Log message:
www/drupal11: update to 11.1.9
11.1.6 (2025-04-02)
This is a patch (bugfix) release of Drupal 11 and is ready for use on
production sites.
11.1.7 (2025-05-08)
This is a patch (bugfix) release of Drupal 11 and is ready for use on
production sites.
11.1.8 (2025-06-05)
This is a patch (bugfix) release of Drupal 11 and is ready for use on
production sites.
11.1.9 (2025-11-12)
This is a security release of the Drupal 11 series.
This release fixes security vulnerabilities. Sites are urged to update
immediately after reading the notes below and the security announcements:
* Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005
* Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006
* Drupal core - Moderately critical - Defacement - SA-CORE-2025-007
* Drupal core - Moderately critical - Information disclosure -
SA-CORE-2025-008
Important update information
* SA-CORE-2025-005 removes a feature of an underlying library where request
attributes can be manipulated. It is possible that some sites are
actually relying on this feature. In this case, the behavior can be
replicated by implementing a custom stack middleware to alter the incoming
request.
* Symfony Framework released CVE-2025-64500 today. Drupal core does not
expose this vulnerability.
Drupal 11.1 has Symfony 7.2 as minimum version, which is no longer
supported by Symfony as of this month (November 2025). Since Drupal is
not affected by the Symfony security vulnerability, we are not raising the
minimum Symfony version for Drupal 11.1. Sites can update to Symfony 7.3
via Composer if needed, or update to Drupal 11.2. Sites should also aim
to update to Drupal 11.2 or higher before Drupal 11.1 reaches its
end-of-life in December.
Which release do I choose? Security coverage information
* Drupal 11.1.x will receive security coverage until December 2025 when
Drupal 11.3.0 is released and sites should plan to update to Drupal 11.2
or higher by December 2025.
* Sites on Drupal 11.2.x should update immediately to Drupal 11.2.8.
* Sites on Drupal 10.5.x should update immediately to Drupal 10.5.6.
* Sites on Drupal 10.4.x should update immediately to Drupal 10.4.9.
* Drupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive
security coverage.
Other changes in this release
Additional test-only fixes are included in the release:
* Issue #3539331 by dww, godotislate, nicxvan: Incorrect warning for system
requirements for APCu memory
* Issue #3539366 by dimitriskr, andypost, godotislate: Default DB
transaction isolation set to read-committed breaks
InstallerIsolationLevelExistingSettingsTest test
|
Log message:
www/drupal11: update to 11.1.5
Drupal 11.1.5 contains security fix: https://www.drupal.org/sa-core-2025-004
11.1.4 (2025-03-05)
* Issue #3508733 by gábor hojtsy, griffynh: Add griffynh as provisional core
team facilitator
* Issue #3498326 by rinku jacob 13, rkoller, smustgrave, ckrina: Focus
outline has a too low color contrast and uses a different green than Claro
* Issue #3487014 by liam morland, nod_, smustgrave, quietone: Fix
documentation for optional params in MessengerInterface
* Issue #3493858 by vidorado, xavier.masson, smustgrave: Extend
ViewsBlockBase to merge cache metadata from display handler
* Issue #3496485 by annmarysruthy, wombatbuddy, thejimbirch, smustgrave:
example recipe.yml has incorrect comment above "actions" section
* Issue #3490948 by rowrowrowrow, bbrala: Change hardcoded entity key 'uid'
to getKey in ResourceTestBase
* Issue #3508028 by markconroy: Offer to become maintainer of Stable9
* Merged 11.1.3.
* Issue #3499275 by acbramley: Remove --quiet from updatedb in Validatable
config job
* Issue #3501237 by nikolay shapovalov, nicxvan: Improve HookCollectorPass
test
* Issue #3056698 by mondrake, quietone: Sqlite
Connection::createConnectionOptionsFromUrl should not convert relative
paths to full
* Issue #3497758 by nicxvan, oily, alexpott, cilefen, catch, longwave,
wlofgren, dries, wim leers, smustgrave: Regression: RssResponseCdata
filtering out common HTML tags from RSS feeds
* Issue #3469116 by prashant.c, pameeela, kostask, shalini_jha,
sagarmohite0031, benjifisher, mrdalesmith, smustgrave,
kristiaanvandeneynde, quietone, b_sharpe, nod_: Logout confirmation form
shows inappropriate confirmation description
* Issue #3504265 by finnsky, ksenzee, smustgrave: Yarn watch task broken
* Issue #3096570 by recrit, raman.b, ameymudras, ranjith_kumar_k_u, Oscaner,
smustgrave, peterwcm, pameeela: Redirect correct language page after node
save
* Issue #2927338 by berdir, anmolgoyal74, swatichouhan012, smustgrave,
alexpott, gábor hojtsy: Ensure config entity langcode property does not
change when installing, adding or editing a language
* Issue #3503190 by phenaproxima, thejimbirch: Allow recipes to contain an
"extra" property with arbitrary information for specific modules to use
11.1.5 (2025-03-19)
This release fixes a security vulnerability. Sites are urged to update
immediately after reading the notes below and the security announcement:
Drupal core - Moderately critical - Cross-Site Scripting - SA-CORE-2025-004
No other fixes are included.
|
Log message:
Import drupal-11.1.0 as www/drupal11
Drupal is a free web Content Management System (CMS) that allows an
individual or a community of users to easily publish, manage and organize
a wide variety of content on a website.
Drupal is ready to go from the moment you download it. It even has an
easy-to-use web installer! The built-in functionality, combined with dozens
of freely available add-on modules, will enable features such as: Content
Management Systems, Blogs, Collaborative authoring environments, Forums,
Peer-to-peer networking, Newsletters, Podcasting, Picture galleries, File
uploads/downloads and much more.
|