18 Sep 2025
Drupal.org aggregator
Nonprofit Drupal posts: September Drupal for Nonprofits Chat
Join us THURSDAY, September 18 at 1pm ET / 10am PT, for our regularly scheduled call to chat about all things Drupal and nonprofits.(Convert to your local time zone.)
We don't have anything specific on the agenda this month, so we'll have plenty of time to discuss anything that's on our minds at the intersection of Drupal and nonprofits. Got something specific you want to talk about? Feel free to share ahead of time in our collaborative Google document!
All nonprofit Drupal devs and users, regardless of experience level, are always welcome on this call.
This free call is sponsored by NTEN.org and open to everyone.
Information on joining the meeting can be found in our collaborative Google document.
18 Sep 2025 12:08am GMT
17 Sep 2025
Drupal.org aggregator
Security public service announcements: Third-Party Libraries and Supply Chains - PSA-2025-09-17
Supply-chain attack via maintainer account takeover
NPM packages have been targeted in maintainer account takeover attacks. Attackers have deployed an automatic credential scanning tool. The scanning tool tries to find secret keys that may have been published to public systems like build automation and continuous integration (CI) systems and sends such credentials back to the attacker. From there, the vulnerable NPM packages are downloaded, modified to insert a trojan-like script bundle, and then republished. These maliciously modified packages can then be used to exploit any application that has installed these packages.
Coverage and advice on remediation:
- The Hacker News - 40 NPM Packages Compromised
- Socket.dev - Supply Chain Attack
- Aikido - S1ngularity/nx attackers strike again
- Aikido - npm debug and chalk packages compromised
- Wiz.io - Shai-Halud npm supply chain attack
While this attack has targeted NPM packages, the same strategy could be used to exploit other packages as well.
Managing supply-chain security
Website owners should actively manage their dependencies, potentially leveraging a Software Bill of Materials (SBOM) or scanner services. Other relevant tools include CSP and SRI.
It is the policy of the Drupal Security Team that site owners are responsible for monitoring and maintaining the security of third-party libraries and any non-Drupal components of the stack. In rare cases, the Drupal Security Team will post an informational public service announcement (PSA) such as this one, but the remit of the Drupal Security Team remains limited to code hosted on Drupal.org's systems. Previous PSAs on third-party code in the Drupal ecosystem include:
- External libraries and plugins - PSA-2011-002
- Various Third-Party Vulnerabilities - PSA-2019-09-04
- Third-Party Libraries and Supply Chains - PSA-2024-06-26
Impact to the Drupal project itself
Drupal's infrastructure maintainers, the Drupal Security Team, and Drupal core maintainers have received tips about this situation from several sources. Individuals in those groups have evaluated their exposure and we believe the Drupal project itself is not affected by this issue. If you have information about concerns that Drupal is affected please reach out to us.
This post is likely to be be updated as the situation evolves and more information is available.
- Greg Knaddison (greggles) of the Drupal Security Team
- Tim Hestenes Lehnen (hestenet)
- Dave Long (longwave) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- cilefen of the Drupal Security Team
17 Sep 2025 8:30pm GMT
jofitz: How to add a Composer package from a GitHub repository
Sometimes you want to add a Composer package that is not available through drupal.org or Asset Packagist. This article shows you how to add a package directly from its version control repository.
17 Sep 2025 4:31pm GMT
27 Aug 2025
W3C - Blog
26 awardees in W3C's TPAC Inclusion and Invited Expert Support funds
In this blog post, W3C CEO Seth Dobbs reports on the selection of 26 recipients in a funding program related to W3C's stakeholder strategy and Community Engagement support.
27 Aug 2025 10:29am GMT
11 Aug 2025
Official jQuery Blog
jQuery 4.0.0 Release Candidate 1
It's here! Almost. jQuery 4.0.0-rc.1 is now available. It's our way of saying, "we think this is ready; now poke it with many sticks". If nothing is found that requires a second release candidate, jQuery 4.0.0 final will follow. Please try out this release and let us know if you encounter any issues. A 4.0 … Continue reading
11 Aug 2025 5:35pm GMT
31 Jul 2025
W3C - Blog
Vision for W3C to reach durable and sustainable success
In this blog post about the newly published W3C Statement "Vision for W3C", W3C CEO Seth Dobbs emphasizes the importance of principle-driven leadership and how vision gives clarity to move towards meaningful goals.
31 Jul 2025 6:59am GMT
29 Jul 2025
W3C - Blog
Vision for W3C: a manifesto for our operations and decision making
Today, W3C is pleased to announce the publication as a W3C Statement of Vision for W3C. W3C Statements provide a stable reference for documents not intended to be formal standards but that have been formally reviewed and are endorsed by W3C.
29 Jul 2025 10:27am GMT
17 Jul 2024
Official jQuery Blog
Second Beta of jQuery 4.0.0
Last February, we released the first beta of jQuery 4.0.0. We're now ready to release a second, and we expect a release candidate to come soon™. This release comes with a major rewrite to jQuery's testing infrastructure, which removed all deprecated or under-supported dependencies. But the main change that warranted a second beta was a … Continue reading
17 Jul 2024 2:03pm GMT
17 Apr 2024
Official jQuery Blog
Upgrading jQuery: Working Towards a Healthy Web
jQuery's influence on the web will always be evident. When it was first introduced in 2006, jQuery became a fundamental tool for web developers almost immediately. It simplified JavaScript programming, making it easier to manipulate HTML documents, handle events, perform animations, and much more. Since then, it has played and continues to play a major … Continue reading
17 Apr 2024 5:00pm GMT
29 May 2023
Smiley Cat: Christian Watson's Web Design Blog
7 Types of Article Headlines: Craft the Perfect Title Every Time
When it comes to crafting an article, the headline is crucial for grabbing the reader's attention and enticing them to read further. In this post, I'll explore the 7 types of article headlines and provide examples for each using the subjects of product management, user experience design, and search engine optimization. 1. The Know-it-All The […]
The post 7 Types of Article Headlines: Craft the Perfect Title Every Time first appeared on Smiley Cat.
29 May 2023 10:20pm GMT
09 Apr 2023
Smiley Cat: Christian Watson's Web Design Blog
5 Product Management Myths You Need to Stop Believing
Product management is one of the most exciting and rewarding careers in the tech world. But it's also one of the most misunderstood and misrepresented. There are many myths and misconceptions that cloud the reality of what product managers do, how they do it, and what skills they need to succeed. In this blog post, […]
The post 5 Product Management Myths You Need to Stop Believing first appeared on Smiley Cat.
09 Apr 2023 5:28pm GMT
11 Dec 2022
Smiley Cat: Christian Watson's Web Design Blog
The Key Strengths of the Best Product Managers
The role of a product manager is crucial to the success of any product. They are responsible for managing the entire product life cycle, from conceptualization to launch and beyond. A product manager must possess a unique blend of skills and qualities to be effective in their role. Strong strategic thinking A product manager must […]
The post The Key Strengths of the Best Product Managers first appeared on Smiley Cat.
11 Dec 2022 4:43pm GMT