Files
cc-ci-orchestrator/cc-ci-plan/upstream/n8n.md
T
autonomic-bot 3307bdb0fe advisory-scan: separate benign source absence from real failures; fix pgautoupgrade URLs
Two refinements found by running the scan across all 14 recipes of the 2026-08-07 run:

1. A repo with no advisory feed returns HTTP 404 on /security-advisories (e.g. the
   pgautoupgrade sidecar image). That is a BENIGN ABSENCE, not a failed check.
   Likewise registry entries that are TEMPLATE urls for humans
   (…/changelog/v<VERSION>/, …/<vX.Y.Z>/…) are documentation, not fetchable.
   Counting either as a failure pushed most recipes to '?', which would make the
   unknown-vs-clean distinction meaningless again — the exact signal the ? exists to
   preserve. Both are now recorded in sources_benign; only genuine errors (rate
   limit, network, 5xx, wrong URL) land in sources_failed.

2. upstream/*.md pointed at github.com/pgautoupgrade/pgautoupgrade, which 404s —
   the repo is pgautoupgrade/docker-pgautoupgrade. Corrected in n8n, lasuite-docs,
   lasuite-drive, lasuite-meet. A 404ing registry URL means we were not scanning a
   source we believed we were.

Effect on the 2026-08-07 data: recipes with genuine failed sources 5 -> 3 (the
remainder are really unreachable vendor pages). CVE counts unchanged where they
were already sound: discourse 130, gitea 2, plausible 1.
2026-08-10 18:45:45 +00:00

4.3 KiB

Upstream sources — n8n

service image source repo releases / changelog
app n8nio/n8n https://github.com/n8n-io/n8n https://github.com/n8n-io/n8n/releases
db pgautoupgrade/pgautoupgrade https://github.com/pgautoupgrade/docker-pgautoupgrade https://hub.docker.com/r/pgautoupgrade/pgautoupgrade/tags

Standing notes

  • pgautoupgrade uses a non-standard tag scheme (e.g. 17-alpine, 18-alpine) mapping to the TARGET Postgres major version. 18-alpine = upgrade-on-start to Postgres 18. The compose.postgres.yml controls this image; the main compose.yml uses only n8nio/n8n (sqlite mode).
  • n8n 2.x: standard rolling upgrade is safe between 2.x versions; DB migrations run automatically on startup. Confirmed live on cc-ci 2026-07-15 (2.27.2 -> 2.31.0, sqlite mode): all TypeORM migrations completed cleanly on boot, editor served HTTP 200 immediately after.
  • The n8n Docker image on Docker Hub uses plain semver tags (e.g. 2.25.3); no -stable suffix needed.
  • https://docs.n8n.io/release-notes/ now 404s (checked 2026-07-15) -- n8n appears to have dropped the docs-site changelog. Use GitHub Releases instead: https://github.com/n8n-io/n8n/releases (tag format n8n@<version>, e.g. n8n@2.31.0) -- this is the canonical source now.
  • 2.31.0 shipped "private credentials enabled by default" (UI renamed to "end-user credentials") and a Notion node API migration -- functional/UX changes worth a heads-up to the operator, not deployment blockers (no compose/env/migration impact).
  • 2.32.0 (minor, 2026-06-xx): Instance AI / AI Agent builder + core bug fixes. No breaking changes, no N8N_* env renames, no required manual migration. 2.32.1-2.32.7 = patch bugfixes (AI Agent preview rename to "V1", agent channel credential setup, Instance AI follow-up-loop guard, AI Assistant verification LLM fallback). Confirmed live on cc-ci 2026-07-24 (2.31.0 -> 2.32.4): TypeORM migrations clean, editor served HTTPS 200.
  • 2.33.0 (minor, 2026-07-28; GitHub release marked "Pre-release" but the 2.33.x line stabilized -- 2.33.3 carries the "Latest" badge): features = admin-managed instance credentials, workflow review requests + publish/unpublish public API endpoints, API deprecation of workflow activate/deactivate public API endpoints (replaced by publish/unpublish; old endpoints still work but deprecated -- flag for operators who automate via the public API), new OPTIONAL env N8N_SCHEDULER_MAX_ATTEMPTS (scheduler dead-letter threshold), OpenTelemetry config API, Microsoft Excel (SharePoint) node, custom OAuth scopes for Google/Microsoft creds. core: Prevent concurrent instance startups from racing database migrations is a relevant migration-safety fix. No breaking compose/config changes; no required operator action for the recipe. 2.33.1-2.33.3 = patch bugfixes (2.33.3: security-audit risk reporter import + MCP server trigger execution-data save).
  • 2.34.0 (2026-08-04, marked Pre-release on GitHub) is a larger minor (Agent management in instance MCP, LDAP/OIDC SSO config API, editor OIDC logout, durable-scheduler misfire policy, etc.). The GitHub release body lists mostly "Bug Fixes" (core task-broker/runner resilience, SSE/OTel fixes, editor OAuth/credential/agent-credential fixes); no breaking compose/env/migration changes, no N8N_* env renames. No required operator action for the recipe.
  • 2.33.4 (2026-08-05, patch): core task-broker resilience when a runner dies + recover unresponsive task runners; template "see all" tracking; skip redundant workflow-edit approval in AI Assistant.
  • 2.33.5 (2026-08-06, carries the Latest badge as of this run): single editor bugfix (focus Markdown editor input before toolbar).
  • 2.34.1 (2026-08-05, Pre-release): core recover unresponsive task runners + editor agent-capability chip spacing.
  • 2.34.2 (2026-08-06, Pre-release): editor bugfixes (focus Markdown editor input before toolbar; show agent tool credentials above configuration).
  • 2026-08-07 run: operator directed 2.33.3 -> 2.34.2 (the newest). The whole 2.34.x line is still marked Pre-release on GitHub (2.33.5 holds the Latest badge); flagged in the PR body. No breaking changes across 2.33.3 -> 2.34.2; rolling upgrade safe (TypeORM migrations auto-run on boot).