Co-op Cloud Recipe CI · Weekly Edition
The Recipe Report
Week of September 11, 2026report.ci.commoninternet.net2026-09-14 14:20 UTC
A clean sheet, and a lesson about blind spots: all twenty fleet recipes came through healthy — thirteen upgrade PRs, every single one GREEN on its first !testme run, none failed, none stale, seven up to date — and the mirror reconcile closed four PRs that had already merged upstream. Work the table from the top: gitea's MariaDB overlay turned out to be seventeen patches behind and invisible to the survey, and catching it up fixes thirty-two CVEs including two criticals; then mattermost-lts's move off its expired 10.11 ESR line (fourteen CVEs), and immich's valkey re-pin (six CVEs, four high).
The full wire — every recipe, in priority order
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| gitea | mariadb 10.11.2 → 10.11.19 | GREEN | 32 | build 1349 ✓ | #9 | … | The git forge's MariaDB overlay — 17 patches behind, invisible to the survey (both db overlays define service db; abra keeps only one). 32 CVEs fixed, 2 critical + 4 high, all on the MariaDB sidecar; app already latest, postgres overlay held at 15.19 (majors unsupported). Count is a floor: two OSV-only app advisories unjudged. Reconcile fix PR #4. |
| mattermost-lts | 10.11.22 → 11.7.10 | GREEN | 14 | build 1355 ✓ | #2 | … | Off the 10.11 ESR line, which ended 2026-08-15 — 11.7 is the current LTS, not a major leap. 14 CVEs incl. CVE-2026-13426 (path-traversal API redirect, never backported to 10.11 — even 10.11.23 would stay vulnerable). postgres held 15-alpine. Reconcile restore-fix PR #1. |
| immich | 3.1.0 → 3.2.0 | GREEN | 6 | build 1356 ✓ | #4 | … | server+ML lockstep to v3.2.0; valkey re-pinned to immich's official 9.1.1 digest — 6 CVEs (4 high) on the redis-compatible cache sidecar. Count is a floor (the old `9` digest is an unresolvable historical build). pg combo deliberately unchanged — exactly what v3.2.0 pins. |
| discourse | 2026.7.1 → 2026.7.2 | GREEN | none | build 1347 ✓ | #9 | … | Security intermediate on the 2026.7 ESR line: 8 vendor security-fix groups (stored XSS in video placeholder, iframe allowlist/userinfo bypasses, hidden post-revision exposure…) — no CVE ids assigned; CVE-2025-53016 (low) still unjudged. Green since 08-31; re-verified fresh this run. |
| hedgedoc | db 16-alpine → 17-alpine | GREEN | none | build 1350 ✓ | #3 | … | pgautoupgrade db major — walked back from last week's 18-alpine (PG18 changes the data-dir layout; one-major policy). In-place 16.15 → 17.11 verified with byte-identical pad data. App 1.12.0 already latest. |
| matrix-synapse | v1.157.1 → v1.160.0 | GREEN | none | build 1354 ✓ | #5 | … | synapse v1.160.0 + MAS 1.24.0 + mautrix-telegram/signal v0.2608.0 + nginx 1.31.5. Dependency security refreshes (rustls-webpki, pyo3, MAS h2) — no CVE ids. Bridge DBs held at 13-alpine (plain postgres can't auto-migrate; flagged in PR). |
| ghost | 6.60.0-alpine → 6.63.0-alpine | GREEN | none | build 1348 ✓ | #7 | … | 6.61/6.62 (reviewed 09-04) extended to 6.63.0 — three minors, no migrations, Node 24 added to engines. mysql held at 8.4 LTS: abra's 26.7/9.x offers are schema artifacts; Ghost supports MySQL 8 only. |
| lasuite-docs | v5.4.1 → v5.6.1 | GREEN | none | build 1351 ✓ | #8 | … | impress quartet v5.6.1 + nginx 1.31.5 (no security entries in 1.31.4/1.31.5). All 51 historical nginx advisories adjudicated as predating the 1.31.4 base — none fixed by this window. Clean. |
| lasuite-drive | v0.21.0 → v0.22.0 | GREEN | none | build 1352 ✓ | #7 | … | App quartet v0.22.0 (restricted-access migration core.0030) + carried mailcatcher v0.11.0 (rack/sinatra/thin security refresh, no CVE ids named) + nginx 1.31.5. 11/11 services converged — abra's poll window timed out, cosmetic only. |
| lasuite-meet | v1.30.0 → v1.31.0 | GREEN | none | build 1353 ✓ | #10 | … | App-only bump on top of upstream-published 0.6.0+v1.30.0, which already delivered the campaign's 4 CVE fixes (nginx ×3, redis CVE-2026-62356) reported on 09-07. github-advisories failed for unmoved sidecar repos in both scans (vendor pages worked); the PR's own window scanned clean. |
| n8n | 2.38.4 → 2.39.2 | GREEN | none | build 1357 ✓ | #8 | … | Six TypeORM migrations clean; 2.39.0 encryption-key rework verified live with the injected secret. Prior run's upgrade landed upstream as 3.5.0+2.38.4. CVE-2026-73088 (browserslist) still unfixed on 2.x — fix lives only on the 1.123.x line. |
| wordpress | 7.0.4 → 7.1.0 | GREEN | none | build 1358 ✓ | #1 | … | Rebased onto upstream #77's admin_password secret + the auto-updates fix — this green validates the previously-untested combo (the last green, build 1301 on 08-21, predated #77). |
| bluesky-pds | 0.4.5027 → 0.4.5034 | GREEN | none | build 1346 ✓ | #5 | … | Patch-level app bump (@atproto/pds 0.5.27 → 0.5.34: safeFetch outbound hardening, bounded decoded proxy responses, OTEL rework) — no config, no migrations. Routing-fix PR #4 still has no CI verdict (see Addendum). |
| custom-html-tiny | 2.43.0 → 2.44.0 | GREEN | none | build 1159 ✓ | #9 | … | Carry-over: static-web-server 2.44.0, green since the 09-04 run — up-to-date this week, awaiting upstream merge. Nothing new to action. |
| mailu | — | GREEN | none | build 483 ✓ | #3 | … | Not an upgrade: backupbot v2 backup labels (admin sqlite /data + imap mail /mail). Long-standing carry-over, green at build 483; recipe otherwise up-to-date. |
| plausible | clickhouse → 23.4.6.25-alpine | GREEN | none | build 1286 ✓ | #5 | … | 23.4 LTS patch, green since August. External (maintained elsewhere) yet the mirror PR stays unreviewed — fourth week. Merge or close. |
| custom-html | — | UPTODATE | none | | | | Up-to-date — nginx 1.31.4/1.31.5 (no security entries; last CVE batch was in the pinned 1.31.3) landed upstream in the 09-07 run; this survey (after a retried 429) confirms nothing newer. |
| keycloak | — | UPTODATE | none | | | | Up-to-date — the 22-CVE 26.7.3 security batch (last week's #2 row) was merged upstream via coop-cloud PR #43 and published as 10.9.3+26.7.3 on 09-07. The survey's contrary offer was a stale-checkout false positive, now fixed. |
| cryptpad | — | UPTODATE | none | | | | Up-to-date — image tag not semver-parseable (WARN only); no newer pin exists. |
| drone | — | UPTODATE | none | | | | Up-to-date. |
| mumble | — | UPTODATE | none | | | | Up-to-date. |
Addendum
- gitea exposed a standing survey blind spot: both db overlays (postgres, mariadb) define the same service `db`, and abra's machine output keeps only one — so the mariadb overlay sat 17 patch releases behind, invisible to every weekly survey. It was found only by a direct Docker-Hub tag check this run; a standing note is now in the registry, but the survey tooling itself still cannot see overlay shadowing.
- keycloak's survey offer (26.7.1 → 26.7.3) was a false positive: upstream had already merged and published it on 2026-09-07 (coop-cloud PR #43, 10.9.3+26.7.3). The root cause was a stale mirror checkout ref — fixed — and the 22-CVE fix from last week's report is already live upstream. Worth checking whether other mirrors carry the same staleness.
- Three recipes hold PR pairs to reconcile: gitea (#9 the MariaDB upgrade + #4 the writable-app.ini fix, both green), mattermost-lts (#2 the ESR upgrade + #1 the pg-restore fix), and bluesky-pds (#5 the upgrade + #4 the routing fix). Decide which of each pair lands.
- bluesky-pds PR #4 (rename the main service app→pds so caddy resolves this stack on the shared proxy) remains the only open PR in the fleet with no CI verdict at all — open since June and flagged in each recent edition. It needs a !testme run or a deliberate manual review.
- plausible is classified external ('maintained elsewhere'), yet its mirror still carries open green PR #5 (clickhouse 23.4 LTS patch, build 1286) — now four weeks without a merge-or-close decision. Until that lands, the classification and the mirror disagree.
- mattermost-lts's registry hint 'stay same-major' was simply wrong — 10.11's ESR ended 2026-08-15 and Mattermost's docs require ≥ 11.7. Corrected against upstream docs this run, but registry hints are advisory: the ESR-calendar check that caught this deserves to be automatic.
- hedgedoc's db target walked back from 18-alpine (as announced in the 09-07 edition) to 17-alpine: PG18 changes the data-directory layout (docker-library/postgres#1259), so the one-major-at-a-time policy applies. The prior run had also left a stash-conflict (UU) in compose.yml that made abra FATA 'unable to validate recipe' — cleaned before this run; the PR diff is now exactly the one-line bump.
- The `abra app new` checkout-reset gotcha bit four subagents this run (bluesky-pds, matrix-synapse, immich, wordpress): each first --chaos deploy silently ran the OLD tree until the WIP branch was re-checked-out. Known and worked around every time, but the recurrence in every run makes it a candidate for an abra-side fix rather than another registry note.
- n8n's CVE-2026-73088 (browserslist) remains unfixed on the 2.x line — the fix ships only on the 1.123.x maintenance line. Carried flag, re-verified this run; nothing the recipe can do except keep tracking.
Security Bulletin
🔒 Critical CVE upgrades
gitea — MariaDB 10.11.2 → 10.11.19 · 32 CVEs incl. 2 critical + 4 high · the db sidecar, not the app
The optional MariaDB overlay had drifted seventeen patch releases — invisible to every survey because both db overlays define the same service name and abra's machine output keeps only one. The catch-up fixes 32 CVEs on the MariaDB sidecar: two critical (CVE-2026-49261, fixed in 10.11.18, GHSA-3p3m-4x7c-p4pw; CVE-2026-85746, fixed in 10.11.19, GHSA-8fvj-c57c-pggx) and four high (CVE-2026-44168, CVE-2026-48163, CVE-2026-48165, CVE-2026-86047), plus privilege hardening (wsrep_sst_auth / wsrep_node_address shell-injection fixes). The
gitea app itself stays at 1.27.3-rootless (already latest); the postgres overlay stays at 15.19 (major bumps unsupported — no pg_upgrade tooling in the recipe). CI exercises the sqlite3 path, so the changed image was verified by a live in-place deploy: a 10.11.2-initialized volume opened cleanly under 10.11.19. The count is a floor — two OSV-only app advisories (CVE-2026-58439, CVE-2025-68939) carry no version windows and could not be judged. Highest-value merge of the week.
immich — valkey re-pin to 9.1.1 · 6 CVEs incl. 4 high · redis-compatible cache sidecar
immich v3.2.0 re-pins the cache sidecar from an unresolvable historical valkey `9` build to
immich's official 9.1.1 digest, picking up six fixes: four high (CVE-2025-67733 GHSA-p876-p7q5-hv2m, CVE-2026-27623 GHSA-93p9-5vc7-8wgr, CVE-2026-56684 GHSA-53mc-f3m3-99vh, CVE-2026-63639 GHSA-mvcj-73cw-22m4), CVE-2026-25243 (invalid memory access in RESTORE, verified fixed in 9.0.4), and CVE-2026-21863 (medium). The count is a floor: the old digest no longer maps to a named tag, so the 9 → 9.1.1 window is conservative. The database combo is deliberately unchanged — exactly what v3.2.0 pins; renovate's pg16/17/18 offers were rejected.
Mattermost's 10.11 ESR ended 2026-08-15; the recipe's registry hint to stay same-major was wrong and has been corrected. The move to the current 11.7 ESR fixes fourteen CVEs — thirteen medium/low from NVD, plus CVE-2026-13426 (MMSA-2025-00532): the server fails to validate path parameters when constructing API route paths, letting an attacker redirect API calls to unintended endpoints via crafted IDs containing path-traversal components. That one was never backported — even the survey's conditional 10.11.23 target would have stayed vulnerable. postgres is held at 15-alpine; the floating tag already picks up the 15.19 security backports on re-pull.
discourse — 2026.7.2 security intermediate · 8 vendor security-fix groups, no CVE ids
The vendor changelog for v2026.7.2 (43 changes) names eight security-fix groups without assigning CVE ids: hidden post-revision exposure, iframe allowlist and userinfo bypasses, embed-URL escaping, chat-history scoping, and a stored XSS in the video placeholder, among them. Internet-facing forums should take this promptly. One advisory remains unmeasured: CVE-2025-53016 (low, GHSA-48h6-hpp2-357h — HTML injection in solved posts) publishes no fixed version, so whether 2026.7.2 addresses it could not be judged; treat the fix count as open-ended. Rails migrations run automatically on boot; one optional new site setting (livestream_allowed_hosts).
What changed
mariadb overlay 10.11.2 → 10.11.19 — the only change. The app is already at 1.27.3-rootless (latest); the postgres overlay is held at 15.19 because the recipe has no pg_upgrade tooling, its backups are logical-only, its README carries no migration guidance, and the CI path (sqlite3) never exercises it. The changed image was live-verified instead: an in-place deploy opened a 10.11.2-initialized volume cleanly under 10.11.19. 32 CVEs fixed (2 critical, 4 high) — see the Security Bulletin. Release with `abra recipe release
gitea -z` after merge; reconcile with the writable-app.ini fix PR #4.
10.11.22 → 11.7.10 — the LTS line, not a major leap: 10.11's ESR ended 2026-08-15 and Mattermost's current ESR is 11.7 (the registry's contrary hint is corrected and flagged in the PR body). 14 CVEs fixed, incl. the never-backported CVE-2026-13426. postgres held at 15-alpine; recent pg security fixes are covered by the floating 15.19 tag on re-pull. Reconcile with restore-fix PR #1 (the restore-was-a-no-op fix, green at build 901).
server + machine-learning to v3.2.0 in lockstep, valkey re-pinned to
immich's official 9.1.1 digest — 6 CVEs (4 high) on the cache sidecar; the count is a floor (the old `9` digest is unresolvable). The database combo is deliberately unchanged: it is exactly what v3.2.0 pins, and renovate's pg16/17/18 offers were rejected. Tooling note now in the registry: ghcr's tags/list API is paginated (~100/page, lexicographic) — the pinned pg tag looked absent but sat on page 2 of 174, which is how the earlier tag+digest FATA was resolved via the upstream-direct cross-check.
2026.7.1 → 2026.7.2, a security intermediate on the current 2026.7 ESR line: 43 changes, 8 of them security-fix groups (no CVE ids assigned by the vendor). db:migrate runs automatically on boot, pg18 auto-upgrades in place, no .hbs delta — custom themes unaffected. One optional site setting (livestream_allowed_hosts). The PR was extended from the 08-28 run's branch (first green 08-31, builds 1303/1305) and re-verified fresh this run.
db pgautoupgrade 16-alpine → 17-alpine, walked back from the prior tip's 18-alpine: PG18 changes the data-directory layout (docker-library/postgres#1259), so the one-major-at-a-time policy applies and 18 is deferred to a dedicated cycle. Live --chaos deploy verified the in-place PG 16.15 → 17.11 upgrade with byte-identical pad content and unchanged row counts. The previous tip's drift (spurious MAINTENANCE.md/README/renovate.json reverts) is healed — the PR diff is now exactly the one-line db bump. App 1.12.0 confirmed latest.
synapse v1.157.1 → v1.160.0, MAS 1.21.0 → 1.24.0, mautrix-telegram v0.2608.0, mautrix-signal v26.02.2 → v0.2608.0, nginx 1.31.3 → 1.31.5. Bridge DBs are held at 13-alpine — plain postgres cannot auto-migrate, flagged in the PR body. Dependency security refreshes (rustls-webpki GHSA-82j2-j2ch-gfr8, pyo3 GHSA-36hh-v3qg-5jq4 + GHSA-chgr-c6px-7xpp, MAS's h2 RUSTSEC fix) are security-positive but carry no CVE ids. The first advisory-scan pass hit GitHub's anonymous API rate limit (403 across all 8 sources); it was re-run after the reset with all 24 sources live — the verdict quoted is from the complete run.
6.60.0-alpine → 6.63.0-alpine, extending the 09-04 run's branch: three minor releases (6.61 gift subscriptions, 6.62, 6.63 — Node 24 added to the engines range, a Portal false-success fix, admin-search and LinkedIn-URL fixes), no breaking changes and no new migrations. mysql is held at 8.4 LTS — abra's 26.7/9.x offers are schema artifacts and Ghost supports MySQL 8 only. First-boot schema migration is slow (~6–15 min); the recipe ships 15m start_period on both healthchecks.
impress quartet v5.4.1 → v5.6.1 + nginx 1.31.4 → 1.31.5 (five image lines). Migration core.0033 applied cleanly; gunicorn 25.3.0 → 26.0.0. The advisory scan's 51 open nginx cases were adjudicated: every fix predates the 1.31.4 base, and the 1.31.4/1.31.5 changelog sections contain zero Security: lines — 0 CVEs for this window, 18 sources checked, none failed.
App quartet v0.21.0 → v0.22.0 (frontend/backend/celery/celery-beat), carrying mailcatcher v0.11.0 (a rack/sinatra/thin security refresh that names no CVE id) and nginx 1.31.4 → 1.31.5 from the branch tail. Migration core.0030 (restricted-access feature) applied on top of the v0.21.x tail. All 11 services converged on the target images — abra's deploy poll window reported a timeout, but the stack itself was green. collabora 26.04 redesign and minio AIStor are tracked as future work, not in this PR.
App-only bump v1.30.0 → v1.31.0, opened on top of upstream-published 0.6.0+v1.30.0 — which already delivered the campaign's livekit v1.13.6, redis 8.10.1 and nginx 1.31.5, and with them the 4 CVE fixes reported in the 09-07 edition (nginx CVE-2026-42533/56434/60005, redis CVE-2026-62356). The PR's own window scanned clean (0 CVEs); the github-advisories API failed for unmoved sidecar repos in both scans, but the vendor pages that bear the CVEs all worked and the meet source itself succeeded.
2.38.4 → 2.39.2 — a fresh PR (the prior run's upgrade landed upstream as 3.5.0+2.38.4 and its mirror PR #7 was closed as merged). Six 2.39.x TypeORM migrations ran cleanly; the 2.39.0 encryption-key module rework and 2.39.1 legacy-key repair were exercised with the recipe's injected N8N_ENCRYPTION_KEY secret — clean. API deprecations and env renames are informational. CVE-2026-73088 (browserslist) remains unfixed on 2.x — the fix lives only on the 1.123.x maintenance line.
7.0.4 → 7.1.0 — the PR was rebased onto upstream #77's admin_password secret (which landed after its prior green run) plus the enable_auto_updates fix. This run's green validates that previously-untested combination: the earlier green (build 1301, 2026-08-21) predated #77. The deploy exercise also confirmed admin_password is consumed by `abra.sh core_install`, not the install wizard.
0.4.5027 → 0.4.5034 (@atproto/pds 0.5.27 → 0.5.34, node 24.18 → 24.19-alpine3.23): outbound calls moved to safeFetch, decoded proxy responses bounded at proxy.maxResponseSize, a HandleNotFound fix for resolveHandle, x-atproto-* header forwarding, and an OTEL bootstrap rework — all patch-level. No config, no migrations, no digest pins. Live checks: /xrpc/_health reports 0.4.5034, a marker account round-tripped via goat. Release with `abra recipe release
bluesky-pds -z` after merge.
Carry-over from the 09-04 run: static-web-server 2.43.0 → 2.44.0. Up-to-date this week (the open PR already carries the current bump); awaiting upstream merge, green at build 1159.
Not an upgrade — backupbot v2 backup labels for the admin sqlite (/data) and imap mail (/mail) volumes. Green at build 483 and open a long while; the recipe itself is up-to-date this week, so nothing else to review here.
clickhouse 23.4 LTS patch (23.4.6.25-alpine) on the external recipe's mirror — green at build 1286 and unreviewed for four weeks. Plausible is maintained elsewhere per used-recipes.md; the mirror PR needs a merge-or-close decision so the mirror and the classification stop disagreeing.