re-verify (no diff; already upstream): discourse 2026.7.2 — released 1.1.1+2026.7.2 #10

Closed
autonomic-bot wants to merge 0 commits from upgrade-d1f9b66 into main
Owner

This PR intentionally carries NO diff (head d1f9b66 == main tip) — it exists as this week's
!testme verification vehicle only.

What happened (2026-09-21, mid-run)

While this week's /recipe-upgrade discourse run was in its step-2b live check, upstream merged the
2026.7.2 bump and published the release:

  • upstream PR coop-cloud/discourse#19 merged commit 89420d3 (chore: upgrade app to discourse/discourse:2026.7.2) — the exact commit this mirror's PR #9 carried (!testme GREEN last week, drone run 1363)
  • upstream main @ d1f9b66 chore: publish 1.1.1+2026.7.2 release — version label bumped, released
  • mirror PR #9 was therefore auto-closed by the reconcile (its changes are in upstream main — merging would be a no-op)
  • this PR (#10) is the race artifact of that mid-run merge: the graft found head == main and pushed
    the verification branch upgrade-d1f9b66. It will be closed as redundant after the !testme
    below — nothing to merge here.

Image tag changes (now in upstream main / released 1.1.1+2026.7.2)

service image was now
app discourse/discourse 2026.7.1 2026.7.2
db discourse/postgres pg18 pg18 (unchanged — still newest major, no pg19, re-pushed 2026-09-02)
redis redis 8.10-alpine 8.10-alpine (unchanged — latest per abra)

Upstream release notes: app 2026.7.1→2026.7.2: https://releases.discourse.org/changelog/v2026.7.2/

Advisory scan (GitHub advisories API + vendor pages, cc-ci-plan/upstream/discourse.md)

8 CVEs fixed by this upgrade (patched ranges name 2026.7.2): 2 high — CVE-2026-91122
(GHSA-8m44-f6g9-7cg7), CVE-2026-91123 (GHSA-6pwj-wgg8-4rjc); 6 medium — CVE-2026-91119/91120/91121/
91132/91133/91134. 1 low (CVE-2025-53016, GHSA-48h6-hpp2-357h) remains STILL-UNKNOWN: its vulnerable
range is pinned to a commit that no longer resolves in discourse/discourse (GitHub 422), no fix
version published — not counted, not assumed unaffected.

Operator Action Required

None — already merged upstream and released (abra recipe release discourse -z was executed
upstream as d1f9b66; catalogue version 1.1.1+2026.7.2). Same ESR line as 1.1.0+2026.7.1; converges
in place. Verified live on the cc-ci swarm 2026-09-21 (step 2b): in-place chaos redeploy
2026.7.1→2026.7.2 at PR head, migrations + boot clean, /srv/status and / HTTP 200, no restarts;
dev stack torn down cleanly afterwards.

cc @trav @notplants

**This PR intentionally carries NO diff** (head `d1f9b66` == main tip) — it exists as this week's `!testme` verification vehicle only. ## What happened (2026-09-21, mid-run) While this week's `/recipe-upgrade discourse` run was in its step-2b live check, upstream merged the 2026.7.2 bump and published the release: - upstream PR coop-cloud/discourse#19 merged commit 89420d3 (`chore: upgrade app to discourse/discourse:2026.7.2`) — the exact commit this mirror's PR #9 carried (!testme GREEN last week, drone run 1363) - upstream main @ d1f9b66 `chore: publish 1.1.1+2026.7.2 release` — version label bumped, released - mirror PR #9 was therefore auto-closed by the reconcile (its changes are in upstream main — merging would be a no-op) - this PR (#10) is the race artifact of that mid-run merge: the graft found head == main and pushed the verification branch `upgrade-d1f9b66`. It will be closed as redundant after the `!testme` below — nothing to merge here. ## Image tag changes (now in upstream main / released 1.1.1+2026.7.2) | service | image | was | now | |---|---|---|---| | app | discourse/discourse | 2026.7.1 | **2026.7.2** | | db | discourse/postgres | pg18 | pg18 (unchanged — still newest major, no pg19, re-pushed 2026-09-02) | | redis | redis | 8.10-alpine | 8.10-alpine (unchanged — latest per abra) | **Upstream release notes:** app 2026.7.1→2026.7.2: https://releases.discourse.org/changelog/v2026.7.2/ ## Advisory scan (GitHub advisories API + vendor pages, cc-ci-plan/upstream/discourse.md) **8 CVEs fixed by this upgrade** (patched ranges name 2026.7.2): 2 high — CVE-2026-91122 (GHSA-8m44-f6g9-7cg7), CVE-2026-91123 (GHSA-6pwj-wgg8-4rjc); 6 medium — CVE-2026-91119/91120/91121/ 91132/91133/91134. 1 low (CVE-2025-53016, GHSA-48h6-hpp2-357h) remains STILL-UNKNOWN: its vulnerable range is pinned to a commit that no longer resolves in discourse/discourse (GitHub 422), no fix version published — not counted, not assumed unaffected. ## Operator Action Required None — already merged upstream and released (`abra recipe release discourse -z` was executed upstream as d1f9b66; catalogue version 1.1.1+2026.7.2). Same ESR line as 1.1.0+2026.7.1; converges in place. Verified live on the cc-ci swarm 2026-09-21 (step 2b): in-place chaos redeploy 2026.7.1→2026.7.2 at PR head, migrations + boot clean, `/srv/status` and `/` HTTP 200, no restarts; dev stack torn down cleanly afterwards. cc @trav @notplants
autonomic-bot requested review from trav 2026-09-21 16:48:46 +00:00
autonomic-bot requested review from notplants 2026-09-21 16:48:46 +00:00
autonomic-bot changed title from chore: upgrade app to discourse/discourse:2026.7.2 to re-verify (no diff; already upstream): discourse 2026.7.2 — released 1.1.1+2026.7.2 2026-09-21 16:51:11 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — discourse @ d1f9b66a ❌ failure → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1377

(summary card unavailable — see the run for details.) full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `discourse` @ `d1f9b66a` ❌ **failure** → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1377 _(summary card unavailable — see the run for details.)_ [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1377) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

!testme

!testme
Author
Owner

cc-ci: failed to start a CI run (see bridge logs).

cc-ci: failed to start a CI run (see bridge logs).
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — discourse @ d1f9b66a ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `discourse` @ `d1f9b66a` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/2/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/2) [![level](https://ci.autonomic.zone/runs/2/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/2) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/2) · [dashboard](https://ci.autonomic.zone/)
Author
Owner

Closing as redundant — this PR intentionally carried no diff (head d1f9b66 == main tip) and there is nothing to merge.

Why this PR existed

During this week's /recipe-upgrade discourse run (2026-09-21), upstream merged the 2026.7.2 bump and published the release mid-run: coop-cloud/discourse#19 merged commit 89420d3 (the exact commit mirror PR #9 carried, !testme GREEN last week on drone run 1363), then d1f9b66 published 1.1.1+2026.7.2. The mirror reconcile therefore auto-closed PR #9 (its changes are in upstream main — merging would be a no-op), and this PR was pushed as the verification vehicle for the same tree.

This week's verification — GREEN

  • cc-ci !testme run (drone build 2, https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/2 — full suite on this head): all tiers pass — install / upgrade (1.1.0+2026.7.1 → head) / backup / restore / custom — clean_teardown, no_secret_leak, level 5, lint pass. (A first attempt, build 1377 on the pre-cutover drone, was SIGTERMed mid-restore by the drone-stack domain-cutover reconcile at 16:59 — all tiers that completed there were green too; not a recipe issue.)
  • Step-2b live check (cc-ci swarm, earlier today): in-place --chaos redeploy 2026.7.1 → 2026.7.2 at the PR head, migrations + boot clean, /srv/status and / HTTP 200, no restarts; dev stack torn down cleanly.
  • Advisory scan: 8 CVEs fixed by 2026.7.2 (2 high: CVE-2026-91122, CVE-2026-91123; 6 medium), 1 low STILL-UNKNOWN (CVE-2025-53016 — vulnerable range pinned to a commit that no longer resolves upstream; not counted, not assumed unaffected).

Operator notes

  • Release is already published upstream (1.1.1+2026.7.2); no further recipe action needed.
  • Infra (not recipe): the gitea commit-status API currently 500s, so the bridge's cc-ci/testme commit status for this run could not be posted (the PR comment above is the result record); 4 zombie pending push builds from the cutover window remain in the removed drone_ci_commoninternet_net DB volume; warm-gitea canonical was crash-looping (0/1) around 17:45.
  • Nothing was merged by the agent; upstream merge/release was done upstream, and this PR is closed as a no-op.

cc @trav @notplants

Closing as **redundant** — this PR intentionally carried **no diff** (head `d1f9b66` == main tip) and there is nothing to merge. ## Why this PR existed During this week's `/recipe-upgrade discourse` run (2026-09-21), **upstream merged the 2026.7.2 bump and published the release mid-run**: coop-cloud/discourse#19 merged commit `89420d3` (the exact commit mirror PR #9 carried, !testme GREEN last week on drone run 1363), then `d1f9b66` published **1.1.1+2026.7.2**. The mirror reconcile therefore auto-closed PR #9 (its changes are in upstream main — merging would be a no-op), and this PR was pushed as the verification vehicle for the same tree. ## This week's verification — GREEN - **cc-ci `!testme` run** (drone build 2, https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/2 — full suite on this head): **all tiers pass** — install / upgrade (1.1.0+2026.7.1 → head) / backup / restore / custom — `clean_teardown`, `no_secret_leak`, level 5, lint pass. (A first attempt, build 1377 on the pre-cutover drone, was SIGTERMed mid-restore by the drone-stack domain-cutover reconcile at 16:59 — all tiers that completed there were green too; not a recipe issue.) - **Step-2b live check** (cc-ci swarm, earlier today): in-place `--chaos` redeploy 2026.7.1 → 2026.7.2 at the PR head, migrations + boot clean, `/srv/status` and `/` HTTP 200, no restarts; dev stack torn down cleanly. - **Advisory scan:** 8 CVEs fixed by 2026.7.2 (2 high: CVE-2026-91122, CVE-2026-91123; 6 medium), 1 low STILL-UNKNOWN (CVE-2025-53016 — vulnerable range pinned to a commit that no longer resolves upstream; not counted, not assumed unaffected). ## Operator notes - Release is already published upstream (`1.1.1+2026.7.2`); no further recipe action needed. - Infra (not recipe): the gitea commit-status API currently 500s, so the bridge's `cc-ci/testme` commit status for this run could not be posted (the PR comment above is the result record); 4 zombie `pending` push builds from the cutover window remain in the removed `drone_ci_commoninternet_net` DB volume; `warm-gitea` canonical was crash-looping (0/1) around 17:45. - Nothing was merged by the agent; upstream merge/release was done upstream, and this PR is closed as a no-op. cc @trav @notplants
autonomic-bot closed this pull request 2026-09-21 18:08:59 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/discourse#10