27 Nov 2025

feedDrupal.org aggregator

The Drop Times: Oaisys 25 Is Almost Here; Vidit Anjaria Has the Inside Story

With Oaisys 25 just days away, QED42 Engineering Manager Vidit Anjaria sits down with The DropTimes to talk about the evolution of engineering culture, the lessons that shaped his approach to architecture, and why this weekend's open-source AI practitioners' event could mark a turning point for the community.

27 Nov 2025 2:32pm GMT

Dries Buytaert: Thank you, Drupal Security Team

A blue heart

Today is Thanksgiving in the US. I know it's not a global holiday, but it has me thinking about gratitude, and specifically about a team that rarely gets the recognition it deserves: the Drupal Security Team.

As Drupal's project lead, I'm barely involved in our security work. And you know what? That is a sign that things are working really well.

Our Security Team reviews reports, analyzes vulnerabilities, coordinates patches across supported Drupal versions, and publishes advisories. They work with Drupal module maintainers and reporters to protect millions of websites. They also educate our community proactively, ensuring problems are prevented, not just fixed. It can be a lot of work, and delicate work.

To get an idea of the quality of their work, check out recent advisories at drupal.org/security. I know it's maybe strange to point out security advisories, but their work meets the highest standards of maturity. For example, Drupal is authorized as a CVE Numbering Authority, which means our security processes meet international standards for vulnerability coordination.

Whether you're running a small blog or critical government infrastructure, the Security Team protects you with the same consistency and professionalism.

While I'm on our private security team mailing list, they do all this without needing me to oversee or interfere. In fact, the team handles everything so smoothly that my involvement would only slow them down. In the world of open source leadership, there is no higher compliment I can pay them.

Security work is largely invisible when done well. Nobody celebrates the absence of breaches. The researchers who report issues often get more recognition than the team members who spend hours verifying, patching, and coordinating fixes.

All software has security bugs, and fortunately for Drupal, critical security bugs are rare. What really matters is how you deal with security releases.

To our Security Team: thank you for your excellence. Thank you for protecting Drupal's reputation through consistent, professional, often invisible work, week after week.

27 Nov 2025 1:00pm GMT

The Drop Times: The Human Edge in Presales: Beating AI-Drafted Drupal Proposals

AI has sped up proposal writing-but made them all sound the same. In this DrupalCon Vienna session, Monisha Navlani explores how Drupal agencies can rise above the noise with real-world context, trust, and a human voice.

27 Nov 2025 7:39am GMT