Maintainers, Association leaders, developers, and community organisers faced versions of the same question this week: how should Drupal fund, govern, and sustain the work its users rely on? Reporting from 20–27 July 2026 followed that question across Association finances, security response, artificial intelligence, technical maintenance, and community participation. Read together, the stories show that shared infrastructure remains dependable only when responsibility for maintaining it is made visible.
The funding question became explicit in The DropTimes’ written exchange with Tiffany Farriss, interim CEO of the Drupal Association. Farriss proposed programme-level cost accounting and the possible use of usage-based contributions for enterprise-facing utility and infrastructure services, while separating that work from digital-public-good programmes and ecosystem advocacy. The proposals are not approved policy, but they move the discussion beyond general appeals for support towards clearer questions about cost, value, and who benefits from Drupal’s shared systems.
Interim CEO Tiffany Farriss has proposed programme-level cost accounting and possible usage-based funding for enterprise-facing utility and infrastructure services. Her interim agreement restricts her involvement in matters directly affecting Palantir.net and places several partner decisions under Finance Committee and Board oversight. Tim Doyle called his departure a natural transition point, while Board-specific details about the interim appointment and permanent search remain unavailable.
The Drupal Security Team issued ten contributed-project security advisories on 22 July 2026 and separately removed security coverage from QA Accounts. Five projects received fixed releases, while five unsupported projects must be uninstalled, and the remaining issues involve access bypass or cross-site scripting under specific conditions. Drupal site teams need to review installed versions, project support status, permissions, and environment exposure before deciding what action to take.
Chris Kelly discusses the candidacy for the Drupal Association Board in written answers to The DropTimes. Kelly connects AI-assisted code, digital sovereignty, institutional neutrality, installation guidance, secure updates, and public-sector contribution to proposals for lowering barriers to Drupal adoption. The interview frames accessibility as a practical issue of documentation, security, independence, and support from major Drupal users.
Scott Falconer discusses his candidacy for the Drupal Association Board in written answers to The DropTimes. He connects provider-neutral AI, data portability, contribution pathways, digital sovereignty, conflict-of-interest safeguards, and transparent decision-making to a goal of increasing Drupal adoption. The interview frames growth as a practical issue of maintainer accountability, open standards, community governance, and freedom from vendor lock-in.
Matthew Saunders discusses his candidacy for the Drupal Association Board in written answers to The DropTimes. He connects responsible support for AI-related work, organisational contribution, beginner access, digital sovereignty, neuroinclusion, and financial resilience to proposals for public baselines, recurring reports, and consultation tracking. The interview frames trust as a practical issue of listening, accessibility, participation, and measurable accountability.
Dries Buytaert has proposed two terms for distinguishing open-source code that is simply shared from projects maintained as shared infrastructure. “License-only Open Source” and “Stewarded Open Source” separate licence rights from security response, releases, governance, infrastructure, and long-term care. For Drupal organisations, the distinction provides a vocabulary for discussing dependency risk and the funding required to maintain widely used software.
New Relic, an observability software company, will end Drupal 7 and Drupal 9 monitoring support in its PHP agent on 15 October 2026. The company says affected installations will lose Drupal-specific insights and may produce incorrect alerts from stale or missing metrics. Teams still operating these versions need to include monitoring changes in migration and incident-response planning.
Scott Falconer used an Acquia Engage Paris session to argue that Drupal’s governance model makes it suitable for AI-agent workflows. He pointed to structured content, permissions, workflow controls, integrations, and security as foundations for agents acting on managed content. Drupal teams still need those capabilities to become easier for external agents to discover, invoke, and verify.
Michael Anello built an automated tracker for Drupal modules and recipes that declare a hard dependency on the AI module. The scripts verify project type, dependency, and Drupal compatibility before adding release, activity, and security information where available. The resulting ecosystem tables are now included in the AI Dashboard module’s documentation.
US restrictions and review processes affecting Anthropic and OpenAI models have shown how quickly access to closed AI systems can change. Open-weight models and multi-provider routing give teams more deployment options, but they also add operational, security, and cost responsibilities. For Drupal teams, the practical task is to keep permissions, review, logging, and provider replacement inside the site architecture.
UpGuard identified 2,167 government and education domains in copyright takedown records that indicate likely use in parasite SEO campaigns. Cybersecurity writer Dark Marc separately documented movie-themed spam files in public upload directories, including paths associated with Drupal Webform. Drupal administrators should prevent untrusted files from being stored in publicly accessible locations and investigate unexpected indexed content.
Documentation from CERN, GovCMS, and Stanford Sites shows three ways to govern large Drupal services. Their models divide responsibility through central distributions, service tiers, module controls, and named site ownership. For Drupal teams, the comparison shows why every customisation needs a maintainer, an upgrade path, and a support boundary.
Károly Négyesi has described a Temporal integration for Drupal in a Tag1 Consulting blog post. The integration separates deterministic workflows from Drupal-based activities and uses event history, retry policies, heartbeats, and workers to support long-running processes. It gives Drupal teams another model for workloads that require more recovery and orchestration control than the core Batch and Queue APIs provide.
Juho Vepsäläinen’s 2026 Journal of Web Engineering paper argues that developers should begin with modern HTML before adding heavier frontend abstractions. The paper does not discuss Drupal directly, but it raises questions that can be applied to server rendering, Twig, render arrays, Single Directory Components, and JavaScript use. For the Drupal community, the practical value is a clearer test for when frontend tools support Drupal’s rendering model and when they add avoidable complexity.
A review of the Humanizer skill argues that useful checks for vague attribution, promotional padding, and formulaic prose should not become universal rules for human writing. It examines the skill’s treatment of dashes, heading case, quotation marks, and hyphenation, showing how those defaults can override an author’s or publication’s established style. The piece recommends using the skill as an editorial filter with voice calibration and human sign-off, rather than adopting it unchanged across Drupal agency projects.
Thirty-two unique attendees joined The Drop Times Open Town Hall on 22 July 2026, with at least 29 present for most of the meeting. Community members and newsroom staff discussed editorial standards, digital sovereignty, external outreach, event reporting, artificial intelligence, orchestration and documentation. The meeting also produced plans for an Editorial Working Group and closer collaboration between subject experts and TDT editors.