Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of September 18, 2026report.ci.commoninternet.net2026-09-21 16:24 UTC

A productive run despite a mid-run stall: of 20 recipes considered, 13 upgrade PRs are !testme GREEN and merge-ready, and not a single recipe failed — the only RED (lasuite-docs) is an external CI-base breakage, not the recipe. Address the security content first: discourse leads with 8 CVEs (2 high) on a chat/forum platform, keycloak ships 6 identity-provider fixes, and the nginx 1.31.6 HTTP/3 heap-overflow patch (CVE-2026-90439) rolls across custom-html, lasuite-docs, lasuite-drive, lasuite-meet and matrix-synapse.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
discourse2026.7.1 → 2026.7.2GREEN8build 1363 ✓#9…Security intermediate on the 2026.7 ESR line: 8 CVEs (2 high, 6 medium — hidden post-revision exposure, iframe allowlist/userinfo bypasses, stored XSS). One low (CVE-2025-53016) remains STILL-UNKNOWN — a floor, not a clean bill. db/redis unchanged.
keycloak26.7.3 → 26.7.4GREEN6build 1366 ✓#9…Identity provider — 6 security fixes incl. CVE-2026-90997 (high; MariaDB row-count replay gates, relevant here), unauthenticated DoS, SAML redirect leak. Breaking: Authorization Services URI-matching normalization. MariaDB held at 12.3 (13.0 major declined).
mattermost-lts10.11.22 → 11.7.11GREEN14build 1373 ✓#2…The critical ESR move: 10.11 ESR EXPIRED 2026-08-15; 14 CVEs across the jump (13 medium/low + 1 adjudicated) plus 6 more MMSA advisories in 11.7.11 itself (CVE ids pending disclosure). Migration + seeded-user survival verified live; postgres held at 15-alpine. Reconcile with fix PR #1.
matrix-synapsev1.157.1 → v1.161.0GREEN16build 1371 ✓#5…16 advisories: 12 synapse v1.157.2 GHSAs (6 high — federation servers urged), 3 dep-refresh GHSAs, MAS h2 RUSTSEC-2026-0258, nginx CVE-2026-90439. MAS 1.21→1.24, both mautrix bridges to v0.2609.0. Bridge DBs held at pg13 (EOL — future attended bump advisable).
custom-html1.31.5 → 1.31.6GREEN1build 1361 ✓#8…nginx CVE-2026-90439 (HTTP/3 heap overflow, Medium 6.5 — not exploitable in this recipe's plain-HTTP/1.1 shape, but the fix ships). Post-run: upstream published 1.14.1+1.31.6 and the mirror PR was closed as merged-upstream on Sep 20 — already landed; no action left.
lasuite-docsv5.6.1 → v5.7.0FAILED1RED 1368 · install (dead CI base)#9…impress v5.7.0 quartet + nginx 1.31.6 (CVE-2026-90439) + docspec switch to ghcr.io/docspec/api:1.21.4 (port 4000→3000). RED is EXTERNAL: every CI base pins docker.io minio/minio, which Docker Hub removed — unpullable before any test runs. Live 2b verification was green (9/9 services). Operator unblock paths in PR comment 15950.
lasuite-drivev0.21.0 → v0.22.0GREEN1build 1370 ✓ (attempt 2)#7…Drive quartet v0.22.0 + nginx 1.31.6 (CVE-2026-90439) + mailcatcher v0.11.0 + MinIO repinned to quay.io (Docker Hub removed the repo). Attempt 1 RED on the same dead base — fixed gate-neutrally by warming the host cache. collabora 26.04 line deferred (service redesign).
lasuite-meetv1.30.0 → v1.31.0GREEN1build 1372 ✓#10…meet v1.31.0 (1080p option, Traefik media-auth header) + livekit v1.13.7 + nginx 1.31.6 (CVE-2026-90439). No breaking changes; migrations auto-run. Ready to merge.
hedgedocpg 16-alpine → 18-alpineGREENnonebuild 1365 ✓#3…App 1.12.0 already latest; the change is the deferred db jump to pgautoupgrade 18-alpine WITH the required volume-mount move to /var/lib/postgresql (PG18 layout — tag-only cherry-picks hit an empty-instance gotcha). 16→18 in one deploy verified live, data byte-identical.
immichv3.2.0 → v3.2.2GREENnonebuild 1367 ✓#5…Server + ML lockstep patch bump (bug-fix-only); pg-vectorchord + valkey pins re-verified byte-identical to immich's official v3.2.2 compose. abra's tag+digest FATA worked around via upstream-direct check. Advisory scan had 3 failed sources (GitHub rate-limit) — release-note read completes the union at 0.
ghost6.60.0-alpine → 6.64.0-alpineGREENnonebuild 1364 ✓#7…Four minor releases, no breaking changes/migrations; rolling upgrade exercised the full 6.61–6.64 migration chain live with data intact. MySQL held at 8.4 (Ghost supports only MySQL 8). Clean scan.
n8n2.38.4 → 2.40.2GREENnonebuild 1374 ✓#8…Two feature minors; 15 TypeORM migrations verified live. 2.40.0 enables the workflow publication service by default (API callers: activate/deactivate deprecated in favour of publish/unpublish). 2.40.3 published mid-run — deliberately held to the snapshot target, flagged in the PR.
wordpress7.0.4 → 7.1.0GREENnonebuild 1375 ✓#1…7.1 "Mary Lou": post editor is ALWAYS iframed (plugin/theme compat is a site-owner concern), jQuery UI → 1.14.2, client-side media pipeline. Branch re-parented on upstream main tip, fixing a spurious version-label downgrade in the diff. Mariadb held at 12.3. Scan rate-limited on github-advisories — union 0 from readable sources.
bluesky-pds0.4.5027 → 0.4.5034GREENnonebuild 1362 ✓#5…All-patch window (safeFetch hardening, proxy response-size bound, blob-upload back-pressure); no operator action. Clean scan. Unrelated PR #4 (routing alias) still pending.
gitea—SKIPPEDnone#4…Up-to-date: app 1.27.3-rootless latest; postgres 15.19 is the newest 15.x (majors 16/17/18 not in-place-safe, pg15 pinned deliberately + supported to Nov 2027). Unrelated app.ini fix PR #4 still open.
cryptpad—UPTODATEnoneUp-to-date — version-2026.5.1 is the newest version-* tag.
custom-html-tiny—UPTODATEnonebuild 1159 ✓#9…Up-to-date — existing PR #9 already carries the current bump, awaiting upstream merge.
drone—UPTODATEnoneUp-to-date.
mailu—UPTODATEnonebuild 483 ✓#3…Up-to-date (unrelated backupbot-labels PR #3 still open, green).
mumble—UPTODATEnoneUp-to-date.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

discourse 2026.7.2 — eight CVEs on the forum platform (2 high) · discourse
discourse 2026.7.1 → 2026.7.2 (ESR security intermediate, released 2026-08-25) carries 8 security-fix groups, now matched to CVE ids by GitHub advisories: 2 high — CVE-2026-91122 (GHSA-8m44-f6g9-7cg7) and CVE-2026-91123 (GHSA-6pwj-wgg8-4rjc) — and 6 medium (CVE-2026-91119/91120/91121/91132/91133/91134). The vendor's changelog groups them as hidden post-revision exposure, iframe allowlist and userinfo bypasses, embed-URL escaping, chat-history scoping, and stored XSS in the video placeholder. All 8 have 2026.7.2 in their patched ranges. One low advisory (CVE-2025-53016, HTML injection in solved posts) could NOT be judged — treat the count as a floor. Rails migrations run automatically; no config action. !testme GREEN at build 1363 (fourth consecutive green at this head).
keycloak 26.7.4 — six CVEs on the identity provider (1 high) · keycloak
keycloak 26.7.3 → 26.7.4 is a security patch carrying six fixes: CVE-2026-90997 (high, GHSA-xpwp-2pcm-8xq3 — MySQL/MariaDB row-count stateless replay gates; directly relevant, this recipe runs mariadb), CVE-2026-79651 (unauthenticated DoS via unbounded locale caching, GHSA-8qv5-pjhw-3gx4), CVE-2026-74909 (percent-encoded-semicolon PathMatcher bypass, incomplete-fix follow-up, GHSA-5639-qg9x-rw29), CVE-2026-19607 (username takeover → lockout, GHSA-h87q-rx56-87wm), CVE-2026-17526 (impersonation role can impersonate realm admin, GHSA-j7cq-x5cp-qpcx), and CVE-2026-18212 (SAML Redirect DEFLATE zlib state leak, GHSA-wgrv-cjmx-4vfw). One breaking change: Authorization Services resource-URI matching now normalizes matrix parameters, dot segments and encoded slashes — review resource/policy config if you distinguish resources by those URI forms. MariaDB deliberately held at 12.3. !testme GREEN at build 1366, first attempt.
mattermost 10.11 → 11.7.11 ESR move — 14+ CVEs and an expired ESR line · mattermost-lts
The 10.11 ESR ended 2026-08-15, so upstream main's 10.11.22 pin is unsupported; PR #2 completes the move to the 11.7 ESR (supported to 2027-05-15), now at 11.7.11 (2026-09-15 security patch). The deterministic scan counts 14 CVEs closed across 10.11.22 → 11.7.11 (13 medium/low by NVD ranges + CVE-2026-13426 adjudicated as fixed via git ancestry) — and 11.7.11 itself adds 6 more MMSA advisories (1 low, 5 medium) whose CVE ids are withheld until 2026-10-15 responsible-disclosure, so 14 is a floor. The 10.11 → 11.7 schema migration was exercised live with a seeded admin user surviving intact. Take a backup before deploying; postgres held at 15-alpine. !testme GREEN at build 1373 (all five tiers).
matrix-synapse v1.161.0 — 16 advisories incl. six high-severity federation fixes · matrix-synapse
The v1.157.1 → v1.161.0 window absorbs synapse v1.157.2, a security patch fixing 12 GHSAs — six high (ELEMENTSEC-2026-1071/-1520/-1717/-1721/-1729/-1740; federation and open-federation servers were explicitly urged to upgrade) plus three moderate and three low — of which the scan maps 9 to CVE/GHSA ids and credits the window with 16 advisories total: the 12 synapse GHSAs, 3 dependency-refresh GHSAs in v1.160.0 (rustls-webpki, pyo3 ×2), MAS 1.24.0's h2 fix (RUSTSEC-2026-0258), and nginx 1.31.6's CVE-2026-90439. MAS moves 1.21.0 → 1.24.0 and both mautrix bridges to v0.2609.0. Note: the bridge databases stay at postgres:13-alpine (EOL) — an attended dump/restore bump is advisable for bridge users and is deliberately NOT bundled here. No config action for the recipe's default deployment. !testme GREEN at build 1371.
nginx 1.31.6 — CVE-2026-90439 HTTP/3 heap buffer overflow (Medium 6.5) · custom-html, lasuite-docs, lasuite-drive, lasuite-meet, matrix-synapse
nginx 1.31.6 (15 Sep 2026) fixes CVE-2026-90439: a heap memory buffer overflow in a worker process when using HTTP/3 with OpenSSL ≤ 3.5.0 during the TLS handshake (CVSS v3.1 6.5; 1.29.2–1.31.5 vulnerable, fixed in 1.31.6/1.30.5). Five recipes ship the fix this week: custom-html PR #8 (already merged upstream as 1.14.1+1.31.6 on Sep 20 — landed), lasuite-docs PR #9, lasuite-drive PR #7, lasuite-meet PR #10 and matrix-synapse PR #5. Exposure note: all five serve as plain reverse proxies without an HTTP/3/QUIC listener, so the vulnerable configuration isn't in use — but these are internet-facing edges and the bump is still worth prioritising. lasuite-docs is the only one not yet CI-green (dead CI base, see Addendum), despite the upgrade itself having been live-verified green.

What changed

2026.7.1 → 2026.7.2, a security-only intermediate on the 2026.7 ESR line: 8 CVEs (2 high, 6 medium) and one optional feature (livestream_allowed_hosts). Rails db:migrate runs on boot; pg18 and redis 8.10-alpine unchanged. One low advisory (CVE-2025-53016) remains unjudged — floor, not a clean bill. PR #9 extended (head unchanged since Aug 28; four greens at this head).
26.7.3 → 26.7.4. Six security fixes (see Bulletin) plus Quarkus 3.33.3.2 and a perf fix for a 26.6.2 regression. Breaking: Authorization Services URI-matching normalization (matrix params, dot segments, encoded slashes) — review resource/policy config if you rely on those forms. MariaDB held at 12.3 (13.0 major declined, per policy). Schema auto-updates on start; no recipe config changes.
10.11.22 → 11.7.11: the required ESR-line move (10.11 expired 2026-08-15; 11.7 supported to 2027-05-15), now topped with the 2026-09-15 security patch. DB schema migrations run automatically on boot — the 10→11 move was exercised live with a seeded admin user surviving. Postgres held at 15-alpine (majors are a separate operator-guided step). The PR also ships pg_backup.sh backupbot hooks; take a backup before upgrading. Reconcile with fix PR #1.
synapse v1.157.1 → v1.161.0 (absorbing the v1.157.2 security patch), MAS 1.21.0 → 1.24.0, mautrix-telegram and mautrix-signal both to v0.2609.0, nginx 1.31.3 → 1.31.6. One deprecation: v1.161.0 deprecates matrix_rtc.livekit_service_url (LiveKit MatrixRTC users add the sibling url; the recipe doesn't ship this config). Bridge DBs deliberately held at postgres:13-alpine (EOL; attended bump advisable but not bundled). PR #5 extended and rebased on the upstream main tip, preserving MAINTNANCE.md/renovate.json.
nginx 1.31.5 → 1.31.6 (CVE-2026-90439; Medium 6.5, not exploitable in this recipe's plain-HTTP/1.1 shape but the fix ships) — a one-line compose bump. alpine/git v2.54.0 and the floating openssh-server tag unchanged. The upgrade is already in production: upstream published 1.14.1+1.31.6 and the mirror PR was closed as merged-upstream on Sep 20, after this run. No action left on PR #8.
impress quartet v5.6.1 → v5.7.0 (fine-tuned redis cache options, full last-update date, email-confirmation page redesign; favorites API endpoint moved to /documents/favorites/ — breaking for external API consumers only), nginx 1.31.6, and the docspec sidecar switched from the archived Elixir ghcr.io/docspecio/api:3.0.2 to the Rust rewrite ghcr.io/docspec/api:1.21.4 with its port moving 4000 → 3000 (DOCSPEC_API_URL + healthcheck updated in the same change). The quay.io minio pin (upstream #25) was deploy-verified for the first time. The upgrade itself is verified: 9/9 services live, docspec healthy on :3000, migrations applied. CI-red only because every base pins the removed docker.io minio.
Drive quartet v0.21.0 → v0.22.0 (restricted folder access behind a feature flag, swappable permission-decision backend, malware re-analysis fixes; new migration core.0030_item_add_restriction_target), nginx 1.31.6, mailcatcher v0.11.0, and both minio services repinned to quay.io/minio (same release) after Docker Hub removed the repo. collabora held at 25.04 (26.04's shell-less entrypoint is a service redesign, deferred). !testme green on attempt 2 after a gate-neutral host-cache warm; migrations verified over a v0.21.0-initialized DB.
meet v1.30.0 → v1.31.0 (1080p sending option, Traefik media-auth header support, external-API room attributes), livekit v1.13.6 → v1.13.7 (VP9/AV1 simulcast, SDP hardening), nginx 1.31.6. No breaking changes; migrations no-op. Ready to merge; recommended release -y (0.7.0+v1.31.0).
db pgautoupgrade 16-alpine → 18-alpine together with the REQUIRED volume-mount move from /var/lib/postgresql/data to /var/lib/postgresql (PG18 data-dir layout; mounting at the old path errors or silently yields an empty instance — the tag bump and mount change must travel together). App 1.12.0 confirmed latest (full quay tag list). Live-verified: 16.15 → 18.6 multi-major pg_upgrade chain in one deploy, test pad byte-identical after. Recommended release -z. Note the cc-ci suite exercises the sqlite backend; the pg override was verified in the live step.
immich-server + immich-machine-learning v3.2.0 → v3.2.2 in lockstep (bug-fix-only: connection-pool exhaustion during sync, person merge, reassign-faces; server now auto-VACUUMs after TypeORM migrations). Postgres-vectorchord and valkey digest pins re-verified byte-identical to immich's official v3.2.2 compose — no sidecar change. abra's tag+digest FATA worked around by checking each image directly upstream. First PR since the tag+digest parsing skip earlier this summer — immich is back in the weekly rotation.
6.60.0-alpine → 6.64.0-alpine across four minors (Source v1.7.5, newsletter-subscription and audit-log fixes, malformed-CSS email-render crash fix) — no breaking changes, no required migrations. The rolling upgrade exercised the full 6.61–6.64 automatic migration chain live with seed data intact. MySQL held at 8.4 LTS (Ghost supports MySQL 8 only; 9.x/26.x declined). Ready to merge.
2.38.4 → 2.40.2 across two feature minors (~150 bugfixes, Dataverse node, AI agent tool calls, Git-based promotion model). 15 TypeORM migrations verified live over real data; encryption-key module rework exercised clean. Watch items: 2.40.0 enables the workflow publication service by default (API callers — publish/unpublish replaces activate/deactivate), and N8N_DB_PING_TIMEOUT is deprecated warn-only (recipe doesn't set it). 2.40.3 published mid-run, deliberately not taken; trivial catch-up next week. Recommended release -y.
7.0.4 → 7.1.0 "Mary Lou": responsive styling controls, always-iframed post editor (plugin/theme compatibility is a site-owner concern the recipe can't gate), jQuery UI 1.14.2, client-side media pipeline (WASM libvips). WP auto-migrates its schema on first admin visit. Mariadb held at 12.3; sftp overlay untouched. PR #1 re-parented on the upstream main tip, clearing the spurious version-label downgrade its diff used to show. Recommended release -y.
0.4.5027 → 0.4.5034: an all-patch window (outbound calls via safeFetch, bounded proxy response size, blob-upload back-pressure, OTEL improvements). No breaking changes, no migrations, no env changes. Recommended release -z. Clean scan; PR #4 (harness routing alias) remains open separately.
Skipped — nothing safe to bump. App 1.27.3-rootless is latest; postgres 15.19 is the newest 15.x (16/17/18 are majors that would crash-loop existing PGDATA, and pg15 is pinned deliberately upstream and supported to Nov 2027); mariadb 10.11.19 also latest. A pg major bump, if ever wanted, should be coordinated with upstream and shipped with a documented pg_dumpall path — an operator-authored change, not a weekly bump. Unrelated app.ini fix PR #4 remains open.
No new upgrade — the existing PR #9 already carries the current bump (static-web-server 2.44.0) and awaits upstream merge; CI green at build 1159.
Up-to-date this week. The unrelated backupbot-v2 backup-labels PR #3 (admin sqlite + imap mail) remains open and green at build 483 — a data-safety fix worth reviewing.
Up-to-date — version-2026.5.1 remains the newest version-* tag (the opendesk-* tags are a different variant line).
Up-to-date; mirror main advanced during the fleet-wide reconcile. No PR, no changes this week.
Up-to-date. No changes this week.