Skip to content

Upstream version report (2026-09-21) #27

Description

@github-actions

Upstream Version Check — 2026-09-21

Component Current Latest Status Note
elasticsearch 8.19.16 9.5.3 ⏸ HOLD RAGFlow требует ES 9.x совместимый с DOC_ENGINE=elasticsearch.
langgenius/dify-api 1.14.2 1.17.1 ⏸ HOLD Plugin Daemon co-bump required; bump только после verify в dify-plugin-daemon.
langgenius/dify-plugin-daemon 0.6.1-local 0.6.10 ⏸ HOLD Local build — track upstream stable carefully. 0.6.x = current target.
langgenius/dify-sandbox 0.2.15 0.2.15 ⏸ HOLD Dify stack — co-bumped with dify-api; bump только после full Dify re-verify.
langgenius/dify-web 1.14.2 1.17.1 ⏸ HOLD Dify stack — co-bumped with dify-api; bump только после full Dify re-verify.
milvusdb/milvus v2.6.21 v3.0.2 ⏸ HOLD v3.0.0: one-way Storage V3 data transition on a LIVE vector DB, no GA release notes at review, Dify's pymilvus 2.6.12 unverified against 3.0 — hold the major; patches on 2.6.x OK.
mysql 8.0.46-oraclelinux9 26.7.0 ⏸ HOLD Dify requires MySQL 8.x (verified); do not bump to 9.x until Dify re-verify.
node 24-bookworm-slim 26.9.0 ⏸ HOLD Node 26 not LTS until 2026-10-28 (stay on 24 LTS); node:26 image drops corepack so Dockerfile.agent-ui pnpm bootstrap needs a rewrite first — not a bare FROM swap.
postgres 17.10-alpine3.22 18.6 ⏸ HOLD Dify metadata store on PG 17 LTS (verified 2026-05-16); bump majors только после Dify re-verify.
quay.io/coreos/etcd v3.5.25 v3.7.1 ⏸ HOLD 3.6/3.7 need sequential minor upgrades from 3.5.26+ (live data dir is 3.5-written) AND milvus 2.6 officially pins etcd v3.5.25 — stay on 3.5.x until milvus moves.
redis 8.4.3-alpine 8.10.1 ⏸ HOLD Dify task queue + plugin cache on Redis 8 (verified 2026-05-09); bump majors только после Dify re-verify.
amir20/dozzle v10.6.13 v11.1.1 ⚠️ major templates/services/dozzle.yaml
arizephoenix/phoenix version-19.10.0-nonroot version-20.14 ⚠️ major templates/services/phoenix.yaml
infiniflow/ragflow v0.25.5 v1.0 ⚠️ major templates/services/ragflow.yaml (HOLD expired since 2026-09-01)
tecnativa/docker-socket-proxy v0.5.0 3.4-pr-186 ⚠️ major templates/services/docker-socket-proxy.yaml
ghcr.io/homarr-labs/homarr v1.62.0 v1.77.2 🔄 minor templates/services/homarr.yaml (HOLD expired since 2026-09-01)
grafana/alloy v1.18.0 v1.19.2 🔄 minor templates/services/alloy.yaml
grafana/grafana 13.1.1 13.2.2 🔄 minor templates/services/grafana.yaml
louislam/uptime-kuma 2.4.0 2.5.5 🔄 minor templates/services/uptime-kuma.yaml
n8nio/n8n 2.32.6 2.40.4-pc 🔄 minor templates/services/n8n.yaml
netdata/netdata v2.10.4 v2.11.1 🔄 minor templates/services/netdata.yaml
oliver006/redis_exporter v1.88.0 v1.91.1 🔄 minor templates/services/redis-exporter.yaml
portainer/portainer-ce 2.41.1 2.45.1 🔄 minor templates/services/portainer.yaml (HOLD expired since 2026-09-01)
prom/alertmanager v0.33.1 v0.34.1 🔄 minor templates/services/alertmanager.yaml
prom/prometheus v3.13.1 v3.14.0 🔄 minor templates/services/prometheus.yaml
prompve/prometheus-pve-exporter 3.9.0 3.10 🔄 minor templates/services/proxmox-exporter.yaml
python 3.12-slim 3.14.7 🔄 minor docker/Dockerfile.agent-agno
qdrant/qdrant v1.18.3 v1.19.1 🔄 minor templates/services/qdrant.yaml
quay.io/docling-project/docling-serve-cpu v1.28.0 v1.34.0 🔄 minor templates/services/docling.yaml
semitechnologies/weaviate 1.38.8 v1.39.5 🔄 minor templates/services/weaviate.yaml
quay.io/minio/minio RELEASE.2025-09-07T16-13-09Z.hotfix.7aa24e772 ? 📌 non_semver calendar/non-semver tag (e.g. RELEASE.) — track manually
authelia/authelia 4.39.20 4.39.28 📦 patch templates/services/authelia.yaml
ghcr.io/open-webui/open-webui v0.11.0 v0.11.3 📦 patch templates/services/openwebui.yaml
grafana/loki 3.7.4 v3.7.8 📦 patch templates/services/loki.yaml
traefik v3.7.9 v3.7.13 📦 patch templates/services/traefik.yaml
ghcr.io/ggml-org/llama.cpp server-vulkan-b9049 v0.4.1 ? unknown templates/services/llama-embed.yaml (HOLD expired since 2026-08-01)
containrrr/watchtower 1.7.1 1.7.1 ✅ up_to_date templates/services/watchtower.yaml
gcr.io/cadvisor/cadvisor v0.55.1 v0.55.1 ✅ up_to_date templates/services/cadvisor.yaml
pgvector/pgvector 0.8.6-pg17 0.8.6-pg18 ✅ up_to_date templates/services/agent-db.yaml
prom/node-exporter v1.12.1 v1.12.1 ✅ up_to_date templates/services/node-exporter.yaml
prometheuscommunity/postgres-exporter v0.20.1 v0.20.1 ✅ up_to_date templates/services/postgres-exporter.yaml
ubuntu/squid 7.2-26.04_edge 7.2-26.04_edge ✅ up_to_date templates/services/ssrf-proxy.yaml

Legend

  • ✅ up_to_date — pin совпадает с latest registry tag.
  • 📦 patch — patch-bump доступен (semver Z).
  • 🔄 minor — minor-bump доступен (semver Y).
  • ⚠️ major — major-bump доступен (semver X). Breaking changes — review.
  • ↥ newer_than_probe — committed pin is newer than probed latest; registry probe may be incomplete.
  • ⏸ HOLD — pin намеренно остановлен, см. templates/version_holds.yaml → reason.
  • 📌 non_semver — image uses calendar/non-semver tags (e.g. minio RELEASE.<date>); track manually.
  • ❌ error — probe failed (network / registry rate-limit / unknown image).
  • strict-pin — component updates must keep the current explicit pin until reviewed.
  • compatible-patch / compatible-minor — component can move within the stated compatibility window after verification.
  • manual-hold — component is intentionally held until a documented compatibility review.
  • pinned-by-parent — version follows a parent stack such as Dify or RAGFlow.

Update policies

  • strict-pin — keep the exact pin until a component owner reviews and verifies the bump.
  • compatible-patch — patch updates may be planned automatically but still require local verification.
  • compatible-minor — minor updates are acceptable after changelog review and component verification.
  • manual-hold — do not bump without a research note or explicit compatibility evidence.
  • upstream-compatible — follow upstream's supported compatibility window.
  • patch-auto — legacy issue-report term for patch updates that can be planned automatically.
  • minor-review — legacy issue-report term for minor updates that need changelog review.
  • major-hold — legacy issue-report term for major updates blocked until explicit review.
  • grouped — update the whole stack together, not a single service in isolation.
  • pinned-by-parent — version follows a parent stack contract.
  • volatile — upstream tags are noisy; prefer explicit known-good pins.

Component update policies

Component Kind Current Recommended Policy Source Note
agent-stack app 0.1.0 0.1.0 manual-hold local AGmind-authored agent images built on-host from shipped source (compose build:).
app-interfaces app 2026-05-23-r20 2026-05-23-r20 compatible-minor manual templates/components/app-interfaces.yaml
automation-stack app 2.22.3 2.22.3 compatible-patch registry templates/components/automation-stack.yaml
dify app 1.14.2 1.14.2 strict-pin registry Dify api, web, worker, sandbox, and plugin daemon update as one stack.
ragflow app v0.25.5 v0.25.5 manual-hold registry v1.x requires R18 compatibility review before bump.
ssrf-proxy app 7.2-26.04_edge 7.2-26.04_edge compatible-minor registry templates/components/ssrf-proxy.yaml
agmind-core core 0.1.0.dev0 0.6.0 compatible-minor local templates/components/agmind-core.yaml
edge-proxy edge 2026-05-23-r20 2026-05-23-r20 compatible-minor manual templates/components/edge-proxy.yaml
llama-cpp-gfx1151 inference server-vulkan-b9049 server-vulkan-b9049 manual-hold registry Strix Halo baseline is measured on b9049; bump only after re-bench.
model-catalog model 2026-05-23-r20 2026-05-23-r20 compatible-minor manual templates/components/model-catalog.yaml
observability-stack ops 2026-05-26-r22 2026-05-26-r22 compatible-minor manual templates/components/observability-stack.yaml
stateful-services stateful 2026-05-23-r20 2026-05-23-r20 compatible-minor manual templates/components/stateful-services.yaml

Non-container dependency pins

Name Specifier Source File
ansible.posix >=1.5.0 ansible-galaxy ansible/requirements.yml
community.docker >=4.0.0 ansible-galaxy ansible/requirements.yml
community.general >=9.0.0 ansible-galaxy ansible/requirements.yml
PyYAML >=6.0,<7 constraint:core constraints/core.txt
ansible-core >=2.16,<2.22 constraint:core constraints/core.txt
argon2-cffi >=23.1,<26 constraint:core constraints/core.txt
huggingface_hub >=0.24,<2 constraint:core constraints/core.txt
numpy >=2.0,<3 constraint:core constraints/core.txt
platformdirs >=4.2,<5 constraint:core constraints/core.txt
pydantic >=2.7,<3 constraint:core constraints/core.txt
pyfiglet >=1.0,<2 constraint:core constraints/core.txt
questionary >=2.0,<3 constraint:core constraints/core.txt
rich >=13.7,<16 constraint:core constraints/core.txt
structlog >=24.0,<26 constraint:core constraints/core.txt
textual >=0.80,<9 constraint:core constraints/core.txt
typer >=0.26,<1 constraint:core constraints/core.txt
zeroconf >=0.130,<1 constraint:core constraints/core.txt
llama-cpp-python >=0.3.23,<0.4 constraint:cpu constraints/cpu.txt
numpy >=2.0,<3 constraint:cpu constraints/cpu.txt
onnxruntime >=1.22,<2 constraint:cpu constraints/cpu.txt
scipy >=1.14,<2 constraint:cpu constraints/cpu.txt
torch >=2.7,<3 constraint:cpu constraints/cpu.txt
torchaudio >=2.7,<3 constraint:cpu constraints/cpu.txt
torchvision >=0.22,<1 constraint:cpu constraints/cpu.txt
jsonschema >=4.0,<5 constraint:dev constraints/dev.txt
mypy >=1.10,<3 constraint:dev constraints/dev.txt
pre-commit >=4.0,<5 constraint:dev constraints/dev.txt
pytest >=8.0,<10 constraint:dev constraints/dev.txt
pytest-asyncio >=1.0,<2 constraint:dev constraints/dev.txt
pytest-benchmark >=4.0,<6 constraint:dev constraints/dev.txt
pytest-cov >=5.0,<8 constraint:dev constraints/dev.txt
ruff ==0.15.13 constraint:dev constraints/dev.txt
types-PyYAML >=6.0,<7 constraint:dev constraints/dev.txt
types-psutil >=7.0,<8 constraint:dev constraints/dev.txt
llama-cpp-python >=0.3.23,<0.4 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
numpy >=2.0,<3 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
onnxruntime >=1.22,<2 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
pip >=24,<26 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
scipy >=1.14,<2 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
setuptools >=68,<90 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
torch >=2.7,<3 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
torchaudio >=2.7,<3 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
torchvision >=0.22,<1 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
wheel >=0.43,<1 constraint:rocm-gfx1151 constraints/rocm-gfx1151.txt
llama-cpp-python >=0.3.23,<0.4 constraint:vulkan constraints/vulkan.txt
numpy >=2.0,<3 constraint:vulkan constraints/vulkan.txt
onnxruntime >=1.22,<2 constraint:vulkan constraints/vulkan.txt
scipy >=1.14,<2 constraint:vulkan constraints/vulkan.txt
torch >=2.7,<3 constraint:vulkan constraints/vulkan.txt
llama-cpp-python >=0.3.23,<0.4 dockerfile-pip docker/Dockerfile.cpu
llama-cpp-python >=0.3.23,<0.4 dockerfile-pip docker/Dockerfile.rocm
llama-cpp-python >=0.3.23,<0.4 dockerfile-pip docker/Dockerfile.vulkan
pip >=24,<26 dockerfile-pip docker/Dockerfile.base
pip >=24,<26 dockerfile-pip docker/Dockerfile.rocm
setuptools >=68,<90 dockerfile-pip docker/Dockerfile.base
setuptools >=68,<90 dockerfile-pip docker/Dockerfile.rocm
wheel >=0.43,<1 dockerfile-pip docker/Dockerfile.base
wheel >=0.43,<1 dockerfile-pip docker/Dockerfile.rocm
PyYAML >=6.0,<7 pyproject pyproject.toml
ansible-core >=2.16,<2.22 pyproject pyproject.toml
argon2-cffi >=23.1,<26 pyproject pyproject.toml
huggingface_hub >=0.24,<2 pyproject pyproject.toml
jsonschema >=4.0,<5 pyproject pyproject.toml
llama-cpp-python >=0.3.23,<0.4 pyproject pyproject.toml
llama-cpp-python >=0.3.23,<0.4 pyproject pyproject.toml
llama-cpp-python >=0.3.23,<0.4 pyproject pyproject.toml
mypy >=1.10,<3 pyproject pyproject.toml
numpy >=2.0,<3 pyproject pyproject.toml
onnxruntime >=1.22,<2 pyproject pyproject.toml
onnxruntime >=1.22,<2 pyproject pyproject.toml
onnxruntime >=1.22,<2 pyproject pyproject.toml
platformdirs >=4.2,<5 pyproject pyproject.toml
pre-commit >=4.0,<5 pyproject pyproject.toml
pydantic >=2.7,<3 pyproject pyproject.toml
pyfiglet >=1.0,<2 pyproject pyproject.toml
pytest >=8.0,<10 pyproject pyproject.toml
pytest-asyncio >=1.0,<2 pyproject pyproject.toml
pytest-benchmark >=4.0,<6 pyproject pyproject.toml
pytest-cov >=5.0,<8 pyproject pyproject.toml
questionary >=2.0,<3 pyproject pyproject.toml
rich >=13.7,<16 pyproject pyproject.toml
ruff ==0.15.13 pyproject pyproject.toml
scipy >=1.14,<2 pyproject pyproject.toml
scipy >=1.14,<2 pyproject pyproject.toml
scipy >=1.14,<2 pyproject pyproject.toml
structlog >=24.0,<26 pyproject pyproject.toml
textual >=0.80,<9 pyproject pyproject.toml
torch >=2.7,<3 pyproject pyproject.toml
torch >=2.7,<3 pyproject pyproject.toml
torch >=2.7,<3 pyproject pyproject.toml
typer >=0.26,<1 pyproject pyproject.toml
types-PyYAML >=6.0,<7 pyproject pyproject.toml
types-psutil >=7.0,<8 pyproject pyproject.toml
zeroconf >=0.130,<1 pyproject pyproject.toml

How to update

  1. Run agmind upgrade --check and inspect this report.
  2. For a component update, run agmind upgrade --component <id> --version <target> --plan.
  3. If the plan is acceptable, run agmind upgrade --component <id> --version <target> --apply.
  4. Run agmind doctor and the component verification commands listed in templates/components/<id>.yaml.
  5. Run docker compose --env-file /opt/agmind/.env -f <rendered-compose.yml> config --quiet for the affected rendered profiles.
  6. Commit descriptor, contract, and digest changes only after verification.
  7. If verification fails, run agmind upgrade --rollback.

How to bump

  1. Update image: или FROM tag в templates/services/*.yaml / docker/Dockerfile.*
  2. Update digest: docker buildx imagetools inspect <image>:<tag> → copy sha256:...
  3. Local verify: agmind doctor + pytest -q + scripts/checks/audit_forbidden.py
  4. Commit + push; weekly version-check.yml подтвердит ✅ в next report.

Generated by scripts/checks/version_check.py at 2026-09-21.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    upstream-updateUpstream image/dep bump available

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions