5.0 KiB
5.0 KiB
Upstream sources — lasuite-meet
| service | image | source repo | releases / changelog |
|---|---|---|---|
| app | lasuite/meet-frontend | https://github.com/suitenumerique/meet | https://github.com/suitenumerique/meet/releases |
| backend | lasuite/meet-backend | https://github.com/suitenumerique/meet | https://github.com/suitenumerique/meet/releases |
| celery | lasuite/meet-backend | https://github.com/suitenumerique/meet | https://github.com/suitenumerique/meet/releases |
| db | pgautoupgrade/pgautoupgrade | https://github.com/pgautoupgrade/pgautoupgrade | https://github.com/pgautoupgrade/pgautoupgrade/releases |
| redis | redis | https://github.com/redis/redis | https://hub.docker.com/_/redis/tags |
| livekit | livekit/livekit-server | https://github.com/livekit/livekit | https://github.com/livekit/livekit/releases |
| web | nginx | https://github.com/nginx/nginx | https://nginx.org/en/CHANGES |
Standing notes
- meet-frontend, meet-backend (used for both backend + celery services) share the same version tag from the suitenumerique/meet monorepo. Upgrade app, backend, and celery in lockstep.
- AUTO_MIGRATIONS=true means DB migrations run automatically on backend startup. No manual step needed.
- v1.17.0–v1.19.0: no breaking changes documented; feature additions only (participant muting, PiP, S3 recording, API exposure). Standard rolling upgrade applies.
- v1.19.0: security fix for CVE-2026-45409 (idna ≥3.15) — no operator action needed (baked into image).
- Recipe version label convention: 0.X.Y+vA.B.C where A.B.C is the meet version.
- LiveKit version is decoupled from meet version; only bump if explicitly required.
- v1.13.1: removes backwards compatibility for TURN auth without TTL (deprecated in v1.12.0). Operators who never set TURN TTL must add it before upgrading LiveKit to v1.13.x. No new required env vars for standard deployments.
- v1.13.2: patch (Added/Changed/Fixed — Prometheus metrics for join latency, 512 KiB metadata cap, egress v2 api, etc.); no breaking changes within v1.13.x.
- v1.13.3: patch (mock API server for SDK testing, data track schema metadata, whip ingress bitrates, webrtc interop fix for bundled datachannel, WHIP notifier fix); no breaking changes.
- v1.22.0: feature release (purge deleted/pending files, generalized STT API, LiveKit egress_ended fallback for recordings, PiP tile cap/pagination, reject user access tokens on API, dedicated PostHog feature-flag domain, backend analytics). No breaking changes; no new required env vars for the standalone meet recipe.
- v1.23.0: feature release (migrate visio integration to summary API v2, summary feature flag, Sentry monitoring for agents, MuteEveryoneButton admin/owner gate, dep upgrades). ⚠️ Special mention: removed
api/v1code from thesummarysub-project BUT kept meet→summary v1-API compatibility as the DEFAULT —SUMMARY_SERVICE_VERSION: 2is only needed if deploying the latest meet AND summary from the monorepo together. The lasuite-meet recipe deploys meet standalone (no summary service, noSUMMARY_SERVICE_VERSIONenv), so NO operator action is required for this recipe. - v1.24.0: feature release (deprecate
SUMMARY_SERVICE_VERSION=1— only matters when deploying meet+summary together, NOT the standalone recipe; prioritize screen share in PiP; recording admin search by owner email; participant color gradient when camera off; PostHog external-user identification; new OPTIONAL envAUTHENTICATED_PARTICIPANTS_CAN_EDIT_DISPLAY_NAMEdefaultingtrue— setfalseto force SSO display name; mjml v5; info-panel crash fix for unregistered rooms; Outsource Outlook add-on calendar fix; whisper call error handling). No breaking changes / no required migrations / no new required env for the standalone meet recipe. AUTO_MIGRATIONS=true applies any Django migrations on backend startup. Standard rolling upgrade. - livekit v1.13.2/v1.13.3/v1.13.4: patch series within v1.13.x (Prometheus metrics for join latency, mock SDK test API, WHIP ingress bitrates, WEBRTC interop fix for bundled datachannel; v1.13.4 adds SIP mocking, IPv6-exclusion option, forward-stats API method, data-track buffering-under-congestion fix, goroutine-leak fix, pion/ice hang-on-close fix). No breaking changes within v1.13.x; the v1.13.1 TURN-TTL note (only relevant if TURN was ever configured) is the only standing operator action in this line.
- nginx 1.31.3: SECURITY patch release (CVE-2026-42533 heap buffer overflow in
mapwith regex; CVE-2026-60005 uninitialized memory withslice/background cache update; CVE-2026-56434 use-after-free in ssi filter on proxied backend responses). Change: HTTP/2 response header/trailer sizes now bounded byproxy_buffer_size/grpc_buffer_size; external entities disabled in xslt module by default. Bugfixes in HTTP/2 flow control, proxy_v2/ tunnel modules. No required config change for the recipe (nginx serves static frontend + proxies to backend); standard rolling upgrade. - Redis 8.8.0: compatible drop-in upgrade; includes ReJSON module with V5–V7 API exported. No config or persistence-format changes.