This extends the existing upgrade PR (branch upgrade-358b376) with today's delta: MAS 1.24.0 → 1.25.1 (last week's pass had it at 1.25.0). One evolving upgrade PR; no second PR.
Image tag table
service
image
current (upstream main)
new (this PR)
app
matrixdotorg/synapse
v1.161.0
v1.161.0 (unchanged — latest stable; v1.162.0rc1 is a pre-release)
mas
ghcr.io/element-hq/matrix-authentication-service
1.24.0
1.25.1
signalbridge
dock.mau.dev/mautrix/signal
v0.2609.0
v0.2609.0 (held — "v26.02.2" is a downgrade, see below)
telegrambridge
dock.mau.dev/mautrix/telegram
v0.2609.0
v0.2609.0 (current)
discordbridge
halfshot/matrix-appservice-discord
v1.0.0
v1.0.0 (current)
web
nginx
1.31.6
1.31.6 (current)
admin
awesometechnologies/synapse-admin
0.11.4
0.11.4 (current)
db
pgautoupgrade/pgautoupgrade
18-alpine
18-alpine (current)
signaldb / telegramdb / discorddb
postgres
13-alpine
13-alpine (held deliberately)
Diff: 1 line — compose.mas.yml MAS image 1.24.0 → 1.25.1.
v1.25.0 (2026-09-21): bug fixes only — back_to_client template error when no state param (#5922); policy-violation rendering with empty code (#5921); translations; internal/CI; http-body-util 0.1.3→0.1.5. Notable behavioral change: M_APPSERVICE_LOGIN_UNSUPPORTED returned for m.login.application_service (#5961).
v1.25.1 (2026-09-21): one bugfix — rendering of the password registration page when a CAPTCHA provider is configured (#5992).
No breaking changes, no config-schema changes, no new required config. DB migrations run automatically on startup (verified live below).
mautrix/signal v0.2609.0 → "v26.02.2": DECLINED. v26.09 (git/docker tag v0.2609.0, released 16 Sep 2026) is the GitHub [Latest] release. v26.02.2 is the display-name form of v0.2602.2, released 02 Mar 2026 — ~7 months older. abra's semver-ish sort mis-reports it as an upgrade. The recipe correctly pins dock.mau.dev/mautrix/signal:v0.2609.0. https://github.com/mautrix/signal/releases
Held: bridge DBs at postgres:13-alpine
The 14/15/16/17/18-alpine "upgrades" abra reports are MAJOR pg jumps; plain postgres cannot auto-migrate a data dir across majors, so an unattended bump would crash-loop deployments with existing bridge data. Established recipe precedent — not bumped here.
Operator Action Required
None. MAS is an optional overlay (compose.mas.yml); deployments without MAS are unaffected. MAS 1.25.x is a drop-in bugfix line (1.25.0 + 1.25.1). No config/secrets/DB changes; migrations auto-run on startup.
Security
Advisory scan (deterministic, --from 1.161.0 --to 1.161.0 --image matrix-authentication-service=1.24.0:1.25.1 --image mautrix/signal=v0.2609.0:v26.02.2): 0 CVEs fixed identified; 24 sources checked, no failed sources. Union with release-note reading: 0 CVEs fixed by this window (MAS 1.25.0/1.25.1 name no security fixes).
Recommended release command (operator, after merge)
The version label (7.3.2+v1.161.0) is intentionally untouched in this PR.
dev-matrix-synapse.ci.commoninternet.net deployed --chaos with the MAS overlay + secrets enabled:
all 4 services (app, db, mas, web) converged 1/1
mas logs: Starting up version="v1.25.1" → Running pending database migrations → Syncing providers and clients → Listening on http://[::]:8080; worker leader elected
## Recipe upgrade — matrix-synapse (extends PR #7)
This extends the existing upgrade PR (branch `upgrade-358b376`) with today's delta: **MAS 1.24.0 → 1.25.1** (last week's pass had it at 1.25.0). One evolving upgrade PR; no second PR.
### Image tag table
| service | image | current (upstream main) | new (this PR) |
|---|---|---|---|
| app | matrixdotorg/synapse | v1.161.0 | v1.161.0 (unchanged — latest stable; v1.162.0rc1 is a pre-release) |
| mas | ghcr.io/element-hq/matrix-authentication-service | 1.24.0 | **1.25.1** |
| signalbridge | dock.mau.dev/mautrix/signal | v0.2609.0 | v0.2609.0 (**held** — "v26.02.2" is a downgrade, see below) |
| telegrambridge | dock.mau.dev/mautrix/telegram | v0.2609.0 | v0.2609.0 (current) |
| discordbridge | halfshot/matrix-appservice-discord | v1.0.0 | v1.0.0 (current) |
| web | nginx | 1.31.6 | 1.31.6 (current) |
| admin | awesometechnologies/synapse-admin | 0.11.4 | 0.11.4 (current) |
| db | pgautoupgrade/pgautoupgrade | 18-alpine | 18-alpine (current) |
| signaldb / telegramdb / discorddb | postgres | 13-alpine | 13-alpine (**held deliberately**) |
Diff: 1 line — `compose.mas.yml` MAS image `1.24.0` → `1.25.1`.
### Upstream release notes
- **mas 1.24.0 → 1.25.1**: https://github.com/element-hq/matrix-authentication-service/releases
- v1.25.0 (2026-09-21): bug fixes only — `back_to_client` template error when no `state` param (#5922); policy-violation rendering with empty `code` (#5921); translations; internal/CI; `http-body-util` 0.1.3→0.1.5. Notable behavioral change: `M_APPSERVICE_LOGIN_UNSUPPORTED` returned for `m.login.application_service` (#5961).
- v1.25.1 (2026-09-21): one bugfix — rendering of the password registration page when a CAPTCHA provider is configured (#5992).
- **No breaking changes, no config-schema changes, no new required config.** DB migrations run automatically on startup (verified live below).
- **mautrix/signal v0.2609.0 → "v26.02.2"**: DECLINED. `v26.09` (git/docker tag `v0.2609.0`, released 16 Sep 2026) is the GitHub `[Latest]` release. `v26.02.2` is the display-name form of `v0.2602.2`, released **02 Mar 2026** — ~7 months older. abra's semver-ish sort mis-reports it as an upgrade. The recipe correctly pins `dock.mau.dev/mautrix/signal:v0.2609.0`. https://github.com/mautrix/signal/releases
### Held: bridge DBs at postgres:13-alpine
The 14/15/16/17/18-alpine "upgrades" abra reports are MAJOR pg jumps; plain postgres cannot auto-migrate a data dir across majors, so an unattended bump would crash-loop deployments with existing bridge data. Established recipe precedent — not bumped here.
### Operator Action Required
None. MAS is an optional overlay (`compose.mas.yml`); deployments without MAS are unaffected. MAS 1.25.x is a drop-in bugfix line (1.25.0 + 1.25.1). No config/secrets/DB changes; migrations auto-run on startup.
### Security
Advisory scan (deterministic, `--from 1.161.0 --to 1.161.0 --image matrix-authentication-service=1.24.0:1.25.1 --image mautrix/signal=v0.2609.0:v26.02.2`): **0 CVEs fixed identified**; 24 sources checked, no failed sources. Union with release-note reading: **0 CVEs fixed by this window** (MAS 1.25.0/1.25.1 name no security fixes).
### Recommended release command (operator, after merge)
The version label (`7.3.2+v1.161.0`) is intentionally untouched in this PR.
```
abra recipe release matrix-synapse -z
```
→ publishes `7.3.3+v1.161.0` (bugfix-only sidecar bump; app image unchanged).
### Live verification (step 2b, cc-ci direct deploy)
`dev-matrix-synapse.ci.commoninternet.net` deployed `--chaos` with the MAS overlay + secrets enabled:
- all 4 services (`app`, `db`, `mas`, `web`) converged **1/1**
- mas logs: `Starting up version="v1.25.1"` → `Running pending database migrations` → `Syncing providers and clients` → `Listening on http://[::]:8080`; worker leader elected
- running image digest `sha256:54f03be8ef26b9a6f2ab594d2a4c6e8074c3c09fbe05890a00ea50939d3e152a` — **matches the upstream v1.25.1 release artifact exactly**
- synapse serves `/_matrix/client/versions` (HTTP 200, full manifest) via nginx 1.31.6; web `/` → 302
- teardown verified: 0 stacks / 0 volumes / 0 secrets with the `dev-matrix-synapse` prefix
Tested on the cc-ci recipe CI server (`!testme`, full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Recipe upgrade — matrix-synapse (extends PR #7)
This extends the existing upgrade PR (branch
upgrade-358b376) with today's delta: MAS 1.24.0 → 1.25.1 (last week's pass had it at 1.25.0). One evolving upgrade PR; no second PR.Image tag table
Diff: 1 line —
compose.mas.ymlMAS image1.24.0→1.25.1.Upstream release notes
back_to_clienttemplate error when nostateparam (#5922); policy-violation rendering with emptycode(#5921); translations; internal/CI;http-body-util0.1.3→0.1.5. Notable behavioral change:M_APPSERVICE_LOGIN_UNSUPPORTEDreturned form.login.application_service(#5961).v26.09(git/docker tagv0.2609.0, released 16 Sep 2026) is the GitHub[Latest]release.v26.02.2is the display-name form ofv0.2602.2, released 02 Mar 2026 — ~7 months older. abra's semver-ish sort mis-reports it as an upgrade. The recipe correctly pinsdock.mau.dev/mautrix/signal:v0.2609.0. https://github.com/mautrix/signal/releasesHeld: bridge DBs at postgres:13-alpine
The 14/15/16/17/18-alpine "upgrades" abra reports are MAJOR pg jumps; plain postgres cannot auto-migrate a data dir across majors, so an unattended bump would crash-loop deployments with existing bridge data. Established recipe precedent — not bumped here.
Operator Action Required
None. MAS is an optional overlay (
compose.mas.yml); deployments without MAS are unaffected. MAS 1.25.x is a drop-in bugfix line (1.25.0 + 1.25.1). No config/secrets/DB changes; migrations auto-run on startup.Security
Advisory scan (deterministic,
--from 1.161.0 --to 1.161.0 --image matrix-authentication-service=1.24.0:1.25.1 --image mautrix/signal=v0.2609.0:v26.02.2): 0 CVEs fixed identified; 24 sources checked, no failed sources. Union with release-note reading: 0 CVEs fixed by this window (MAS 1.25.0/1.25.1 name no security fixes).Recommended release command (operator, after merge)
The version label (
7.3.2+v1.161.0) is intentionally untouched in this PR.→ publishes
7.3.3+v1.161.0(bugfix-only sidecar bump; app image unchanged).Live verification (step 2b, cc-ci direct deploy)
dev-matrix-synapse.ci.commoninternet.netdeployed--chaoswith the MAS overlay + secrets enabled:app,db,mas,web) converged 1/1Starting up version="v1.25.1"→Running pending database migrations→Syncing providers and clients→Listening on http://[::]:8080; worker leader electedsha256:54f03be8ef26b9a6f2ab594d2a4c6e8074c3c09fbe05890a00ea50939d3e152a— matches the upstream v1.25.1 release artifact exactly/_matrix/client/versions(HTTP 200, full manifest) via nginx 1.31.6; web/→ 302dev-matrix-synapseprefixTested on the cc-ci recipe CI server (
!testme, full suite, cold, against this PR head). NOT merged — for operator review.cc @trav @notplants
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
matrix-synapse@358b3769✅ passedfull logs · dashboard
chore: upgrade MAS to 1.25.0to chore: upgrade MAS to 1.25.1!testme
🌻 cc-ci —
matrix-synapse@9960b74f✅ passedfull logs · dashboard
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.