Coordinated bump of the whole mailu image set (all six mailu services share one tag and must move
together) plus the redis cache sidecar. This extends the existing open upgrade PR #8 (branch upgrade-2024.06.60, previously at .60) to the newest mailu patch 2024.06.61 — one evolving
upgrade PR, not a second one.
mailu 2024.06.59 (2026-09-23): fix "Please don't turn CURLOPT_SSL_VERIFYCLIENT off" on modern
roundcube; upgrade to roundcube 1.6.18. Pure patch.
mailu 2024.06.60 (2026-09-28): fix three boolean settings that could not be turned off
(DEFER_ON_TLS_ERROR=False, ADMIN=false, FULL_TEXT_SEARCH_ATTACHMENTS=False); fix a NameError
that masked the error message for an unusable PROXY_PROTOCOL entry.
mailu 2024.06.61 (2026-09-30, latest): clear stale webmail session cookies on SSO login, so
switching accounts without logging out no longer leaves the webmail on the previous user
(AUTHENTICATIONFAILED folders error).
CVE-2024-49767 (GHSA-53v4-wgj8-wpvp, CVSS 7.5 high) — a crafted HTTP header can stop the mailu admin container answering, which also halts IMAP/POP3/SMTP authentication for the whole
deployment. Affected <=2024.06.58; patched 2024.06.59. Fixed by this upgrade.
Advisory scan (advisory-scan.py mailu --from 2024.06.58 --to 2024.06.61 --image redis=8.10.1:8.10.2)
confirms 1 CVE fixed. Four further CVEs seen only on the vendor release feeds
(CVE-2026-49217, CVE-2026-54432, CVE-2026-54433 mailu/roundcube; CVE-2026-62356 redis) carry no
version window and could not be classified deterministically — recorded STILL-UNKNOWN, not counted.
Operator Action Required
None for a normal deploy. The mailu releases and the redis release are patch-level with no
migrations, no breaking changes, no new/renamed config.
Behaviour note (not an action): deployments that had set DEFER_ON_TLS_ERROR=False, ADMIN=false,
or FULL_TEXT_SEARCH_ATTACHMENTS=False previously had those ignored by postfix/webmail/nginx/dovecot;
after 2024.06.60 all containers honour them consistently.
redis: new cluster-bus-port-protected-mode defaults to no (unchanged behaviour); mailu's redis
is single-node, so nothing to set.
Release command (operator, after merge)
abra recipe release mailu -z
Patch bump: calver patch (2024.06.58→2024.06.61), roundcube/session and boolean bug fixes, plus a
redis security patch; no breaking change. The recipe version label is intentionally not bumped in
this PR.
Verification
Direct --chaos deploy on cc-ci (dev-mailu.ci.commoninternet.net, TLS_FLAVOR=notls as the
harness uses): all six mailu services + redis 8.10.2 converged 1/1; admin Alembic migration ran to
head 0ba45693748d (6b8f5e8caaa9 -> 0ba45693748d, Add user.change_pw_next_login); redis PING → PONG; nginx front returns 301 (the readiness signal).
Functional live check: created a mailbox via the admin flask mailu CLI and injected a uniquely
marked message via postfix sendmail, then confirmed delivery/storage with doveadm search in the
imap container — the full postfix → rspamd → dovecot round-trip works on 2024.06.61.
Dev stack torn down (abra app undeploy + rm); no dev-mailu* stacks or volumes left.
!testme run on this PR (results below).
Tested on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for
operator review.
## Mailu 2024.06.58 → 2024.06.61 (+ redis 8.10.1-alpine → 8.10.2-alpine)
Coordinated bump of the whole mailu image set (all six mailu services share one tag and must move
together) plus the redis cache sidecar. This **extends the existing open upgrade PR #8** (branch
`upgrade-2024.06.60`, previously at .60) to the newest mailu patch **2024.06.61** — one evolving
upgrade PR, not a second one.
### Image tags
| service | image | current → new |
|---|---|---|
| app | ghcr.io/mailu/nginx | 2024.06.58 → 2024.06.61 |
| admin | ghcr.io/mailu/admin | 2024.06.58 → 2024.06.61 |
| imap | ghcr.io/mailu/dovecot | 2024.06.58 → 2024.06.61 |
| smtp | ghcr.io/mailu/postfix | 2024.06.58 → 2024.06.61 |
| antispam | ghcr.io/mailu/rspamd | 2024.06.58 → 2024.06.61 |
| webmail | ghcr.io/mailu/webmail | 2024.06.58 → 2024.06.61 |
| db | redis | 8.10.1-alpine → 8.10.2-alpine |
| certdumper | ldez/traefik-certs-dumper | v2.11.4 (unchanged) |
### Upstream release notes
**Upstream release notes:** app (mailu/nginx) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
**Upstream release notes:** admin (mailu/admin) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
**Upstream release notes:** imap (mailu/dovecot) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
**Upstream release notes:** smtp (mailu/postfix) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
**Upstream release notes:** antispam (mailu/rspamd) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
**Upstream release notes:** webmail (mailu/webmail) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
**Upstream release notes:** db (redis) 8.10.1-alpine→8.10.2-alpine: https://github.com/redis/redis/releases/tag/8.10.2
**Upstream release notes:** intermediate mailu 2024.06.60: https://github.com/Mailu/Mailu/releases/tag/2024.06.60
**Upstream release notes:** intermediate mailu 2024.06.59: https://github.com/Mailu/Mailu/releases/tag/2024.06.59
### What changed upstream
- **mailu 2024.06.59** (2026-09-23): fix "Please don't turn CURLOPT_SSL_VERIFYCLIENT off" on modern
roundcube; upgrade to roundcube 1.6.18. Pure patch.
- **mailu 2024.06.60** (2026-09-28): fix three boolean settings that could not be turned off
(`DEFER_ON_TLS_ERROR=False`, `ADMIN=false`, `FULL_TEXT_SEARCH_ATTACHMENTS=False`); fix a `NameError`
that masked the error message for an unusable `PROXY_PROTOCOL` entry.
- **mailu 2024.06.61** (2026-09-30, latest): clear stale webmail session cookies on SSO login, so
switching accounts without logging out no longer leaves the webmail on the previous user
(`AUTHENTICATIONFAILED` folders error).
- **redis 8.10.2** (2026-09-17): SECURITY — transaction ACL enforcement (#15673), cluster-bus auth
warning + optional `cluster-bus-port-protected-mode` (default `no`) (#15722), plus TimeSeries/
RedisSearch/Vector Sets crash fixes.
### Security
- **CVE-2024-49767** (GHSA-53v4-wgj8-wpvp, CVSS 7.5 high) — a crafted HTTP header can stop the mailu
**admin** container answering, which also halts IMAP/POP3/SMTP authentication for the whole
deployment. Affected `<=2024.06.58`; patched **2024.06.59**. **Fixed by this upgrade.**
- Advisory scan (`advisory-scan.py mailu --from 2024.06.58 --to 2024.06.61 --image redis=8.10.1:8.10.2`)
confirms **1 CVE fixed**. Four further CVEs seen only on the vendor release feeds
(CVE-2026-49217, CVE-2026-54432, CVE-2026-54433 mailu/roundcube; CVE-2026-62356 redis) carry no
version window and could not be classified deterministically — recorded **STILL-UNKNOWN**, not counted.
### Operator Action Required
- **None** for a normal deploy. The mailu releases and the redis release are patch-level with **no
migrations, no breaking changes, no new/renamed config**.
- Behaviour note (not an action): deployments that had set `DEFER_ON_TLS_ERROR=False`, `ADMIN=false`,
or `FULL_TEXT_SEARCH_ATTACHMENTS=False` previously had those ignored by postfix/webmail/nginx/dovecot;
after 2024.06.60 all containers honour them consistently.
- redis: new `cluster-bus-port-protected-mode` defaults to `no` (unchanged behaviour); mailu's redis
is single-node, so nothing to set.
### Release command (operator, after merge)
```
abra recipe release mailu -z
```
Patch bump: calver patch (2024.06.58→2024.06.61), roundcube/session and boolean bug fixes, plus a
redis security patch; no breaking change. The recipe version label is intentionally **not** bumped in
this PR.
### Verification
- Direct `--chaos` deploy on cc-ci (`dev-mailu.ci.commoninternet.net`, `TLS_FLAVOR=notls` as the
harness uses): all six mailu services + redis 8.10.2 converged 1/1; admin Alembic migration ran to
head `0ba45693748d` (`6b8f5e8caaa9 -> 0ba45693748d, Add user.change_pw_next_login`); redis `PING` →
`PONG`; nginx front returns `301` (the readiness signal).
- Functional live check: created a mailbox via the admin `flask mailu` CLI and injected a uniquely
marked message via postfix `sendmail`, then confirmed delivery/storage with `doveadm search` in the
imap container — the full postfix → rspamd → dovecot round-trip works on 2024.06.61.
- Dev stack torn down (`abra app undeploy` + `rm`); no `dev-mailu*` stacks or volumes left.
- `!testme` run on this PR (results below).
Tested on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for
operator review.
cc @trav @notplants
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
autonomic-bot
changed title from chore: upgrade to 2024.06.60 (mailu + redis 8.10.2-alpine) to chore: upgrade to 2024.06.61 (mailu)2026-10-02 03:08:52 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Mailu 2024.06.58 → 2024.06.61 (+ redis 8.10.1-alpine → 8.10.2-alpine)
Coordinated bump of the whole mailu image set (all six mailu services share one tag and must move
together) plus the redis cache sidecar. This extends the existing open upgrade PR #8 (branch
upgrade-2024.06.60, previously at .60) to the newest mailu patch 2024.06.61 — one evolvingupgrade PR, not a second one.
Image tags
Upstream release notes
Upstream release notes: app (mailu/nginx) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
Upstream release notes: admin (mailu/admin) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
Upstream release notes: imap (mailu/dovecot) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
Upstream release notes: smtp (mailu/postfix) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
Upstream release notes: antispam (mailu/rspamd) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
Upstream release notes: webmail (mailu/webmail) 2024.06.58→2024.06.61: https://github.com/Mailu/Mailu/releases/tag/2024.06.61
Upstream release notes: db (redis) 8.10.1-alpine→8.10.2-alpine: https://github.com/redis/redis/releases/tag/8.10.2
Upstream release notes: intermediate mailu 2024.06.60: https://github.com/Mailu/Mailu/releases/tag/2024.06.60
Upstream release notes: intermediate mailu 2024.06.59: https://github.com/Mailu/Mailu/releases/tag/2024.06.59
What changed upstream
roundcube; upgrade to roundcube 1.6.18. Pure patch.
(
DEFER_ON_TLS_ERROR=False,ADMIN=false,FULL_TEXT_SEARCH_ATTACHMENTS=False); fix aNameErrorthat masked the error message for an unusable
PROXY_PROTOCOLentry.switching accounts without logging out no longer leaves the webmail on the previous user
(
AUTHENTICATIONFAILEDfolders error).warning + optional
cluster-bus-port-protected-mode(defaultno) (#15722), plus TimeSeries/RedisSearch/Vector Sets crash fixes.
Security
admin container answering, which also halts IMAP/POP3/SMTP authentication for the whole
deployment. Affected
<=2024.06.58; patched 2024.06.59. Fixed by this upgrade.advisory-scan.py mailu --from 2024.06.58 --to 2024.06.61 --image redis=8.10.1:8.10.2)confirms 1 CVE fixed. Four further CVEs seen only on the vendor release feeds
(CVE-2026-49217, CVE-2026-54432, CVE-2026-54433 mailu/roundcube; CVE-2026-62356 redis) carry no
version window and could not be classified deterministically — recorded STILL-UNKNOWN, not counted.
Operator Action Required
migrations, no breaking changes, no new/renamed config.
DEFER_ON_TLS_ERROR=False,ADMIN=false,or
FULL_TEXT_SEARCH_ATTACHMENTS=Falsepreviously had those ignored by postfix/webmail/nginx/dovecot;after 2024.06.60 all containers honour them consistently.
cluster-bus-port-protected-modedefaults tono(unchanged behaviour); mailu's redisis single-node, so nothing to set.
Release command (operator, after merge)
Patch bump: calver patch (2024.06.58→2024.06.61), roundcube/session and boolean bug fixes, plus a
redis security patch; no breaking change. The recipe version label is intentionally not bumped in
this PR.
Verification
--chaosdeploy on cc-ci (dev-mailu.ci.commoninternet.net,TLS_FLAVOR=notlsas theharness uses): all six mailu services + redis 8.10.2 converged 1/1; admin Alembic migration ran to
head
0ba45693748d(6b8f5e8caaa9 -> 0ba45693748d, Add user.change_pw_next_login); redisPING→PONG; nginx front returns301(the readiness signal).flask mailuCLI and injected a uniquelymarked message via postfix
sendmail, then confirmed delivery/storage withdoveadm searchin theimap container — the full postfix → rspamd → dovecot round-trip works on 2024.06.61.
abra app undeploy+rm); nodev-mailu*stacks or volumes left.!testmerun on this PR (results below).Tested on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for
operator review.
cc @trav @notplants
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
mailu@302dfd23✅ passedfull logs · dashboard
chore: upgrade to 2024.06.60 (mailu + redis 8.10.2-alpine)to chore: upgrade to 2024.06.61 (mailu)!testme
🌻 cc-ci —
mailu@b244c2d8✅ passedfull logs · dashboard
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.