Software related change records:
https://www.drupal.org/list-changes/drupalorg
Infrastructure related change records:
https://www.drupal.org/list-changes/infrastructure
Announcements
Please review security releases:
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2019-006
Date: 2019-April-17
Security risk: Moderately critical 10/25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon
CVE IDs: CVE-2019-11358
The jQuery project released version 3.4.0, and as part of that, disclosed a security vulnerability that affects all prior versions. As described in their release notes:
jQuery 3.4.0 includes a fix for some unintended behavior when using jQuery.extend(true, {}, ...). If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. This fix is included in jQuery 3.4.0, but patch diffs exist to patch previous jQuery versions.
Drupal core - Moderately critical - Multiple Vulnerabilities - SA-CORE-2019-005
Date: 2019-April-17
Security risk: Moderately critical 14/25 AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:Default
This security release fixes third-party dependencies included in or required by Drupal core.
CVE-2019-10909: Escape validation messages in the PHP templating engine. From that advisory:
Validation messages were not escaped when using the form theme of the PHP templating engine which, when validation messages may contain user input, could result in an XSS.
Previous Sprint Changes
GitLab phase 1
Please review our FAQ’s about GitLab at: https://www.drupal.org/drupalorg/docs/gitlab-integration/gitlab-frequently-asked-questions
If you have questions, please join us in Drupal Slack on channel #gitlab.
Status: Deployed/Completed
Dispatcher Maintenance
We are currently in the process of preparing to migrate Jenkins to a Debian 9 environment for stability. We are planning to schedule this migration the week of April 28th. We will make a planned outage announcement via Twitter once we are closer to scheduling a date and time.
Status: In progress
Permissions for webmaster, content administrator, content moderator, and documentation moderator roles changed
These roles no longer have the “bypass node access” permission. More-specific permissions replace access as-needed. If access to do something is missing, please file a separate follow-up issue.
Drupal.org Issue: https://www.drupal.org/project/drupalorg/issues/2845026
Status: Deployed
Ongoing Changes
Importing existing donation and membership data to new membership system
If you've ever needed to look up a history of your donations to the DA for tax purposes, you'll be happy for this one. Now you will see the full history of donations, not including memberships, on your Drupal.org profile.
Change record: https://www.drupal.org/node/2956455
Issue: https://www.drupal.org/project/drupalorg/issues/2934492
Status: In progress
Implementing Open Demographics Initiative on Drupal.org
To improve the inclusiveness of our community, we want to provide better tools for understanding our community, and for allowing members of our community (at their choice) to positively affirm their identity and expression.
There are a number of important axes of identity and expression, however. We are evaluating making a module to include the Open Demographics Initiative, by @drnikki, with input from @sagesharp, @rachel_norfolk, @justafish, among others.
Change record: https://www.drupal.org/node/2944177
Issue: https://www.drupal.org/project/drupalorg/issues/2938949
Status: We have submitted a pull request to provide all of the questions and answers from ODI in a JSON format: https://github.com/drnikki/open-demographics/pull/48 further reviews are welcome!
Read more about these change notifications.
Sign up to receive change notifications via email.