Recent audited figures give Drupal’s sustainability debate a concrete baseline. The Drupal Association says unrestricted reserves are about $960,000, equal to 2.3 months of operating expenses and below the board’s three-month minimum. Its 2025 accounts put Drupal.org and supporting services at about $2.1 million in programme expenses, without a dedicated funding mechanism. The question is no longer whether shared work has a cost, but how those costs become recurring commitments.
The same problem appears across infrastructure, security review, dependency maintenance and contribution. These responsibilities continue after software is adopted and cannot be assumed to exist indefinitely through volunteer capacity, one-off grants, donated services or event revenue. Current proposals differ on the mechanism, but increasingly treat stewardship as capacity that organisations and institutions have to plan and fund.
That makes this week’s question narrower than whether Drupal needs stewardship. It is who pays, for what, and on what recurring basis. With voting in the 2026 Drupal Association at-large board election open until 14 August 2026 at 23:59 UTC, those choices are also part of a live governance decision.
Audited statements show the Drupal Association ended 2025 with a $224,072 decline in total net assets after restating the 2024 decline to $922,731. Management says unrestricted reserves fell to about $960,000, equal to 2.3 months of operating expenses, while donated and exchanged services accounted for more than $1 million of 2025 support and revenue. For the Drupal community, the figures sharpen questions about how Drupal.org will be funded and how the board will receive reconciled financial reports.
James Abrahams is standing for the at-large seat on the Drupal Association Board in the 2026 election. He argues that sustainable funding should support open-source AI, stakeholder-led contribution, digital sovereignty, and clearer governance for AI agents. He asks to be evaluated on progress towards a durable funding model and a concise Drupal-wide strategy.
Helge Notø has set out his priorities as a candidate in the Drupal Association’s 2026 at-large board election. He calls for clear rules on AI-assisted contributions, stronger institutional support for open source, and cooperation with the PHP Foundation. His proposals connect maintainer capacity and long-term Drupal stewardship to jobs and credible career paths for new contributors.
The European Commission published its EU Open Source Strategy on 3 June 2026 as part of its technology sovereignty package. It proposes procurement reform, support for maintainers and foundations, security measures, skills programmes and funding for essential open-source components. For Drupal organisations, the strategy could influence how public software is selected, maintained, shared and transferred between suppliers.
Adopting an open-source dependency does not end technical due diligence. Hosted access, licensing, maintainer capacity, successor projects, and regulation can change during its operational life. Drupal teams can prepare through accurate inventories, sustainable maintenance practices, and practical continuity planning.
Drupal hosting providers are presenting sovereignty through managed regional platforms, customer-controlled cloud accounts, certified commercial services, government-managed platforms, and self-hosted infrastructure. These models distribute control over data, infrastructure, operations, supply chains, and migration in different ways. Drupal buyers need to test each control separately rather than treating a hosting region as proof of sovereignty.
Decoupled Days 2026 will bring open-source web practitioners to Montréal on 6 and 7 August 2026. Four featured speakers will examine content modelling, configurable applications, neurodivergent working experiences, and development processes for artificial intelligence tools. Their sessions offer Drupal and broader decoupled-web teams practical perspectives on governance, application structure, workplace agency, and software delivery.
Drupal core maintainers released Drupal 11.4.5 and Drupal 10.6.15 on 6 August 2026. Drupal 11.4.5 fixes the AJAX error that could prevent administrators from creating a new content-based View and includes a wider set of core bug fixes. Drupal 11.4.x has security coverage until June 2027, while Drupal 10.6.x remains under security support until December 2026.
The Drupal Security Team published two Moderately Critical contributed-module security advisories on 5 August 2026 for Entity Browser and Edit in-place field. Entity Browser has a stored cross-site scripting flaw in tab titles, while Edit in-place field can let users with a specific permission modify fields without normal entity access checks. Maintainers using affected releases should update to Entity Browser 8.x-2.16 and Edit in-place field 2.1.1.
Display Builder 1.0.0-beta6 was released on 6 August 2026 with new UX, preview, and Drupal 11.4 compatibility work. The release follows Beta 5’s shift to revision-backed history and incorporates the interface refresh demonstrated at UI Suite Monthly #37. Translation and accessibility work remain as the project moves toward a release candidate.
Webform 6.3.0 became the module’s first stable release compatible with Drupal 11 on 7 July 2026. It requires Drupal 10.3 or Drupal 11 and records 292 resolved issues from 229 contributors, while maintainers flag caching, asset-loading, and submodule concerns. Drupal site teams now have a stable upgrade path but should test affected configurations before production deployment.
Joshua Mitchell has detailed PDFa11y, a Drupal module that reviews uploaded PDFs for selected accessibility issues. The module examines document metadata and structure, records passed, failed, or skipped results, and can be configured to warn editors or block uploads when checks fail. Drupal teams can use it as an early publishing control, but the project does not present automated scanning as a comprehensive accessibility assessment.
Rod Martin surveys Drupal’s unsettled site-building landscape across Layout Builder, Paragraphs, Canvas, UI Patterns, and Display Builder. He recommends keeping content structured, using Single-Directory Components for frontend work, and choosing one primary builder for each project. The approach aims to preserve portability while Drupal’s builder roles and integration paths continue to evolve.
Drupal AI Videos published a demonstration of a self-hosted observability stack created with the One Line Installer. The setup sends OpenTelemetry data through Alloy to Tempo, Mimir, and Loki, while Grafana displays requests, costs, and agent-session traces. The example gives Drupal teams a reference for testing local monitoring of AI calls and nested agent activity.