Files
cc-ci-orchestrator/.claude/skills/recipe-report/example-spec.json
T
autonomic-botandClaude Opus 4.8 d31378b180 feat(recipe-report): restructure page — priority-sorted wire table w/ CVE column, addendum, per-recipe changes
New page order: short lead -> the full wire table (sorted by priority-to-address,
CVE recipes first, new CVEs count column) -> Addendum (bullets of real special
issues, omitted if clean) -> Security Bulletin -> per-recipe "What changed".

- recipe-report.py: _table() gains a CVEs column + recipe-name linking; new
  _changes() helper; render() reordered; docstring SPEC SHAPE updated
  (cve/addendum/changes added, needs_attention/routine removed).
- recipe-report/SKILL.md + example-spec.json: new procedure, spec shape, and
  gold-standard template (2026-06-05, new format).
- launch-report.py: kickoff text reflects the new priority-ordered structure.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-05 17:06:43 +00:00

427 lines
22 KiB
JSON

{
"date": "2026-06-05",
"subtitle": "Week of June 5, 2026",
"lead": "A clean run: of 18 recipes, thirteen upgrades are !testme GREEN and merge-ready, custom-html landed directly upstream, three are up-to-date, and only plausible is red. The table below is ordered by what to address first — CVE-bearing PRs at the top (keycloak, the nginx batch, mailu, uptime-kuma), then the one failure, then routine bumps.",
"table": [
{
"recipe": "keycloak",
"change": "10.7.1+26.6.2 → 10.8.0+26.6.3",
"status": "GREEN",
"cve": 16,
"ci": "build 187 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/187",
"pr": "#3",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/keycloak/pulls/3",
"notes": "Identity provider — 16 security fixes (OIDC/SAML/WebAuthn/LDAP) + MariaDB 12.2→12.3. Close superseded PR #2 (26.6.2)."
},
{
"recipe": "lasuite-drive",
"change": "0.8.0+v0.18.0 → 0.9.0+v0.18.0",
"status": "GREEN",
"cve": 7,
"ci": "build 189 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/189",
"pr": "#1",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/lasuite-drive/pulls/1",
"notes": "nginx 1.30 → 1.31.1 (memory-safety + HTTP/3-spoofing CVE batch) + redis 8.6.4. Ready to merge."
},
{
"recipe": "matrix-synapse",
"change": "7.1.1+v1.149.1 → 7.3.0+v1.154.0",
"status": "GREEN",
"cve": 7,
"ci": "build 192 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/192",
"pr": "#1",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/matrix-synapse/pulls/1",
"notes": "synapse v1.154.0 + nginx 1.31.1 (same CVE batch) + MAS 1.18 (device_code_grant now defaults false — set true if used) + pg17→18. Bridges deferred."
},
{
"recipe": "mailu",
"change": "3.0.1+2024.06.37 → 3.0.1+2024.06.52",
"status": "GREEN",
"cve": 1,
"ci": "build 191 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/191",
"pr": "#1",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/mailu/pulls/1",
"notes": "Internet-facing Roundcube webmail CVE-2026-49217 + certdumper v2.11.2 + redis 8.0.6 (corrected from an unintended 8.8 jump)."
},
{
"recipe": "uptime-kuma",
"change": "3.0.0+2.2.1 → 4.0.0+2.4.0",
"status": "GREEN",
"cve": 1,
"ci": "build 165 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/165",
"pr": "#2",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/uptime-kuma/pulls/2",
"notes": "Authenticated RCE fix (LiquidJS) + MariaDB 11.8 → 12.3 (back up the mariadb overlay first)."
},
{
"recipe": "lasuite-meet",
"change": "0.3.0+v1.16.0 → 0.4.0+v1.19.0",
"status": "GREEN",
"cve": 1,
"ci": "build 190 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/190",
"pr": "#3",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/lasuite-meet/pulls/3",
"notes": "meet v1.19.0 (CVE-2026-45409 idna) + redis 8.6.4. Stale PR #4 closed. Ready to merge."
},
{
"recipe": "custom-html-tiny",
"change": "1.0.1+2.38.0 → 1.1.0+2.42.0",
"status": "GREEN",
"cve": 1,
"ci": "build 164 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/164",
"pr": "#6",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/custom-html-tiny/pulls/6",
"notes": "static-web-server 2.42 (Basic-Auth timing CVE-2026-27480) + alpine/git v2.52.0. Ready to merge."
},
{
"recipe": "plausible",
"change": "3.0.1+v2.0.0 → 4.0.0+v2.0.0",
"status": "FAILED",
"cve": 0,
"ci": "RED 200 · install",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/200",
"pr": "#2",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/plausible/pulls/2",
"notes": "pg 13→14 only (app stays v2.0.0, despite the v2.1.5 branch name). ClickHouse crash-loops every ~6s; v3 entrypoint may not redeploy. See companion PR #1 (also RED)."
},
{
"recipe": "immich",
"change": "—",
"status": "SKIPPED",
"cve": 0,
"ci": "RED 121 · backup PR",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/121",
"pr": "#1",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/immich/pulls/1",
"notes": "abra can't parse tag+digest image pins, so no upgrade computed. Pre-existing backup-fix PR #1 sits RED at build 121."
},
{
"recipe": "cryptpad",
"change": "0.5.5+v2026.2.0 → 0.6.0+v2026.5.1",
"status": "GREEN",
"cve": 0,
"ci": "build 181 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/181",
"pr": "#5",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/cryptpad/pulls/5",
"notes": "2026.5.1 office-corruption + security fixes; nginx already 1.31. SSO users: move SSO plugin to v0.5.0+. (Summary mis-filed it as skipped.)"
},
{
"recipe": "discourse",
"change": "0.7.0+3.3.1 → 0.9.0+3.5.0",
"status": "GREEN",
"cve": 0,
"ci": "build 184 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/184",
"pr": "#2",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/discourse/pulls/2",
"notes": "discourse 3.5.0, redis 7.4→8.0, pg13→pgvector pg17 (manual dump/restore), bitnami→bitnamilegacy. Reconcile with fix PR #1. (183 flaked, 184 green.)"
},
{
"recipe": "ghost",
"change": "1.3.0+6.42.0-alpine → 1.4.0+6.44.0-alpine",
"status": "GREEN",
"cve": 0,
"ci": "build 185 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/185",
"pr": "#4",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/ghost/pulls/4",
"notes": "ghost 6.44.0 (no breaking changes) + MySQL 8.0 → 8.4 LTS, in-place. Ready to merge."
},
{
"recipe": "lasuite-docs",
"change": "0.3.4+v5.1.0 → 0.3.4+v5.2.0",
"status": "GREEN",
"cve": 0,
"ci": "build 188 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/188",
"pr": "#5",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/lasuite-docs/pulls/5",
"notes": "impress v5.2.0; auto-migration 0027; two optional new config vars. Clean."
},
{
"recipe": "mattermost-lts",
"change": "2.1.10+10.11.18 → 2.1.11+10.11.19",
"status": "GREEN",
"cve": 0,
"ci": "build 196 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/196",
"pr": "#2",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/mattermost-lts/pulls/2",
"notes": "10.11.19 LTS patch; pg kept at 15 (16 broke PGDATA). Backup/restore reworked to inline labels (fixes a Swarm config-race). Reconcile with fix PR #1."
},
{
"recipe": "n8n",
"change": "3.3.0+2.23.2 → 3.4.0+2.25.3",
"status": "GREEN",
"cve": 0,
"ci": "build 197 ✓",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/197",
"pr": "#5",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/n8n/pulls/5",
"notes": "n8n 2.25.3 ($jmespath unsafe-token hardening); pg unchanged at 18; no required migrations. Clean."
},
{
"recipe": "custom-html",
"change": "1.11.0+1.29.0 → 1.13.0+1.31.1",
"status": "UPTODATE",
"cve": 0,
"ci": "build 182 ✓ · merged upstream",
"ci_url": "https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/182",
"pr": "",
"notes": "nginx 1.31.1 CVE batch + alpine/git v2.52.0 — merged directly into coopcloud upstream; mirror synced, PR #1 closed. No PR to action (CVEs already landed)."
},
{
"recipe": "bluesky-pds",
"change": "—",
"status": "UPTODATE",
"cve": 0,
"ci": "",
"pr": "#1",
"pr_url": "https://git.autonomic.zone/recipe-maintainers/bluesky-pds/pulls/1",
"notes": "Up-to-date. Stray recipe-create-pr smoke-test PR #1 lingers — can be closed."
},
{
"recipe": "mumble",
"change": "—",
"status": "UPTODATE",
"cve": 0,
"ci": "",
"pr": "",
"notes": "Up-to-date."
}
],
"addendum": [
"cryptpad is filed under “skipped / up-to-date” in the upgrade-all summary, yet it carries a green upgrade PR (#5, build 181). The run's counts double-count it (13+1+1+4 = 19 vs 18 considered) — worth fixing the survey's classification so a recipe with an open upgrade PR is never also counted as skipped.",
"Four recipes hold two open PRs each to reconcile: keycloak (#3 supersedes the older #2 — close #2), discourse (#2 upgrade + #1 bitnami→bitnamilegacy fix), mattermost-lts (#2 upgrade + #1 restore fix, now folded into #2), and plausible (#2 + #1, both RED). Decide which of each pair lands.",
"plausible's PR branch is named v2.1.5 but the actual change is a conservative pg13→14 (the app stays at v2.0.0). The misleading branch name is worth correcting so reviewers aren't misled.",
"plausible is RED: the clickhouse container restart-loops every ~6s at build 200. Either the CLICKHOUSE_ENTRYPOINT_VERSION=v3 config bump isn't being re-deployed under abra's --chaos deploy, or the 23.4.2.11-alpine image needs a version bump. Needs operator investigation — not a regression from the pg bump itself.",
"immich was skipped because abra can't parse its tag-plus-digest image pins (e.g. …postgres:14-vectorchord@sha256:…). This is a tooling gap in abra, not a recipe regression — but it silently removes immich from the weekly survey, and its pre-existing backup-fix PR #1 (RED at build 121) guards real data and deserves a look.",
"Backup-tier CI flakiness recurred this run: keycloak needed a re-run (186 backup flake → 187 green) and discourse did too (183 flake → 184 green). The recipe upgrades themselves are fine, but the backup tier is intermittently failing on first attempt — worth investigating to cut wasted re-runs.",
"Two non-upgrade PRs linger and can be closed: bluesky-pds #1 (a recipe-create-pr skill smoke test) and hedgedoc #1 (a cc-ci generic-suite probe, green at build 113). hedgedoc is not part of the 18-recipe fleet."
],
"security": [
{
"title": "nginx 1.31.1 — memory-safety + HTTP/3-spoofing CVE batch (high) · lasuite-drive, matrix-synapse",
"body": "The nginx 1.29/1.30 → 1.31.1 bump closes a cluster of CVEs fixed in 1.31.0/1.31.1: heap buffer overflows in the rewrite/scgi/uwsgi modules (CVE-2026-42945/42946/9256), a charset-decode overread (CVE-2026-42934), proxy_set_body data injection on HTTP/2 backends (CVE-2026-42926), an HTTP/3 connection-migration address-spoofing flaw (CVE-2026-40460), and a use-after-free in the ssl_ocsp/DNS path (CVE-2026-40701). It ships GREEN this week in lasuite-drive (1.30.0→1.31.1, also redis 8.6.4) and matrix-synapse (1.29.6→1.31.1). cryptpad and custom-html already run 1.31.x. nginx serves here as a standard reverse proxy / static server, so the 1.31.0 HTTP/2 hop-by-hop header rejection does not affect well-behaved clients. Highest-value merges of the week.",
"links": [
{
"text": "lasuite-drive PR #1 (build 189)",
"url": "https://git.autonomic.zone/recipe-maintainers/lasuite-drive/pulls/1"
},
{
"text": "matrix-synapse PR #1 (build 192)",
"url": "https://git.autonomic.zone/recipe-maintainers/matrix-synapse/pulls/1"
}
]
},
{
"title": "keycloak 26.6.3 — sixteen security fixes on the identity provider (high) · keycloak",
"body": "keycloak 26.6.2 → 26.6.3 is a security patch release carrying sixteen fixes — including CVE issues across OIDC token handling, SAML processing, WebAuthn validation, and LDAP federation — plus a Quarkus 3.33.2 bump. As an identity provider fronting other services, keycloak is a high-priority merge. Bundled with a routine MariaDB 12.2 → 12.3 bump; no config changes required. !testme GREEN at build 187 (build 186 was a backup-tier flake). Note an older superseded upgrade PR (#2, 26.6.2) is still open — close it in favour of #3.",
"links": [
{
"text": "keycloak PR #3 (build 187)",
"url": "https://git.autonomic.zone/recipe-maintainers/keycloak/pulls/3"
}
]
},
{
"title": "mailu — Roundcube webmail CVE-2026-49217 (high) · internet-facing",
"body": "mailu 2024.06.37 → 2024.06.52 rolls up the Roundcube security fix CVE-2026-49217 along with certdumper v2.11.2 and a redis 8.0.6 patch (corrected back from an unintended 8.8 jump). Webmail is exposed on a mail host, so this one is worth prioritising. No config changes; !testme GREEN at build 191.",
"links": [
{
"text": "mailu PR #1 (build 191)",
"url": "https://git.autonomic.zone/recipe-maintainers/mailu/pulls/1"
}
]
},
{
"title": "uptime-kuma — authenticated RCE fix (high) · plus MariaDB 12.3 major bump",
"body": "uptime-kuma 2.2.1 → 2.4.0 patches a remote-code-execution flaw in the upstream LiquidJS dependency (exploitable by authenticated users; 2.2.1 had only a partial fix). It is bundled with a MariaDB 11.8 → 12.3 major-version bump on the mariadb overlay, so take a database backup before deploying that overlay. !testme GREEN at build 165 (head unchanged since 2026-06-02).",
"links": [
{
"text": "uptime-kuma PR #2 (build 165)",
"url": "https://git.autonomic.zone/recipe-maintainers/uptime-kuma/pulls/2"
}
]
},
{
"title": "lasuite-meet — CVE-2026-45409 (moderate) · lasuite-meet",
"body": "lasuite-meet v1.16.0 → v1.19.0 picks up CVE-2026-45409 (idna ≥3.15, baked into the image) in v1.19.0, alongside a deprecated-LiveKit-room-options API replacement and a redis 8.6.4 patch. No breaking changes; AUTO_MIGRATIONS handles the DB. !testme GREEN at build 190.",
"links": [
{
"text": "lasuite-meet PR #3 (build 190)",
"url": "https://git.autonomic.zone/recipe-maintainers/lasuite-meet/pulls/3"
}
]
}
],
"changes": [
{
"recipe": "keycloak",
"body": "10.7.1+26.6.2 → 10.8.0+26.6.3. A security patch release: sixteen fixes spanning OIDC token handling, SAML processing, WebAuthn validation and LDAP federation, plus a Quarkus 3.33.2 bump and a routine MariaDB 12.2 → 12.3. No config changes. An older superseded PR #2 (26.6.2) is still open — close it for #3.",
"links": [
{
"text": "PR #3 (build 187)",
"url": "https://git.autonomic.zone/recipe-maintainers/keycloak/pulls/3"
}
]
},
{
"recipe": "lasuite-drive",
"body": "0.8.0 → 0.9.0 (drive app already at v0.18.0). nginx 1.30 → 1.31.1 brings in the memory-safety + HTTP/3-spoofing CVE batch; redis patched to 8.6.4. Clean GREEN.",
"links": [
{
"text": "PR #1 (build 189)",
"url": "https://git.autonomic.zone/recipe-maintainers/lasuite-drive/pulls/1"
}
]
},
{
"recipe": "matrix-synapse",
"body": "synapse v1.149.1 → v1.154.0, with MAS 1.14 → 1.18, nginx 1.31.1 (same CVE batch) and pgautoupgrade 17 → 18. One gotcha: MAS 1.18 changes device_code_grant_enabled to default false — set oauth.device_code_grant_enabled: true if you rely on device-code grants. The signal/telegram bridges and their pg13→17 dump/restore were deliberately deferred to a later PR.",
"links": [
{
"text": "PR #1 (build 192)",
"url": "https://git.autonomic.zone/recipe-maintainers/matrix-synapse/pulls/1"
}
]
},
{
"recipe": "mailu",
"body": "2024.06.37 → 2024.06.52. Rolls up the Roundcube webmail fix CVE-2026-49217, certdumper v2.11.2, and a redis 8.0.6 patch (corrected back from an unintended 8.8 jump). Internet-facing — prioritise. No config changes.",
"links": [
{
"text": "PR #1 (build 191)",
"url": "https://git.autonomic.zone/recipe-maintainers/mailu/pulls/1"
}
]
},
{
"recipe": "uptime-kuma",
"body": "2.2.1 → 2.4.0. Patches an authenticated RCE in the upstream LiquidJS dependency (2.2.1 had only a partial fix), bundled with a MariaDB 11.8 → 12.3 major bump — back up the mariadb overlay before deploying it.",
"links": [
{
"text": "PR #2 (build 165)",
"url": "https://git.autonomic.zone/recipe-maintainers/uptime-kuma/pulls/2"
}
]
},
{
"recipe": "lasuite-meet",
"body": "v1.16.0 → v1.19.0. Picks up CVE-2026-45409 (idna ≥3.15), replaces a deprecated LiveKit room-options API, and patches redis to 8.6.4. AUTO_MIGRATIONS handles the DB; no breaking changes. Stale PR #4 was closed.",
"links": [
{
"text": "PR #3 (build 190)",
"url": "https://git.autonomic.zone/recipe-maintainers/lasuite-meet/pulls/3"
}
]
},
{
"recipe": "custom-html-tiny",
"body": "2.38.0 → 2.42.0. static-web-server 2.42 fixes the Basic-Auth timing leak CVE-2026-27480; alpine/git bumped to v2.52.0. Clean GREEN.",
"links": [
{
"text": "PR #6 (build 164)",
"url": "https://git.autonomic.zone/recipe-maintainers/custom-html-tiny/pulls/6"
}
]
},
{
"recipe": "plausible",
"body": "A conservative postgres 13.12 → 14.18 in-place upgrade (the app stays at v2.0.0, despite the v2.1.5 branch name). RED across three runs: the clickhouse container restart-loops every ~6s at build 200. Two pre-existing recipe bugs were fixed along the way (a missing stack-prefixed CLICKHOUSE_DATABASE_URL and a fragile ClickHouse entrypoint), but the v3 entrypoint bump may not redeploy under abra --chaos, or the image needs bumping. Companion fix PR #1 is also RED.",
"links": [
{
"text": "upgrade PR #2 (build 200 RED)",
"url": "https://git.autonomic.zone/recipe-maintainers/plausible/pulls/2"
},
{
"text": "companion fix PR #1 (build 122 RED)",
"url": "https://git.autonomic.zone/recipe-maintainers/plausible/pulls/1"
}
]
},
{
"recipe": "immich",
"body": "No upgrade was computed — abra can't parse immich's tag-plus-digest image pins, so it was skipped from the survey. Separately, its pre-existing backup-fix PR #1 (back up the postgres database, previously unprotected) is RED at build 121 and guards real data.",
"links": [
{
"text": "PR #1 (build 121 RED)",
"url": "https://git.autonomic.zone/recipe-maintainers/immich/pulls/1"
}
]
},
{
"recipe": "cryptpad",
"body": "0.5.5+v2026.2.0 → 0.6.0+v2026.5.1. 2026.5.1 ships office-corruption and security fixes; nginx is already 1.31. SSO users must move the SSO plugin to v0.5.0+. (The upgrade-all summary mis-filed this as skipped/up-to-date.)",
"links": [
{
"text": "PR #5 (build 181)",
"url": "https://git.autonomic.zone/recipe-maintainers/cryptpad/pulls/5"
}
]
},
{
"recipe": "discourse",
"body": "0.7.0+3.3.1 → 0.9.0+3.5.0. discourse 3.5.0, redis 7.4 → 8.0, postgres 13 → pgvector pg17 (manual dump/restore per the recipe README), and bitnami → bitnamilegacy after Docker Hub emptied bitnami/discourse. Reconcile with fix PR #1. (183 flaked, 184 green.)",
"links": [
{
"text": "PR #2 (build 184)",
"url": "https://git.autonomic.zone/recipe-maintainers/discourse/pulls/2"
}
]
},
{
"recipe": "ghost",
"body": "6.42.0 → 6.44.0 (no breaking changes) plus a conservative MySQL 8.0 → 8.4 LTS in-place bump with no schema changes. Ready to merge.",
"links": [
{
"text": "PR #4 (build 185)",
"url": "https://git.autonomic.zone/recipe-maintainers/ghost/pulls/4"
}
]
},
{
"recipe": "lasuite-docs",
"body": "0.3.4+v5.1.0 → 0.3.4+v5.2.0. impress v5.2.0 with auto-migration 0027 and two optional new config vars. Clean GREEN.",
"links": [
{
"text": "PR #5 (build 188)",
"url": "https://git.autonomic.zone/recipe-maintainers/lasuite-docs/pulls/5"
}
]
},
{
"recipe": "mattermost-lts",
"body": "10.11.18 → 10.11.19 LTS patch. postgres kept at 15 (16 broke PGDATA). Backup/restore reworked to inline labels, fixing a Swarm config-race. Reconcile with fix PR #1 (the restore-was-a-no-op fix, now folded into #2).",
"links": [
{
"text": "PR #2 (build 196)",
"url": "https://git.autonomic.zone/recipe-maintainers/mattermost-lts/pulls/2"
}
]
},
{
"recipe": "n8n",
"body": "3.3.0+2.23.2 → 3.4.0+2.25.3. Spans n8n 2.24/2.25 with a $jmespath unsafe-token hardening; postgres unchanged at 18; no required migrations. Clean.",
"links": [
{
"text": "PR #5 (build 197)",
"url": "https://git.autonomic.zone/recipe-maintainers/n8n/pulls/5"
}
]
},
{
"recipe": "custom-html",
"body": "1.11.0+1.29.0 → 1.13.0+1.31.1. nginx 1.31.1 CVE batch + alpine/git v2.52.0 — but this one was merged directly into coopcloud upstream, so the mirror was synced and PR #1 closed. No PR to action; the CVE fixes have already landed.",
"links": []
}
]
}