Drupal.org changes for the sprint from 24 Feb to 09 Mar 2019

30 views
Skip to first unread message

Drupal.org change notifications

unread,
Feb 26, 2019, 8:30:15 PM2/26/19
to Drupal.org change notifications

Software related change records:

https://www.drupal.org/list-changes/drupalorg

Infrastructure related change records:

https://www.drupal.org/list-changes/infrastructure




Announcements


Please review security releases:


Drupal core - Highly critical - Remote Code Execution - SA-CORE-2019-003

Date: 2019-February-20

CVE ID: CVE-2019-6340

Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.


A site is only affected by this if one of the following conditions is met:


  • The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows GET, PATCH or POST requests, or


  • the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7.


Read more:  https://www.drupal.org/sa-core-2019-003



Previous Sprint Changes


Rollback:  Change the issue credit attribution to default to crediting commenters (maintainers must deselect commenters to remove credit attribution)


Based on feedback from the community, we have decided to rollback this change.  We will review our Granting Issue Credit as a Maintainer guide and some new issues that were created as a result of maintainer feedback after this change, and revisit this issue at a later date.


Change record: https://www.drupal.org/node/2974366

Issue: https://www.drupal.org/project/drupalorg/issues/2972225

Status: Rollback


GitLab phase 1 production readiness

The Engineering Team has been working on our pre and post deployment checklist for phase 1.  We are in the process of testing our disaster recovery plans, maintaining our staging servers and planning routine upgrades.


Status: In progress




Upcoming Changes


Scheduling Phase 1 of the GitLab migration

We recently announced our partnership with GitLab to power the developer tools on Drupal.org. This will be a multi-phase process. In the first phase we'll be replacing the current Git backend as well as the code viewing tools with GitLab. The team is currently evaluating the latest release of GitLab and testing our migration process, before scheduling a migration window.


For more information about the upcoming changes, check out this video:

https://www.youtube.com/watch?v=q06taaJPGDw


Change record: https://www.drupal.org/node/3002828

Issue: https://www.drupal.org/project/infrastructure/issues/3002827

Status: Provisionally scheduled for the week of March 3rd or March 10th, we will put out further messaging as we firm the migration date.




Ongoing Changes


Importing existing donation and membership data to new membership system

If you've ever needed to look up a history of your donations to the DA for tax purposes, you'll be happy for this one. Now you will see the full history of donations, not including memberships, on your Drupal.org profile.


Change record: https://www.drupal.org/node/2956455

Issue: https://www.drupal.org/project/drupalorg/issues/2934492

Status: In progress


Implementing Open Demographics Initiative on Drupal.org

To improve the inclusiveness of our community, we want to provide better tools for understanding our community, and for allowing members of our community (at their choice) to positively affirm their identity and expression.


There are a number of important axes of identity and expression, however. We are evaluating making a module to include the Open Demographics Initiative, by @drnikki, with input from @sagesharp, @rachel_norfolk, @justafish, among others.


Change record: https://www.drupal.org/node/2944177

Issue: https://www.drupal.org/project/drupalorg/issues/2938949

Status: We have submitted a pull request to provide all of the questions and answers from ODI in a JSON format: https://github.com/drnikki/open-demographics/pull/48 further reviews are welcome!



Read more about these change notifications.

Sign up to receive change notifications via email.

Reply all
Reply to author
Forward
0 new messages