Software related change records:
https://www.drupal.org/list-changes/drupalorg
Infrastructure related change records:
https://www.drupal.org/list-changes/infrastructure
Announcements
Please review security releases:
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2019-003
Date: 2019-February-20
CVE ID: CVE-2019-6340
Some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
A site is only affected by this if one of the following conditions is met:
The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows GET, PATCH or POST requests, or
the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7.
Read more: https://www.drupal.org/sa-core-2019-003
Previous Sprint Changes
Rollback: Change the issue credit attribution to default to crediting commenters (maintainers must deselect commenters to remove credit attribution)
Based on feedback from the community, we have decided to rollback this change. We will review our Granting Issue Credit as a Maintainer guide and some new issues that were created as a result of maintainer feedback after this change, and revisit this issue at a later date.
Change record: https://www.drupal.org/node/2974366
Issue: https://www.drupal.org/project/drupalorg/issues/2972225
Status: Rollback
GitLab phase 1 production readiness
The Engineering Team has been working on our pre and post deployment checklist for phase 1. We are in the process of testing our disaster recovery plans, maintaining our staging servers and planning routine upgrades.
Status: In progress
Upcoming Changes
Scheduling Phase 1 of the GitLab migration
We recently announced our partnership with GitLab to power the developer tools on Drupal.org. This will be a multi-phase process. In the first phase we'll be replacing the current Git backend as well as the code viewing tools with GitLab. The team is currently evaluating the latest release of GitLab and testing our migration process, before scheduling a migration window.
For more information about the upcoming changes, check out this video:
https://www.youtube.com/watch?v=q06taaJPGDw
Change record: https://www.drupal.org/node/3002828
Issue: https://www.drupal.org/project/infrastructure/issues/3002827
Status: Provisionally scheduled for the week of March 3rd or March 10th, we will put out further messaging as we firm the migration date.
Ongoing Changes
Importing existing donation and membership data to new membership system
If you've ever needed to look up a history of your donations to the DA for tax purposes, you'll be happy for this one. Now you will see the full history of donations, not including memberships, on your Drupal.org profile.
Change record: https://www.drupal.org/node/2956455
Issue: https://www.drupal.org/project/drupalorg/issues/2934492
Status: In progress
Implementing Open Demographics Initiative on Drupal.org
To improve the inclusiveness of our community, we want to provide better tools for understanding our community, and for allowing members of our community (at their choice) to positively affirm their identity and expression.
There are a number of important axes of identity and expression, however. We are evaluating making a module to include the Open Demographics Initiative, by @drnikki, with input from @sagesharp, @rachel_norfolk, @justafish, among others.
Change record: https://www.drupal.org/node/2944177
Issue: https://www.drupal.org/project/drupalorg/issues/2938949
Status: We have submitted a pull request to provide all of the questions and answers from ODI in a JSON format: https://github.com/drnikki/open-demographics/pull/48 further reviews are welcome!
Read more about these change notifications.
Sign up to receive change notifications via email.