Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of September 4, 2026report.ci.commoninternet.net2026-09-04 03:28 UTC

A clean sweep: of the 20 recipes considered, the run extended eight open upgrade PRs and every one re-verified !testme GREEN — no failures, no stale tests, and nothing new this week carries a CVE. What needs attention is older: gitea (26 CVEs, five high) and keycloak (22 security fixes) have sat green and unmerged since Aug 31 on the forge and identity tiers, with mattermost-lts's ESR move (13 CVEs, off a line whose support expired Aug 15) and lasuite-meet's nginx high batch + redis security release (4) behind them. The table is ordered by what to address first — work it top-down.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
gitea1.27.2-rootless → 1.27.3-rootlessGREEN26build 1306 ✓#8…The git forge itself: 26-CVE security release, five high (Actions approval bypasses, restricted-user leaks, registry/token scopes); count is a floor (CVE-2025-68939 unjudged). postgres 15 held. Green and unmerged since 08-31 — merge, then release -z. Unrelated fix PR #4 (writable app.ini) also open, green.
keycloak26.7.2 → 26.7.3GREEN22build 1307 ✓#8…Identity provider: 22 security fixes — unsigned signed-JWT assertion bypass, LDAP cert hostname verification, redirect_uri/FGAP authz bypasses, PII disclosure. Deploying from ≤26.7.1 also lands critical CVE-2026-18963 (fixed in 26.7.2, already in main). No migrations; mariadb held. Green and unmerged since 08-31.
lasuite-meetv1.21.0 → v1.30.0GREEN4build 1320 ✓#9…Extended to v1.30.0 + nginx 1.31.5 this week. The PR crosses nginx 1.31.2→1.31.5 (three high fixed in 1.31.3: CVE-2026-42533/56434/60005) and redis 8.10.1 (CVE-2026-62356 heap OOB — a floor, more unnamed fixes); livekit v1.13.6 rides along. Recordings now finalize via LiveKit webhook only — recipe already configured for it.
mattermost-lts10.11.22 → 11.7.10GREEN13build 1323 ✓#2…ESR move off 10.11 (EOL expired 2026-08-15) onto 11.7 (EOL 2027-05-15); 13 CVEs, all medium/low. Re-verified green this week — 11.7.10 is still the newest ESR patch; 11.8–11.10 are innovation releases, deliberately not taken. postgres 15 held; release is a major (-x). Fold decision with fix PR #1 still pending.
discourse2026.7.1 → 2026.7.2GREENnonebuild 1305 ✓#9…Security patch on the 2026.7 ESR line: eight vendor security-fix groups / 18 SECURITY commits, but upstream publishes no CVE IDs — the none here means no identified CVEs, not no security content. Migrations auto-run on boot. Green and unmerged since 08-31 (1303; duplicate trigger 1305 also green).
custom-html1.31.3 → 1.31.5GREENnonebuild 1315 ✓#7…nginx mainline 1.31.4 + 1.31.5 — no security entries in either (the last CVE batch was fixed in the pinned 1.31.3); the 1.31.5 HTTP/2-proxying use-after-free fix is proactive hardening. Static-file serving unaffected by the 1.31.4 :authority change. One-line diff; ready to merge.
ghost6.60.0-alpine → 6.62.0-alpineGREENnonebuild 1316 ✓#7…6.61 gift subscriptions + 6.62 React tag-details screen and member-facing fixes (wrong-member unsubscribe links, private-site landing page). No breaking changes; mysql deliberately held at 8.4 — Ghost supports MySQL 8 only. Ready to merge.
lasuite-docsv5.4.1 → v5.6.0GREENnonebuild 1318 ✓#8…impress v5.5/v5.6 (math + diagram blocks, find-and-replace, word count, anchor links; whitenoise removed — recipe unaffected) + nginx 1.31.5. AUTO_MIGRATIONS ran clean. The scan's 51 contested nginx CVEs were adjudicated historical (fixed at/below the pin) — 0. Ready to merge.
lasuite-drivev0.21.0 → v0.21.2GREENnone1317 flake → build 1319 ✓#7…App quartet stays at the 08-31-verified v0.21.2; this pass adds mailcatcher v0.11.0 (rack/sinatra/thin security dep bumps — no CVE IDs named) + nginx 1.31.5. Run 1 was RED on a warm-keycloak dep provisioning flake; the re-test is fully green. collabora/minio/onlyoffice held (26.04 redesign, Docker Hub cap, 9.4.1.2 newest).
matrix-synapsev1.159.0 → v1.160.0GREENnonebuild 1321 ✓#5…synapse v1.160.0 + MAS 1.24.0 + nginx 1.31.5. No numbered CVEs, but advisory fixes ride along: rustls-webpki (GHSA-82j2-j2ch-gfr8) and pyo3 (two GHSAs) in synapse, h2 (RUSTSEC-2026-0258) in MAS. Telegram bridge carried; DB majors held (bridge dump/restore is an operator step). Ready to merge.
n8n2.34.4 → 2.38.3GREENnonebuild 1322 ✓#7…2.38.x expression-engine hardening (copy-on-write writes, shared time budgets), new model providers, worker-cleanup fix. No breaking config; TypeORM auto-migrates. 2.38.x is still pre-release upstream — tracking the newest tag is the standing precedent. CVE-2026-73088 adjudicated NOT-FIXED here (see Addendum). Ready to merge.
hedgedocdb 16-alpine → 18-alpineGREENnonebuild 1302 ✓#3…pgautoupgrade in-place DB major; app already latest at 1.12.0. Carry-over, green since 08-22 — merge-ready.
wordpress7.0.4 → 7.1.0GREENnonebuild 1301 ✓#1…Carry-over, green since 08-21 — merge-ready; nothing new this run.
custom-html-tiny2.43.0 → 2.44.0GREENnonebuild 1159 ✓#9…static-web-server 2.44.0 + alpine/git v2.54.0. Main still pins 2.43.0/v2.52.0 — the run's 'up-to-date' quotes the PR's targets (see Addendum). Green carry-over — merge-ready.
mailu—GREENnonebuild 483 ✓#3…A feature, not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). App up-to-date at 2024.06.58.
plausibleclickhouse → 23.4.6.25-alpineGREENnonebuild 1286 ✓#5…23.4 LTS patch. External (maintained elsewhere) — the mirror PR is green but nobody here merges it; see Addendum.
bluesky-pds—UPTODATEnonepending · no CI run#4…App up-to-date (pds 0.4.5027). Routing-fix PR #4 (app→pds rename so caddy resolves this stack on the shared proxy) still has no !testme verdict — flagged last week, still untested.
immich—UPTODATEnonebuild 1211 ✓ · overtaken by main#4…Up-to-date: upstream main now pins v3.1.0 itself — PR #4's head is byte-identical to main (verified for this report). The PR is an empty artifact and can be closed; see Addendum.
cryptpad—UPTODATEnoneUp-to-date at 2026.5.1 (direct registry check — abra can't parse the version-… tag).
drone—UPTODATEnoneUp-to-date at 2.28.2.
mumble—UPTODATEnoneUp-to-date at v1.6.870-0.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

gitea 1.27.3 — 26-CVE security batch incl. Actions approval bypasses (high) · the git forge itself, green and unmerged since Aug 31
1.27.2-rootless → 1.27.3-rootless fixes 26 CVEs — the deterministic scan's 24, plus CVE-2026-62925 (adjudicated FIXED from the vendor's patch note) and CVE-2026-70406 (named in the vendor security post, not yet in GHSA). Five are rated high per the vendor, four with GHSA advisories so far: CVE-2026-60010, -66877, -68957, -71184 — fork-PR Actions approval bypasses (code execution where self-hosted runners are enabled), restricted-user data leaks, package-registry access control and token-scope enforcement. The count is a floor: sidecar advisory CVE-2025-68939 could not be judged and is unmeasured, not unaffected. postgres is deliberately held at 15 (a DB-major bump needs an operator dump/restore). !testme GREEN at build 1306 and unmerged for a week — the forge itself runs 1.27.2 until this lands. Merge, then abra recipe release gitea -z.
keycloak 26.7.3 — 22 security fixes on the identity provider (high) · green and unmerged since Aug 31
26.7.2 → 26.7.3 closes 22 CVEs named in the vendor changelog: an unsigned signed-JWT assertion bypass (CVE-2026-16093), LDAP certificate hostname verification (CVE-2026-35563), an incomplete redirect_uri fix (CVE-2026-18209), FGAP/role authorization bypasses (CVE-2026-16105, -16106, -18570, -18571), user PII disclosure in GET /roles/{role}/users (CVE-2026-17059), raw reCAPTCHA secret exposure (CVE-2026-16104), and an incomplete path-traversal fix (CVE-2026-19729), among others. Operators deploying from ≤26.7.1 additionally land critical CVE-2026-18963 (unauthenticated account takeover via reset-credentials bypass, fixed in 26.7.2 — already carried in main). Known 26.7.x watch-items, not blockers: admin-API cost growth with many realms (#51554) and post-upgrade high CPU (#51523). No migrations; mariadb 12.3 held. !testme GREEN at build 1307, awaiting merge since Aug 31.
lasuite-meet — nginx 1.31.3 high batch + redis 8.10.1 security release (high) · extended to v1.30.0 this week
The v1.21.0 → v1.30.0 PR crosses nginx 1.31.2 → 1.31.5, picking up the three high nginx CVEs fixed in 1.31.3 (CVE-2026-42533, -56434, -60005), plus redis 8.8.0 → 8.10.1 — a SECURITY release fixing CVE-2026-62356 (heap out-of-bounds write in CMSketch RDB loading) and several further flaws the vendor names without CVE ranges, so the count of 4 is a floor. livekit v1.13.6 rides along (its only default change is the H.264 baseline codec leaving the enabled list — standard clients unaffected). This week's extension to v1.30.0 adds the Voxtral realtime agent engine and Spanish i18n, and changes recording finalization to LiveKit's egress_ended webhook only — the recipe's livekit config already points there. AUTO_MIGRATIONS handled the database. !testme GREEN at build 1320.
discourse 2026.7.2 — eight vendor security-fix groups, severities undisclosed · internet-facing, green and unmerged since Aug 31
The 2026.7.1 → 2026.7.2 patch on the 2026.7 ESR line carries eight security-fix groups (18 SECURITY-tagged commits): stored XSS in video placeholders and email video titles, iframe allowlist / userinfo / wildcard fixes, embed-URL escaping in the footer, LIKE-metachar escaping on upload paths, hidden-post-revision reconstruction blocking, anonymous-cache-key partitioning, and more. Upstream publishes no CVE IDs for this release (advisory scan: 0; the one candidate, CVE-2025-53016, predates the window and was adjudicated already-fixed in 2026.7.1) — so the table's none means 'no identified CVEs', not 'no security content'. Rails migrations auto-run on boot; no config changes. !testme GREEN at build 1303 (a duplicate trigger also resolved green at 1305) — internet-facing and unmerged since Aug 31.

What changed

1.27.2-rootless → 1.27.3-rootless, a pure security patch: 26 CVEs, five high (see the bulletin) — fork-PR Actions approval bypasses, restricted-user data leaks, package-registry access and token-scope fixes. No config or migration changes; postgres deliberately held at 15 (16/17/18 is an operator dump/restore step). Green and unmerged since 08-31; after merge, abra recipe release gitea -z. The separate app.ini fix PR #4 (green at build 1250) awaits its own decision — and likely also cures the warm-dep crash-loop (see Addendum).
26.7.2 → 26.7.3: 22 security fixes — unsigned signed-JWT assertion bypass, LDAP certificate hostname verification, redirect_uri and FGAP authz bypasses, PII disclosure, reCAPTCHA secret exposure (see the bulletin). No migrations, no KC_* env changes; mariadb 12.3 held. Green and unmerged since 08-31. Watch-items: admin-API cost growth with many realms (#51554), post-upgrade CPU spikes (#51523). Release: abra recipe release keycloak -z.
v1.21.0 → v1.30.0 (app/backend/celery) — this week's extension adds v1.30.0 (Voxtral realtime agent engine, Spanish i18n, publish-permissions exposure) and nginx 1.31.4 → 1.31.5 on top of the PR's existing v1.29.0 tail, redis 8.10.1 (security release) and livekit v1.13.6. One behavioural change to know: recordings now finalize only via LiveKit's egress_ended webhook — the recipe's livekit config already points there, and the removed S3 storage-event envs were never set here. AUTO_MIGRATIONS ran clean; !testme GREEN at build 1320.
10.11.22 → 11.7.10, re-verified this week: 11.7.10 (released 2026-08-26) is still the newest 11.7 ESR patch — the 11.8/11.9/11.10 tags abra offers are innovation releases with weeks-left EOLs, deliberately not taken; the 11.7 ESR line runs to 2027-05-15. A vendor-supported ESR→ESR move off the 10.11 line that expired 2026-08-15, with DB migrations on boot; 13 CVEs (all medium/low) land with it. postgres 15-alpine held as a separate operator step. The pg_backup restore fix is folded into this PR — close #1 after it merges. Release: abra recipe release mattermost-lts -x (major).
2026.7.1 → 2026.7.2, a security patch on the 2026.7 ESR line — eight vendor security-fix groups, 18 SECURITY-tagged commits (stored XSS, iframe allowlist, embed-URL escaping — see the bulletin), plus one optional livestream_allowed_hosts site setting and a reviewables performance index. No config changes; Rails db:migrate runs automatically on boot. Green since 08-31 (builds 1303 and 1305). Release: abra recipe release discourse -z.
nginx 1.31.3 → 1.31.5, two mainline releases: 1.31.4 (PROXY-protocol v2 in stream/mail, the :authority/Host backend-header change) and 1.31.5 (control API, predicate locations, json module, client_body_early_read, plus a use-after-free fix in buffered HTTP/2 proxying). Neither carries a security entry — the last CVE batch was fixed in the already-pinned 1.31.3 — so this is proactive hardening; static-file serving is unaffected by the header change. One-line diff; !testme GREEN at build 1315.
6.60.0-alpine → 6.62.0-alpine: 6.61.0's emailable gift subscriptions + 6.62.0's React tag-details screen and a batch of member-facing fixes (wrong-member unsubscribe links, private-site landing page, stale sidebar selections). No breaking changes, no required migrations; the slow first-boot MySQL schema migration is covered by the recipe's 15m start_period. mysql deliberately held at 8.4 — Ghost supports MySQL 8 only (abra's 9.x/26.x candidates are false positives). !testme GREEN at build 1316.
impress v5.4.1 → v5.6.0 across app/backend/celery/y-provider, plus nginx 1.31.4 → 1.31.5. v5.5.0 adds presenter slide links and new i18n locales (cn_CN renamed zh_CN — only matters if explicitly configured); v5.6.0 adds math + diagram blocks, find-and-replace, word count and anchor links, and removes whitenoise (the recipe uses Django's default staticfiles backend — unaffected). AUTO_MIGRATIONS ran clean; the scan's 51 contested nginx CVEs were adjudicated historical (fixed at/below the pin). !testme GREEN at build 1318.
PR #7's evolving tail: the app quartet stays at v0.21.2 (verified green 08-31); this pass adds mailcatcher v0.10.0 → v0.11.0 (rack/sinatra/thin security dependency bumps — no CVE IDs named; ruby 3.4 base) and nginx 1.31.4 → 1.31.5. collabora stays at 25.04 (26.04 is a shell-less image redesign, flagged to the maintainer), minio at its Docker Hub cap, onlyoffice at 9.4.1.2 (newest). !testme run 1 was RED on a warm-keycloak dep provisioning flake; the unchanged re-test is fully GREEN at build 1319.
synapse v1.159.0 → v1.160.0 + MAS 1.23.0 → 1.24.0 + nginx 1.31.4 → 1.31.5. Routine releases, but each carries a security-relevant dependency fix: rustls-webpki (GHSA-82j2-j2ch-gfr8) and pyo3 (GHSA-36hh-v3qg-5jq4, GHSA-chgr-c6px-7xpp) in synapse, h2 (RUSTSEC-2026-0258) in MAS — advisory IDs, no numbered CVEs, hence the table's none. mautrix-telegram v0.2608.0 rides along; the app DB and bridge DBs stay on their held majors (operators with bridge-DB data must dump/restore across postgres majors). !testme GREEN at build 1321.
2.34.4 → 2.38.3, spanning the 2.38.x line: expression-engine hardening (copy-on-write writes on VM lazy proxies, one shared time budget across nested evaluations, validated timeout/memory limits), new model providers (Moonshot/MiniMax/Qwen Cloud), and a worker-cleanup fix on rejected runs. No breaking compose/env changes; TypeORM auto-migrates on boot. 2.38.x is still pre-release upstream (2.37.9 holds the stable badge) — tracking the newest tag is the established precedent, and the full five-tier suite passed at build 1322. CVE-2026-73088 (browserslist) is adjudicated NOT-FIXED in this window — see the Addendum.
db pgautoupgrade 16-alpine → 18-alpine, an in-place DB major via pgautoupgrade; the app is already latest at 1.12.0. Green since 08-22 — merge-ready.
7.0.4 → 7.1.0. Carry-over, green since 08-21 — merge-ready; nothing new this run.
static-web-server 2.43.0 → 2.44.0 + alpine/git v2.52.0 → v2.54.0. Note the run's skip table files this recipe 'up-to-date at 2.44.0' — those are the PR's targets; main still pins 2.43.0/v2.52.0, so the PR is the vehicle for the bump (see Addendum). Green carry-over — merge-ready.
A feature, not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). App up-to-date at 2024.06.58; green at build 483 and awaiting an operator decision like everything else.
clickhouse → 23.4.6.25-alpine, a 23.4 LTS patch. Plausible is classified external (maintained elsewhere); the mirror PR stays green at build 1286 with nobody here to merge it — the merge-or-close decision from last week is still open (see Addendum).
Not an upgrade — the app is up-to-date at pds 0.4.5027. PR #4 renames the main service app→pds so caddy resolves this stack on the shared proxy; it predates the cert outage and has still never been !testme'd. It needs a CI run before any merge decision (see Addendum).
Nothing left to merge: upstream landed v3.1.0 on main itself, and PR #4's head compose is byte-identical to main (verified for this report) — the PR is an empty artifact and can be closed. The run's skip table still describes it as 'open PR #4 covers v3.1.0', which now overstates the PR (see Addendum).