chore: upgrade n8nio/n8n to 2.40.5 #8

Closed
autonomic-bot wants to merge 0 commits from upgrade-ef0dd56 into main
Owner

Extends this evolving upgrade PR (previously 2.39.2 then 2.40.2, !testme GREEN 2026-09-18, drone run 1374) to 2.40.5 — the flagged 2.40.3 catch-up plus the two newer patch releases — on the current upstream main tip (0b436ec, 3.5.0+2.38.4). Diff vs main is a single-line compose.yml image bump — the recipe version label is intentionally untouched (the release/publish is the operator's final step, command at the end).

Image tag table

service image current (upstream main) new
app n8nio/n8n 2.38.4 2.40.5
db pgautoupgrade/pgautoupgrade (optional compose.postgres.yml only) 18-alpine unchanged — abra: "no new versions available … assuming 18-alpine is the latest"

Upstream release notes

Upstream release notes: app 2.38.4→2.40.5: https://github.com/n8n-io/n8n/releases (tags n8n@2.39.x / n8n@2.40.x)

Operator notes

  • No recipe deploy action required — rolling upgrade within 2.x; TypeORM migrations run automatically on startup (sqlite default; postgres variant unchanged). 2.40.2→2.40.5 adds no new migrations beyond the 15 verified at 2.40.2 (bugfix-only window).
  • API callers only (no recipe impact): 2.33.0 activate/deactivate endpoints deprecated (use publish/unpublish); 2.36.0 Array.merge→Array.mergeIntoObject + workflow-tags API migration; 2.37.0 "Any workflow" caller-policy deprecation + Content-Type: application/json required on decorator body routes + binary-data endpoint adapt; 2.39.0 workflow version endpoint (old two-variable path deprecated); 2.40.0 workflow publication service enabled by default; 2.40.x POST /rest/login now takes emailOrLdapLoginId instead of email (login-API request shape — scripts posting email need the new field name).
  • Informational: 2.39.0/2.39.1/2.40.3 encryption-key module rework + legacy/raw-key repair (recipe's N8N_ENCRYPTION_KEY secret path — exercised live below, clean). The legacy WEBHOOK_URL env still emits its pre-existing deprecation notice (honored; unchanged since the 2.38.4 boot).
  • The stable badge sits on the 2.39.x line (2.39.9/2.39.10 released 2026-09-21); the 2.40.x line is pre-release, consistent with this pipeline's tracking-the-newest-tag precedent (2.34.2/2.35.2/2.36.3/2.37.3/2.37.6/2.38.4/2.39.2/2.40.2 were all pre-release when taken). Docker Hub 2.40.5 manifest verified active multi-arch (amd64+arm64).

Live verification on cc-ci (direct deploy, before CI)

  • Real in-place upgrade over existing data (--chaos, baseline deploy of upstream main 0b436ec7 @ 2.38.4 first, seeded owner + workflow + CI marker, then WIP bf946679, image 2.38.4 → 2.40.5): all 2.39.x/2.40.x TypeORM migrations Finished cleanly (incl. CreatePromotionsTables, CreateAiPreferenceTable, DropGitConnectionTables); Recorded version change: 2.38.4 -> 2.40.5; Version: 2.40.5; n8n Task Broker ready; no encryption-key errors (raw-key repair path exercised with existing data, clean).
  • Serving: /healthz → 200 {"status":"ok"}; editor / → 200; GET /rest/login → 401 JSON (expected no-session shape).
  • Data survival (the cc-ci tier flows, pre-flighted live): fresh login as the pre-upgrade owner → 200 (n8n-auth cookie; credentials + user survived); pre-upgrade workflow read-back → 200 with id/name/nodes preserved; /home/node/.n8n/ci-marker.txt still reads upgrade-survives.
  • Dev deploy torn down after verification (0 stacks / 0 services / 0 volumes / 0 secrets / 0 app env files leaked).

Recommended release (operator, after merge)

abra recipe release n8n -y

Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.

cc @trav @notplants

Extends this evolving upgrade PR (previously **2.39.2** then **2.40.2**, `!testme` GREEN 2026-09-18, drone run 1374) to **2.40.5** — the flagged 2.40.3 catch-up plus the two newer patch releases — on the current upstream main tip (`0b436ec`, `3.5.0+2.38.4`). Diff vs main is a single-line `compose.yml` image bump — the recipe version label is intentionally untouched (the release/publish is the operator's final step, command at the end). ## Image tag table | service | image | current (upstream main) | new | |---------|-------|-------------------------|-----| | app | n8nio/n8n | 2.38.4 | **2.40.5** | | db | pgautoupgrade/pgautoupgrade (optional `compose.postgres.yml` only) | 18-alpine | unchanged — abra: "no new versions available … assuming 18-alpine is the latest" | ## Upstream release notes **Upstream release notes:** app 2.38.4→2.40.5: https://github.com/n8n-io/n8n/releases (tags `n8n@2.39.x` / `n8n@2.40.x`) - 2.39.0 (feature minor): https://github.com/n8n-io/n8n/releases/tag/n8n%402.39.0 — public-API source-control endpoints; workflow version endpoint (two-variable path deprecated); instance reporting; encryption-key module rework; no breaking compose/env changes - 2.40.0 (feature minor): https://github.com/n8n-io/n8n/releases/tag/n8n%402.40.0 — Microsoft Dataverse node; Git-based promotion model; workflow publication service enabled by default; v3 migration-report warnings; ~150 bugfixes; no breaking compose/env changes, no `N8N_*` renames - 2.40.3 (this run's flagged catch-up): https://github.com/n8n-io/n8n/releases/tag/n8n%402.40.3 — core "repair data-encryption keys stored as the raw instance key" + editor blank-workflow-preview fix - 2.40.4: https://github.com/n8n-io/n8n/releases/tag/n8n%402.40.4 — core trigger teardown when publication meets an unloadable node type; perf (skip project members when listing credentials) - 2.40.5 (target): https://github.com/n8n-io/n8n/releases/tag/n8n%402.40.5 — core "limit declarative routing during base URL ownership checks" - intermediates 2.38.5–2.38.7, 2.39.1–2.39.7, 2.40.1–2.40.2: patch bugfixes (2.39.6 adds a warn-only `N8N_DB_PING_TIMEOUT` deprecation — this recipe does not set it) ## Operator notes - **No recipe deploy action required** — rolling upgrade within 2.x; TypeORM migrations run automatically on startup (sqlite default; postgres variant unchanged). 2.40.2→2.40.5 adds **no new migrations** beyond the 15 verified at 2.40.2 (bugfix-only window). - **API callers only** (no recipe impact): 2.33.0 activate/deactivate endpoints deprecated (use publish/unpublish); 2.36.0 `Array.merge`→`Array.mergeIntoObject` + workflow-tags API migration; 2.37.0 "Any workflow" caller-policy deprecation + `Content-Type: application/json` required on decorator body routes + binary-data endpoint adapt; 2.39.0 workflow version endpoint (old two-variable path deprecated); 2.40.0 workflow publication service enabled by default; 2.40.x `POST /rest/login` now takes `emailOrLdapLoginId` instead of `email` (login-API request shape — scripts posting `email` need the new field name). - **Informational:** 2.39.0/2.39.1/2.40.3 encryption-key module rework + legacy/raw-key repair (recipe's `N8N_ENCRYPTION_KEY` secret path — exercised live below, clean). The legacy `WEBHOOK_URL` env still emits its pre-existing deprecation notice (honored; unchanged since the 2.38.4 boot). - The `stable` badge sits on the **2.39.x** line (2.39.9/2.39.10 released 2026-09-21); the 2.40.x line is pre-release, consistent with this pipeline's tracking-the-newest-tag precedent (2.34.2/2.35.2/2.36.3/2.37.3/2.37.6/2.38.4/2.39.2/2.40.2 were all pre-release when taken). Docker Hub `2.40.5` manifest verified active multi-arch (amd64+arm64). ## Live verification on cc-ci (direct deploy, before CI) - Real in-place upgrade over existing data (`--chaos`, baseline deploy of upstream main `0b436ec7` @ 2.38.4 first, seeded owner + workflow + CI marker, then WIP `bf946679`, image `2.38.4 → 2.40.5`): all 2.39.x/2.40.x TypeORM migrations `Finished` cleanly (incl. `CreatePromotionsTables`, `CreateAiPreferenceTable`, `DropGitConnectionTables`); `Recorded version change: 2.38.4 -> 2.40.5`; `Version: 2.40.5`; `n8n Task Broker ready`; no encryption-key errors (raw-key repair path exercised with existing data, clean). - Serving: `/healthz` → 200 `{"status":"ok"}`; editor `/` → 200; `GET /rest/login` → 401 JSON (expected no-session shape). - Data survival (the cc-ci tier flows, pre-flighted live): fresh **login as the pre-upgrade owner → 200** (`n8n-auth` cookie; credentials + user survived); **pre-upgrade workflow read-back → 200 with id/name/nodes preserved**; `/home/node/.n8n/ci-marker.txt` still reads `upgrade-survives`. - Dev deploy torn down after verification (0 stacks / 0 services / 0 volumes / 0 secrets / 0 app env files leaked). ## Recommended release (operator, after merge) `abra recipe release n8n -y` Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review. cc @trav @notplants
autonomic-bot added 1 commit 2026-09-11 07:32:11 +00:00
autonomic-bot requested review from trav 2026-09-11 07:32:11 +00:00
autonomic-bot requested review from notplants 2026-09-11 07:32:11 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — n8n @ ef0dd56a ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `n8n` @ `ef0dd56a` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1357/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1357) [![level](https://ci.commoninternet.net/runs/1357/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1357) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1357) · [dashboard](https://ci.commoninternet.net/)
autonomic-bot changed title from chore: upgrade n8nio/n8n to 2.39.2 to chore: upgrade n8nio/n8n to 2.40.2 2026-09-18 07:50:39 +00:00
autonomic-bot added 1 commit 2026-09-18 07:50:40 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — n8n @ b64c1daa ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `n8n` @ `b64c1daa` ✅ **passed** [![cc-ci result card](https://ci.commoninternet.net/runs/1374/summary.png)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1374) [![level](https://ci.commoninternet.net/runs/1374/badge.svg)](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1374) [full logs](https://drone.ci.commoninternet.net/recipe-maintainers/cc-ci/1374) · [dashboard](https://ci.commoninternet.net/)
autonomic-bot changed title from chore: upgrade n8nio/n8n to 2.40.2 to chore: upgrade n8nio/n8n to 2.40.5 2026-09-21 20:54:57 +00:00
autonomic-bot added 1 commit 2026-09-21 20:54:59 +00:00
Author
Owner

!testme

!testme
Author
Owner

🌻 cc-ci — n8n @ 6103b6ef ✅ passed

cc-ci result card

level

full logs · dashboard

<!-- cc-ci:testme --> 🌻 **cc-ci** — `n8n` @ `6103b6ef` ✅ **passed** [![cc-ci result card](https://ci.autonomic.zone/runs/6/summary.png)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/6) [![level](https://ci.autonomic.zone/runs/6/badge.svg)](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/6) [full logs](https://drone.ci.autonomic.zone/recipe-maintainers/cc-ci/6) · [dashboard](https://ci.autonomic.zone/)
Author
Owner

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced

Auto-closed by /recipe-upgrade: its changes are already in upstream main (merged upstream); mirror main re-synced
autonomic-bot closed this pull request 2026-09-28 21:47:19 +00:00

Pull request closed

Please reopen this pull request to perform a merge.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: recipe-maintainers/n8n#8