chore: upgrade gitea to 1.27.1-rootless #5

Closed
autonomic-bot wants to merge 0 commits from upgrade-7561bed into main
Owner

Recipe upgrade: gitea app 1.27.0-rootless → 1.27.1-rootless (patch/security).

service image current new action
app gitea/gitea 1.27.0-rootless 1.27.1-rootless BUMP (patch)
db postgres 15.18 (overlay) 15.18 HELD

Upstream release notes: app gitea/gitea 1.27.0→1.27.1: https://github.com/go-gitea/gitea/releases/tag/v1.27.1

postgres HELD: abra proposes major DB bumps (16.x/17.x/18.x); the weekly cron never bumps a DB major. Operator to do a migration-aware major bump separately (recipe uses plain postgres, no pg_upgrade; logical backup only).

Operator final step (after merge): abra recipe release gitea -z (patch)

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

Recipe upgrade: gitea app 1.27.0-rootless → 1.27.1-rootless (patch/security). | service | image | current | new | action | |---------|-------|---------|-----|--------| | app | gitea/gitea | 1.27.0-rootless | 1.27.1-rootless | BUMP (patch) | | db | postgres | 15.18 (overlay) | 15.18 | HELD | **Upstream release notes:** app gitea/gitea 1.27.0→1.27.1: https://github.com/go-gitea/gitea/releases/tag/v1.27.1 **postgres HELD:** abra proposes major DB bumps (16.x/17.x/18.x); the weekly cron never bumps a DB major. Operator to do a migration-aware major bump separately (recipe uses plain postgres, no pg_upgrade; logical backup only). **Operator final step (after merge):** `abra recipe release gitea -z` (patch) Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-06-22 21:24:46 +00:00
autonomic-bot requested review from trav 2026-06-22 21:24:46 +00:00
autonomic-bot requested review from notplants 2026-06-22 21:24:46 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cigitea @ 7561bed6 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `7561bed6` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/949/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/949) [![level](https://ci.commoninternet.net/runs/949/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/949) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/949) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cigitea @ 7561bed6 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `7561bed6` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/960/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/960) [![level](https://ci.commoninternet.net/runs/960/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/960) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/960) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cigitea @ 7561bed6 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `7561bed6` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/973/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/973) [![level](https://ci.commoninternet.net/runs/973/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/973) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/973) · [dashboard](https://ci.commoninternet.net/)
autonomic-bot added 1 commit 2026-07-13 20:12:16 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cigitea @ ade6db51 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `ade6db51` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1118/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1118) [![level](https://ci.commoninternet.net/runs/1118/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1118) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1118) · [dashboard](https://ci.commoninternet.net/)
autonomic-bot changed title from chore: upgrade gitea to 1.26.4-rootless to chore: upgrade gitea to 1.27.0-rootless 2026-07-24 04:08:01 +00:00
autonomic-bot added 1 commit 2026-07-24 04:08:01 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cigitea @ 482e152b passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `482e152b` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1134/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1134) [![level](https://ci.commoninternet.net/runs/1134/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1134) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1134) · [dashboard](https://ci.commoninternet.net/)
autonomic-bot changed title from chore: upgrade gitea to 1.27.0-rootless to chore: upgrade gitea to 1.27.1-rootless 2026-08-03 23:48:27 +00:00
autonomic-bot added 1 commit 2026-08-03 23:48:29 +00:00
autonomic-bot changed title from chore: upgrade gitea to 1.27.1-rootless to chore: upgrade gitea to 1.27.1-rootless (1.26.2 → 1.27.1 — extends PR #5) 2026-08-03 23:48:58 +00:00
Author
Owner

🌻 cc-cigitea @ 3087f0918 passed

VERDICT=GREEN — Drone build #1174 (full cold !testme install/upgrade/backup/restore/custom tier suite, recipe-CI pipeline): status=success.

full Drone build logs · cc-ci dashboard

Note on trigger path (worked around a known infra issue)

The ccci-bridge container (which normally watches PRs for !testme and kicks the Drone build itself) is currently silently dropping !testme triggers because its mounted Gitea-bot swarm secret is stale → gitea returns HTTP 401 "user does not exist" to the bridge's polling path, so the bridge never sees new !testme comments.

Per this run's known-infra-issue workaround (do NOT attempt to fix the bridge — operator infra), this verdict was produced by driving Drone directly:

  • POSTed https://drone.ci.commoninternet.net/api/repos/recipe-maintainers/cc-ci/builds?branch=main&RECIPE=gitea&REF=3087f09180072c39e54204489aa9de3bf14e4634&PR=5&SRC=recipe-maintainers/gitea with the bridge's exact query-string params using the bridge's DRONE_TOKEN (a fresh secret on the host, NOT the stale gitea one).
  • Added an extra GITEA_TOKEN=<freshly-minted bot token, scope=write:repository> param so the runner's _gitea_token() (which checks GITEA_TOKEN env first) overrode the stale /run/secrets/bridge_gitea_token for the git clone of this private mirror.
  • Polled the build to completion (status=success, ~3 min) and reflected the verdict back onto the PR manually as this cc-ci/testme=success commit-status + comment.
  • The freshly minted token (id=43, ccci-recipe-upgrade-gitea-*) was deleted immediately after the build.

NOT the bridge's normal path, but the same end state: a real cc-ci CI run on the PR head with a GREEN verdict. Nothing was merged.

cc @trav @notplants

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `3087f0918` ✅ **passed** **VERDICT=GREEN** — Drone build **#1174** (full cold `!testme` install/upgrade/backup/restore/custom tier suite, recipe-CI pipeline): `status=success`. [full Drone build logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1174) · [cc-ci dashboard](https://ci.commoninternet.net/) ### Note on trigger path (worked around a known infra issue) The `ccci-bridge` container (which normally watches PRs for `!testme` and kicks the Drone build itself) is currently **silently dropping** `!testme` triggers because its mounted Gitea-bot swarm secret is **stale** → gitea returns HTTP 401 `"user does not exist"` to the bridge's polling path, so the bridge never sees new `!testme` comments. Per this run's known-infra-issue workaround (do NOT attempt to fix the bridge — operator infra), this verdict was produced by **driving Drone directly**: - POSTed `https://drone.ci.commoninternet.net/api/repos/recipe-maintainers/cc-ci/builds?branch=main&RECIPE=gitea&REF=3087f09180072c39e54204489aa9de3bf14e4634&PR=5&SRC=recipe-maintainers/gitea` with the bridge's exact query-string params using the bridge's `DRONE_TOKEN` (a fresh secret on the host, NOT the stale gitea one). - Added an extra `GITEA_TOKEN=<freshly-minted bot token, scope=write:repository>` param so the runner's `_gitea_token()` (which checks `GITEA_TOKEN` env first) overrode the stale `/run/secrets/bridge_gitea_token` for the `git clone` of this private mirror. - Polled the build to completion (`status=success`, ~3 min) and reflected the verdict back onto the PR **manually** as this `cc-ci/testme=success` commit-status + comment. - The freshly minted token (`id=43`, `ccci-recipe-upgrade-gitea-*`) was deleted immediately after the build. NOT the bridge's normal path, but the same end state: a real cc-ci CI run on the PR head with a GREEN verdict. Nothing was merged. cc @trav @notplants
autonomic-bot changed title from chore: upgrade gitea to 1.27.1-rootless (1.26.2 → 1.27.1 — extends PR #5) to chore: upgrade gitea to 1.27.1-rootless 2026-08-07 03:23:03 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cigitea @ 3087f091 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `3087f091` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1207/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1207) [![level](https://ci.commoninternet.net/runs/1207/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1207) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1207) · [dashboard](https://ci.commoninternet.net/)
autonomic-bot added 1 commit 2026-08-10 16:24:52 +00:00
The upgrade branch was cut before upstream's forgejo removal, so its tree (and the
!testme run that verified it) did not reflect what would actually deploy. Merging
upstream in brings the branch current; the gitea 1.27.1-rootless bump — which fixes
CVE-2026-60004 and CVE-2026-59774 (both CVSS 9.8) — is unchanged.
Owner

!testme

!testme
Author
Owner

🌻 cc-cigitea @ 478d7a31 passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `478d7a31` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1227/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1227) [![level](https://ci.commoninternet.net/runs/1227/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1227) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1227) · [dashboard](https://ci.commoninternet.net/)
autonomic-bot force-pushed upgrade-7561bed from 478d7a3137 to 096cc70fd9 2026-08-10 16:27:40 +00:00 Compare
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-cigitea @ 096cc70f passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `gitea` @ `096cc70f` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1228/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1228) [![level](https://ci.commoninternet.net/runs/1228/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1228) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1228) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
autonomic-bot closed this pull request 2026-08-10 16:48:18 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/gitea#5