Drupal.org Completes Security Issue Migration to GitLab
Security issues from Drupal.org’s legacy site at security.drupal.org have moved to its GitLab instance at git.drupalcode.org. Greg Knaddison, a Drupal Security Team member, announced the completed migration in a Drupal.org blog post published 17 July 2026. Drupal.org had directed new security reports to GitLab by default for several months before the migration ran from 9 to 12 July 2026.
The change brings automated testing to merge requests for security issues. Core security tests previously required manual triggering, while testing was unavailable for contributed-project security issues. GitLab also adds automation for advisory preparation, along with labels, comments, and threaded merge-request reviews.
Security reports should still begin through the “Report a security vulnerability” link on a project page. Projects whose public issue queues have moved to GitLab can also accept issues marked confidential when they are created, and the Security Team triages confidential reports for projects covered by Drupal’s security advisory policy. Neil Drumm, Drupal.org architect, developed the migration process with support from the Drupal Association. Drupal.org suppressed most migration emails, although some users received additional notifications about current or older issues. The former security site now redirects issue requests to GitLab, and Security Team members can retrieve material if migrated content appears to be missing.
References
-
GitLab issues for Drupal.org projects (8 July 2026)
-
Reporting a security issue (27 July 2026)


