Files
cc-ci-orchestrator/cc-ci-plan/upstream/n8n.md
T
autonomic-bot 3307bdb0fe advisory-scan: separate benign source absence from real failures; fix pgautoupgrade URLs
Two refinements found by running the scan across all 14 recipes of the 2026-08-07 run:

1. A repo with no advisory feed returns HTTP 404 on /security-advisories (e.g. the
   pgautoupgrade sidecar image). That is a BENIGN ABSENCE, not a failed check.
   Likewise registry entries that are TEMPLATE urls for humans
   (…/changelog/v<VERSION>/, …/<vX.Y.Z>/…) are documentation, not fetchable.
   Counting either as a failure pushed most recipes to '?', which would make the
   unknown-vs-clean distinction meaningless again — the exact signal the ? exists to
   preserve. Both are now recorded in sources_benign; only genuine errors (rate
   limit, network, 5xx, wrong URL) land in sources_failed.

2. upstream/*.md pointed at github.com/pgautoupgrade/pgautoupgrade, which 404s —
   the repo is pgautoupgrade/docker-pgautoupgrade. Corrected in n8n, lasuite-docs,
   lasuite-drive, lasuite-meet. A 404ing registry URL means we were not scanning a
   source we believed we were.

Effect on the 2026-08-07 data: recipes with genuine failed sources 5 -> 3 (the
remainder are really unreachable vendor pages). CVE counts unchanged where they
were already sound: discourse 130, gitea 2, plausible 1.
2026-08-10 18:45:45 +00:00

53 lines
4.3 KiB
Markdown

# Upstream sources — n8n
| service | image | source repo | releases / changelog |
|---------|-------|-------------|----------------------|
| app | n8nio/n8n | https://github.com/n8n-io/n8n | https://github.com/n8n-io/n8n/releases |
| db | pgautoupgrade/pgautoupgrade | https://github.com/pgautoupgrade/docker-pgautoupgrade | https://hub.docker.com/r/pgautoupgrade/pgautoupgrade/tags |
## Standing notes
- pgautoupgrade uses a non-standard tag scheme (e.g. `17-alpine`, `18-alpine`) mapping to the TARGET
Postgres major version. `18-alpine` = upgrade-on-start to Postgres 18. The compose.postgres.yml
controls this image; the main compose.yml uses only `n8nio/n8n` (sqlite mode).
- n8n 2.x: standard rolling upgrade is safe between 2.x versions; DB migrations run automatically on startup.
Confirmed live on cc-ci 2026-07-15 (2.27.2 -> 2.31.0, sqlite mode): all TypeORM migrations completed
cleanly on boot, editor served HTTP 200 immediately after.
- The n8n Docker image on Docker Hub uses plain semver tags (e.g. `2.25.3`); no `-stable` suffix needed.
- `https://docs.n8n.io/release-notes/` now 404s (checked 2026-07-15) -- n8n appears to have dropped the
docs-site changelog. Use GitHub Releases instead: https://github.com/n8n-io/n8n/releases (tag format
`n8n@<version>`, e.g. `n8n@2.31.0`) -- this is the canonical source now.
- 2.31.0 shipped "private credentials enabled by default" (UI renamed to "end-user credentials") and a
Notion node API migration -- functional/UX changes worth a heads-up to the operator, not deployment
blockers (no compose/env/migration impact).
- 2.32.0 (minor, 2026-06-xx): Instance AI / AI Agent builder + core bug fixes. No breaking changes, no
`N8N_*` env renames, no required manual migration. 2.32.1-2.32.7 = patch bugfixes (AI Agent preview
rename to "V1", agent channel credential setup, Instance AI follow-up-loop guard, AI Assistant
verification LLM fallback). Confirmed live on cc-ci 2026-07-24 (2.31.0 -> 2.32.4): TypeORM migrations
clean, editor served HTTPS 200.
- 2.33.0 (minor, 2026-07-28; GitHub release marked "Pre-release" but the 2.33.x line stabilized --
2.33.3 carries the "Latest" badge): features = admin-managed instance credentials, workflow review
requests + publish/unpublish public API endpoints, **API deprecation of workflow activate/deactivate
public API endpoints** (replaced by publish/unpublish; old endpoints still work but deprecated -- flag
for operators who automate via the public API), new OPTIONAL env `N8N_SCHEDULER_MAX_ATTEMPTS`
(scheduler dead-letter threshold), OpenTelemetry config API, Microsoft Excel (SharePoint) node, custom
OAuth scopes for Google/Microsoft creds. `core: Prevent concurrent instance startups from racing
database migrations` is a relevant migration-safety fix. No breaking compose/config changes; no
required operator action for the recipe. 2.33.1-2.33.3 = patch bugfixes (2.33.3: security-audit risk
reporter import + MCP server trigger execution-data save).
- 2.34.0 (2026-08-04, marked **Pre-release** on GitHub) is a larger minor (Agent management in
instance MCP, LDAP/OIDC SSO config API, editor OIDC logout, durable-scheduler misfire policy, etc.).
The GitHub release body lists mostly "Bug Fixes" (core task-broker/runner resilience, SSE/OTel fixes,
editor OAuth/credential/agent-credential fixes); no breaking compose/env/migration changes, no
`N8N_*` env renames. No required operator action for the recipe.
- 2.33.4 (2026-08-05, patch): core task-broker resilience when a runner dies + recover unresponsive
task runners; template "see all" tracking; skip redundant workflow-edit approval in AI Assistant.
- 2.33.5 (2026-08-06, carries the **Latest** badge as of this run): single editor bugfix (focus
Markdown editor input before toolbar).
- 2.34.1 (2026-08-05, Pre-release): core recover unresponsive task runners + editor agent-capability
chip spacing.
- 2.34.2 (2026-08-06, Pre-release): editor bugfixes (focus Markdown editor input before toolbar; show
agent tool credentials above configuration).
- 2026-08-07 run: operator directed 2.33.3 -> 2.34.2 (the newest). The whole 2.34.x line is still
marked Pre-release on GitHub (2.33.5 holds the Latest badge); flagged in the PR body. No breaking
changes across 2.33.3 -> 2.34.2; rolling upgrade safe (TypeORM migrations auto-run on boot).