v3.2.1 + v3.2.2 are bug-fix-only releases: sync connection-pool exhaustion, search modal fixes, partner assets on people page, person merge, server auto-VACUUM after TypeORM migrations (v3.2.1); reassign-faces fix that skips other users' faces (v3.2.2). No breaking changes, no new/renamed config, no DB scheme change — TypeORM migrations auto-run on boot.
service
image
current
new
app
ghcr.io/immich-app/immich-server
v3.2.0
v3.2.2
immich-machine-learning
ghcr.io/immich-app/immich-machine-learning
v3.2.0
v3.2.2
redis
docker.io/valkey/valkey
9@sha256:70739f85…
unchanged — identical to immich v3.2.2's official pin (still resolvable; the live 9 tag has drifted to 9.1.2 but we keep immich's tested 9.1.1 pin, per the established precedent)
unchanged — identical to immich v3.2.2's official pin; live tag digest re-verified via docker buildx imagetools inspect = the pin (not stale). No newer tag on the same PG14+VectorChord0.4.3+pgvectors0.2.0 scheme is shipped by immich v3.2.2 — do NOT jump to pg18/VectorChord 0.5.x (unsupported)
example.env @ v3.2.2 is byte-identical to v3.2.0 — no .env.sample change needed.
Direct --chaos deploy of this exact commit on the cc-ci swarm: all 4 services converged 1/1, TypeORM migrations ran clean, app healthcheck healthy (RestartCount=0), web UI served HTTP 200 via traefik, running container digest verified = the ghcr immich-server:v3.2.2 manifest (sha256:79cc1623…); machine-learning healthy (Application startup complete, server logged "Machine learning server became healthy"). Dev deploy torn down + verified nothing leaked afterwards.
Advisory scan (GitHub security-advisories API + vendor release pages + OSV, union with release-note reading): 0 CVEs fixed by this upgrade (v3.2.1/v3.2.2 name no CVEs). For the record: valkey CVE-2026-56684 / CVE-2026-63639 were fixed in valkey 9.1.1 (2026-07-21) — already covered by this recipe's pinned valkey; valkey CVE-2026-25243 (zipmap RESTORE) is named only in valkey 7.2.14's notes — whether 9.1.1's related zipmap hardening (PR #3920) covers it is unverified, recorded as still-unknown. Scan had failed GitHub-advisory sources (rate-limited), so the deterministic count is a floor; release-note reading found no additional CVEs.
!testme (real cc-ci recipe CI) runs below — results in this PR.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
## Upgrade: immich v3.2.0 → v3.2.2 (bug-fix-only patches)
v3.2.1 + v3.2.2 are bug-fix-only releases: sync connection-pool exhaustion, search modal fixes, partner assets on people page, person merge, **server auto-VACUUM after TypeORM migrations** (v3.2.1); reassign-faces fix that skips other users' faces (v3.2.2). No breaking changes, no new/renamed config, no DB scheme change — TypeORM migrations auto-run on boot.
| service | image | current | new |
|---|---|---|---|
| app | ghcr.io/immich-app/immich-server | v3.2.0 | **v3.2.2** |
| immich-machine-learning | ghcr.io/immich-app/immich-machine-learning | v3.2.0 | **v3.2.2** |
| redis | docker.io/valkey/valkey | 9@sha256:70739f85… | unchanged — identical to immich v3.2.2's official pin (still resolvable; the live `9` tag has drifted to 9.1.2 but we keep immich's *tested* 9.1.1 pin, per the established precedent) |
| database | ghcr.io/immich-app/postgres | 14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357… | unchanged — identical to immich v3.2.2's official pin; live tag digest re-verified via `docker buildx imagetools inspect` = the pin (not stale). No newer tag on the same PG14+VectorChord0.4.3+pgvectors0.2.0 scheme is shipped by immich v3.2.2 — do NOT jump to pg18/VectorChord 0.5.x (unsupported) |
`example.env` @ v3.2.2 is byte-identical to v3.2.0 — no `.env.sample` change needed.
**Upstream release notes:** app v3.2.0→v3.2.1: https://github.com/immich-app/immich/releases/tag/v3.2.1
**Upstream release notes:** app v3.2.1→v3.2.2: https://github.com/immich-app/immich/releases/tag/v3.2.2
**Upstream release notes:** immich-machine-learning v3.2.0→v3.2.2 (same monorepo releases): https://github.com/immich-app/immich/releases/tag/v3.2.2
### Operator Action Required
None. TypeORM migrations run automatically on deploy; v3.2.1 additionally runs a VACUUM automatically after migrations.
### Recommended release bump (operator's final step — the version label is intentionally untouched in this PR)
`abra recipe release immich -z`
(patch `-z`: bug-fix-only upstream releases → publishes `1.11.1+v3.2.2`)
### Verification / evidence
- Direct `--chaos` deploy of this exact commit on the cc-ci swarm: all 4 services converged 1/1, TypeORM migrations ran clean, app healthcheck healthy (RestartCount=0), web UI served HTTP 200 via traefik, running container digest verified = the ghcr `immich-server:v3.2.2` manifest (`sha256:79cc1623…`); machine-learning healthy (`Application startup complete`, server logged "Machine learning server became healthy"). Dev deploy torn down + verified nothing leaked afterwards.
- Advisory scan (GitHub security-advisories API + vendor release pages + OSV, union with release-note reading): **0 CVEs fixed by this upgrade** (v3.2.1/v3.2.2 name no CVEs). For the record: valkey CVE-2026-56684 / CVE-2026-63639 were fixed in valkey 9.1.1 (2026-07-21) — already covered by this recipe's pinned valkey; valkey CVE-2026-25243 (zipmap RESTORE) is named only in valkey 7.2.14's notes — whether 9.1.1's related zipmap hardening (PR #3920) covers it is unverified, recorded as still-unknown. Scan had failed GitHub-advisory sources (rate-limited), so the deterministic count is a floor; release-note reading found no additional CVEs.
- `!testme` (real cc-ci recipe CI) runs below — results in this PR.
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Upgrade: immich v3.2.0 → v3.2.2 (bug-fix-only patches)
v3.2.1 + v3.2.2 are bug-fix-only releases: sync connection-pool exhaustion, search modal fixes, partner assets on people page, person merge, server auto-VACUUM after TypeORM migrations (v3.2.1); reassign-faces fix that skips other users' faces (v3.2.2). No breaking changes, no new/renamed config, no DB scheme change — TypeORM migrations auto-run on boot.
9tag has drifted to 9.1.2 but we keep immich's tested 9.1.1 pin, per the established precedent)docker buildx imagetools inspect= the pin (not stale). No newer tag on the same PG14+VectorChord0.4.3+pgvectors0.2.0 scheme is shipped by immich v3.2.2 — do NOT jump to pg18/VectorChord 0.5.x (unsupported)example.env@ v3.2.2 is byte-identical to v3.2.0 — no.env.samplechange needed.Upstream release notes: app v3.2.0→v3.2.1: https://github.com/immich-app/immich/releases/tag/v3.2.1
Upstream release notes: app v3.2.1→v3.2.2: https://github.com/immich-app/immich/releases/tag/v3.2.2
Upstream release notes: immich-machine-learning v3.2.0→v3.2.2 (same monorepo releases): https://github.com/immich-app/immich/releases/tag/v3.2.2
Operator Action Required
None. TypeORM migrations run automatically on deploy; v3.2.1 additionally runs a VACUUM automatically after migrations.
Recommended release bump (operator's final step — the version label is intentionally untouched in this PR)
abra recipe release immich -z(patch
-z: bug-fix-only upstream releases → publishes1.11.1+v3.2.2)Verification / evidence
--chaosdeploy of this exact commit on the cc-ci swarm: all 4 services converged 1/1, TypeORM migrations ran clean, app healthcheck healthy (RestartCount=0), web UI served HTTP 200 via traefik, running container digest verified = the ghcrimmich-server:v3.2.2manifest (sha256:79cc1623…); machine-learning healthy (Application startup complete, server logged "Machine learning server became healthy"). Dev deploy torn down + verified nothing leaked afterwards.!testme(real cc-ci recipe CI) runs below — results in this PR.Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
immich@dcef16c5✅ passedfull logs · dashboard
Auto-closed by cc-ci canonical sweep: its changes are already in upstream main (merged upstream); mirror main re-synced
Pull request closed