Display SA coverage icon based on a release/branch of the module going to be installed

Created on 6 December 2024, about 2 months ago

Problem/Motivation

This is a follow-up to πŸ› Missing information about the version of the project going to be installed Active

Currently it seems like that the information about the security coverage of the module is a global information (based on a module), rather than information about the security coverage of the specific release/branch, which is going to be installed on a site by project browser.

So it can happen, that for example Webform has the icon, that the project is covered, but you do not see a version and when you install it, you will get Webform 6.3.0-alpha2, which is not covered.

This has a potential to cause a lot of confusion for users and a false sense of security (there was an icon, so why I am not covered, etc..).

(I selected Webform as an example, but this can be even more risky on smaller modules)

I have added a Security tag, as this have security implications.

Steps to reproduce

On Drupal 11.1RC:
Open project browser (/admin/modules/browse)
Find Webform module
Observe that there is a SA coverage icon displayed
Try to find a version, which is going to be installed if you click so - you will be unable to find it
Install Webform
Observe that Webform 6.3.0-alpha2 was installed, which is not covered by SA policy

Proposed resolution

Show the SA coverage icon based on the release/branch going to be installed, not globally

πŸ› Bug report
Status

Active

Version

2.0

Component

Code

Created by

πŸ‡ΈπŸ‡°Slovakia poker10

Live updates comments and jobs are added and updated live.
  • Security

    It is used for security vulnerabilities which do not need a security advisory. For example, security issues in projects which do not have security advisory coverage, or forward-porting a change already disclosed in a security advisory. See Drupal’s security advisory policy for details. Be careful publicly disclosing security vulnerabilities! Use the β€œReport a security vulnerability” link in the project page’s sidebar. See how to report a security issue for details.

Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024