A light, clean week: of the 20 recipes considered, the run extended only two upgrade PRs — lasuite-docs to v5.6.1 and n8n to 2.38.4 — both !testme GREEN on the first run and neither carrying a CVE, while custom-html's nginx 1.31.5 bump turned out to be already in coopcloud upstream (mirror synced, PR closed, nothing to action). The urgency is all in the queue, not the news: gitea's 26-CVE security release (five high) and keycloak's 22 security fixes have now sat green and unmerged for a week on the forge and identity tiers, with mattermost-lts's ESR move (13 CVEs off a line that expired Aug 15), lasuite-meet's nginx high batch + redis security release (4), and discourse's CVE-less security patch stacked behind them. The table is ordered by what to address first — work it top-down.
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|---|---|---|---|---|---|---|
| gitea | 1.27.2-rootless → 1.27.3-rootless | GREEN | 26 | build 1306 ✓ | #8 | … | The git forge itself: 26-CVE security release, five high (fork-PR Actions approval bypasses, restricted-user leaks, registry/token-scope fixes); count is a floor (sidecar CVE-2025-68939 unjudged). postgres 15 held. Green and unmerged since 08-31 — merge, then release -z. Unrelated fix PR #4 (writable app.ini) also open, green. |
| keycloak | 26.7.2 → 26.7.3 | GREEN | 22 | build 1307 ✓ | #8 | … | Identity provider: 22 security fixes — unsigned signed-JWT assertion bypass, LDAP cert hostname verification, redirect_uri/FGAP authz bypasses, PII disclosure. Deploying from ≤26.7.1 also lands critical CVE-2026-18963 (fixed in 26.7.2, already in main). No migrations; mariadb held. Green and unmerged since 08-31. |
| lasuite-meet | v1.21.0 → v1.30.0 | GREEN | 4 | build 1320 ✓ | #9 | … | Crosses nginx 1.31.2→1.31.5 (three high fixed in 1.31.3: CVE-2026-42533/56434/60005) + the redis sidecar to 8.10.1 (CVE-2026-62356 heap OOB — a floor, more unnamed fixes); livekit v1.13.6 rides along. Recordings finalize via LiveKit webhook only — recipe already configured. Green since 09-04. |
| mattermost-lts | 10.11.22 → 11.7.10 | GREEN | 13 | build 1323 ✓ | #2 | … | ESR move off 10.11 (EOL expired 2026-08-15) onto 11.7 (EOL 2027-05-15); 13 CVEs, all medium/low. 11.7.10 still the newest ESR patch; 11.8–11.10 are innovation releases, deliberately not taken. postgres 15 held; release is a major (-x). Fold decision with fix PR #1 still pending. |
| discourse | 2026.7.1 → 2026.7.2 | GREEN | none | build 1305 ✓ | #9 | … | Security patch on the 2026.7 ESR line: eight vendor security-fix groups / 18 SECURITY commits, but upstream publishes no CVE IDs — the none here means no identified CVEs, not no security content. Migrations auto-run on boot. Green and unmerged since 08-31. |
| lasuite-docs | v5.4.1 → v5.6.1 | GREEN | none | build 1338 ✓ · first run | #8 | … | This week: extended to v5.6.1 (PDF slide export) on top of v5.6.0 (math/diagram blocks, find-and-replace, word count) + nginx 1.31.5. 51 contested nginx CVEs adjudicated historical (fixed at/below the pin) — 0. AUTO_MIGRATIONS ran clean; green on the first run. Ready to merge. |
| n8n | 2.34.4 → 2.38.4 | GREEN | none | build 1339 ✓ · first run | #7 | … | This week: extended to 2.38.4. 2.38.x expression-engine hardening, new model providers; TypeORM auto-migrates; 2.38.x still pre-release upstream (tracking the newest tag is the standing precedent). CVE-2026-73088 re-checked NOT-FIXED in 2.x (see Addendum). Green on the first run. |
| ghost | 6.60.0-alpine → 6.62.0-alpine | GREEN | none | build 1332 ✓ · re-verified 09-07 | #7 | … | 6.61 gift subscriptions + 6.62 React tag-details screen and member-facing fixes (wrong-member unsubscribe links, private-site landing page). No breaking changes; mysql deliberately held at 8.4 — Ghost supports MySQL 8 only. Re-verified green today (1332, level 5/5) — ready to merge. |
| lasuite-drive | v0.21.0 → v0.21.2 | GREEN | none | 1317 flake → build 1319 ✓ | #7 | … | App quartet at v0.21.2 (verified 08-31); adds mailcatcher v0.11.0 (rack/sinatra/thin security dep bumps — no CVE IDs named) + nginx 1.31.5. Run 1 was RED on a warm-keycloak dep provisioning flake; the re-test is fully green. collabora/minio/onlyoffice held. |
| matrix-synapse | v1.159.0 → v1.160.0 | GREEN | none | build 1321 ✓ | #5 | … | synapse v1.160.0 + MAS 1.24.0 + nginx 1.31.5. No numbered CVEs, but advisory fixes ride along: rustls-webpki (GHSA-82j2-j2ch-gfr8) and pyo3 (two GHSAs) in synapse, h2 (RUSTSEC-2026-0258) in MAS. Telegram bridge carried; DB majors held. Ready to merge. |
| hedgedoc | db 16-alpine → 18-alpine | GREEN | none | build 1302 ✓ | #3 | … | pgautoupgrade in-place DB major; app already latest at 1.12.0. Carry-over, green since 08-22 — merge-ready. |
| wordpress | 7.0.4 → 7.1.0 | GREEN | none | build 1301 ✓ | #1 | … | Carry-over, green since 08-21 — merge-ready; nothing new this run. The deployed tests copy was refreshed today and now carries the full wordpress suite. |
| custom-html-tiny | 2.43.0 → 2.44.0 | GREEN | none | build 1159 ✓ | #9 | … | static-web-server 2.44.0 + alpine/git v2.54.0. Main still pins 2.43.0/v2.52.0 — the run's 'up-to-date' again quotes the PR's targets (see Addendum). Green carry-over — merge-ready. |
| mailu | — | GREEN | none | build 483 ✓ | #3 | … | A feature, not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). App up-to-date at 2024.06.58. |
| plausible | clickhouse → 23.4.6.25-alpine | GREEN | none | build 1286 ✓ | #5 | … | 23.4 LTS patch. External (maintained elsewhere) — the mirror PR is green but nobody here merges it; see Addendum. |
| custom-html | 1.31.3 → 1.31.5 | UPTODATE | none | build 1315 ✓ · landed upstream | nginx 1.31.4 + 1.31.5 (no security entries — proactive HTTP/2-proxying hardening) was already in coopcloud upstream main; the mirror re-synced this run and PR #7 closed as superseded. No PR to action — the change is live on main. | ||
| bluesky-pds | — | UPTODATE | none | pending · no CI run | #4 | … | App up-to-date (pds 0.4.5027). Routing-fix PR #4 (app→pds rename so caddy resolves this stack on the shared proxy) — open since June and still never !testme'd; flagged two weeks running. |
| immich | — | UPTODATE | none | build 1211 ✓ · diverged from main | #4 | … | Up-to-date at v3.1.0 — upstream landed it and has since refreshed the sidecar pins + label (1.10.0+v3.1.0). PR #4 now diverges from main (different postgres/valkey pins, stale 1.9.0+v3.0.1 label) — close it rather than merge; see Addendum. |
| cryptpad | — | UPTODATE | none | Up-to-date at 2026.5.1 (direct registry check — abra can't parse the version-* tag). | |||
| drone | — | UPTODATE | none | Up-to-date at 2.28.2. | |||
| mumble | — | UPTODATE | none | Up-to-date at v1.6.870-0. |
Addendum