If the site is on an insecure version of an old minor and there is a secure version of that old minor available, the update status report should link that release

Created on 3 August 2018, almost 6 years ago
Updated 5 June 2024, 24 days ago

Problem/Motivation

In #2942591: Start reporting specific releases as insecure in update status XML β†’ and #2804155: If the next minor version of core has a security release, status still says "Security update required!" even if the site is on an equivalent, secure release already β†’ , Drupal.org and core are being changed to allow the Drupal security team to automatically mark old releases as insecure, but to manually mark an older release as secure. This is useful when (for example) the same security advisory is fixed in two different minor branches, which we already have to do about 30% of the time for Drupal 8 core and which we want to do for every release when we adopt #2909665: [plan] Extend security support to cover the previous minor version of Drupal β†’ .

Following the Drupal.org change that has already been made, the Drupal status report only links the latest security release. So, for example, in this scenario:

  • SA-CORE-2018-002 creates the following core security releases, all of which are considered equally secure: 8.3.9, 8.4.6, and 8.5.1.
  • The site is on 8.4.5.

The status report will link to 8.5.1, but the site owner also actually has the option to update to 8.4.6.

Proposed resolution

If the site is on an insecure version of an old minor and there is a secure version of that old minor available, link the latest secure release of the old minor branch on the update status report.

Continue to also provide a link to the latest version.

Testing results:

For 10.0 the displayed options are:
Recommended: 10.2.4 (The latest version)
Security Update: 10.2.2 (The latest security version)
Security Update: 10.1.8 (The latest security version for the earlier supported version of core)

For Drupal core 10.1.2 the displayed options are:
Recommended: 10.2.4 (The latest version)
Security Update: 10.2.2 (The latest security version)
Security Update: 10.1.8 (The latest security version for this version of core)

Remaining tasks

Review

User interface changes

Before

After

API changes

N/A

Data model changes

N/A

πŸ› Bug report
Status

Needs review

Version

11.0 πŸ”₯

Component
UpdateΒ  β†’

Last updated 5 days ago

  • Maintained by
  • πŸ‡ΊπŸ‡ΈUnited States @tedbow
  • πŸ‡ΊπŸ‡ΈUnited States @dww
Created by

πŸ‡ΊπŸ‡ΈUnited States xjm

Live updates comments and jobs are added and updated live.
  • Usability

    Makes Drupal easier to use. Preferred over UX, D7UX, etc.

Sign in to follow issues

Merge Requests

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.69.0 2024