An upstream security advisory does not automatically trigger CRA reporting. For manufacturers in scope, the decisive question is whether an actively exploited flaw affects their own product, and if it does, a 24-hour reporting clock can start.
The Ahmedabad meetup puts practical Drupal work at the centre, with project demonstrations, tools, experiments, and discussion replacing formal slide-led sessions.
...more
Updating alone is not enough for every affected site. One module introduces a new permission requirement, while another has no fixed release and should be uninstalled.
...more
Bug reproductions are difficult to hand to coding agents when the workflow depends on a browser and undocumented frontend behaviour. The phpstan-drupal playground now exposes the information those agents need directly.
...more
Registration timing will matter more for Orlando than it did for Chicago. Waiting until the final ticket tier will add $550 to the standard admission price.
...more
Resource-constrained maintainers can now seek subsidised cyber access, but OpenAI has not published criteria showing how independent open-source projects will qualify.
...more
A known database state can now return automatically when a DDEV project starts with an empty database, removing a repeated restoration step from local Drupal work.
...more
Twig has lacked the automated standards enforcement already available for PHP, JavaScript and CSS. The shared GitLab CI job brings contributed projects closer to the same checks now running in Drupal core.
...more
For Drupal teams responsible for production systems, the session offers a look at how a former Acquia senior product manager is approaching observability across multiple DevOps tools.
...more