 → 1.31.5. collabora stays at 25.04 (26.04 is a shell-less image redesign, flagged to the maintainer), minio at its Docker Hub cap, onlyoffice at 9.4.1.2 (newest). !testme run 1 was RED on a warm-keycloak dep provisioning flake; the unchanged re-test is fully GREEN at build 1319.
synapse v1.159.0 → v1.160.0 + MAS 1.23.0 → 1.24.0 + nginx 1.31.4 → 1.31.5. Routine releases, but each carries a security-relevant dependency fix: rustls-webpki (GHSA-82j2-j2ch-gfr8) and pyo3 (GHSA-36hh-v3qg-5jq4, GHSA-chgr-c6px-7xpp) in synapse, h2 (RUSTSEC-2026-0258) in MAS — advisory IDs, no numbered CVEs, hence the table's none. mautrix-telegram v0.2608.0 rides along; the app DB and bridge DBs stay on their held majors (operators with bridge-DB data must dump/restore across postgres majors). !testme GREEN at build 1321.
2.34.4 → 2.38.3, spanning the 2.38.x line: expression-engine hardening (copy-on-write writes on VM lazy proxies, one shared time budget across nested evaluations, validated timeout/memory limits), new model providers (Moonshot/MiniMax/Qwen Cloud), and a worker-cleanup fix on rejected runs. No breaking compose/env changes; TypeORM auto-migrates on boot. 2.38.x is still pre-release upstream (2.37.9 holds the stable badge) — tracking the newest tag is the established precedent, and the full five-tier suite passed at build 1322. CVE-2026-73088 (browserslist) is adjudicated NOT-FIXED in this window — see the Addendum.
db pgautoupgrade 16-alpine → 18-alpine, an in-place DB major via pgautoupgrade; the app is already latest at 1.12.0. Green since 08-22 — merge-ready.
7.0.4 → 7.1.0. Carry-over, green since 08-21 — merge-ready; nothing new this run.
static-web-server 2.43.0 → 2.44.0 + alpine/git v2.52.0 → v2.54.0. Note the run's skip table files this recipe 'up-to-date at 2.44.0' — those are the PR's targets; main still pins 2.43.0/v2.52.0, so the PR is the vehicle for the bump (see Addendum). Green carry-over — merge-ready.
A feature, not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). App up-to-date at 2024.06.58; green at build 483 and awaiting an operator decision like everything else.
clickhouse → 23.4.6.25-alpine, a 23.4 LTS patch. Plausible is classified external (maintained elsewhere); the mirror PR stays green at build 1286 with nobody here to merge it — the merge-or-close decision from last week is still open (see Addendum).
Not an upgrade — the app is up-to-date at pds 0.4.5027. PR #4 renames the main service app→pds so caddy resolves this stack on the shared proxy; it predates the cert outage and has still never been !testme'd. It needs a CI run before any merge decision (see Addendum).
Nothing left to merge: upstream landed v3.1.0 on main itself, and PR #4's head compose is byte-identical to main (verified for this report) — the PR is an empty artifact and can be closed. The run's skip table still describes it as 'open PR #4 covers v3.1.0', which now overstates the PR (see Addendum).