Co-op Cloud Recipe CI · Weekly Edition

The Recipe Report

Week of September 21, 2026report.ci.autonomic.zone2026-09-28 17:00 UTC

A run of two halves: the resumed upgrade session re-verified ten recipes and watched five upgrades get merged and released upstream mid-flight (discourse 2026.7.2, keycloak 26.7.4, matrix-synapse 7.3.2, lasuite-drive 0.13.0, lasuite-meet 0.7.0) while CI was cut over to a new drone host the same afternoon — then the session died before finishing, leaving no run summary. Address lasuite-drive first: its open PR carries the week's only HIGH CVE (Collabora CVE-2026-77276) plus a redis security release, but sits RED on an install-tier failure that was never diagnosed. lasuite-docs is red for a second week on the dead Docker-Hub minio base; everything else is green, merged, or awaiting the operator.

The full wire — every recipe, in priority order

RecipeChangeTESTSCVEsCIPRSTATUSNotes
discourse2026.7.1 → 2026.7.2GREEN8build 2 ✓ (new drone)#10…Landed upstream mid-run: coop-cloud merged the exact PR commit and released 1.1.1+2026.7.2. Eight fixes (2 high, 6 medium; +1 low still-unknown — count is a floor). PR #9 auto-closed as merged-upstream; #10 was a no-diff verification vehicle, closed after carrying this week's GREEN evidence. Operators: deploy the released tag.
lasuite-driveredis 8.10.1 → 8.10.2 · collabora 25.04 → 26.04FAILED4RED 9 · install#8…Fresh PR after #7 landed upstream (0.13.0+v0.22.0): redis SECURITY release + collabora major with entrypoint migration (4 CVEs, 1 high). CI died in under a minute at the install tier, before any test ran — never diagnosed or re-run because the upgrade session died mid-run. 2 of 3 !testme runs unspent; the tree itself was live-verified green.
keycloak26.7.3 → 26.7.4GREEN6build 1 ✓ (new drone)#9…Merged upstream mid-run (coop-cloud#46) and published 10.9.4+26.7.4 — six security fixes incl. high CVE-2026-90997; mariadb 13.0 major declined. Mirror default branch still points at a stale master (26.7.3), which abra misreads — flip it to main (see Addendum).
mattermost-lts10.11.22 → 11.7.11GREEN14build 7 ✓ (level 5)#2…Re-adjudicated and unchanged: 10.11.24 is post-EOL on the dead 10.11 line, 11.11.0 is an innovation release not ESR — 11.7.11 confirmed (supported to 2027-05-15). 14 CVEs is a floor (all medium; 6+ MMSA fix ids pending disclosure). Live 10→11 migration with seeded-user survival; postgres held 15-alpine. Awaiting merge, then `abra recipe release mattermost-lts -x`.
lasuite-docsv5.6.1 → v5.7.0FAILED1RED 5 · install (dead base)#9…Week 2 RED on the same external cause: Docker Hub removed minio/minio, canonical 0.4.0 + fallback 0.4.1 are unpullable, and the quay-fixed live 0.4.2 can't serve as a base until a >0.4.2 release exists. PR extended with redis 8.10.2; the tree re-verified green live (docspec :3000, migrations). Unblock: merge + release >0.4.2.
custom-html1.31.5 → 1.31.6GREEN1build 1361 ✓#8…nginx CVE-2026-90439 (HTTP/3 heap overflow) — merged upstream; the canonical sweep auto-closed the mirror PR on 09-20 as already in upstream main. Nothing to action.
matrix-synapseMAS 1.24.0 → 1.25.0GREENnonebuild 4 ✓#7…Fresh PR on top of the week's landed 16-advisory synapse batch (#5 merged upstream, released 7.3.2+v1.161.0): MAS 1.25.0 bugfix-only. abra's mautrix-signal "upgrade" was declined as a downgrade-in-disguise (v26.02.2 = Feb 2026, ~7 months older than pinned v0.2609.0). Bridge DBs held at pg13.
lasuite-meetredis 8.10.1 → 8.10.2GREENnonebuild 8 ✓#11…Cache-sidecar SECURITY patch (transaction ACL-revocation bypass, cluster-bus hardening — no CVE ids published) after the v1.31.0 upgrade landed upstream (0.7.0). Identical to upstream renovate PR #27; release with -z after merge.
n8n2.38.4 → 2.40.5GREENnonebuild 6 ✓#8…Extended the 09-18 PR from the flagged 2.40.2 snapshot to 2.40.5 (two more pre-release patches); the full migration chain re-verified live with data survival. No CVEs; release -y after merge.
ghost6.60.0-alpine → 6.64.0-alpineGREENnonebuild 3 ✓ (new drone)#7…Re-verified on the new drone: full 6.61→6.64 migration chain ran clean with seed data intact; mysql held at 8.4 (Ghost supports MySQL 8 only). Release -y after merge.
bluesky-pds0.4.5027 → 0.4.5034GREENnonebuild 1376 ✓#5…All-patch window re-verified live and in CI (safeFetch hardening, proxy response-size bound); release -z after merge. Unrelated routing-fix PR #4 (app→pds service rename so caddy resolves this stack on a shared proxy) still open/pending.
hedgedocpg 16-alpine → 18-alpineGREENnonebuild 1365 ✓#3…Unchanged since 09-18 — not re-run this week (the session died first). PG 16.15→18.6 auto-upgrade was live-verified with byte-identical data; required volume-mount change included. Awaiting operator review.
wordpress7.0.4 → 7.1.0GREENnonebuild 1375 ✓#1…Unchanged from 09-18: 7.1 "Mary Lou" (post editor always iframed — plugin/theme compat is a site-owner concern); mariadb held at 12.3. Awaiting operator review.
immichv3.2.0 → v3.2.2GREENnonebuild 1367 ✓#5…Merged upstream; the canonical sweep auto-closed the mirror PR on 09-27 as already in upstream main. Nothing to action.
gitea—SKIPPEDnonebuild 1250 ✓ · app.ini fix#4…Up-to-date — app 1.27.3-rootless latest; postgres 15.x pinned deliberately (majors not in-place-safe). PR #4 (seed app.ini into a writable config volume for Gitea 1.24+) still open, green.
custom-html-tiny—UPTODATEnonebuild 1159 ✓ · awaiting merge#9…Up-to-date; existing PR #9 (static-web-server 2.44.0) awaits upstream merge.
mailu—UPTODATEnonebuild 483 ✓ · backup PR#3…Up-to-date; unrelated backupbot-labels PR #3 (admin sqlite + imap mail) still open, green.
cryptpad—UPTODATEnoneUp-to-date — version-2026.5.1 is the newest version-* tag.
drone—UPTODATEnoneUp-to-date — but the drone CI stack itself was cut over mid-run (see Addendum).
mumble—UPTODATEnoneUp-to-date.

Addendum

Security Bulletin

🔒 Critical CVE upgrades

lasuite-drive — collabora CVE-2026-77276 (high) + three medium, redis 8.10.2 security release · open PR RED, needs a re-test
Open PR #8 moves collabora/code 25.04.10.3.1 → 26.04.4.1.1, closing CVE-2026-77276 (high, GHSA-cf9v-hrj7-8p4v) plus CVE-2025-66208, CVE-2026-46499 and CVE-2026-48164 (medium) — all four affect the pinned 25.04.10.3.1 — and patches redis 8.10.1 → 8.10.2 (SECURITY release: transaction ACL-revocation bypass #15673, unauthenticated cluster-bus join #15722; no CVE ids published). The 26.04 image ships no shell, so the PR also migrates entrypoint/healthcheck and retires the collabora_p docker secret — the Collabora admin panel stays locked until COLLABORA_ADMIN_PASSWORD is set in the .env (empty = locked, verified). The tree is live-verified green, but CI is RED on an undiagnosed sub-minute install failure: investigate and re-test before merging.
discourse 2026.7.2 — eight CVEs on the forum platform (2 high) · landed upstream + released mid-run
The 2026.7.1 → 2026.7.2 security patch carries eight fixes: high CVE-2026-91122 (GHSA-8m44-f6g9-7cg7) and CVE-2026-91123 (GHSA-6pwj-wgg8-4rjc) plus six medium, all fixed in 2026.7.2 on the 2026.7 ESR line. coop-cloud merged the upgrade commit itself and published 1.1.1+2026.7.2 mid-run, so nothing is left to merge — operators running discourse should move to the released tag. One further low advisory (CVE-2025-53016, HTML injection in solved posts when display names are shown) remains unmeasurable: the advisory's fix ref does not resolve in the upstream repo, so the eight is a floor, not a clean bill.
keycloak 26.7.4 — six CVEs on the identity provider (1 high) · landed upstream + released mid-run
keycloak 26.7.3 → 26.7.4 is the identity-provider security patch (six fixes incl. high CVE-2026-90997). It was merged upstream (coop-cloud#46) and published as 10.9.4+26.7.4 during the run, with the mirror PR merged and closed behind it; mariadb 13.0 remains declined as an unsupported major. As with discourse, nothing is left to review — deploy the released tag. Caveat: the recipe-maintainers mirror's default branch still points at a stale master reading 26.7.3 (see Addendum).

What changed

2026.7.1 → 2026.7.2, a security patch within the 2026.7 ESR line: 43 commits, eight security fixes (2 high, 6 medium), no breaking changes, Rails migrations on boot only. The unusual part is how it landed: coop-cloud merged the exact commit PR #9 carried and published 1.1.1+2026.7.2 while the run was in its live check — PR #9 auto-closed as merged-upstream, and a no-diff PR #10 served as the week's !testme vehicle (all five tiers pass on the new drone) before being closed as redundant. pg18 and redis 8.10-alpine held.
Fresh PR #8 after #7 landed upstream (0.13.0+v0.22.0): redis 8.10.1 → 8.10.2 (SECURITY release) and collabora 25.04.10.3.1 → 26.04.4.1.1 with a real config migration — the 26.04 image has no shell, so the entrypoint override is dropped, the healthcheck switches to coolwsd --probe, extra_params goes away, and the collabora_p secret is retired in favour of COLLABORA_ADMIN_PASSWORD (unset = admin panel locked). Four collabora CVEs fixed (1 high). The live deploy converged 9/9 with the new probe; CI is RED on an undiagnosed sub-minute install failure and needs a re-run.
26.7.3 → 26.7.4 (six security fixes incl. high CVE-2026-90997; mariadb held at 12.3 — 13.0 major declined). The whole lifecycle played out mid-run: upstream coop-cloud/keycloak#46 merged the exact PR #9 commit, published 10.9.4+26.7.4, and the operator merged the mirror PR — a later !testme on the new drone (build 1, level 5) confirmed the merged tree green. Nothing to action beyond deploying the release.
No new commit — PR #2's 11.7.11 target was re-adjudicated and confirmed: vendor docs state the 10.11 ESR ended 2026-08-15 and 10.11.24 is a post-EOL release on the dead line (its High fix isn't even in the vendor feed; the CVE-2026-13426 fix commit is absent from it), 11.11.0 is an innovation release not ESR, and 11.7.11 is the newest ESR patch, actively receiving security fixes. The 10.11.22 → 11.7.11 jump was re-exercised live with a seeded admin user surviving the migration; postgres held at 15-alpine. Awaiting operator merge, then `abra recipe release mattermost-lts -x`.
PR #9 extended again: impress v5.7.0 quartet, nginx 1.31.6 (CVE-2026-90439), the docspec image switch to ghcr.io/docspec/api:1.21.4 (port 4000→3000) and now redis 8.10.2. Live re-verification was green (9/9 services, docspec :3000 healthy, malware_detection migrations applied). CI stays deterministically RED on the dead Docker-Hub minio base — every base candidate is unpullable and none of the remaining 2 !testme runs were burned on it; the explanatory PR comment carries the evidence and the two unblock paths.
nginx 1.31.5 → 1.31.6 (CVE-2026-90439, HTTP/3 heap overflow) was merged upstream; the canonical sweep auto-closed mirror PR #8 on 09-20 as already in upstream main and re-synced the mirror. No PR to action — the CVE fix has landed.
Two events in one week. First, last week's big batch (synapse v1.161.0, MAS 1.24.0, mautrix-telegram/-signal v0.2609.0, nginx 1.31.6 — 16 advisories incl. six high) was merged upstream and released as 7.3.2+v1.161.0. Then fresh PR #7 with only today's delta: MAS 1.24.0 → 1.25.0 (bugfix-only, no config changes; optional overlay). Notably, abra offered a mautrix-signal "upgrade" to v26.02.2 that is actually seven months older than the pinned v0.2609.0 — declined after checking the upstream releases list. Bridge DBs held at 13-alpine.
The v1.31.0 upgrade (meet + livekit 1.13.7 + nginx 1.31.6) was merged upstream and released as 0.7.0+v1.31.0, closing PR #10 — then fresh PR #11 carries the week's delta: redis 8.10.1 → 8.10.2, the SECURITY release (ACL-revocation bypass in transactions, cluster-bus authentication hardening; cache-only sidecar here, no persistence). GREEN on build 8; identical to upstream renovate PR #27, so the operator can merge either. Release -z after merge.
PR #8 extended from 2.40.2 to 2.40.5 (the flagged catch-up plus two more pre-release patches — data-encryption-key repair, workflow-trigger teardown, declarative-routing hardening). The full in-place upgrade was re-exercised live: all TypeORM migrations finished, owner login and pre-upgrade workflow data read back intact; note 2.40.x changed the login API request shape (emailOrLdapLoginId) — cc-ci tests unaffected. No CVEs; 2.40.x remains a pre-release line, consistent with tracking-the-newest precedent. Release -y after merge.
PR #7 unchanged (one-line 6.60.0-alpine → 6.64.0-alpine) and re-verified end to end on the new drone: live rolling upgrade ran the full 6.61→6.64 migration chain in seconds with seed data intact, then build 3 passed all tiers. mysql deliberately held at 8.4 (Ghost supports MySQL 8 only; abra's 9.x/26.x majors declined). Release -y after merge.
PR #5 (0.4.5027 → 0.4.5034) re-verified: live deploy exercised health, account create/session, record round-trip and on-demand subdomain TLS on 0.4.5034, then build 1376 passed again — all-patch window (safeFetch hardening, proxy response-size bound, blob-upload back-pressure), no operator action. Release -z after merge. Unrelated PR #4 (rename the main service app→pds so caddy resolves this stack on a shared proxy) remains open and pending.
No change this week — PR #3 (pgautoupgrade 16-alpine → 18-alpine with the required PG18 volume-mount move to /var/lib/postgresql; app 1.12.0 already latest) was not re-run because the upgrade session died before reaching it. Its 09-18 verification stands: PG 16.15 → 18.6 auto-upgrade with byte-identical data. Awaiting operator review.
No change this week — PR #1 (7.0.4 → 7.1.0 "Mary Lou": the post editor is always iframed, mariadb held at 12.3) was not re-run because the upgrade session died before reaching it. Its 09-18 verification (build 1375) stands. Awaiting operator review.
PR #5 (server + ML lockstep to v3.2.2, bug-fix-only; pg-vectorchord and valkey pins re-verified against immich's official compose) was merged upstream; the canonical sweep auto-closed the mirror PR on 09-27 as already in upstream main. No PR to action.
Up-to-date — app 1.27.3-rootless is latest and postgres is pinned at 15.x deliberately (16/17/18 are majors, not in-place-safe). Open non-upgrade PR #4 seeds app.ini into a writable config volume for Gitea 1.24+ (green at build 1250); the older mariadb 10.11.19 PR #9 was merged upstream on 09-14.
Up-to-date; existing PR #9 (static-web-server 2.43.0 → 2.44.0, green) still awaits upstream merge.
Up-to-date; the unrelated PR #3 (backupbot v2 backup labels for the admin sqlite /data and imap /mail) remains open and green.