upstream(mattermost-lts): 2026-09-11 re-check — 11.7.10 still ESR tip; CVE-2026-13426 adjudicated FIXED (window count 14)

This commit is contained in:
2026-09-11 07:20:26 +00:00
parent 8e9d2ef759
commit 55ce8e3830
+14
View File
@@ -6,6 +6,20 @@
| postgres | postgres | https://github.com/postgres/postgres | https://www.postgresql.org/docs/release/ |
## Standing notes
- **2026-09-11 re-check** (Mattermost Server Releases docs; endoflife.date/api/mattermost.json;
GitHub releases + module tags): **11.7 ESR line UNCHANGED** — newest patch still **11.7.10**
(2026-08-26; no 11.7.11; v11.11.0 is still a GitHub **prerelease**, innovation). **10.11 ESR
expired 2026-08-15; 10.11.23 (2026-08-13) was its FINAL patch** — the "10.x is LTS, never
11.x" survey hint appeared a THIRD time (2026-06-26, 2026-08-07, 2026-09-11) and was again
NOT followed: no supported 10.x LTS exists (10.12 = innovation, expired 2025-12-15). PR #2
re-verified unchanged (tree 59e8c2c0; direct `--chaos` deploy converged + ping 200;
`!testme` GREEN, drone 1355). **Adjudicated CVE-2026-13426 (MMSA-2025-00532, medium) FIXED by
the 10.11.22 → 11.7.10 window**: module fix `server/public` v0.1.22 (commit 3321db82, tag cut
2026-01-30 from the 11.4.0 cycle) is an ancestor of v11.7.10 but NOT of v10.11.22/v10.11.23
(GitHub compare evidence) → CVE count for the ESR move = **14** (13 deterministic + 1
adjudicated). postgres **15-alpine HELD** (recipe has no compose overlays beyond compose.yml;
no pg_upgrade/pgautoupgrade support in recipe or cc-ci tests; the floating 15-alpine tag picks
up 15.x patches on re-pull — pg 15.19 fixes CVE-2026-14662/14663/14664).
- **2026-08-28 re-check** (endoflife.date/api/mattermost.json 2026-08-28; Docker Hub; GitHub
releases): **11.7.10** (released 2026-08-26, "various bug fixes", not prerelease) is the newest
11.7.x ESR patch — the ESR/LTS line has NOT moved, still **11.7** (EOL **2027-05-15**). This run