chore: upgrade immich-server + immich-machine-learning to v3.2.2 #5

Closed
autonomic-bot wants to merge 1 commits from upgrade-dcef16c into main
Owner

Upgrade: immich v3.2.0 → v3.2.2 (bug-fix-only patches)

v3.2.1 + v3.2.2 are bug-fix-only releases: sync connection-pool exhaustion, search modal fixes, partner assets on people page, person merge, server auto-VACUUM after TypeORM migrations (v3.2.1); reassign-faces fix that skips other users' faces (v3.2.2). No breaking changes, no new/renamed config, no DB scheme change — TypeORM migrations auto-run on boot.

service image current new
app ghcr.io/immich-app/immich-server v3.2.0 v3.2.2
immich-machine-learning ghcr.io/immich-app/immich-machine-learning v3.2.0 v3.2.2
redis docker.io/valkey/valkey 9@sha256:70739f85… unchanged — identical to immich v3.2.2's official pin (still resolvable; the live 9 tag has drifted to 9.1.2 but we keep immich's tested 9.1.1 pin, per the established precedent)
database ghcr.io/immich-app/postgres 14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357… unchanged — identical to immich v3.2.2's official pin; live tag digest re-verified via docker buildx imagetools inspect = the pin (not stale). No newer tag on the same PG14+VectorChord0.4.3+pgvectors0.2.0 scheme is shipped by immich v3.2.2 — do NOT jump to pg18/VectorChord 0.5.x (unsupported)

example.env @ v3.2.2 is byte-identical to v3.2.0 — no .env.sample change needed.

Upstream release notes: app v3.2.0→v3.2.1: https://github.com/immich-app/immich/releases/tag/v3.2.1
Upstream release notes: app v3.2.1→v3.2.2: https://github.com/immich-app/immich/releases/tag/v3.2.2
Upstream release notes: immich-machine-learning v3.2.0→v3.2.2 (same monorepo releases): https://github.com/immich-app/immich/releases/tag/v3.2.2

Operator Action Required

None. TypeORM migrations run automatically on deploy; v3.2.1 additionally runs a VACUUM automatically after migrations.

Recommended release bump (operator's final step — the version label is intentionally untouched in this PR)

abra recipe release immich -z

(patch -z: bug-fix-only upstream releases → publishes 1.11.1+v3.2.2)

Verification / evidence

  • Direct --chaos deploy of this exact commit on the cc-ci swarm: all 4 services converged 1/1, TypeORM migrations ran clean, app healthcheck healthy (RestartCount=0), web UI served HTTP 200 via traefik, running container digest verified = the ghcr immich-server:v3.2.2 manifest (sha256:79cc1623…); machine-learning healthy (Application startup complete, server logged "Machine learning server became healthy"). Dev deploy torn down + verified nothing leaked afterwards.
  • Advisory scan (GitHub security-advisories API + vendor release pages + OSV, union with release-note reading): 0 CVEs fixed by this upgrade (v3.2.1/v3.2.2 name no CVEs). For the record: valkey CVE-2026-56684 / CVE-2026-63639 were fixed in valkey 9.1.1 (2026-07-21) — already covered by this recipe's pinned valkey; valkey CVE-2026-25243 (zipmap RESTORE) is named only in valkey 7.2.14's notes — whether 9.1.1's related zipmap hardening (PR #3920) covers it is unverified, recorded as still-unknown. Scan had failed GitHub-advisory sources (rate-limited), so the deterministic count is a floor; release-note reading found no additional CVEs.
  • !testme (real cc-ci recipe CI) runs below — results in this PR.

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

## Upgrade: immich v3.2.0 → v3.2.2 (bug-fix-only patches) v3.2.1 + v3.2.2 are bug-fix-only releases: sync connection-pool exhaustion, search modal fixes, partner assets on people page, person merge, **server auto-VACUUM after TypeORM migrations** (v3.2.1); reassign-faces fix that skips other users' faces (v3.2.2). No breaking changes, no new/renamed config, no DB scheme change — TypeORM migrations auto-run on boot. | service | image | current | new | |---|---|---|---| | app | ghcr.io/immich-app/immich-server | v3.2.0 | **v3.2.2** | | immich-machine-learning | ghcr.io/immich-app/immich-machine-learning | v3.2.0 | **v3.2.2** | | redis | docker.io/valkey/valkey | 9@sha256:70739f85… | unchanged — identical to immich v3.2.2's official pin (still resolvable; the live `9` tag has drifted to 9.1.2 but we keep immich's *tested* 9.1.1 pin, per the established precedent) | | database | ghcr.io/immich-app/postgres | 14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357… | unchanged — identical to immich v3.2.2's official pin; live tag digest re-verified via `docker buildx imagetools inspect` = the pin (not stale). No newer tag on the same PG14+VectorChord0.4.3+pgvectors0.2.0 scheme is shipped by immich v3.2.2 — do NOT jump to pg18/VectorChord 0.5.x (unsupported) | `example.env` @ v3.2.2 is byte-identical to v3.2.0 — no `.env.sample` change needed. **Upstream release notes:** app v3.2.0→v3.2.1: https://github.com/immich-app/immich/releases/tag/v3.2.1 **Upstream release notes:** app v3.2.1→v3.2.2: https://github.com/immich-app/immich/releases/tag/v3.2.2 **Upstream release notes:** immich-machine-learning v3.2.0→v3.2.2 (same monorepo releases): https://github.com/immich-app/immich/releases/tag/v3.2.2 ### Operator Action Required None. TypeORM migrations run automatically on deploy; v3.2.1 additionally runs a VACUUM automatically after migrations. ### Recommended release bump (operator's final step — the version label is intentionally untouched in this PR) `abra recipe release immich -z` (patch `-z`: bug-fix-only upstream releases → publishes `1.11.1+v3.2.2`) ### Verification / evidence - Direct `--chaos` deploy of this exact commit on the cc-ci swarm: all 4 services converged 1/1, TypeORM migrations ran clean, app healthcheck healthy (RestartCount=0), web UI served HTTP 200 via traefik, running container digest verified = the ghcr `immich-server:v3.2.2` manifest (`sha256:79cc1623…`); machine-learning healthy (`Application startup complete`, server logged "Machine learning server became healthy"). Dev deploy torn down + verified nothing leaked afterwards. - Advisory scan (GitHub security-advisories API + vendor release pages + OSV, union with release-note reading): **0 CVEs fixed by this upgrade** (v3.2.1/v3.2.2 name no CVEs). For the record: valkey CVE-2026-56684 / CVE-2026-63639 were fixed in valkey 9.1.1 (2026-07-21) — already covered by this recipe's pinned valkey; valkey CVE-2026-25243 (zipmap RESTORE) is named only in valkey 7.2.14's notes — whether 9.1.1's related zipmap hardening (PR #3920) covers it is unverified, recorded as still-unknown. Scan had failed GitHub-advisory sources (rate-limited), so the deterministic count is a floor; release-note reading found no additional CVEs. - `!testme` (real cc-ci recipe CI) runs below — results in this PR. Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-09-18 03:14:04 +00:00
autonomic-bot requested review from trav 2026-09-18 03:14:04 +00:00
autonomic-bot requested review from notplants 2026-09-18 03:14:04 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — immich @ dcef16c5 ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `immich` @ `dcef16c5` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1367/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1367) [![level](https://ci.commoninternet.net/runs/1367/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1367) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1367) · [dashboard](https://ci.commoninternet.net/)
Author
Owner

Auto-closed by cc-ci canonical sweep: its changes are already in upstream main (merged upstream); mirror main re-synced

Auto-closed by cc-ci canonical sweep: its changes are already in upstream main (merged upstream); mirror main re-synced
autonomic-bot closed this pull request 2026-09-27 03:30:53 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/immich#5