{ "date": "2026-06-05", "subtitle": "Week of June 5, 2026", "lead": "A clean run: of 18 recipes, thirteen upgrades are !testme GREEN and merge-ready, custom-html landed directly upstream, three are up-to-date, and only plausible is red. The table below is ordered by what to address first — CVE-bearing PRs at the top (keycloak, the nginx batch, mailu, uptime-kuma), then the one failure, then routine bumps.", "table": [ { "recipe": "keycloak", "change": "10.7.1+26.6.2 → 10.8.0+26.6.3", "status": "GREEN", "cve": 16, "ci": "build 187 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/187", "pr": "#3", "pr_url": "https://git.autonomic.zone/recipe-maintainers/keycloak/pulls/3", "notes": "Identity provider — 16 security fixes (OIDC/SAML/WebAuthn/LDAP) + MariaDB 12.2→12.3. Close superseded PR #2 (26.6.2)." }, { "recipe": "lasuite-drive", "change": "0.8.0+v0.18.0 → 0.9.0+v0.18.0", "status": "GREEN", "cve": 7, "ci": "build 189 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/189", "pr": "#1", "pr_url": "https://git.autonomic.zone/recipe-maintainers/lasuite-drive/pulls/1", "notes": "nginx 1.30 → 1.31.1 (memory-safety + HTTP/3-spoofing CVE batch) + redis 8.6.4. Ready to merge." }, { "recipe": "matrix-synapse", "change": "7.1.1+v1.149.1 → 7.3.0+v1.154.0", "status": "GREEN", "cve": 7, "ci": "build 192 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/192", "pr": "#1", "pr_url": "https://git.autonomic.zone/recipe-maintainers/matrix-synapse/pulls/1", "notes": "synapse v1.154.0 + nginx 1.31.1 (same CVE batch) + MAS 1.18 (device_code_grant now defaults false — set true if used) + pg17→18. Bridges deferred." }, { "recipe": "mailu", "change": "3.0.1+2024.06.37 → 3.0.1+2024.06.52", "status": "GREEN", "cve": 1, "ci": "build 191 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/191", "pr": "#1", "pr_url": "https://git.autonomic.zone/recipe-maintainers/mailu/pulls/1", "notes": "Internet-facing Roundcube webmail CVE-2026-49217 + certdumper v2.11.2 + redis 8.0.6 (corrected from an unintended 8.8 jump)." }, { "recipe": "uptime-kuma", "change": "3.0.0+2.2.1 → 4.0.0+2.4.0", "status": "GREEN", "cve": 1, "ci": "build 165 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/165", "pr": "#2", "pr_url": "https://git.autonomic.zone/recipe-maintainers/uptime-kuma/pulls/2", "notes": "Authenticated RCE fix (LiquidJS) + MariaDB 11.8 → 12.3 (back up the mariadb overlay first)." }, { "recipe": "lasuite-meet", "change": "0.3.0+v1.16.0 → 0.4.0+v1.19.0", "status": "GREEN", "cve": 1, "ci": "build 190 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/190", "pr": "#3", "pr_url": "https://git.autonomic.zone/recipe-maintainers/lasuite-meet/pulls/3", "notes": "meet v1.19.0 (CVE-2026-45409 idna) + redis 8.6.4. Stale PR #4 closed. Ready to merge." }, { "recipe": "custom-html-tiny", "change": "1.0.1+2.38.0 → 1.1.0+2.42.0", "status": "GREEN", "cve": 1, "ci": "build 164 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/164", "pr": "#6", "pr_url": "https://git.autonomic.zone/recipe-maintainers/custom-html-tiny/pulls/6", "notes": "static-web-server 2.42 (Basic-Auth timing CVE-2026-27480) + alpine/git v2.52.0. Ready to merge." }, { "recipe": "plausible", "change": "3.0.1+v2.0.0 → 4.0.0+v2.0.0", "status": "FAILED", "cve": 0, "ci": "RED 200 · install", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/200", "pr": "#2", "pr_url": "https://git.autonomic.zone/recipe-maintainers/plausible/pulls/2", "notes": "pg 13→14 only (app stays v2.0.0, despite the v2.1.5 branch name). ClickHouse crash-loops every ~6s; v3 entrypoint may not redeploy. See companion PR #1 (also RED)." }, { "recipe": "immich", "change": "—", "status": "SKIPPED", "cve": 0, "ci": "RED 121 · backup PR", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/121", "pr": "#1", "pr_url": "https://git.autonomic.zone/recipe-maintainers/immich/pulls/1", "notes": "abra can't parse tag+digest image pins, so no upgrade computed. Pre-existing backup-fix PR #1 sits RED at build 121." }, { "recipe": "cryptpad", "change": "0.5.5+v2026.2.0 → 0.6.0+v2026.5.1", "status": "GREEN", "cve": 0, "ci": "build 181 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/181", "pr": "#5", "pr_url": "https://git.autonomic.zone/recipe-maintainers/cryptpad/pulls/5", "notes": "2026.5.1 office-corruption + security fixes; nginx already 1.31. SSO users: move SSO plugin to v0.5.0+. (Summary mis-filed it as skipped.)" }, { "recipe": "discourse", "change": "0.7.0+3.3.1 → 0.9.0+3.5.0", "status": "GREEN", "cve": 0, "ci": "build 184 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/184", "pr": "#2", "pr_url": "https://git.autonomic.zone/recipe-maintainers/discourse/pulls/2", "notes": "discourse 3.5.0, redis 7.4→8.0, pg13→pgvector pg17 (manual dump/restore), bitnami→bitnamilegacy. Reconcile with fix PR #1. (183 flaked, 184 green.)" }, { "recipe": "ghost", "change": "1.3.0+6.42.0-alpine → 1.4.0+6.44.0-alpine", "status": "GREEN", "cve": 0, "ci": "build 185 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/185", "pr": "#4", "pr_url": "https://git.autonomic.zone/recipe-maintainers/ghost/pulls/4", "notes": "ghost 6.44.0 (no breaking changes) + MySQL 8.0 → 8.4 LTS, in-place. Ready to merge." }, { "recipe": "lasuite-docs", "change": "0.3.4+v5.1.0 → 0.3.4+v5.2.0", "status": "GREEN", "cve": 0, "ci": "build 188 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/188", "pr": "#5", "pr_url": "https://git.autonomic.zone/recipe-maintainers/lasuite-docs/pulls/5", "notes": "impress v5.2.0; auto-migration 0027; two optional new config vars. Clean." }, { "recipe": "mattermost-lts", "change": "2.1.10+10.11.18 → 2.1.11+10.11.19", "status": "GREEN", "cve": 0, "ci": "build 196 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/196", "pr": "#2", "pr_url": "https://git.autonomic.zone/recipe-maintainers/mattermost-lts/pulls/2", "notes": "10.11.19 LTS patch; pg kept at 15 (16 broke PGDATA). Backup/restore reworked to inline labels (fixes a Swarm config-race). Reconcile with fix PR #1." }, { "recipe": "n8n", "change": "3.3.0+2.23.2 → 3.4.0+2.25.3", "status": "GREEN", "cve": 0, "ci": "build 197 ✓", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/197", "pr": "#5", "pr_url": "https://git.autonomic.zone/recipe-maintainers/n8n/pulls/5", "notes": "n8n 2.25.3 ($jmespath unsafe-token hardening); pg unchanged at 18; no required migrations. Clean." }, { "recipe": "custom-html", "change": "1.11.0+1.29.0 → 1.13.0+1.31.1", "status": "UPTODATE", "cve": 0, "ci": "build 182 ✓ · merged upstream", "ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/182", "pr": "", "notes": "nginx 1.31.1 CVE batch + alpine/git v2.52.0 — merged directly into coopcloud upstream; mirror synced, PR #1 closed. No PR to action (CVEs already landed)." }, { "recipe": "bluesky-pds", "change": "—", "status": "UPTODATE", "cve": 0, "ci": "", "pr": "#1", "pr_url": "https://git.autonomic.zone/recipe-maintainers/bluesky-pds/pulls/1", "notes": "Up-to-date. Stray recipe-create-pr smoke-test PR #1 lingers — can be closed." }, { "recipe": "mumble", "change": "—", "status": "UPTODATE", "cve": 0, "ci": "", "pr": "", "notes": "Up-to-date." } ], "addendum": [ "cryptpad is filed under “skipped / up-to-date” in the upgrade-all summary, yet it carries a green upgrade PR (#5, build 181). The run's counts double-count it (13+1+1+4 = 19 vs 18 considered) — worth fixing the survey's classification so a recipe with an open upgrade PR is never also counted as skipped.", "Four recipes hold two open PRs each to reconcile: keycloak (#3 supersedes the older #2 — close #2), discourse (#2 upgrade + #1 bitnami→bitnamilegacy fix), mattermost-lts (#2 upgrade + #1 restore fix, now folded into #2), and plausible (#2 + #1, both RED). Decide which of each pair lands.", "plausible's PR branch is named v2.1.5 but the actual change is a conservative pg13→14 (the app stays at v2.0.0). The misleading branch name is worth correcting so reviewers aren't misled.", "plausible is RED: the clickhouse container restart-loops every ~6s at build 200. Either the CLICKHOUSE_ENTRYPOINT_VERSION=v3 config bump isn't being re-deployed under abra's --chaos deploy, or the 23.4.2.11-alpine image needs a version bump. Needs operator investigation — not a regression from the pg bump itself.", "immich was skipped because abra can't parse its tag-plus-digest image pins (e.g. …postgres:14-vectorchord@sha256:…). This is a tooling gap in abra, not a recipe regression — but it silently removes immich from the weekly survey, and its pre-existing backup-fix PR #1 (RED at build 121) guards real data and deserves a look.", "Backup-tier CI flakiness recurred this run: keycloak needed a re-run (186 backup flake → 187 green) and discourse did too (183 flake → 184 green). The recipe upgrades themselves are fine, but the backup tier is intermittently failing on first attempt — worth investigating to cut wasted re-runs.", "Two non-upgrade PRs linger and can be closed: bluesky-pds #1 (a recipe-create-pr skill smoke test) and hedgedoc #1 (a cc-ci generic-suite probe, green at build 113). hedgedoc is not part of the 18-recipe fleet." ], "security": [ { "title": "nginx 1.31.1 — memory-safety + HTTP/3-spoofing CVE batch (high) · lasuite-drive, matrix-synapse", "body": "The nginx 1.29/1.30 → 1.31.1 bump closes a cluster of CVEs fixed in 1.31.0/1.31.1: heap buffer overflows in the rewrite/scgi/uwsgi modules (CVE-2026-42945/42946/9256), a charset-decode overread (CVE-2026-42934), proxy_set_body data injection on HTTP/2 backends (CVE-2026-42926), an HTTP/3 connection-migration address-spoofing flaw (CVE-2026-40460), and a use-after-free in the ssl_ocsp/DNS path (CVE-2026-40701). It ships GREEN this week in lasuite-drive (1.30.0→1.31.1, also redis 8.6.4) and matrix-synapse (1.29.6→1.31.1). cryptpad and custom-html already run 1.31.x. nginx serves here as a standard reverse proxy / static server, so the 1.31.0 HTTP/2 hop-by-hop header rejection does not affect well-behaved clients. Highest-value merges of the week.", "links": [ { "text": "lasuite-drive PR #1 (build 189)", "url": "https://git.autonomic.zone/recipe-maintainers/lasuite-drive/pulls/1" }, { "text": "matrix-synapse PR #1 (build 192)", "url": "https://git.autonomic.zone/recipe-maintainers/matrix-synapse/pulls/1" } ] }, { "title": "keycloak 26.6.3 — sixteen security fixes on the identity provider (high) · keycloak", "body": "keycloak 26.6.2 → 26.6.3 is a security patch release carrying sixteen fixes — including CVE issues across OIDC token handling, SAML processing, WebAuthn validation, and LDAP federation — plus a Quarkus 3.33.2 bump. As an identity provider fronting other services, keycloak is a high-priority merge. Bundled with a routine MariaDB 12.2 → 12.3 bump; no config changes required. !testme GREEN at build 187 (build 186 was a backup-tier flake). Note an older superseded upgrade PR (#2, 26.6.2) is still open — close it in favour of #3.", "links": [ { "text": "keycloak PR #3 (build 187)", "url": "https://git.autonomic.zone/recipe-maintainers/keycloak/pulls/3" } ] }, { "title": "mailu — Roundcube webmail CVE-2026-49217 (high) · internet-facing", "body": "mailu 2024.06.37 → 2024.06.52 rolls up the Roundcube security fix CVE-2026-49217 along with certdumper v2.11.2 and a redis 8.0.6 patch (corrected back from an unintended 8.8 jump). Webmail is exposed on a mail host, so this one is worth prioritising. No config changes; !testme GREEN at build 191.", "links": [ { "text": "mailu PR #1 (build 191)", "url": "https://git.autonomic.zone/recipe-maintainers/mailu/pulls/1" } ] }, { "title": "uptime-kuma — authenticated RCE fix (high) · plus MariaDB 12.3 major bump", "body": "uptime-kuma 2.2.1 → 2.4.0 patches a remote-code-execution flaw in the upstream LiquidJS dependency (exploitable by authenticated users; 2.2.1 had only a partial fix). It is bundled with a MariaDB 11.8 → 12.3 major-version bump on the mariadb overlay, so take a database backup before deploying that overlay. !testme GREEN at build 165 (head unchanged since 2026-06-02).", "links": [ { "text": "uptime-kuma PR #2 (build 165)", "url": "https://git.autonomic.zone/recipe-maintainers/uptime-kuma/pulls/2" } ] }, { "title": "lasuite-meet — CVE-2026-45409 (moderate) · lasuite-meet", "body": "lasuite-meet v1.16.0 → v1.19.0 picks up CVE-2026-45409 (idna ≥3.15, baked into the image) in v1.19.0, alongside a deprecated-LiveKit-room-options API replacement and a redis 8.6.4 patch. No breaking changes; AUTO_MIGRATIONS handles the DB. !testme GREEN at build 190.", "links": [ { "text": "lasuite-meet PR #3 (build 190)", "url": "https://git.autonomic.zone/recipe-maintainers/lasuite-meet/pulls/3" } ] } ], "changes": [ { "recipe": "keycloak", "body": "10.7.1+26.6.2 → 10.8.0+26.6.3. A security patch release: sixteen fixes spanning OIDC token handling, SAML processing, WebAuthn validation and LDAP federation, plus a Quarkus 3.33.2 bump and a routine MariaDB 12.2 → 12.3. No config changes. An older superseded PR #2 (26.6.2) is still open — close it for #3.", "links": [ { "text": "PR #3 (build 187)", "url": "https://git.autonomic.zone/recipe-maintainers/keycloak/pulls/3" } ] }, { "recipe": "lasuite-drive", "body": "0.8.0 → 0.9.0 (drive app already at v0.18.0). nginx 1.30 → 1.31.1 brings in the memory-safety + HTTP/3-spoofing CVE batch; redis patched to 8.6.4. Clean GREEN.", "links": [ { "text": "PR #1 (build 189)", "url": "https://git.autonomic.zone/recipe-maintainers/lasuite-drive/pulls/1" } ] }, { "recipe": "matrix-synapse", "body": "synapse v1.149.1 → v1.154.0, with MAS 1.14 → 1.18, nginx 1.31.1 (same CVE batch) and pgautoupgrade 17 → 18. One gotcha: MAS 1.18 changes device_code_grant_enabled to default false — set oauth.device_code_grant_enabled: true if you rely on device-code grants. The signal/telegram bridges and their pg13→17 dump/restore were deliberately deferred to a later PR.", "links": [ { "text": "PR #1 (build 192)", "url": "https://git.autonomic.zone/recipe-maintainers/matrix-synapse/pulls/1" } ] }, { "recipe": "mailu", "body": "2024.06.37 → 2024.06.52. Rolls up the Roundcube webmail fix CVE-2026-49217, certdumper v2.11.2, and a redis 8.0.6 patch (corrected back from an unintended 8.8 jump). Internet-facing — prioritise. No config changes.", "links": [ { "text": "PR #1 (build 191)", "url": "https://git.autonomic.zone/recipe-maintainers/mailu/pulls/1" } ] }, { "recipe": "uptime-kuma", "body": "2.2.1 → 2.4.0. Patches an authenticated RCE in the upstream LiquidJS dependency (2.2.1 had only a partial fix), bundled with a MariaDB 11.8 → 12.3 major bump — back up the mariadb overlay before deploying it.", "links": [ { "text": "PR #2 (build 165)", "url": "https://git.autonomic.zone/recipe-maintainers/uptime-kuma/pulls/2" } ] }, { "recipe": "lasuite-meet", "body": "v1.16.0 → v1.19.0. Picks up CVE-2026-45409 (idna ≥3.15), replaces a deprecated LiveKit room-options API, and patches redis to 8.6.4. AUTO_MIGRATIONS handles the DB; no breaking changes. Stale PR #4 was closed.", "links": [ { "text": "PR #3 (build 190)", "url": "https://git.autonomic.zone/recipe-maintainers/lasuite-meet/pulls/3" } ] }, { "recipe": "custom-html-tiny", "body": "2.38.0 → 2.42.0. static-web-server 2.42 fixes the Basic-Auth timing leak CVE-2026-27480; alpine/git bumped to v2.52.0. Clean GREEN.", "links": [ { "text": "PR #6 (build 164)", "url": "https://git.autonomic.zone/recipe-maintainers/custom-html-tiny/pulls/6" } ] }, { "recipe": "plausible", "body": "A conservative postgres 13.12 → 14.18 in-place upgrade (the app stays at v2.0.0, despite the v2.1.5 branch name). RED across three runs: the clickhouse container restart-loops every ~6s at build 200. Two pre-existing recipe bugs were fixed along the way (a missing stack-prefixed CLICKHOUSE_DATABASE_URL and a fragile ClickHouse entrypoint), but the v3 entrypoint bump may not redeploy under abra --chaos, or the image needs bumping. Companion fix PR #1 is also RED.", "links": [ { "text": "upgrade PR #2 (build 200 RED)", "url": "https://git.autonomic.zone/recipe-maintainers/plausible/pulls/2" }, { "text": "companion fix PR #1 (build 122 RED)", "url": "https://git.autonomic.zone/recipe-maintainers/plausible/pulls/1" } ] }, { "recipe": "immich", "body": "No upgrade was computed — abra can't parse immich's tag-plus-digest image pins, so it was skipped from the survey. Separately, its pre-existing backup-fix PR #1 (back up the postgres database, previously unprotected) is RED at build 121 and guards real data.", "links": [ { "text": "PR #1 (build 121 RED)", "url": "https://git.autonomic.zone/recipe-maintainers/immich/pulls/1" } ] }, { "recipe": "cryptpad", "body": "0.5.5+v2026.2.0 → 0.6.0+v2026.5.1. 2026.5.1 ships office-corruption and security fixes; nginx is already 1.31. SSO users must move the SSO plugin to v0.5.0+. (The upgrade-all summary mis-filed this as skipped/up-to-date.)", "links": [ { "text": "PR #5 (build 181)", "url": "https://git.autonomic.zone/recipe-maintainers/cryptpad/pulls/5" } ] }, { "recipe": "discourse", "body": "0.7.0+3.3.1 → 0.9.0+3.5.0. discourse 3.5.0, redis 7.4 → 8.0, postgres 13 → pgvector pg17 (manual dump/restore per the recipe README), and bitnami → bitnamilegacy after Docker Hub emptied bitnami/discourse. Reconcile with fix PR #1. (183 flaked, 184 green.)", "links": [ { "text": "PR #2 (build 184)", "url": "https://git.autonomic.zone/recipe-maintainers/discourse/pulls/2" } ] }, { "recipe": "ghost", "body": "6.42.0 → 6.44.0 (no breaking changes) plus a conservative MySQL 8.0 → 8.4 LTS in-place bump with no schema changes. Ready to merge.", "links": [ { "text": "PR #4 (build 185)", "url": "https://git.autonomic.zone/recipe-maintainers/ghost/pulls/4" } ] }, { "recipe": "lasuite-docs", "body": "0.3.4+v5.1.0 → 0.3.4+v5.2.0. impress v5.2.0 with auto-migration 0027 and two optional new config vars. Clean GREEN.", "links": [ { "text": "PR #5 (build 188)", "url": "https://git.autonomic.zone/recipe-maintainers/lasuite-docs/pulls/5" } ] }, { "recipe": "mattermost-lts", "body": "10.11.18 → 10.11.19 LTS patch. postgres kept at 15 (16 broke PGDATA). Backup/restore reworked to inline labels, fixing a Swarm config-race. Reconcile with fix PR #1 (the restore-was-a-no-op fix, now folded into #2).", "links": [ { "text": "PR #2 (build 196)", "url": "https://git.autonomic.zone/recipe-maintainers/mattermost-lts/pulls/2" } ] }, { "recipe": "n8n", "body": "3.3.0+2.23.2 → 3.4.0+2.25.3. Spans n8n 2.24/2.25 with a $jmespath unsafe-token hardening; postgres unchanged at 18; no required migrations. Clean.", "links": [ { "text": "PR #5 (build 197)", "url": "https://git.autonomic.zone/recipe-maintainers/n8n/pulls/5" } ] }, { "recipe": "custom-html", "body": "1.11.0+1.29.0 → 1.13.0+1.31.1. nginx 1.31.1 CVE batch + alpine/git v2.52.0 — but this one was merged directly into coopcloud upstream, so the mirror was synced and PR #1 closed. No PR to action; the CVE fixes have already landed.", "links": [] } ] }