Co-op Cloud Recipe CI · Weekly Edition
The Recipe Report
Week of September 18, 2026report.ci.commoninternet.net2026-09-21 16:24 UTC
A productive run despite a mid-run stall: of 20 recipes considered, 13 upgrade PRs are !testme GREEN and merge-ready, and not a single recipe failed — the only RED (lasuite-docs) is an external CI-base breakage, not the recipe. Address the security content first: discourse leads with 8 CVEs (2 high) on a chat/forum platform, keycloak ships 6 identity-provider fixes, and the nginx 1.31.6 HTTP/3 heap-overflow patch (CVE-2026-90439) rolls across custom-html, lasuite-docs, lasuite-drive, lasuite-meet and matrix-synapse.
The full wire — every recipe, in priority order
| Recipe | Change | TESTS | CVEs | CI | PR | STATUS | Notes |
|---|
| discourse | 2026.7.1 → 2026.7.2 | GREEN | 8 | build 1363 ✓ | #9 | … | Security intermediate on the 2026.7 ESR line: 8 CVEs (2 high, 6 medium — hidden post-revision exposure, iframe allowlist/userinfo bypasses, stored XSS). One low (CVE-2025-53016) remains STILL-UNKNOWN — a floor, not a clean bill. db/redis unchanged. |
| keycloak | 26.7.3 → 26.7.4 | GREEN | 6 | build 1366 ✓ | #9 | … | Identity provider — 6 security fixes incl. CVE-2026-90997 (high; MariaDB row-count replay gates, relevant here), unauthenticated DoS, SAML redirect leak. Breaking: Authorization Services URI-matching normalization. MariaDB held at 12.3 (13.0 major declined). |
| mattermost-lts | 10.11.22 → 11.7.11 | GREEN | 14 | build 1373 ✓ | #2 | … | The critical ESR move: 10.11 ESR EXPIRED 2026-08-15; 14 CVEs across the jump (13 medium/low + 1 adjudicated) plus 6 more MMSA advisories in 11.7.11 itself (CVE ids pending disclosure). Migration + seeded-user survival verified live; postgres held at 15-alpine. Reconcile with fix PR #1. |
| matrix-synapse | v1.157.1 → v1.161.0 | GREEN | 16 | build 1371 ✓ | #5 | … | 16 advisories: 12 synapse v1.157.2 GHSAs (6 high — federation servers urged), 3 dep-refresh GHSAs, MAS h2 RUSTSEC-2026-0258, nginx CVE-2026-90439. MAS 1.21→1.24, both mautrix bridges to v0.2609.0. Bridge DBs held at pg13 (EOL — future attended bump advisable). |
| custom-html | 1.31.5 → 1.31.6 | GREEN | 1 | build 1361 ✓ | #8 | … | nginx CVE-2026-90439 (HTTP/3 heap overflow, Medium 6.5 — not exploitable in this recipe's plain-HTTP/1.1 shape, but the fix ships). Post-run: upstream published 1.14.1+1.31.6 and the mirror PR was closed as merged-upstream on Sep 20 — already landed; no action left. |
| lasuite-docs | v5.6.1 → v5.7.0 | FAILED | 1 | RED 1368 · install (dead CI base) | #9 | … | impress v5.7.0 quartet + nginx 1.31.6 (CVE-2026-90439) + docspec switch to ghcr.io/docspec/api:1.21.4 (port 4000→3000). RED is EXTERNAL: every CI base pins docker.io minio/minio, which Docker Hub removed — unpullable before any test runs. Live 2b verification was green (9/9 services). Operator unblock paths in PR comment 15950. |
| lasuite-drive | v0.21.0 → v0.22.0 | GREEN | 1 | build 1370 ✓ (attempt 2) | #7 | … | Drive quartet v0.22.0 + nginx 1.31.6 (CVE-2026-90439) + mailcatcher v0.11.0 + MinIO repinned to quay.io (Docker Hub removed the repo). Attempt 1 RED on the same dead base — fixed gate-neutrally by warming the host cache. collabora 26.04 line deferred (service redesign). |
| lasuite-meet | v1.30.0 → v1.31.0 | GREEN | 1 | build 1372 ✓ | #10 | … | meet v1.31.0 (1080p option, Traefik media-auth header) + livekit v1.13.7 + nginx 1.31.6 (CVE-2026-90439). No breaking changes; migrations auto-run. Ready to merge. |
| hedgedoc | pg 16-alpine → 18-alpine | GREEN | none | build 1365 ✓ | #3 | … | App 1.12.0 already latest; the change is the deferred db jump to pgautoupgrade 18-alpine WITH the required volume-mount move to /var/lib/postgresql (PG18 layout — tag-only cherry-picks hit an empty-instance gotcha). 16→18 in one deploy verified live, data byte-identical. |
| immich | v3.2.0 → v3.2.2 | GREEN | none | build 1367 ✓ | #5 | … | Server + ML lockstep patch bump (bug-fix-only); pg-vectorchord + valkey pins re-verified byte-identical to immich's official v3.2.2 compose. abra's tag+digest FATA worked around via upstream-direct check. Advisory scan had 3 failed sources (GitHub rate-limit) — release-note read completes the union at 0. |
| ghost | 6.60.0-alpine → 6.64.0-alpine | GREEN | none | build 1364 ✓ | #7 | … | Four minor releases, no breaking changes/migrations; rolling upgrade exercised the full 6.61–6.64 migration chain live with data intact. MySQL held at 8.4 (Ghost supports only MySQL 8). Clean scan. |
| n8n | 2.38.4 → 2.40.2 | GREEN | none | build 1374 ✓ | #8 | … | Two feature minors; 15 TypeORM migrations verified live. 2.40.0 enables the workflow publication service by default (API callers: activate/deactivate deprecated in favour of publish/unpublish). 2.40.3 published mid-run — deliberately held to the snapshot target, flagged in the PR. |
| wordpress | 7.0.4 → 7.1.0 | GREEN | none | build 1375 ✓ | #1 | … | 7.1 "Mary Lou": post editor is ALWAYS iframed (plugin/theme compat is a site-owner concern), jQuery UI → 1.14.2, client-side media pipeline. Branch re-parented on upstream main tip, fixing a spurious version-label downgrade in the diff. Mariadb held at 12.3. Scan rate-limited on github-advisories — union 0 from readable sources. |
| bluesky-pds | 0.4.5027 → 0.4.5034 | GREEN | none | build 1362 ✓ | #5 | … | All-patch window (safeFetch hardening, proxy response-size bound, blob-upload back-pressure); no operator action. Clean scan. Unrelated PR #4 (routing alias) still pending. |
| gitea | — | SKIPPED | none | | #4 | … | Up-to-date: app 1.27.3-rootless latest; postgres 15.19 is the newest 15.x (majors 16/17/18 not in-place-safe, pg15 pinned deliberately + supported to Nov 2027). Unrelated app.ini fix PR #4 still open. |
| cryptpad | — | UPTODATE | none | | | | Up-to-date — version-2026.5.1 is the newest version-* tag. |
| custom-html-tiny | — | UPTODATE | none | build 1159 ✓ | #9 | … | Up-to-date — existing PR #9 already carries the current bump, awaiting upstream merge. |
| drone | — | UPTODATE | none | | | | Up-to-date. |
| mailu | — | UPTODATE | none | build 483 ✓ | #3 | … | Up-to-date (unrelated backupbot-labels PR #3 still open, green). |
| mumble | — | UPTODATE | none | | | | Up-to-date. |
Addendum
- Docker Hub removed the minio/minio repository, and it bit twice this run: lasuite-docs PR #9 is RED at build 1368 because EVERY CI base candidate (canonical 0.4.0 + fallback 0.4.1) pins docker.io minio and is unpullable before any test runs — deterministically, not flaky; only a release newer than 0.4.2 (quay-pinned) can serve as a live base. lasuite-drive hit the identical wall in its first !testme (fixed gate-neutrally by warming the host image cache). Operator unblock paths for lasuite-docs are in PR comment 15950; watch other minio-pinning recipes next week.
- lasuite-docs and lasuite-drive each carry the fix but with opposite fates — a useful control group: lasuite-drive's PR #7 repins minio to quay.io (mergeable, green), while lasuite-docs' PR #9 also switched to quay but cannot be CI-verified until the base problem is fixed. The weekly sweep is equally stuck on lasuite-docs (run_on_tag(0.4.2) would base on the dead canonical).
- The run stalled once on a usage limit after lasuite-drive (10/15 done). The resume contract held — 0 leaked dev-* stacks, 0 duplicated PRs, all 5 resumed recipes extended their existing PRs — but the stall is worth watching as pool size grows.
- Shared-/tmp hazard caught in the act: ghost's PR body was briefly contaminated by a concurrent agent's leftover /tmp/opencode/pr-body.txt (mattermost's body), corrected via the API within minutes. All subsequent subagents switched to unique tmp prefixes; baking the unique-prefix rule into the upgrade skill would prevent a recurrence.
- lasuite-drive's abra 401 ("fetching tags list") on lasuite/drive-* images remains an unexplained abra-side auth quirk — tags are fine on the Hub API; the bump was done by hand. Worth an upstream abra look.
- mattermost-lts holds two open PRs to reconcile: the upgrade #2 (11.7.11 ESR, green) and the older backup-restore fix #1 — decide which lands (the restore fix may already be folded into #2's pg_backup rework). Unrelated strays elsewhere: bluesky-pds #4 (routing alias) and gitea #4 (app.ini fix) are non-upgrade PRs pending operator review.
- Two versions-behind flags for next week: n8n published 2.40.3 the day of the run (PR deliberately held at the operator's 2.40.2 snapshot — trivial catch-up), and collabora 26.04 for lasuite-drive remains a deliberate deferral (shell-less entrypoint = service redesign, operator decision).
Security Bulletin
🔒 Critical CVE upgrades
discourse 2026.7.1 → 2026.7.2 (ESR security intermediate, released 2026-08-25) carries 8 security-fix groups, now matched to CVE ids by GitHub advisories: 2 high — CVE-2026-91122 (GHSA-8m44-f6g9-7cg7) and CVE-2026-91123 (GHSA-6pwj-wgg8-4rjc) — and 6 medium (CVE-2026-91119/91120/91121/91132/91133/91134). The vendor's changelog groups them as hidden post-revision exposure, iframe allowlist and userinfo bypasses, embed-URL escaping, chat-history scoping, and stored XSS in the video placeholder. All 8 have 2026.7.2 in their patched ranges. One low advisory (CVE-2025-53016, HTML injection in solved posts) could NOT be judged — treat the count as a floor. Rails migrations run automatically; no config action. !testme GREEN at build 1363 (fourth consecutive green at this head).
keycloak 26.7.3 → 26.7.4 is a security patch carrying six fixes: CVE-2026-90997 (high, GHSA-xpwp-2pcm-8xq3 — MySQL/MariaDB row-count stateless replay gates; directly relevant, this recipe runs mariadb), CVE-2026-79651 (unauthenticated DoS via unbounded locale caching, GHSA-8qv5-pjhw-3gx4), CVE-2026-74909 (percent-encoded-semicolon PathMatcher bypass, incomplete-fix follow-up, GHSA-5639-qg9x-rw29), CVE-2026-19607 (username takeover → lockout, GHSA-h87q-rx56-87wm), CVE-2026-17526 (impersonation role can impersonate realm admin, GHSA-j7cq-x5cp-qpcx), and CVE-2026-18212 (SAML Redirect DEFLATE zlib state leak, GHSA-wgrv-cjmx-4vfw). One breaking change: Authorization Services resource-URI matching now normalizes matrix parameters, dot segments and encoded slashes — review resource/policy config if you distinguish resources by those URI forms. MariaDB deliberately held at 12.3. !testme GREEN at build 1366, first attempt.
mattermost 10.11 → 11.7.11 ESR move — 14+ CVEs and an expired ESR line ·
mattermost-ltsThe 10.11 ESR ended 2026-08-15, so upstream main's 10.11.22 pin is unsupported; PR #2 completes the move to the 11.7 ESR (supported to 2027-05-15), now at 11.7.11 (2026-09-15 security patch). The deterministic scan counts 14 CVEs closed across 10.11.22 → 11.7.11 (13 medium/low by NVD ranges + CVE-2026-13426 adjudicated as fixed via git ancestry) — and 11.7.11 itself adds 6 more MMSA advisories (1 low, 5 medium) whose CVE ids are withheld until 2026-10-15 responsible-disclosure, so 14 is a floor. The 10.11 → 11.7 schema migration was exercised live with a seeded admin user surviving intact. Take a backup before deploying; postgres held at 15-alpine. !testme GREEN at build 1373 (all five tiers).
The v1.157.1 → v1.161.0 window absorbs synapse v1.157.2, a security patch fixing 12 GHSAs — six high (ELEMENTSEC-2026-1071/-1520/-1717/-1721/-1729/-1740; federation and open-federation servers were explicitly urged to upgrade) plus three moderate and three low — of which the scan maps 9 to CVE/GHSA ids and credits the window with 16 advisories total: the 12 synapse GHSAs, 3 dependency-refresh GHSAs in v1.160.0 (rustls-webpki, pyo3 ×2), MAS 1.24.0's h2 fix (RUSTSEC-2026-0258), and nginx 1.31.6's CVE-2026-90439. MAS moves 1.21.0 → 1.24.0 and both mautrix bridges to v0.2609.0. Note: the bridge databases stay at postgres:13-alpine (EOL) — an attended dump/restore bump is advisable for bridge users and is deliberately NOT bundled here. No config action for the recipe's default deployment. !testme GREEN at build 1371.
nginx 1.31.6 (15 Sep 2026) fixes CVE-2026-90439: a heap memory buffer overflow in a worker process when using HTTP/3 with OpenSSL ≤ 3.5.0 during the TLS handshake (CVSS v3.1 6.5; 1.29.2–1.31.5 vulnerable, fixed in 1.31.6/1.30.5). Five recipes ship the fix this week:
custom-html PR #8 (already merged upstream as 1.14.1+1.31.6 on Sep 20 — landed),
lasuite-docs PR #9,
lasuite-drive PR #7,
lasuite-meet PR #10 and
matrix-synapse PR #5. Exposure note: all five serve as plain reverse proxies without an HTTP/3/QUIC listener, so the vulnerable configuration isn't in use — but these are internet-facing edges and the bump is still worth prioritising.
lasuite-docs is the only one not yet CI-green (dead CI base, see Addendum), despite the upgrade itself having been live-verified green.
What changed
2026.7.1 → 2026.7.2, a security-only intermediate on the 2026.7 ESR line: 8 CVEs (2 high, 6 medium) and one optional feature (livestream_allowed_hosts). Rails db:migrate runs on boot; pg18 and redis 8.10-alpine unchanged. One low advisory (CVE-2025-53016) remains unjudged — floor, not a clean bill. PR #9 extended (head unchanged since Aug 28; four greens at this head).
26.7.3 → 26.7.4. Six security fixes (see Bulletin) plus Quarkus 3.33.3.2 and a perf fix for a 26.6.2 regression. Breaking: Authorization Services URI-matching normalization (matrix params, dot segments, encoded slashes) — review resource/policy config if you rely on those forms. MariaDB held at 12.3 (13.0 major declined, per policy). Schema auto-updates on start; no recipe config changes.
10.11.22 → 11.7.11: the required ESR-line move (10.11 expired 2026-08-15; 11.7 supported to 2027-05-15), now topped with the 2026-09-15 security patch. DB schema migrations run automatically on boot — the 10→11 move was exercised live with a seeded admin user surviving. Postgres held at 15-alpine (majors are a separate operator-guided step). The PR also ships pg_backup.sh backupbot hooks; take a backup before upgrading. Reconcile with fix PR #1.
synapse v1.157.1 → v1.161.0 (absorbing the v1.157.2 security patch), MAS 1.21.0 → 1.24.0, mautrix-telegram and mautrix-signal both to v0.2609.0, nginx 1.31.3 → 1.31.6. One deprecation: v1.161.0 deprecates matrix_rtc.livekit_service_url (LiveKit MatrixRTC users add the sibling url; the recipe doesn't ship this config). Bridge DBs deliberately held at postgres:13-alpine (EOL; attended bump advisable but not bundled). PR #5 extended and rebased on the upstream main tip, preserving MAINTNANCE.md/renovate.json.
nginx 1.31.5 → 1.31.6 (CVE-2026-90439; Medium 6.5, not exploitable in this recipe's plain-HTTP/1.1 shape but the fix ships) — a one-line compose bump. alpine/git v2.54.0 and the floating openssh-server tag unchanged. The upgrade is already in production: upstream published 1.14.1+1.31.6 and the mirror PR was closed as merged-upstream on Sep 20, after this run. No action left on PR #8.
impress quartet v5.6.1 → v5.7.0 (fine-tuned redis cache options, full last-update date, email-confirmation page redesign; favorites API endpoint moved to /documents/favorites/ — breaking for external API consumers only), nginx 1.31.6, and the docspec sidecar switched from the archived Elixir ghcr.io/docspecio/api:3.0.2 to the Rust rewrite ghcr.io/docspec/api:1.21.4 with its port moving 4000 → 3000 (DOCSPEC_API_URL + healthcheck updated in the same change). The quay.io minio pin (upstream #25) was deploy-verified for the first time. The upgrade itself is verified: 9/9 services live, docspec healthy on :3000, migrations applied. CI-red only because every base pins the removed docker.io minio.
Drive quartet v0.21.0 → v0.22.0 (restricted folder access behind a feature flag, swappable permission-decision backend, malware re-analysis fixes; new migration core.0030_item_add_restriction_target), nginx 1.31.6, mailcatcher v0.11.0, and both minio services repinned to quay.io/minio (same release) after Docker Hub removed the repo. collabora held at 25.04 (26.04's shell-less entrypoint is a service redesign, deferred). !testme green on attempt 2 after a gate-neutral host-cache warm; migrations verified over a v0.21.0-initialized DB.
meet v1.30.0 → v1.31.0 (1080p sending option, Traefik media-auth header support, external-API room attributes), livekit v1.13.6 → v1.13.7 (VP9/AV1 simulcast, SDP hardening), nginx 1.31.6. No breaking changes; migrations no-op. Ready to merge; recommended release -y (0.7.0+v1.31.0).
db pgautoupgrade 16-alpine → 18-alpine together with the REQUIRED volume-mount move from /var/lib/postgresql/data to /var/lib/postgresql (PG18 data-dir layout; mounting at the old path errors or silently yields an empty instance — the tag bump and mount change must travel together). App 1.12.0 confirmed latest (full quay tag list). Live-verified: 16.15 → 18.6 multi-major pg_upgrade chain in one deploy, test pad byte-identical after. Recommended release -z. Note the cc-ci suite exercises the sqlite backend; the pg override was verified in the live step.
immich-server + immich-machine-learning v3.2.0 → v3.2.2 in lockstep (bug-fix-only: connection-pool exhaustion during sync, person merge, reassign-faces; server now auto-VACUUMs after TypeORM migrations). Postgres-vectorchord and valkey digest pins re-verified byte-identical to
immich's official v3.2.2 compose — no sidecar change. abra's tag+digest FATA worked around by checking each image directly upstream. First PR since the tag+digest parsing skip earlier this summer —
immich is back in the weekly rotation.
6.60.0-alpine → 6.64.0-alpine across four minors (Source v1.7.5, newsletter-subscription and audit-log fixes, malformed-CSS email-render crash fix) — no breaking changes, no required migrations. The rolling upgrade exercised the full 6.61–6.64 automatic migration chain live with seed data intact. MySQL held at 8.4 LTS (Ghost supports MySQL 8 only; 9.x/26.x declined). Ready to merge.
2.38.4 → 2.40.2 across two feature minors (~150 bugfixes, Dataverse node, AI agent tool calls, Git-based promotion model). 15 TypeORM migrations verified live over real data; encryption-key module rework exercised clean. Watch items: 2.40.0 enables the workflow publication service by default (API callers — publish/unpublish replaces activate/deactivate), and N8N_DB_PING_TIMEOUT is deprecated warn-only (recipe doesn't set it). 2.40.3 published mid-run, deliberately not taken; trivial catch-up next week. Recommended release -y.
7.0.4 → 7.1.0 "Mary Lou": responsive styling controls, always-iframed post editor (plugin/theme compatibility is a site-owner concern the recipe can't gate), jQuery UI 1.14.2, client-side media pipeline (WASM libvips). WP auto-migrates its schema on first admin visit. Mariadb held at 12.3; sftp overlay untouched. PR #1 re-parented on the upstream main tip, clearing the spurious version-label downgrade its diff used to show. Recommended release -y.
0.4.5027 → 0.4.5034: an all-patch window (outbound calls via safeFetch, bounded proxy response size, blob-upload back-pressure, OTEL improvements). No breaking changes, no migrations, no env changes. Recommended release -z. Clean scan; PR #4 (harness routing alias) remains open separately.
Skipped — nothing safe to bump. App 1.27.3-rootless is latest; postgres 15.19 is the newest 15.x (16/17/18 are majors that would crash-loop existing PGDATA, and pg15 is pinned deliberately upstream and supported to Nov 2027); mariadb 10.11.19 also latest. A pg major bump, if ever wanted, should be coordinated with upstream and shipped with a documented pg_dumpall path — an operator-authored change, not a weekly bump. Unrelated app.ini fix PR #4 remains open.
No new upgrade — the existing PR #9 already carries the current bump (static-web-server 2.44.0) and awaits upstream merge; CI green at build 1159.
Up-to-date this week. The unrelated backupbot-v2 backup-labels PR #3 (admin sqlite + imap mail) remains open and green at build 483 — a data-safety fix worth reviewing.
Up-to-date — version-2026.5.1 remains the newest version-* tag (the opendesk-* tags are a different variant line).
Up-to-date; mirror main advanced during the fleet-wide reconcile. No PR, no changes this week.
Up-to-date. No changes this week.