chore: upgrade app to discourse/discourse:2026.7.3 #11

Open
autonomic-bot wants to merge 1 commits from upgrade-3f2384f into main
Owner

Recipe upgrade: discourse 2026.7.2 → 2026.7.3

Security patch on the 2026.7 ESR line (Discourse ships YYYY.M.patch calver). The recipe moved
from bitnamilegacy to the official discourse/discourse image upstream; this PR only bumps the app
image tag. No version label bump — the operator publishes with the release command at the bottom.

Image tag table

service image current new action
app discourse/discourse 2026.7.2 2026.7.3 bumped
db discourse/postgres pg18 pg18 held (already newest)
redis redis 8.10-alpine 8.10-alpine held (already newest)

Held-services rationale:

  • redis — abra reports no newer version for the pinned 8.10-alpine; 8.10.2-alpine exists but
    the recipe intentionally tracks the floating 8.10-alpine minor line, and abra's -m check finds
    no bump. Left as-is.
  • db — discourse/postgres tags are pg<MAJOR> (non-semver), which abra cannot parse
    (WARN unable to parse discourse/postgres … skipping upgrade for db). Direct Docker Hub check
    (2026-09-28) shows the newest tag is pg18, which is what we already pin — no pg19 yet. Held.

Upstream release notes

Upstream release notes: app discourse/discourse 2026.7.2 → 2026.7.3: https://releases.discourse.org/changelog/v2026.7.3/

Sidecars unchanged this PR, so no upstream notes to link for them.

Operator Action Required

This is a security patch release (Discourse's 2026-09-22 intermediate release; 3 new security
fixes, all rated High). Nothing here is a hard break for the recipe boot: Rails migrations run
automatically on first boot of the new image, there are no new/renamed env vars, no compose/config
changes, and no recipe code changes
— the image tag is the whole diff.

The three CVEs fixed by moving to 2026.7.3:

  • CVE-2026-91156 (GHSA-gh4f-qr62-vx8q, CVSS 7.5 High) — Chat MessageBus delivers read-restricted
    messages to unauthorized users.
    On sites where Chat access is restricted by group, a user who can
    view a read-restricted category (but is not allowed to use Chat) could receive that category's chat
    content via the MessageBus live/backlog. Workaround if upgrade is delayed: remove the disallowed
    user from the category, or avoid the affected category/chat combination.
    https://github.com/discourse/discourse/security/advisories/GHSA-gh4f-qr62-vx8q
  • CVE-2026-91157 (GHSA-298h-xgw6-4pv3, CVSS 7.5 High) — Media uploads remain publicly
    accessible after category permissions are restricted.
    Only affects sites with secure uploads
    enabled
    : uploads posted while a category was public keep a public flag and stay reachable by
    anonymous users at their short URLs after the category becomes read-restricted. Workaround if
    upgrade is delayed: download+re-upload affected media through a restricted context, or delete the
    affected uploads. Operators who have ever tightened a category from public → restricted should
    treat this as the priority fix in this release.

    https://github.com/discourse/discourse/security/advisories/GHSA-298h-xgw6-4pv3
  • CVE-2026-91159 (GHSA-f9jx-vv33-4282, CVSS 7.7 High) — Stored oEmbed HTML injection via
    allowlisted iframe.
    A regular user with posting rights could inject attacker-controlled HTML/CSS
    into posts through oEmbed processing (an allowlisted iframe plus sibling elements), enabling
    stored phishing/overlay content. No CSP interaction required. No full workaround short of upgrading
    (optionally trim the iframe allowlist).
    https://github.com/discourse/discourse/security/advisories/GHSA-f9jx-vv33-4282

One advisory could not be version-classified and is recorded as STILL-UNKNOWN, not
unaffected: CVE-2025-53016 (low) — HTML injection in solved posts when display_name_on_posts is
enabled; the advisory publishes no patched version (open-ended < commit range), so this window
cannot be shown to fix it. https://github.com/discourse/discourse/security/advisories/GHSA-48h6-hpp2-357h

Advisory scan: 3 CVEs fixed by this upgrade (CVE-2026-91156/91157/91159, all High) + 1
STILL-UNKNOWN (CVE-2025-53016, low). Release-note reading agrees (changelog "3 security fixes").

Recommended release command

Leave the version label as-is; after this PR merges, publish with:

abra recipe release discourse -z

(patch/security release within the same ESR line → -z. No --dry-run — this performs the real
release: bumps the coop-cloud.${STACK_NAME}.version label, tags, and pushes.)

Verification

  • Direct --chaos deploy of this PR head on the cc-ci swarm (dev-discourse.ci.commoninternet.net)
    converged: discourse/discourse:2026.7.3 booted, compiled CSS, ran migrations, started
    unicorn/pitchfork + supervised sidekiqs, and passed its healthcheck (healthy). Dev deploy torn
    down after inspection.
  • abra recipe lint discourse -C -n: no error-severity failures (pre-existing warnings only:
    R005 semver-like tags for pg18/8.10-alpine, R015 secret-name length).

Guardrails

NOT merged — recipe PR only, for operator review. No cc-ci test/harness changes (DEFAULT mode).

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

## Recipe upgrade: discourse `2026.7.2 → 2026.7.3` Security patch on the **2026.7 ESR** line (Discourse ships `YYYY.M.patch` calver). The recipe moved from bitnamilegacy to the official `discourse/discourse` image upstream; this PR only bumps the app image tag. **No version label bump** — the operator publishes with the release command at the bottom. ### Image tag table | service | image | current | new | action | |---|---|---|---|---| | app | `discourse/discourse` | `2026.7.2` | `2026.7.3` | **bumped** | | db | `discourse/postgres` | `pg18` | `pg18` | held (already newest) | | redis | `redis` | `8.10-alpine` | `8.10-alpine` | held (already newest) | Held-services rationale: - **redis** — abra reports no newer version for the pinned `8.10-alpine`; `8.10.2-alpine` exists but the recipe intentionally tracks the floating `8.10-alpine` minor line, and abra's `-m` check finds no bump. Left as-is. - **db** — `discourse/postgres` tags are `pg<MAJOR>` (non-semver), which abra cannot parse (`WARN unable to parse discourse/postgres … skipping upgrade for db`). Direct Docker Hub check (2026-09-28) shows the newest tag is `pg18`, which is what we already pin — no `pg19` yet. Held. ### Upstream release notes **Upstream release notes:** app `discourse/discourse` 2026.7.2 → 2026.7.3: https://releases.discourse.org/changelog/v2026.7.3/ - GitHub compare (39 commits, release/2026.7 backports): https://github.com/discourse/discourse/compare/v2026.7.2...v2026.7.3 - Registry: https://releases.discourse.org/ (per-version changelogs) - Release announcement (September 2026 monthly release + patches): https://meta.discourse.org/t/september-2026-monthly-release/413037 Sidecars unchanged this PR, so no upstream notes to link for them. ### Operator Action Required This is a **security patch release** (Discourse's 2026-09-22 intermediate release; 3 new security fixes, all rated High). Nothing here is a hard break for the recipe boot: Rails migrations run automatically on first boot of the new image, there are **no new/renamed env vars, no compose/config changes, and no recipe code changes** — the image tag is the whole diff. The three CVEs fixed by moving to 2026.7.3: - **CVE-2026-91156** (GHSA-gh4f-qr62-vx8q, CVSS 7.5 High) — *Chat MessageBus delivers read-restricted messages to unauthorized users.* On sites where Chat access is restricted by group, a user who can view a read-restricted category (but is not allowed to use Chat) could receive that category's chat content via the MessageBus live/backlog. Workaround if upgrade is delayed: remove the disallowed user from the category, or avoid the affected category/chat combination. https://github.com/discourse/discourse/security/advisories/GHSA-gh4f-qr62-vx8q - **CVE-2026-91157** (GHSA-298h-xgw6-4pv3, CVSS 7.5 High) — *Media uploads remain publicly accessible after category permissions are restricted.* Only affects sites with **secure uploads enabled**: uploads posted while a category was public keep a public flag and stay reachable by anonymous users at their short URLs after the category becomes read-restricted. Workaround if upgrade is delayed: download+re-upload affected media through a restricted context, or delete the affected uploads. **Operators who have ever tightened a category from public → restricted should treat this as the priority fix in this release.** https://github.com/discourse/discourse/security/advisories/GHSA-298h-xgw6-4pv3 - **CVE-2026-91159** (GHSA-f9jx-vv33-4282, CVSS 7.7 High) — *Stored oEmbed HTML injection via allowlisted iframe.* A regular user with posting rights could inject attacker-controlled HTML/CSS into posts through oEmbed processing (an allowlisted iframe plus sibling elements), enabling stored phishing/overlay content. No CSP interaction required. No full workaround short of upgrading (optionally trim the iframe allowlist). https://github.com/discourse/discourse/security/advisories/GHSA-f9jx-vv33-4282 One advisory could **not** be version-classified and is recorded as **STILL-UNKNOWN**, not unaffected: **CVE-2025-53016** (low) — HTML injection in solved posts when `display_name_on_posts` is enabled; the advisory publishes no patched version (open-ended `< commit` range), so this window cannot be shown to fix it. https://github.com/discourse/discourse/security/advisories/GHSA-48h6-hpp2-357h Advisory scan: **3 CVEs fixed by this upgrade** (CVE-2026-91156/91157/91159, all High) + 1 STILL-UNKNOWN (CVE-2025-53016, low). Release-note reading agrees (changelog "3 security fixes"). ### Recommended release command Leave the version label as-is; after this PR merges, publish with: ``` abra recipe release discourse -z ``` (patch/security release within the same ESR line → `-z`. **No `--dry-run`** — this performs the real release: bumps the `coop-cloud.${STACK_NAME}.version` label, tags, and pushes.) ### Verification - Direct `--chaos` deploy of this PR head on the cc-ci swarm (`dev-discourse.ci.commoninternet.net`) converged: `discourse/discourse:2026.7.3` booted, compiled CSS, ran migrations, started unicorn/pitchfork + supervised sidekiqs, and passed its healthcheck (`healthy`). Dev deploy torn down after inspection. - `abra recipe lint discourse -C -n`: no error-severity failures (pre-existing warnings only: R005 semver-like tags for `pg18`/`8.10-alpine`, R015 secret-name length). ### Guardrails **NOT merged** — recipe PR only, for operator review. No cc-ci test/harness changes (DEFAULT mode). Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-09-28 20:27:19 +00:00
chore: upgrade app to discourse/discourse:2026.7.3
cc-ci/testme cc-ci: success
continuous-integration/drone/pr Build was killed
3f2384fd0e
autonomic-bot requested review from trav 2026-09-28 20:27:19 +00:00
autonomic-bot requested review from notplants 2026-09-28 20:27:19 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — discourse @ 3f2384fd ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `discourse` @ `3f2384fd` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/15/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/15) [![level](https://ci.autonomic.zone/runs/15/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/15) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/15) · [dashboard](https://ci.autonomic.zone/)
Some required checks failed
cc-ci/testme cc-ci: success
continuous-integration/drone/pr Build was killed
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin upgrade-3f2384f:upgrade-3f2384f
git checkout upgrade-3f2384f
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/discourse#11