Drupal CMS News Digest

developments tricks, articles and reviews from Drupal specialists

News Categories: SEO  Design  Marketing
Penyaskito: Canvas Tips&Tricks: Declaring images in SDCs
Canvas Tips&Tricks: Declaring images in SDCs I've read recently about making SDCs dependent on Drupal Canvas because of needing to reference Canvas in the definition of your prop, so the right media widget is used inside Canvas: image: $ref: json-schema-definitions://canvas.module/image type: object title: Image description: > Image of the singer examples: - src: 'micro.webp' alt: 'Nice picture of the singer' width: 200 height: 300That was the case during the alphas. But was fixed long ago, even before the 1.0.0 release. See canvas#3515074. image: type: object title: Image required: [src] properties: src: type: string format: uri-reference contentMediaType: "image/*" x-allowed-schemes: [http, https] # this is image-uri, itself a nested $ref alt: { type: string } width: { type: integer } height: { type: integer } description: > Image of the singer examples: - src: 'micro.webp' alt: 'Nice picture of the singer' width: 200 height: 300That's more verbose, but would make your SDC Canvas-independent and re-usable, and it's 100% equivalent.  If we missed updating some docs, please create an issue on the Canvas issue queue. penyaskito Sat, 07/18/2026 - 17:43 Tags Drupal Drupal Canvas...
BloomIdea: Make-to-Order production for Drupal Commerce: from a spreadsheet to a contrib module
At Josefinas, every pair of shoes is handmade in Portugal after the order is placed. There is no warehouse full of finished stock: a customer buys, and an atelier starts working. For years, the bridge between "order paid" and "order shipped" was a shared spreadsheet. It listed what had to be produced, who was making it, and when it might be ready. It also lived completely outside the store: no link to the actual orders, no states, no history, and no way to know where time was being lost. We replaced that spreadsheet with a Drupal module. It has now been running Josefinas' production for months, and today we are releasing it to the community: Commerce Make-to-Order is available on drupal.org, with a stable 1.0.0 release. What it does Commerce Make-to-Order adds a production layer to Drupal Commerce. Make-to-order (also written made-to-order, or build-to-order) means producing items only after a customer order is received, instead of keeping pre-made inventory. When an order reaches a state you configure (for example, paid), the module creates one MTO order per order item: a production order the team tracks from queue to completion. Each MTO order runs a State Machine workflow designed for real ateliers: Draft, Queued, Waiting for Materials, In Production, Quality Check, Rework, Completed, Canceled. QC failures do not silently loop back into production: they move to a...
Drupal.org blog: Migrating issues from security.drupal.org to git.drupalcode.org
All security issues have been migrated from the older security.drupal.org site to our GitLab instance at git.drupalcode.org. This is the latest in a series of steps to improve Drupal’s coordinated vulnerability disclosure tools. We hope this will help in a few ways: Merge requests for security issues will get automated testing to increase the quality of the releases. (Previously, tests for core security issues had to be triggered manually, and contrib testing was not available.)
GitLab has more automation to help with advisory creation, reducing manual work.
Powerful features like labels, commenting, and thread reviews on merge requests are now possible for security issues as well. Here are some of the key steps we took: We started by evaluating a few solutions. We decided to use the GitLab instance on drupalcode.org. We planned how to remap and improve the current features from security.drupal.org and added some labels and automation to private issues on drupalcode.org. We made new security issue reporting default to git.drupalcode.org for several months. This helped us could gain confidence in the system, fix bugs, and make improvements. While that happened, Neil Drumm worked to create the migration process. The migration finally ran from July 9th to July 12th. This work is possible because of support from the Drupal Association and is very appreciated. We...
Hiking the Presidential Traverse: a hut-to-hut adventure
Years ago, I wrote about hiking the Pemi Loop. To my surprise, many people still read that post. I imagine them sitting at a kitchen table with a map spread before them, trying to figure out what the hike will actually feel like. This post is for that same reader, with a new map spread across the table: New Hampshire's Presidential Range. My friend Chris and I just spent four days hiking through the Presidentials, a rugged chain of peaks named mostly after American presidents. The classic Presidential Traverse covers roughly nineteen to twenty-three miles (31 to 37 kilometers) and involves about nine thousand feet (2,700 meters) of climbing, depending on the route and which summits you include. We traveled from hut to hut rather than carrying a tent. Our four-day itinerary included two full days on the trail, with shorter days at the beginning and end so we could drive to and from the mountains. On paper, the distance and elevation gain look manageable. The numbers didn't capture the effort. Much of our route followed the Appalachian Trail across loose rock and exposed ridgelines, where the weather can turn quickly. The thru-hikers we met called the Presidentials one of their favorite sections and one of the hardest. A mile here can feel like two or three on an easier trail. Unlike the Pemi Loop, this was a point-to-point hike. We traveled south to north, beginning near...
The Drop Times: Three Providers Complete IRAP Assessments for Rules as Code Delivery
Panel access simplifies procurement but does not authorise a deployment. Agencies still need to review the assessment scope, findings, and residual risk against their intended use.
LakeDrops Drupal Consulting, Development and Hosting: A new chapter for the Drupal Association - and why I want you in it
A new chapter for the Drupal Association - and why I want you in it Jürgen Haas Fri 17 Jul 2026 - 14:00 The Drupal Association is changing CEOs, and the community reacted with the intensity it usually reserves for controversy. Jürgen, who sent the DA a formal four-page letter of concern in May, makes the case for constructive engagement over outrage. Leadership means disappointing half the room on almost every decision - disagree with choices without turning decision-makers into enemies. The practical call to action is the 2026 board election. Become a member now to earn the right to vote. If you are already a member, vote. Show up on the quiet days, not only when the alarm goes off. A transition is rare - a moment where the direction is genuinely open.
ImageX: Building a Multi‑Layered Defense with Drupal: Top Security Tools and Practices
A truly secure Drupal site is protected on multiple levels. The web presents a wide range of threats, and each one can be countered with specific modules and techniques. When combined, these defenses create a powerful shield.
Droptica: What to do after Drupal 7: new website, Drupal 11 migration, or another CMS?
Official Drupal 7 support ended on January 5, 2025 - yet many organizations still run sites on it in 2026. The real question is no longer “should we update?” but what platform you want for the next 5-10 years.A practical decision guide: rebuild on Drupal 11 or Drupal CMS, migrate content, switch CMS, go static, or buy time with extended support - plus a prep checklist for pricing and board-ready options.
mark.ie: LocalGov Drupal Microsites Demo Module launched
LocalGov Drupal Microsites Demo Module launched Contributing to LocalGov Microsites and demoing it to others is harder than it should be, due to the lack of a demo content. But no longer ... markconroy 16th Jul 2026
The Drop Times: AWS Outlines Sovereignty Controls as EU Sets Cloud Procurement Tests
For regulated Drupal projects, choosing a cloud region settles only the easiest part of the sovereignty question. Access, key custody, operations, recovery, and exit planning determine whether the hosting claim holds.
The Drop Times: Darren Oh Outlines Drupal Board Priorities on AI, Sovereignty, and Contributor Health
Darren Oh links his board candidacy to a question now facing Drupal: how the project can expand adoption without adding friction for maintainers, smaller projects, and new users.
Webpro Company blog: Drupal core July security updates: what site owners should check now
On July 15, 2026, Drupal published several core security advisories. If an organisation's website, portal or service platform runs on Drupal, now is the time to check not only the version number, but the whole update process. Drupal core July security updates: what site owners should check now On July 15, 2026, Drupal published several core security advisories. According to Drupal.org, the issues include cross-site scripting, commonly known as XSS, and information disclosure risks. The relevant fixes point to Drupal 11.4.4, Drupal 11.3.14 and Drupal 10.6.13. This does not mean every Drupal site is automatically under attack. It does mean that Drupal cannot be treated as a platform to look at "later". For a school, municipality, public-sector body, university, NGO or larger…
DDEV Blog: DDEV July 2026: New Screencasts, Partner Perks
DDEV v1.25.3 Released DDEV v1.25.3 is out, with: New Docker Compose library → Improved UX during ddev start and ddev stop; the separate ~/.ddev/bin/docker-compose binary is no longer needed Way Faster ddev start, ddev stop, and ddev restart → See below MariaDB 12.3 LTS support Podman and Docker rootless are no longer experimental → Both are now stable and ready for general use Node.js improvements → nodejs_version is preserved in .ddev/config.yaml, and you can install several Node.js versions with n install <version> inside the web container See the release announcement and the release notes↗. Start-Time Improvements: Test Them Yourself ddev start in v1.25.3 runs post-healthcheck tasks concurrently (thanks to @jonesrussell), and a fixed bug in the web server startup script removes a ~10-second delay from ddev stop. In our benchmarks, ddev start from a stopped state is about 28% faster on macOS and 21% faster on Linux. Don't take our word for it — a new script lets you benchmark the difference on your own machine: bash scripts/compare-start-perf.sh v1.25.2 v1.25.3 See scripts/compare-start-perf.sh↗ and the demonstration GIFs in the release announcement. Perks for $100+/month Partners Organizations sponsoring at $100/month or more now receive additional partner perks. Become a sponsor↗ or contact us to learn more. $100/month+ Partners get Full unrestricted access...
Drupal Association blog: Tiffany Farriss to lead the Drupal Association
This article is cross-posted with permission from Dries Buytaert's blog. The Drupal Association is entering a new chapter. Tim Doyle is stepping down as CEO, and the Board has appointed Tiffany Farriss as interim CEO. I am grateful to Tim for his leadership and his impact on the Association. He built a strong leadership team that helped guide Drupal through an ambitious period of innovation. That team is well positioned to continue supporting Drupal and its community. Tiffany brings continuity and deep expertise to the Drupal Association. She has contributed to Drupal for many years and served on the Drupal Association Board for more than a decade, including on its Finance Committee. She helped organize DrupalCon and built and ran a successful agency in the Drupal ecosystem. She understands our project, the Association's finances, and the realities our partners, contributors, and users face. I have worked with Tiffany for many years. She is thoughtful, deeply committed to Drupal, and unafraid of hard questions. Although her title is interim CEO, she has the full authority and confidence of the Board, as well as my full support. We expect Tiffany to serve for six to twelve months. During that time, she will focus on strengthening the Association's financial and operational foundation and preparing it for long-term leadership. Later in that period, the Board plans to launch a...
Dries Buytaert: Tiffany Farriss to lead the Drupal Association
The Drupal Association is entering a new chapter. Tim Doyle is stepping down as CEO, and the Board has appointed Tiffany Farriss as interim CEO. I am grateful to Tim for his leadership and his impact on the Association. He built a strong leadership team that helped guide Drupal through an ambitious period of innovation. That team is well positioned to continue supporting Drupal and its community. Tiffany brings continuity and deep expertise to the Drupal Association. She has contributed to Drupal for many years and served on the Drupal Association Board for more than a decade, including on its Finance Committee. She helped organize DrupalCon and built and ran a successful agency in the Drupal ecosystem. She understands our project, the Association's finances, and the realities our partners, contributors, and users face. I have worked with Tiffany for many years. She is thoughtful, deeply committed to Drupal, and unafraid of hard questions. Although her title is interim CEO, she has the full authority and confidence of the Board, as well as my full support. We expect Tiffany to serve for six to twelve months. During that time, she will focus on strengthening the Association's financial and operational foundation and preparing it for long-term leadership. Later in that period, the Board plans to launch a search for the next permanent CEO. Turning innovation into momentum Tiffany...
Tiffany Farriss to lead the Drupal Association
The Drupal Association is entering a new chapter. Tim Doyle is stepping down as CEO, and the Board has appointed Tiffany Farriss as interim CEO. I am grateful to Tim for his leadership and his impact on the Drupal Association. He built a strong leadership team that helped guide Drupal through an ambitious period of innovation. That team is well positioned to continue supporting Drupal and its community. Tiffany brings continuity and deep expertise to the Drupal Association. She has contributed to Drupal for many years and served on the Drupal Association Board for more than a decade, including serving on its Finance Committee. She helped organize DrupalCons and built a successful agency in the Drupal ecosystem. She understands our project, the Drupal Association's finances, and the realities our partners, contributors, and users face. I have worked with Tiffany for many years. She is thoughtful, deeply committed to Drupal, and unafraid of hard questions. Although her title is interim CEO, she has the full authority and confidence of the Board, as well as my full support. We expect Tiffany to serve for six to twelve months. During that time, she will focus on strengthening the Association's financial and operational foundation and preparing it for long-term leadership. Later in that period, the Board plans to launch a search for the next permanent CEO. Turning innovation into...

Number of Total Worldwide Registered Domains