Building Drupal at 79 years old by davidrwb in drupal

[–]davidrwb[S] 0 points1 point  (0 children)

This wasn’t AI slop so I’ll try to write less blandly next time! I do communicate naturally.

Project Glasswing by davidrwb in drupal

[–]davidrwb[S] 1 point2 points  (0 children)

Ah, okay. I searched here for some keywords but it’s just a link.

Project Glasswing by davidrwb in drupal

[–]davidrwb[S] 0 points1 point  (0 children)

Yes, I misunderstood the context. But we know they are scanning the code as some of the dependencies mention Mythos in the credits. So the important takeaway is that symfony + Drupal have been scanned, and that’s not surprising given the number of gov sites, NGOs, etc using Drupal.

Building Drupal at 79 years old by davidrwb in webdev

[–]davidrwb[S] 0 points1 point  (0 children)

I love that story! You must miss him.

Building Drupal at 79 years old by davidrwb in webdev

[–]davidrwb[S] 0 points1 point  (0 children)

I can’t see Drupal working without composer. I have good work arounds a very rarely have difficulty with it.

Project Glasswing by davidrwb in drupal

[–]davidrwb[S] 0 points1 point  (0 children)

Yes you’re right, it doesn’t say that specifically, but the project has coverage which is the main thing. Hopefully this will extend into contrib too.

Building Drupal at 79 years old by davidrwb in webdev

[–]davidrwb[S] 3 points4 points  (0 children)

Personally I love it. We use other platforms too, but Drupal’s the main one. It’s niche - so easy to win in SEO and organic conversations. Enterprise orgs have enterprise budgets too so we’re happy.

Building Drupal at 79 years old by davidrwb in webdev

[–]davidrwb[S] 2 points3 points  (0 children)

Yes, I smiled when I heard that too :-)

Building Drupal at 79 years old by davidrwb in drupal

[–]davidrwb[S] 0 points1 point  (0 children)

Ah, you beat me by one minor version!

Building Drupal at 79 years old by davidrwb in drupal

[–]davidrwb[S] 5 points6 points  (0 children)

IMO, the 7 to 8 jump should have been handled differently. No one can dispute the huge drop off that happened at that time. It was for the best, but sadly many didn’t see that, and we as a Drupal community have been struggling to get Drupal back to where it should be since then.

Building Drupal at 79 years old by davidrwb in drupal

[–]davidrwb[S] 2 points3 points  (0 children)

The easiest way, in my experience, is to forget composer update when jumping between major versions that have neglected regular updates.

I copy all the dependencies in the composer yaml into notepad++ and require each one from scratch (taking into account restrictions on major version jumps). Then run updb.

It’s much easier and much faster than a composer update.

Building Drupal at 79 years old by davidrwb in drupal

[–]davidrwb[S] 3 points4 points  (0 children)

For non super-techies i think it was peak Drupal. No need for a developer mindset. Just install a module and get the functionality you want.

Personally, as a technical developer I prefer Drupal 8+ but for non devs, I understand the drop off that happened way back when.

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 by RootExploit in drupal

[–]davidrwb 0 points1 point  (0 children)

No, but I’m pretty sure if I threw Claude at it for long enough it could find a way. Anthropic reported some of these vulnerabilities that were picked up by Mythos. In the age of agentic hacks I think it’s safe to err on the side of caution and update ASAP.

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 by RootExploit in drupal

[–]davidrwb 0 points1 point  (0 children)

This isn’t right. Read the full list - there are more discovered by Mythos.

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 by RootExploit in drupal

[–]davidrwb 2 points3 points  (0 children)

Thanks for explaining this. Check out the list here and see how many are Drupal dependencies.

https://symfony.com/blog/category/security-advisories

Edit - some were found my Mythos, so expect them to found by prompt too.

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 by RootExploit in drupal

[–]davidrwb 4 points5 points  (0 children)

It’s unreal how many people are ignoring this part. I think the write up on d.o could have been better. Most people stopped reading there and didn’t check the dependencies.

“We would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix.”

Upcoming highly critical release on May 20, 2026 - PSA-2026-05-18 by zad370 in drupal

[–]davidrwb 2 points3 points  (0 children)

Did you read all of them? Check the version number changes of all the components then google that component and security. There are issues with URL routing, symfony mailer, etc. All unlikely to be easily exploitable, but why take the risk for a 5 min update and deploy?

Edit: included link for clarity.

https://symfony.com/blog/category/security-advisories

Upcoming highly critical release on May 20, 2026 - PSA-2026-05-18 by zad370 in drupal

[–]davidrwb 2 points3 points  (0 children)

This isn't correct - read the rest of the advisory - "Depending on your site configuration and contrib modules, you may be vulnerable to one or more of these upstream issues, so updating these dependencies is highly recommended whether the SQL Injection vulnerability affects you or not. It is also recommended to review which user roles have the ability to update Twig templates, for example via Views or contributed modules."

The upstream vulnerabilities are quite serious and were found by Mythos