Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of September 7, 2026report.ci.commoninternet.net2026-09-07 22:11 UTC

A light, clean week: of the 20 recipes considered, the run extended only two upgrade PRs — lasuite-docs to v5.6.1 and n8n to 2.38.4 — both !testme GREEN on the first run and neither carrying a CVE, while custom-html's nginx 1.31.5 bump turned out to be already in coopcloud upstream (mirror synced, PR closed, nothing to action). The urgency is all in the queue, not the news: gitea's 26-CVE security release (five high) and keycloak's 22 security fixes have now sat green and unmerged for a week on the forge and identity tiers, with mattermost-lts's ESR move (13 CVEs off a line that expired Aug 15), lasuite-meet's nginx high batch + redis security release (4), and discourse's CVE-less security patch stacked behind them. The table is ordered by what to address first — work it top-down.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
gitea1.27.2-rootless → 1.27.3-rootlessGREEN26build 1306 ✓#8…The git forge itself: 26-CVE security release, five high (fork-PR Actions approval bypasses, restricted-user leaks, registry/token-scope fixes); count is a floor (sidecar CVE-2025-68939 unjudged). postgres 15 held. Green and unmerged since 08-31 — merge, then release -z. Unrelated fix PR #4 (writable app.ini) also open, green.
keycloak26.7.2 → 26.7.3GREEN22build 1307 ✓#8…Identity provider: 22 security fixes — unsigned signed-JWT assertion bypass, LDAP cert hostname verification, redirect_uri/FGAP authz bypasses, PII disclosure. Deploying from ≤26.7.1 also lands critical CVE-2026-18963 (fixed in 26.7.2, already in main). No migrations; mariadb held. Green and unmerged since 08-31.
lasuite-meetv1.21.0 → v1.30.0GREEN4build 1320 ✓#9…Crosses nginx 1.31.2→1.31.5 (three high fixed in 1.31.3: CVE-2026-42533/56434/60005) + the redis sidecar to 8.10.1 (CVE-2026-62356 heap OOB — a floor, more unnamed fixes); livekit v1.13.6 rides along. Recordings finalize via LiveKit webhook only — recipe already configured. Green since 09-04.
mattermost-lts10.11.22 → 11.7.10GREEN13build 1323 ✓#2…ESR move off 10.11 (EOL expired 2026-08-15) onto 11.7 (EOL 2027-05-15); 13 CVEs, all medium/low. 11.7.10 still the newest ESR patch; 11.8–11.10 are innovation releases, deliberately not taken. postgres 15 held; release is a major (-x). Fold decision with fix PR #1 still pending.
discourse2026.7.1 → 2026.7.2GREENnonebuild 1305 ✓#9…Security patch on the 2026.7 ESR line: eight vendor security-fix groups / 18 SECURITY commits, but upstream publishes no CVE IDs — the none here means no identified CVEs, not no security content. Migrations auto-run on boot. Green and unmerged since 08-31.
lasuite-docsv5.4.1 → v5.6.1GREENnonebuild 1338 ✓ · first run#8…This week: extended to v5.6.1 (PDF slide export) on top of v5.6.0 (math/diagram blocks, find-and-replace, word count) + nginx 1.31.5. 51 contested nginx CVEs adjudicated historical (fixed at/below the pin) — 0. AUTO_MIGRATIONS ran clean; green on the first run. Ready to merge.
n8n2.34.4 → 2.38.4GREENnonebuild 1339 ✓ · first run#7…This week: extended to 2.38.4. 2.38.x expression-engine hardening, new model providers; TypeORM auto-migrates; 2.38.x still pre-release upstream (tracking the newest tag is the standing precedent). CVE-2026-73088 re-checked NOT-FIXED in 2.x (see Addendum). Green on the first run.
ghost6.60.0-alpine → 6.62.0-alpineGREENnonebuild 1332 ✓ · re-verified 09-07#7…6.61 gift subscriptions + 6.62 React tag-details screen and member-facing fixes (wrong-member unsubscribe links, private-site landing page). No breaking changes; mysql deliberately held at 8.4 — Ghost supports MySQL 8 only. Re-verified green today (1332, level 5/5) — ready to merge.
lasuite-drivev0.21.0 → v0.21.2GREENnone1317 flake → build 1319 ✓#7…App quartet at v0.21.2 (verified 08-31); adds mailcatcher v0.11.0 (rack/sinatra/thin security dep bumps — no CVE IDs named) + nginx 1.31.5. Run 1 was RED on a warm-keycloak dep provisioning flake; the re-test is fully green. collabora/minio/onlyoffice held.
matrix-synapsev1.159.0 → v1.160.0GREENnonebuild 1321 ✓#5…synapse v1.160.0 + MAS 1.24.0 + nginx 1.31.5. No numbered CVEs, but advisory fixes ride along: rustls-webpki (GHSA-82j2-j2ch-gfr8) and pyo3 (two GHSAs) in synapse, h2 (RUSTSEC-2026-0258) in MAS. Telegram bridge carried; DB majors held. Ready to merge.
hedgedocdb 16-alpine → 18-alpineGREENnonebuild 1302 ✓#3…pgautoupgrade in-place DB major; app already latest at 1.12.0. Carry-over, green since 08-22 — merge-ready.
wordpress7.0.4 → 7.1.0GREENnonebuild 1301 ✓#1…Carry-over, green since 08-21 — merge-ready; nothing new this run. The deployed tests copy was refreshed today and now carries the full wordpress suite.
custom-html-tiny2.43.0 → 2.44.0GREENnonebuild 1159 ✓#9…static-web-server 2.44.0 + alpine/git v2.54.0. Main still pins 2.43.0/v2.52.0 — the run's 'up-to-date' again quotes the PR's targets (see Addendum). Green carry-over — merge-ready.
mailu—GREENnonebuild 483 ✓#3…A feature, not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). App up-to-date at 2024.06.58.
plausibleclickhouse → 23.4.6.25-alpineGREENnonebuild 1286 ✓#5…23.4 LTS patch. External (maintained elsewhere) — the mirror PR is green but nobody here merges it; see Addendum.
custom-html1.31.3 → 1.31.5UPTODATEnonebuild 1315 ✓ · landed upstreamnginx 1.31.4 + 1.31.5 (no security entries — proactive HTTP/2-proxying hardening) was already in coopcloud upstream main; the mirror re-synced this run and PR #7 closed as superseded. No PR to action — the change is live on main.
bluesky-pds—UPTODATEnonepending · no CI run#4…App up-to-date (pds 0.4.5027). Routing-fix PR #4 (app→pds rename so caddy resolves this stack on the shared proxy) — open since June and still never !testme'd; flagged two weeks running.
immich—UPTODATEnonebuild 1211 ✓ · diverged from main#4…Up-to-date at v3.1.0 — upstream landed it and has since refreshed the sidecar pins + label (1.10.0+v3.1.0). PR #4 now diverges from main (different postgres/valkey pins, stale 1.9.0+v3.0.1 label) — close it rather than merge; see Addendum.
cryptpad—UPTODATEnoneUp-to-date at 2026.5.1 (direct registry check — abra can't parse the version-* tag).
drone—UPTODATEnoneUp-to-date at 2.28.2.
mumble—UPTODATEnoneUp-to-date at v1.6.870-0.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

gitea 1.27.3 — 26-CVE security batch incl. Actions approval bypasses (high) · the git forge itself, green and unmerged since Aug 31
1.27.2-rootless → 1.27.3-rootless fixes 26 CVEs — the deterministic scan's 24, plus CVE-2026-62925 (adjudicated FIXED from the vendor's patch note) and CVE-2026-70406 (named in the vendor security post, not yet in GHSA). Five are rated high per the vendor, four with GHSA advisories so far: CVE-2026-60010, -66877, -68957, -71184 — fork-PR Actions approval bypasses (code execution where self-hosted runners are enabled), restricted-user data leaks, package-registry access control and token-scope enforcement. The count is a floor: sidecar advisory CVE-2025-68939 could not be judged and is unmeasured, not unaffected. postgres is deliberately held at 15 (a DB-major bump needs an operator dump/restore). !testme GREEN at build 1306 and unmerged for a week — the forge itself runs 1.27.2 until this lands. Merge, then abra recipe release gitea -z.
keycloak 26.7.3 — 22 security fixes on the identity provider (high) · green and unmerged since Aug 31
26.7.2 → 26.7.3 closes 22 CVEs named in the vendor changelog: an unsigned signed-JWT assertion bypass (CVE-2026-16093), LDAP certificate hostname verification (CVE-2026-35563), an incomplete redirect_uri fix (CVE-2026-18209), FGAP/role authorization bypasses (CVE-2026-16105, -16106, -18570, -18571), user PII disclosure in GET /roles/{role}/users (CVE-2026-17059), raw reCAPTCHA secret exposure (CVE-2026-16104), and an incomplete path-traversal fix (CVE-2026-19729), among others. Operators deploying from ≤26.7.1 additionally land critical CVE-2026-18963 (unauthenticated account takeover via reset-credentials bypass, fixed in 26.7.2 — already carried in main). Known 26.7.x watch-items, not blockers: admin-API cost growth with many realms (#51554) and post-upgrade high CPU (#51523). No migrations; mariadb 12.3 held. !testme GREEN at build 1307, awaiting merge since Aug 31.
lasuite-meet — nginx 1.31.3 high batch + redis 8.10.1 security release (high) · unmerged since 09-04
The v1.21.0 → v1.30.0 PR crosses nginx 1.31.2 → 1.31.5, picking up the three high nginx CVEs fixed in 1.31.3 (CVE-2026-42533, -56434, -60005), plus the redis sidecar 8.8.0 → 8.10.1 — a SECURITY release fixing CVE-2026-62356 (heap out-of-bounds write in CMSketch RDB loading) and several further flaws the vendor names without CVE ranges, so the count of 4 is a floor. livekit v1.13.6 rides along. Recordings now finalize only via LiveKit's egress_ended webhook — the recipe's livekit config already points there. AUTO_MIGRATIONS handled the database. !testme GREEN at build 1320.
discourse 2026.7.2 — eight vendor security-fix groups, severities undisclosed · internet-facing, green and unmerged since Aug 31
The 2026.7.1 → 2026.7.2 patch on the 2026.7 ESR line carries eight security-fix groups (18 SECURITY-tagged commits): stored XSS in video placeholders and email video titles, iframe allowlist / userinfo / wildcard fixes, embed-URL escaping in the footer, LIKE-metachar escaping on upload paths, hidden-post-revision reconstruction blocking, anonymous-cache-key partitioning, and more. Upstream publishes no CVE IDs for this release (advisory scan: 0; the one candidate, CVE-2025-53016, predates the window and was adjudicated already-fixed in 2026.7.1) — so the table's none means 'no identified CVEs', not 'no security content'. Rails migrations auto-run on boot; no config changes. !testme GREEN at build 1305 — internet-facing and unmerged since Aug 31.

What changed

v5.4.1 → v5.6.1 across app/backend/celery/y-provider, plus nginx 1.31.4 → 1.31.5. This week's extension adds v5.6.1 (export presenter slides as PDF; hide 'Leave' in the doc menu when not logged in; configurable DATA_UPLOAD_MAX_MEMORY_SIZE) on top of v5.6.0's math + diagram blocks, find-and-replace, word count and anchor links (whitenoise removed upstream — the recipe uses Django's default staticfiles backend, unaffected). AUTO_MIGRATIONS ran clean (core.0033); the scan's 51 contested nginx CVEs were adjudicated historical (fixed at/below the pin) → 0 CVEs. !testme GREEN at build 1338 on the first run; release after merge: abra recipe release lasuite-docs -y.
2.34.4 → 2.38.4. This week's extension fast-forwards PR #7 from 2.38.3 to the newest tag: 2.38.x expression-engine hardening (copy-on-write writes on VM lazy proxies, one shared time budget across nested evaluations, validated timeout/memory limits), new model providers (Moonshot/MiniMax/Qwen Cloud), and a worker-cleanup fix on rejected runs. No breaking compose/env changes; TypeORM auto-migrates on boot. API callers only (unchanged since 2.37.0): decorator body routes now require Content-Type: application/json. 2.38.x is still pre-release upstream — tracking the newest tag is the standing precedent. CVE-2026-73088 re-checked NOT-FIXED in this window (see Addendum). !testme GREEN at build 1339 on the first run; release after merge: abra recipe release n8n -y.
1.27.2-rootless → 1.27.3-rootless, a pure security patch: 26 CVEs, five high (see the bulletin) — fork-PR Actions approval bypasses, restricted-user data leaks, package-registry access and token-scope fixes. No config or migration changes; postgres deliberately held at 15 (16/17/18 is an operator dump/restore step). Green and unmerged since 08-31; after merge, abra recipe release gitea -z. The separate app.ini fix PR #4 (green at build 1250) awaits its own decision.
26.7.2 → 26.7.3: 22 security fixes — unsigned signed-JWT assertion bypass, LDAP certificate hostname verification, redirect_uri and FGAP authz bypasses, PII disclosure, reCAPTCHA secret exposure (see the bulletin). No migrations, no KC_* env changes; mariadb 12.3 held. Green and unmerged since 08-31. Watch-items: admin-API cost growth with many realms (#51554), post-upgrade CPU spikes (#51523). Release: abra recipe release keycloak -z.
v1.21.0 → v1.30.0 (app/backend/celery): this PR's tail carries the Voxtral realtime agent engine, Spanish i18n and publish-permissions exposure in v1.30.0, plus nginx 1.31.4 → 1.31.5, the redis 8.10.1 security release and livekit v1.13.6. One behavioural change to know: recordings now finalize only via LiveKit's egress_ended webhook — the recipe's livekit config already points there. AUTO_MIGRATIONS ran clean; !testme GREEN at build 1320, unmerged since 09-04.
10.11.22 → 11.7.10, re-verified green: 11.7.10 is still the newest 11.7 ESR patch — the 11.8/11.9/11.10 tags abra offers are innovation releases with weeks-left EOLs, deliberately not taken; the 11.7 ESR line runs to 2027-05-15, while the 10.11 line it leaves expired 2026-08-15. A vendor-supported ESR→ESR move with DB migrations on boot; 13 CVEs (all medium/low) land with it. postgres 15-alpine held as a separate operator step. The pg_backup restore fix is folded into this PR — close #1 after it merges. Release: abra recipe release mattermost-lts -x (major).
2026.7.1 → 2026.7.2, a security patch on the 2026.7 ESR line — eight vendor security-fix groups, 18 SECURITY-tagged commits (stored XSS, iframe allowlist, embed-URL escaping — see the bulletin), plus one optional livestream_allowed_hosts site setting and a reviewables performance index. No config changes; Rails db:migrate runs automatically on boot. Green since 08-31 (build 1305). Release: abra recipe release discourse -z.
6.60.0-alpine → 6.62.0-alpine: 6.61.0's emailable gift subscriptions + 6.62.0's React tag-details screen and a batch of member-facing fixes (wrong-member unsubscribe links, private-site landing page, stale sidebar selections). No breaking changes; the slow first-boot MySQL schema migration is covered by the recipe's 15m start_period. mysql deliberately held at 8.4 — Ghost supports MySQL 8 only. Re-verified this week: a fresh !testme on the unchanged head went green at build 1332 (level 5/5, part of an adversary re-check) — ready to merge.
The app quartet stays at the 08-31-verified v0.21.2; PR #7's evolving tail adds mailcatcher v0.10.0 → v0.11.0 (rack/sinatra/thin security dependency bumps — no CVE IDs named) and nginx 1.31.4 → 1.31.5. collabora stays at 25.04 (26.04 is a shell-less image redesign, flagged to the maintainer), minio at its Docker Hub cap, onlyoffice at 9.4.1.2 (newest). !testme run 1 was RED on a warm-keycloak dep provisioning flake; the unchanged re-test is fully GREEN at build 1319.
synapse v1.159.0 → v1.160.0, MAS 1.24.0, mautrix-telegram v0.2608.0, and nginx 1.31.4 → 1.31.5. Routine releases, but each carries a security-relevant dependency fix: rustls-webpki (GHSA-82j2-j2ch-gfr8) and pyo3 (GHSA-36hh-v3qg-5jq4, GHSA-chgr-c6px-7xpp) in synapse, h2 (RUSTSEC-2026-0258) in MAS — advisory IDs, no numbered CVEs, hence the table's none. The app DB and bridge DBs stay on their held majors (operators with bridge-DB data must dump/restore across postgres majors). !testme GREEN at build 1321.
db pgautoupgrade 16-alpine → 18-alpine, an in-place DB major via pgautoupgrade; the app is already latest at 1.12.0. Green since 08-22 — merge-ready.
7.0.4 → 7.1.0. Carry-over, green since 08-21 — merge-ready; nothing new this run. (The deployed tests copy on the CI host was refreshed today and now carries the full wordpress suite, so any future re-run exercises the real tiers.)
static-web-server 2.43.0 → 2.44.0 + alpine/git v2.52.0 → v2.54.0. Note the run's skip table files this recipe 'up-to-date at 2.44.0' — those are the PR's targets; main still pins 2.43.0/v2.52.0 (re-verified for this report), so the PR is the vehicle for the bump (see Addendum). Green carry-over — merge-ready.
A feature, not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). App up-to-date at 2024.06.58; green at build 483 and awaiting an operator decision like everything else.
clickhouse → 23.4.6.25-alpine, a 23.4 LTS patch. Plausible is classified external (maintained elsewhere); the mirror PR stays green at build 1286 with nobody here to merge it — the merge-or-close decision flagged three weeks ago is still open (see Addendum).
Not an upgrade — the app is up-to-date at pds 0.4.5027. PR #4 renames the main service app→pds so caddy resolves this stack on the shared proxy; open since June 18, it has still never been !testme'd (see Addendum).
Nothing left to merge: upstream landed v3.1.0 on main itself and has since refreshed the sidecar pins + version label (1.10.0+v3.1.0, postgres/valkey digests matching v3.1.0's official compose). PR #4 — same app tags but its own pgvectors0.3.0/valkey pins and a stale 1.9.0+v3.0.1 label — now diverges from main; merging it would swap the DB pins and downgrade the label. Close it (verified for this report; see Addendum).
nginx 1.31.3 → 1.31.5, two mainline releases: 1.31.4 (PROXY-protocol v2 in stream/mail, the :authority/Host backend-header change) and 1.31.5 (control API, predicate locations, json module, client_body_early_read, plus a use-after-free fix in buffered HTTP/2 proxying). Neither carries a security entry — the last CVE batch was fixed in the already-pinned 1.31.3 — so this is proactive hardening. The change landed directly in coopcloud upstream this run: the mirror force-synced and PR #7 was closed as superseded. No PR to action.