Drupal.org Completes Security Issue Migration to GitLab

Advisory Automation and Threaded Reviews for Confidential Issues
TDT hero card about Drupal.org security issue workflows. Title: “Drupal.org Moves Security Issues to GitLab.” Deck: “Automated Testing and Review for Confidential Vulnerability Work.”

Security issues from Drupal.org’s legacy site at security.drupal.org have moved to its GitLab instance at git.drupalcode.org. Greg Knaddison, a Drupal Security Team member, announced the completed migration in a Drupal.org blog post published 17 July 2026. Drupal.org had directed new security reports to GitLab by default for several months before the migration ran from 9 to 12 July 2026.

The change brings automated testing to merge requests for security issues. Core security tests previously required manual triggering, while testing was unavailable for contributed-project security issues. GitLab also adds automation for advisory preparation, along with labels, comments, and threaded merge-request reviews.

Security reports should still begin through the “Report a security vulnerability” link on a project page. Projects whose public issue queues have moved to GitLab can also accept issues marked confidential when they are created, and the Security Team triages confidential reports for projects covered by Drupal’s security advisory policy. Neil Drumm, Drupal.org architect, developed the migration process with support from the Drupal Association. Drupal.org suppressed most migration emails, although some users received additional notifications about current or older issues. The former security site now redirects issue requests to GitLab, and Security Team members can retrieve material if migrated content appears to be missing.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events

Latest Opportunities