chore: upgrade lasuite/meet to v1.32.1 #11

Open
autonomic-bot wants to merge 2 commits from upgrade-6cb491b into main
Owner

Upgrade: lasuite/meet v1.31.0 → v1.32.1 (+ redis 8.10.1 → 8.10.2)

Extends this existing upgrade PR (branch upgrade-6cb491b). It now carries the meet bump on top of
last week's redis bump; there is one evolving upgrade PR per recipe.

Images

service image current new
app lasuite/meet-frontend v1.31.0 v1.32.1
backend lasuite/meet-backend v1.31.0 v1.32.1
celery lasuite/meet-backend v1.31.0 v1.32.1
redis redis 8.10.1 8.10.2
db pgautoupgrade/pgautoupgrade 18-debian 18-debian (unchanged)
livekit livekit/livekit-server v1.13.7 v1.13.7 (latest, unchanged)
web nginx 1.31.6 1.31.6 (latest, unchanged)

web, db and livekit are already newest for their lines (abra agrees); no change.

Upstream release notes

Upstream release notes: meet v1.31.0→v1.32.1: https://github.com/suitenumerique/meet/releases

  • v1.32.1 — security fixes: CVE-2026-73228 / CVE-2026-73229 in DRF; CRITICAL CVE-2026-63072 / CVE-2026-63073 in libssl3t64.
  • v1.32.0 — features: configurable LiveKit default video codec, screen-share zoom controls; fixes incl. CVE-2026-93990 (libexpat), base image bumped to python:3.13.5-alpine3.24.

Upstream release notes: redis 8.10.1→8.10.2: https://github.com/redis/redis/releases/tag/8.10.2

  • transaction ACL-revocation bypass (#15673); cluster-bus auth warning hardening (#15722, new cluster-bus-port-protected-mode, default no); TimeSeries/RedisSearch/VectorSets crash fixes.

Operator Action Required

None. No breaking changes, no schema migration is operator-visible (backend runs
manage.py migrate automatically on boot; v1.32.0 adds core.0023_alter_recording_status and applies
cleanly — verified live), no new/renamed env vars are required:

  • The new default-video-codec setting is optional.
  • redis is cache-only here (no volume/persistence); not using TLS or cluster mode, so the
    cluster-bus-port-protected-mode default-no option and the cluster-bus startup warning do not apply.
  • Dockerflow health/endpoint changes in v1.32.0 are internal; the recipe's healthchecks (manage.py check, wget /, celery inspect ping, redis-cli ping) are unchanged and all pass.

Recommended release command

PR does not bump the version label. New feature + security → minor. After merging upstream, publish with:

abra recipe release lasuite-meet -y

→ 0.8.0+v1.32.1 (from current label 0.7.0+v1.31.0).

Verification

  • Deployed the recipe head directly on cc-ci (--chaos): all 7 services 1/1, backend migrations applied
    OK, gunicorn serving, celery connected to redis, landing page HTTP 200. Torn down fully.
  • Full cc-ci recipe CI (!testme) on this PR head.

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

## Upgrade: lasuite/meet v1.31.0 → v1.32.1 (+ redis 8.10.1 → 8.10.2) Extends this existing upgrade PR (branch `upgrade-6cb491b`). It now carries the meet bump on top of last week's redis bump; there is **one evolving upgrade PR per recipe**. ### Images | service | image | current | new | |---------|-------|---------|-----| | app | lasuite/meet-frontend | v1.31.0 | **v1.32.1** | | backend | lasuite/meet-backend | v1.31.0 | **v1.32.1** | | celery | lasuite/meet-backend | v1.31.0 | **v1.32.1** | | redis | redis | 8.10.1 | **8.10.2** | | db | pgautoupgrade/pgautoupgrade | 18-debian | 18-debian (unchanged) | | livekit | livekit/livekit-server | v1.13.7 | v1.13.7 (latest, unchanged) | | web | nginx | 1.31.6 | 1.31.6 (latest, unchanged) | `web`, `db` and `livekit` are already newest for their lines (abra agrees); no change. ### Upstream release notes **Upstream release notes:** meet v1.31.0→v1.32.1: https://github.com/suitenumerique/meet/releases - v1.32.1 — security fixes: CVE-2026-73228 / CVE-2026-73229 in DRF; **CRITICAL** CVE-2026-63072 / CVE-2026-63073 in libssl3t64. - v1.32.0 — features: configurable LiveKit default video codec, screen-share zoom controls; fixes incl. CVE-2026-93990 (libexpat), base image bumped to python:3.13.5-alpine3.24. **Upstream release notes:** redis 8.10.1→8.10.2: https://github.com/redis/redis/releases/tag/8.10.2 - transaction ACL-revocation bypass (#15673); cluster-bus auth warning hardening (#15722, new `cluster-bus-port-protected-mode`, default `no`); TimeSeries/RedisSearch/VectorSets crash fixes. ### Operator Action Required **None.** No breaking changes, no schema migration is operator-visible (backend runs `manage.py migrate` automatically on boot; v1.32.0 adds `core.0023_alter_recording_status` and applies cleanly — verified live), no new/renamed env vars are required: - The new default-video-codec setting is optional. - redis is cache-only here (no volume/persistence); not using TLS or cluster mode, so the `cluster-bus-port-protected-mode` default-`no` option and the cluster-bus startup warning do not apply. - Dockerflow health/endpoint changes in v1.32.0 are internal; the recipe's healthchecks (`manage.py check`, `wget /`, `celery inspect ping`, `redis-cli ping`) are unchanged and all pass. ### Recommended release command PR does **not** bump the version label. New feature + security → minor. After merging upstream, publish with: ``` abra recipe release lasuite-meet -y ``` → `0.8.0+v1.32.1` (from current label `0.7.0+v1.31.0`). ### Verification - Deployed the recipe head directly on cc-ci (`--chaos`): all 7 services 1/1, backend migrations applied OK, gunicorn serving, celery connected to redis, landing page HTTP 200. Torn down fully. - Full cc-ci recipe CI (`!testme`) on this PR head. Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-09-21 21:17:55 +00:00
autonomic-bot requested review from trav 2026-09-21 21:17:55 +00:00
autonomic-bot requested review from notplants 2026-09-21 21:17:55 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — lasuite-meet @ 6cb491b7 ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `lasuite-meet` @ `6cb491b7` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/8/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/8) [![level](https://ci.autonomic.zone/runs/8/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/8) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/8) · [dashboard](https://ci.autonomic.zone/)
autonomic-bot changed title from chore: upgrade redis to 8.10.2 to chore: upgrade lasuite/meet to v1.32.1 2026-09-28 21:18:34 +00:00
autonomic-bot added 1 commit 2026-09-28 21:18:36 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — lasuite-meet @ 547536dc ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `lasuite-meet` @ `547536dc` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/19/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/19) [![level](https://ci.autonomic.zone/runs/19/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/19) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/19) · [dashboard](https://ci.autonomic.zone/)
All checks were successful
cc-ci/testme cc-ci: success
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin upgrade-6cb491b:upgrade-6cb491b
git checkout upgrade-6cb491b
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/lasuite-meet#11