Upgrade discourse app image 2026.7.1 → 2026.7.2 (security/patch intermediate on the current 2026.7 ESR line, released 2026-08-25). Re-verified 2026-09-18: upstream main unchanged (5878b3ed), this PR still the only upgrade work; live in-place deploy + !testme re-run below.
Image-tag table
service
image
upstream main (old)
new
app
discourse/discourse
2026.7.1
2026.7.2
db
discourse/postgres
pg18
pg18 (unchanged — non-semver pg<MAJOR> tag; pg18 still newest on Docker Hub, re-checked 2026-09-18; pg-major bumps are an operator decision)
redis
redis
8.10-alpine
8.10-alpine (unchanged — abra: up to date)
Upstream release notes
Upstream release notes: app 2026.7.1→2026.7.2: https://releases.discourse.org/changelog/v2026.7.2/
(43 changes: 8 security-fix groups, incl. hidden post-revision exposure, iframe allowlist/userinfo bypasses, embed-URL escaping, chat-history scoping, stored-XSS in video placeholder; plus 1 optional feature livestream_allowed_hosts site setting — optional; no .hbs change).
Security content (advisory scan 2026-09-18, union with the vendor changelog): 8 CVEs fixed by this window — CVE-2026-91119, -91120, -91121, -91132, -91133, -91134 (medium) and CVE-2026-91122, -91123 (high), all carrying 2026.7.2 in their patched ranges (GHSA-pv3p-p3m9-v8v3, GHSA-h7cg-2vww-m45c, GHSA-34rh-wjfv-65gq, GHSA-8m44-f6g9-7cg7, GHSA-6pwj-wgg8-4rjc, GHSA-4q3q-hph3-3rvp, GHSA-8hxh-573g-52gx, GHSA-54vw-chv3-wjpv) — matching the vendor's "8 security fixes" exactly. Plus 1 STILL-UNKNOWN low (CVE-2025-53016, GHSA-48h6-hpp2-357h: no published patched version, fix commit not in the public repo) — not counted as fixed, not read as unaffected.
Operator action required
None beyond a normal app deployment. Patch on the already-running 2026.7 ESR line: no new/renamed config, no breaking changes, no manual migrations (Rails db:migrate runs automatically on boot via the official image; discourse/postgres auto-upgrades the cluster in place).
Recommended release (operator, after merge — the version label is intentionally NOT bumped in this PR)
abra recipe release discourse -z
→ publishes 1.1.1+2026.7.2 (patch: security intermediate on the current ESR line).
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
Upgrade discourse app image `2026.7.1` → `2026.7.2` (security/patch intermediate on the current **2026.7 ESR** line, released 2026-08-25). Re-verified 2026-09-18: upstream main unchanged (`5878b3ed`), this PR still the only upgrade work; live in-place deploy + `!testme` re-run below.
## Image-tag table
| service | image | upstream main (old) | new |
|---------|-------|---------------------|-----|
| app | discourse/discourse | 2026.7.1 | **2026.7.2** |
| db | discourse/postgres | pg18 | pg18 (unchanged — non-semver `pg<MAJOR>` tag; pg18 still newest on Docker Hub, re-checked 2026-09-18; pg-major bumps are an operator decision) |
| redis | redis | 8.10-alpine | 8.10-alpine (unchanged — abra: up to date) |
## Upstream release notes
**Upstream release notes:** app 2026.7.1→2026.7.2: https://releases.discourse.org/changelog/v2026.7.2/
(43 changes: 8 security-fix groups, incl. hidden post-revision exposure, iframe allowlist/userinfo bypasses, embed-URL escaping, chat-history scoping, stored-XSS in video placeholder; plus 1 optional feature `livestream_allowed_hosts` site setting — optional; no `.hbs` change).
- redis 8.10-alpine (unchanged): https://raw.githubusercontent.com/redis/redis/8.0/00-RELEASENOTES
- discourse/postgres pg18 (unchanged): https://github.com/discourse/discourse-postgres
**Security content (advisory scan 2026-09-18, union with the vendor changelog): 8 CVEs fixed by this window — CVE-2026-91119, -91120, -91121, -91132, -91133, -91134 (medium) and CVE-2026-91122, -91123 (high), all carrying `2026.7.2` in their patched ranges (GHSA-pv3p-p3m9-v8v3, GHSA-h7cg-2vww-m45c, GHSA-34rh-wjfv-65gq, GHSA-8m44-f6g9-7cg7, GHSA-6pwj-wgg8-4rjc, GHSA-4q3q-hph3-3rvp, GHSA-8hxh-573g-52gx, GHSA-54vw-chv3-wjpv) — matching the vendor's "8 security fixes" exactly. Plus 1 STILL-UNKNOWN low (CVE-2025-53016, GHSA-48h6-hpp2-357h: no published patched version, fix commit not in the public repo) — not counted as fixed, not read as unaffected.**
## Operator action required
None beyond a normal app deployment. Patch on the already-running 2026.7 ESR line: no new/renamed config, no breaking changes, no manual migrations (Rails `db:migrate` runs automatically on boot via the official image; `discourse/postgres` auto-upgrades the cluster in place).
## Recommended release (operator, after merge — the version label is intentionally NOT bumped in this PR)
abra recipe release discourse -z
→ publishes `1.1.1+2026.7.2` (patch: security intermediate on the current ESR line).
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Upgrade discourse app image
2026.7.1→2026.7.2(security/patch intermediate on the current 2026.7 ESR line, released 2026-08-25). Re-verified 2026-09-18: upstream main unchanged (5878b3ed), this PR still the only upgrade work; live in-place deploy +!testmere-run below.Image-tag table
pg<MAJOR>tag; pg18 still newest on Docker Hub, re-checked 2026-09-18; pg-major bumps are an operator decision)Upstream release notes
Upstream release notes: app 2026.7.1→2026.7.2: https://releases.discourse.org/changelog/v2026.7.2/
(43 changes: 8 security-fix groups, incl. hidden post-revision exposure, iframe allowlist/userinfo bypasses, embed-URL escaping, chat-history scoping, stored-XSS in video placeholder; plus 1 optional feature
livestream_allowed_hostssite setting — optional; no.hbschange).Security content (advisory scan 2026-09-18, union with the vendor changelog): 8 CVEs fixed by this window — CVE-2026-91119, -91120, -91121, -91132, -91133, -91134 (medium) and CVE-2026-91122, -91123 (high), all carrying
2026.7.2in their patched ranges (GHSA-pv3p-p3m9-v8v3, GHSA-h7cg-2vww-m45c, GHSA-34rh-wjfv-65gq, GHSA-8m44-f6g9-7cg7, GHSA-6pwj-wgg8-4rjc, GHSA-4q3q-hph3-3rvp, GHSA-8hxh-573g-52gx, GHSA-54vw-chv3-wjpv) — matching the vendor's "8 security fixes" exactly. Plus 1 STILL-UNKNOWN low (CVE-2025-53016, GHSA-48h6-hpp2-357h: no published patched version, fix commit not in the public repo) — not counted as fixed, not read as unaffected.Operator action required
None beyond a normal app deployment. Patch on the already-running 2026.7 ESR line: no new/renamed config, no breaking changes, no manual migrations (Rails
db:migrateruns automatically on boot via the official image;discourse/postgresauto-upgrades the cluster in place).Recommended release (operator, after merge — the version label is intentionally NOT bumped in this PR)
abra recipe release discourse -z
→ publishes
1.1.1+2026.7.2(patch: security intermediate on the current ESR line).Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
cc-ci: failed to start a CI run (see bridge logs).
!testme
🌻 cc-ci —
discourse@89420d3f✅ passed → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1303(summary card unavailable — see the run for details.) full logs · dashboard
!testme
🌻 cc-ci —
discourse@89420d3f✅ passed → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1305(summary card unavailable — see the run for details.) full logs · dashboard
!testme
🌻 cc-ci —
discourse@89420d3f✅ passedfull logs · dashboard
!testme
🌻 cc-ci —
discourse@89420d3f✅ passedfull logs · dashboard