An upstream security advisory does not automatically trigger CRA reporting. For manufacturers in scope, the decisive question is whether an actively exploited flaw affects their own product, and if it does, a 24-hour reporting clock can start.
Resource-constrained maintainers can now seek subsidised cyber access, but OpenAI has not published criteria showing how independent open-source projects will qualify.
...more
A known database state can now return automatically when a DDEV project starts with an empty database, removing a repeated restoration step from local Drupal work.
...more
Twig has lacked the automated standards enforcement already available for PHP, JavaScript and CSS. The shared GitLab CI job brings contributed projects closer to the same checks now running in Drupal core.
...more
For Drupal teams responsible for production systems, the session offers a look at how a former Acquia senior product manager is approaching observability across multiple DevOps tools.
...more
Critical ratings are only part of the triage. Project reach varies sharply, and one advisory requires administrators to clean stored data after updating.
...more
A technical design that works well at one scale can become costly as an ecosystem grows. Drupal's update service shows how those costs can fall on a different group from the one that controls the underlying code.
...more
The week’s Drupal calendar stays in person, with a full conference programme in Poland alongside regional community gatherings in Germany and India.
...more