From e7f861ec9efaec6ef29be96db99f97b28031e407 Mon Sep 17 00:00:00 2001 From: autonomic-bot Date: Mon, 31 Aug 2026 20:20:09 +0000 Subject: [PATCH 1/3] upstream(mattermost-lts): 2026-08-31 re-check note (ESR still 11.7.10, PR #2 re-verify) --- cc-ci-plan/upstream/mattermost-lts.md | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/cc-ci-plan/upstream/mattermost-lts.md b/cc-ci-plan/upstream/mattermost-lts.md index 3f0dfef..6f0a315 100644 --- a/cc-ci-plan/upstream/mattermost-lts.md +++ b/cc-ci-plan/upstream/mattermost-lts.md @@ -94,6 +94,16 @@ was on 11.10.0 (operator chose innovation line that week); operator should now decide the `-lts` line. postgres 15-alpine still HELD (DB-major out of scope). +- **2026-08-31 re-check** (endoflife.date/api/mattermost.json 2026-08-31; Docker Hub tag list; + GitHub release `v11.7.10`): **11.7 ESR line UNCHANGED** — latest patch still **11.7.10** + (released 2026-08-26, "various bug fixes"), EOL 2027-05-15. PR #2 already carries 11.7.9 → + 11.7.10; the wildcard cert is RENEWED (valid to 2026-11-29), so this run just RE-VERIFIES PR #2 + via `!testme` (the 2026-08-28 run's `!testme` was infra-blocked). 11.8.5 / 11.9.1 / 11.10.1 + remain innovation (EOL 2026-09-15 / 10-15 / 11-15), NOT ESR — do NOT target; 10.11 ESR ended + 2026-08-15 (upstream main still pins 10.11.22 = EXPIRED ESR → the 10→11 ESR move PR #2 carries + remains required; Mattermost docs: ESR→ESR is "fully supported and tested"). postgres 15-alpine + still HELD (DB-major out of scope, operator dump/pg_upgrade). + ## NVD CPE fallback This project publishes nothing machine-readable we can reach — no GitHub advisory feed, no release-attributable changelog — so its CVE count was `?` (nothing measured). NVD is From d824800f8aa2b6b1fa38c4a8a5d2f90bd1270ecd Mon Sep 17 00:00:00 2001 From: autonomic-bot Date: Mon, 31 Aug 2026 20:31:59 +0000 Subject: [PATCH 2/3] upstream(n8n): 2026-08-31 release-notes (2.34.5/2.34.6, 2.35.4-7, 2.36.8/2.36.9, 2.37.4, 2.37.5 withdrawn, 2.37.6) --- cc-ci-plan/upstream/n8n.md | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/cc-ci-plan/upstream/n8n.md b/cc-ci-plan/upstream/n8n.md index b57cd3f..a969a0e 100644 --- a/cc-ci-plan/upstream/n8n.md +++ b/cc-ci-plan/upstream/n8n.md @@ -111,3 +111,29 @@ taken). Rolling upgrade safe (sqlite, TypeORM auto-migrate on boot). Operator flag: the two 2.37.0 API behavior changes (JSON content-type on decorator body routes; binary-data endpoint adapt) only affect HTTP API callers. Recommended release: `-y` (feature minor). + NOTE: PR #7's `!testme` on this date was BLOCKED — `*.ci.commoninternet.net` wildcard cert expired + (bridge: `CERTIFICATE_VERIFY_FAILED certificate has expired`). UNVERIFIED; operator renewed the cert + (now valid to 2026-11-29). The 2.37.3 work must be re-verified by a fresh `!testme`. +- 2.34.5 (2026-08-12, patch): 1 core fix (apply TLS options per hop through a proxy). +- 2.34.6 (2026-08-14, patch): 3 fixes (core `continueErrorOutput` `details` field; Google Ads sunset + v21→v25 API migration; MS Teams Restore `Group.ReadWrite.All` OAuth2 scope — matches the 2.35.3 + in-progress backports). +- 2.35.4/2.35.5/2.35.6/2.35.7 (2026-08-19..21, patches): API schema for decorator routes in /discover; + Google Ads v25 view metric rename; task-runners not restarted when only slow; expression engine + init on expression commands; test-webhook isolate release after teardown; env normalization before + schema parsing; end-user credential resolution; trigger closeFunction isolate; AI Assistant token + limit raise. All patch bugfixes, no breaking changes. +- 2.36.8 (2026-08-28, patch): 1 core fix (domain-restricted credential usable in its own node) — + cross-backport of the 2.37.4 fix into the stable line. +- 2.36.9 (2026-08-31, patch; **now the Stable/Latest badge** — `stable` tag): 1 core fix (apply proxy + environment variables consistently across packages and processes, cross-backport of 2.37.1/2.37.3). +- 2.37.4 (2026-08-28, Pre-release): 1 core fix (allow a domain-restricted credential to work in its + own node). +- 2.37.5 (2026-08-31): **withdrawn** — no plain `2.37.5` tag on Docker Hub (only partial + `2.37.5-amd64/-arm64/-pc` artifact tags, no manifest). Skip entirely, like 2.37.2/2.36.1. +- 2.37.6 (2026-08-31, Pre-release; **newest 2.37.x tag**): 1 core fix (thread execution id through + dynamic-credential storage). +- 2026-08-31 run: PR #7 extended 2.34.4 → **2.37.6** (newest tag abra lists = 2.37.6/2.37.4/2.37.3/…; + 2.37.5 withdrawn). 2.36.9 holds the Stable/Latest badge; 2.37.x remains Pre-release on GitHub + (consistent precedent). Re-verified 2.37.3→2.37.6 (pure core bugfixes), no breaking changes beyond + the already-flagged 2.37.0 API behavior pair. Rolling upgrade safe. Recommended release: `-y`. From 82d3127c2a20431c8e29950ebe146965aaabde0b Mon Sep 17 00:00:00 2001 From: autonomic-bot Date: Mon, 31 Aug 2026 20:46:55 +0000 Subject: [PATCH 3/3] docs: record weekly upgrade report --- cc-ci-plan/JOURNAL.md | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/cc-ci-plan/JOURNAL.md b/cc-ci-plan/JOURNAL.md index 202cea7..e6bdccb 100644 --- a/cc-ci-plan/JOURNAL.md +++ b/cc-ci-plan/JOURNAL.md @@ -976,3 +976,20 @@ certificate. The operator-managed public gateway at `143.244.213.108` currently closes TLS before presenting a certificate, so its passthrough to cc-ci needs repair/verification. The cc-ci plan explicitly marks the gateway as operator infrastructure; do not change the DNS delegation or add a Gandi token to work around it. + +## Session 2026-08-31 20:45 UTC — weekly DeepSeek Flash run and report complete + +**Completed:** Started the weekly upgrader explicitly on `opencode/deepseek-v4-flash`; its parent +and every recipe subagent were confirmed with that persisted model. All nine eligible recipe PRs +completed `!testme` successfully. The public report was then restarted before publication when the +first handoff was found to use the old GLM model; the replacement report session was confirmed +`opencode/deepseek-v4-flash` and published successfully at +`https://report.ci.commoninternet.net/week-2026-08-31.html` (HTTP 200). + +**Follow-up fixes:** Orchestrator PR #17 (`1b75d98`) made `testme-on-pr.sh` apply the documented +public Gitea-host default. cc-ci PR #31 (`769fd29`) adds that public hostname to `.env.public`. +Both commits were scanned clean and contain no coauthor trailers. No recipe PR was merged. + +**Security note:** A subagent briefly enabled shell tracing while debugging the verifier, exposing +runtime credentials in its private agent trace. No values were committed or put in this journal, +but rotate the affected `/srv/cc-ci/.testenv` credentials as a precaution.