chore: upgrade app to discourse/discourse:2026.7.2 #9

Merged
trav merged 1 commits from upgrade-89420d3 into main 2026-09-21 16:39:16 +00:00
Owner

Upgrade discourse app image 2026.7.1 → 2026.7.2 (security/patch intermediate on the current 2026.7 ESR line, released 2026-08-25). Re-verified 2026-09-18: upstream main unchanged (5878b3ed), this PR still the only upgrade work; live in-place deploy + !testme re-run below.

Image-tag table

service image upstream main (old) new
app discourse/discourse 2026.7.1 2026.7.2
db discourse/postgres pg18 pg18 (unchanged — non-semver pg<MAJOR> tag; pg18 still newest on Docker Hub, re-checked 2026-09-18; pg-major bumps are an operator decision)
redis redis 8.10-alpine 8.10-alpine (unchanged — abra: up to date)

Upstream release notes

Upstream release notes: app 2026.7.1→2026.7.2: https://releases.discourse.org/changelog/v2026.7.2/
(43 changes: 8 security-fix groups, incl. hidden post-revision exposure, iframe allowlist/userinfo bypasses, embed-URL escaping, chat-history scoping, stored-XSS in video placeholder; plus 1 optional feature livestream_allowed_hosts site setting — optional; no .hbs change).

Security content (advisory scan 2026-09-18, union with the vendor changelog): 8 CVEs fixed by this window — CVE-2026-91119, -91120, -91121, -91132, -91133, -91134 (medium) and CVE-2026-91122, -91123 (high), all carrying 2026.7.2 in their patched ranges (GHSA-pv3p-p3m9-v8v3, GHSA-h7cg-2vww-m45c, GHSA-34rh-wjfv-65gq, GHSA-8m44-f6g9-7cg7, GHSA-6pwj-wgg8-4rjc, GHSA-4q3q-hph3-3rvp, GHSA-8hxh-573g-52gx, GHSA-54vw-chv3-wjpv) — matching the vendor's "8 security fixes" exactly. Plus 1 STILL-UNKNOWN low (CVE-2025-53016, GHSA-48h6-hpp2-357h: no published patched version, fix commit not in the public repo) — not counted as fixed, not read as unaffected.

Operator action required

None beyond a normal app deployment. Patch on the already-running 2026.7 ESR line: no new/renamed config, no breaking changes, no manual migrations (Rails db:migrate runs automatically on boot via the official image; discourse/postgres auto-upgrades the cluster in place).

Recommended release (operator, after merge — the version label is intentionally NOT bumped in this PR)

abra recipe release discourse -z

→ publishes 1.1.1+2026.7.2 (patch: security intermediate on the current ESR line).

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

Upgrade discourse app image `2026.7.1` → `2026.7.2` (security/patch intermediate on the current **2026.7 ESR** line, released 2026-08-25). Re-verified 2026-09-18: upstream main unchanged (`5878b3ed`), this PR still the only upgrade work; live in-place deploy + `!testme` re-run below. ## Image-tag table | service | image | upstream main (old) | new | |---------|-------|---------------------|-----| | app | discourse/discourse | 2026.7.1 | **2026.7.2** | | db | discourse/postgres | pg18 | pg18 (unchanged — non-semver `pg<MAJOR>` tag; pg18 still newest on Docker Hub, re-checked 2026-09-18; pg-major bumps are an operator decision) | | redis | redis | 8.10-alpine | 8.10-alpine (unchanged — abra: up to date) | ## Upstream release notes **Upstream release notes:** app 2026.7.1→2026.7.2: https://releases.discourse.org/changelog/v2026.7.2/ (43 changes: 8 security-fix groups, incl. hidden post-revision exposure, iframe allowlist/userinfo bypasses, embed-URL escaping, chat-history scoping, stored-XSS in video placeholder; plus 1 optional feature `livestream_allowed_hosts` site setting — optional; no `.hbs` change). - redis 8.10-alpine (unchanged): https://raw.githubusercontent.com/redis/redis/8.0/00-RELEASENOTES - discourse/postgres pg18 (unchanged): https://github.com/discourse/discourse-postgres **Security content (advisory scan 2026-09-18, union with the vendor changelog): 8 CVEs fixed by this window — CVE-2026-91119, -91120, -91121, -91132, -91133, -91134 (medium) and CVE-2026-91122, -91123 (high), all carrying `2026.7.2` in their patched ranges (GHSA-pv3p-p3m9-v8v3, GHSA-h7cg-2vww-m45c, GHSA-34rh-wjfv-65gq, GHSA-8m44-f6g9-7cg7, GHSA-6pwj-wgg8-4rjc, GHSA-4q3q-hph3-3rvp, GHSA-8hxh-573g-52gx, GHSA-54vw-chv3-wjpv) — matching the vendor's "8 security fixes" exactly. Plus 1 STILL-UNKNOWN low (CVE-2025-53016, GHSA-48h6-hpp2-357h: no published patched version, fix commit not in the public repo) — not counted as fixed, not read as unaffected.** ## Operator action required None beyond a normal app deployment. Patch on the already-running 2026.7 ESR line: no new/renamed config, no breaking changes, no manual migrations (Rails `db:migrate` runs automatically on boot via the official image; `discourse/postgres` auto-upgrades the cluster in place). ## Recommended release (operator, after merge — the version label is intentionally NOT bumped in this PR) abra recipe release discourse -z → publishes `1.1.1+2026.7.2` (patch: security intermediate on the current ESR line). Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-08-28 02:41:57 +00:00
autonomic-bot requested review from trav 2026-08-28 02:41:57 +00:00
autonomic-bot requested review from notplants 2026-08-28 02:41:57 +00:00
Author
Owner

!testme

!testme
Author
Owner

cc-ci: failed to start a CI run (see bridge logs).

cc-ci: failed to start a CI run (see bridge logs).
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — discourse @ 89420d3f ✅ passed → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1303

(summary card unavailable — see the run for details.) full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `discourse` @ `89420d3f` ✅ **passed** → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1303 _(summary card unavailable — see the run for details.)_ [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1303) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — discourse @ 89420d3f ✅ passed → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1305

(summary card unavailable — see the run for details.) full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `discourse` @ `89420d3f` ✅ **passed** → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1305 _(summary card unavailable — see the run for details.)_ [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1305) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — discourse @ 89420d3f ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `discourse` @ `89420d3f` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1347/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1347) [![level](https://ci.commoninternet.net/runs/1347/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1347) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1347) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — discourse @ 89420d3f ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `discourse` @ `89420d3f` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1363/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1363) [![level](https://ci.commoninternet.net/runs/1363/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1363) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1363) · [dashboard](https://ci.commoninternet.net/)
trav merged commit 904e5230c0 into main 2026-09-21 16:39:16 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/discourse#9