CVEs fixed by this upgrade: 0 identified by the deterministic scan (all 74 gitea CVEs + 2 critical CVEs from 1.27.1, CVE-2026-59774 and CVE-2026-60004, fall outside the 1.27.1→1.27.2 window; 1 unjudged: CVE-2025-68939 STILL-UNKNOWN). Postgres 15.19 fixes 20+ documented CVEs. Gitea 1.27.2 release notes list 7 SECURITY-tagged items (CVE IDs not yet assigned/disclosed).
Dev deploy
Deployed and verified on cc-ci (dev-gitea.ci.commoninternet.net): gitea 1.27.2 starts cleanly, serves healthchecks, no crash loops, no migration errors. Teardown completed.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
## Upgrade
| Service | Image | Current | New |
|---|---|---|---|
| app | gitea/gitea | 1.27.1-rootless | 1.27.2-rootless |
| db | postgres | 15.18 | 15.19 |
**Upstream release notes:**
- gitea/gitea 1.27.1→1.27.2: https://github.com/go-gitea/gitea/releases/tag/v1.27.2 (SECURITY: collaborator access mode fix, external render refactor, pull_request_target reusable workflow fix, markup render refactor, WebAuthn user verification, render highlight fix + large batch of bugfixes)
- postgres 15.18→15.19: https://www.postgresql.org/docs/release/15.19/ (20+ CVEs fixed; no dump/restore needed for 15.X)
**Recommended release command:** `abra recipe release gitea -z`
### Advisory scan
CVEs fixed by this upgrade: 0 identified by the deterministic scan (all 74 gitea CVEs + 2 critical CVEs from 1.27.1, CVE-2026-59774 and CVE-2026-60004, fall outside the 1.27.1→1.27.2 window; 1 unjudged: CVE-2025-68939 STILL-UNKNOWN). Postgres 15.19 fixes 20+ documented CVEs. Gitea 1.27.2 release notes list 7 SECURITY-tagged items (CVE IDs not yet assigned/disclosed).
### Dev deploy
Deployed and verified on cc-ci (dev-gitea.ci.commoninternet.net): gitea 1.27.2 starts cleanly, serves healthchecks, no crash loops, no migration errors. Teardown completed.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Upgrade
Upstream release notes:
Recommended release command:
abra recipe release gitea -zAdvisory scan
CVEs fixed by this upgrade: 0 identified by the deterministic scan (all 74 gitea CVEs + 2 critical CVEs from 1.27.1, CVE-2026-59774 and CVE-2026-60004, fall outside the 1.27.1→1.27.2 window; 1 unjudged: CVE-2025-68939 STILL-UNKNOWN). Postgres 15.19 fixes 20+ documented CVEs. Gitea 1.27.2 release notes list 7 SECURITY-tagged items (CVE IDs not yet assigned/disclosed).
Dev deploy
Deployed and verified on cc-ci (dev-gitea.ci.commoninternet.net): gitea 1.27.2 starts cleanly, serves healthchecks, no crash loops, no migration errors. Teardown completed.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
gitea@2f64ddfa✅ passed → https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1263(summary card unavailable — see the run for details.) full logs · dashboard
Pull request closed