Dries Buytaert: Grow the ecosystem, not just yourself
In Open Source software, competition works differently than in proprietary software.
Companies compete through their own products and services, but they all depend on the same commons: the software, the community, the project's reputation, and the shared work that helps people trust and adopt it.
That shared foundation creates a different kind of responsibility: sharing a commons means sharing the work of keeping it strong.
The Open Source companies I admire most show up in two ways. They compete on the merits of their own products: features, support, and price. And they help sustain the commons: through code, documentation, security, marketing, events, education, sponsorships, and more.
Judge companies by what they doOver the past year, Pantheon, one of Acquia's competitors in the Drupal market, has focused much of its messaging on attacking Acquia, including making our private equity ownership part of its story.
I have no quarrel with Pantheon's products or the people who build them. Competition is healthy. My concern is with marketing that attacks another Drupal company, often with misleading or unwarranted messaging.
I've spent nearly twenty years building Acquia through different stages and ownership models. Acquia has grown from a startup into a company backed first by venture capital and later by private equity. Every ownership model creates different pressures, but ownership determines far from everything.
Customers don't choose a platform because of an ownership model. They choose it because it works, because they can get help, and because they trust it will keep getting better.
No one benefits from unwarranted vendor attacks. They benefit when companies build better products, contribute to Drupal, and help more people adopt it.
License permits, stewardship growsFor an Open Source company, the test is not only what they build for themselves. It is what they help build for everyone.
An Open Source license defines what companies are allowed to do. It sets the floor.
Above that floor is a social contract. No one enforces it, but every healthy Open Source ecosystem depends on it.
Stewardship is what companies choose to do beyond the license: contribute code, fund security work, support maintainers, improve documentation, sponsor events, promote adoption, and more.
Drupal thrives because people and organizations honor the social contract and choose to do more than the license requires.
Contribution is one measure of stewardshipDrupal.org credit is one public signal of that commitment. Acquia is the largest single corporate contributor to Drupal, but the wider community contributes far more than any one company.
In the past year, Acquia engineers earned 2,955 weighted credits on Drupal issues, plus 164 from the Drupal Security Team.
These contributions are good for Acquia, for Drupal, and for every organization that builds on Drupal, including our competitors.
In the same period, Pantheon earned 30 issue credits and 2 security credits. Credits don't capture every form of contribution, and Pantheon contributes in other ways too. Even so, the gap is substantial.
What we let pass becomes the social contractI don't usually write publicly about competitors. It's not how I want to spend my voice.
Before writing this, I asked myself a simple question: if a major company contributing to Drupal were under sustained attack from another major Drupal company, would I feel a responsibility as Drupal's founder and project lead to speak up?
I would.
The fact that Acquia is the company being attacked made me slower to respond, but it doesn't change the answer.
When companies built on Drupal spend their energy attacking each other instead of growing the project, it bothers me. It's not good for Drupal.
I'm not writing this believing it will change anyone's marketing and sales tactics. I'm writing it because what we let pass now will shape what is acceptable in Drupal years from now.
Communities like ours evolve their social contract through moments like this, when we say in public what we expect of each other. If this post contributes to a healthier social contract taking hold, I'm happy.
Compete on merit, but grow the commonsEvery company that builds on Drupal depends on the same commons. Every company has a choice about whether to help sustain it, and how much. Drupal gets stronger when more of us invest in it.
My invitation to every company that builds on Drupal is simple: let's compete on the merits of our products and services, not by attacking each other. Let's serve customers well, contribute where we can, and put our energy into helping more organizations choose Drupal in the first place.
That is the social contract I'd like all of us to live by. I want Acquia to be judged by that same standard: what we ship, how well we serve customers, how much we contribute, and whether Drupal is stronger because of our work.
Not by who owns us. Not by claims made about us. By whether we keep building, contributing, and helping the ecosystem grow.
I have said what I wanted to say, and I won't turn this into an ongoing debate or respond to social media comments on this. My focus is on building and contributing.
The Drop Times: Cybersecurity Pressures Intensify Across Enterprise and Open-Source Ecosystems
Cybersecurity remained a central concern across enterprise and open-source ecosystems this month as multiple high-profile incidents and critical vulnerability disclosures affected widely deployed platforms. Security teams continued to face pressure to patch faster, monitor exposed systems more closely, and respond to a growing volume of actively exploited vulnerabilities.
Verizon’s 2026 Data Breach Investigations Report found that the exploitation of vulnerabilities overtook stolen credentials as the leading initial access method in analysed breaches for the first time. Microsoft’s May Patch Tuesday also addressed roughly 120 vulnerabilities affecting Office, SharePoint Server, and Windows enterprise infrastructure.
The open-source sector saw renewed urgency around patch management after the Drupal Security Team released SA-CORE-2026-004, a highly critical SQL injection vulnerability affecting supported Drupal core versions using PostgreSQL databases. The advisory prompted emergency patching efforts across enterprise Drupal deployments.
Security agencies continued to warn about the growing number of actively exploited vulnerabilities tracked in CISA’s Known Exploited Vulnerabilities catalogue.
Elsewhere in the open-source ecosystem, discussion turned toward the widening gap between technological capability and public perception. In a recent post, Dries Buytaert argued that Drupal’s reputation has not kept pace with its technical evolution despite continued investment in structured content architecture, APIs, and AI-oriented tooling.
The discussion reflects a broader challenge facing mature open-source platforms competing for visibility against newer frameworks with stronger marketing momentum. Community perception increasingly shapes how projects are evaluated alongside technical capability, governance maturity, and long-term sustainability.
That said, let us now look at the major developments covered in Volume 4, Issue 21 of The Drop Times weekly newsletter, Editor’s Pick. Story listings are now permanently shifted to teaser blocks below, and we will no longer duplicate linked headlines within the Letter from the Editor.
Additional developments from across the Drupal ecosystem were published during the week. Readers can follow The Drop Times on LinkedIn, Twitter, Bluesky, and Facebook for ongoing updates. The publication is also active on Drupal Slack in the #thedroptimes channel.
Allen Jason
Junior Sub-editor
The Drop Times
1xINTERNET blog: Why 2026 Is the Year for Integration Over Isolation for Membership Bodies
Managing a patchwork of digital systems? Discover why 2026 is the year for membership bodies and charities to trade platform fragmentation for integration.
Specbee: What should content editors know about Drupal accessibility?
1xINTERNET blog: Why 2026 Is the Year for Integration Over Isolation
Managing a patchwork of digital systems? Discover why 2026 is the year for membership bodies and charities to trade platform fragmentation for integration.
The Drop Times: Johanna Bates on Drupal, Nonprofits, and the Problem of Stewardship
Talking Drupal: Talking Drupal #554 - Hey! Scott Tolinski!
Today we are talking about Web Education, Level up Tutorials, and life after Drupal with guest Scott Tolinski. We'll also cover Views Row SDC as our module of the week.
For show notes visit: https://www.talkingDrupal.com/554
Topics- Scott Origin Story
- Level Up Tutorials Era
- Syntax Podcast Beginnings
- Growing The Audience
- Web Components Debate
- Leaving Drupal Behind
- What Drupal Still Nails
- Agency Project Highlights
- Booking Podcast Guests
- Scott Work Week Setup
- Running Syntax Team
- Canvas HTML Experiments
- Livestream Tools Challenges
- Funding Via Sentry
- Project Ideas Process
- Conference Speaking Journey
- Speaking Logistics Family
- Content Focus Passion
- Drupal Influence Today
- Mad CSS Tournament
- AI Coding Workflow
- What Excites Him Now
- Scott Tolinski's Website
- Levelup tutorials
- 1000th episode
- Web awesome
- Talk in Amsterdam - React summit
- This component could have been a class
- Sigraph conference site
- Too fast too furious learning things quickly
- JSNation
- Scratch
- Css tricks
- MadCss Championship
- State of ai survey
- Jazz.tools
- 0sync
- Graffiti
Scott Tolinski - tolin.ski stolinski
HostsNic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Bernardo Martinez - bernardm28
MOTW CorrespondentMartin Anderson-Clutz - mandclu.com mandclu
- Brief description:
- Have you ever wanted to use a Single Directory Component to format the output of a view on your Drupal website? There's a module for that
- Module name/project name:
- Brief history
- How old: created in Apr 2026 by James Shields (lostcarpark), a friend of the podcast
- Versions available: 1.0.0, which works with Drupal 11.3 and 12
- Maintainership
- Actively maintained
- Security coverage
- Number of open issues: 9 open issues, 3 of which are bugs, though two are marked as fixed in the latest release
- Usage stats:
- 4 sites
- Module features and usage
- With this module installed, when you select "Show" in the Format modal for any views display, you'll see a new option for "Single Directory Component", in addition to standard options like "Content view mode" or "Fields"
- You can then select which of the site's available SDCs you want to use to format each result, and then you can map fields defined in the view to the properties and slots defined for the selected component
- You can also place a view using this format into a Drupal Canvas layout by having a block display
- SDCs and Canvas are the new hotness in Drupal theming, so this module gives you some additional ways to incorporate theme into your own Drupal site
ImageX: Deciphering the Acronyms Behind Your Drupal Site: CDN, CTA, NID & More
If your Drupal website spoke in acronyms, it might sound like this: “DNS hands the request to the CDN, TLS encrypts the connection, and the CTA waits patiently at the end.”
These clusters of capital letters can feel like jargon and confuse non-technical users. Yet acronyms, words formed from the first letters of longer phrases, are everywhere because they make complex concepts quicker to say and easier to remember.
Dropsolid Experience Cloud: After the unbundling, the rebundling
#! code: Drupal 11: Building A Link Directory: Part 1
A problem I've been struggling with for a while now is managing my bookmarks. Every time I come across an interesting article I want to read, a good resource I want to keep, or a neat tool I want to try I create a bookmark.
Over time I have collected a large collection of bookmarks so when I add a new one to the list it gets lots in the pile. I've tried to create directories to keep "new" bookmarks or organise them into sections, but I always end up scrabbling to find them.
The problem is that web browsers don't allow you to categorise or search bookmarks so I can never find them again. Also when I swap browsers (which I have done twice this year) I end up having to migrate them over and set up synchronising between computers. This always removes the favicons of the sites so I have even more trouble finding the right link.
After losing yet another bookmark again recently I decided to do something about it. I realised that #! code was the best place for it as I'm always logged into the site, so I set about creating a link directory on the site. I didn't just want a big list of links though. In my mind a good link directory takes a screenshot of the site when the link is created so that it is easy to see what links are there from the screenshot of the original site.
In this article I will go through how I set up the link directory, how links are added, and how the site is able to take screenshots of the links as they are added to the directory.
Creating The Link Content TypeTo store the links I created a content type called "Link" and added a few fields to it.
Freelock Blog: The Night the Internet Tried to Kill Your Website
The rain had been falling on the city for weeks.
Not real rain. The kind that falls on the internet — a constant drumbeat of probes, scans, and automated fists rattling every doorknob on every block, every hour of the day. Most people don't hear it. That's fine. That's what we're here for.
My name doesn't matter. Call me the op. I run a small shop — we keep websites alive, patch the holes before the wrong people find them, and make sure that when something goes sideways, there's always a way back. It's not glamorous work. But this spring? This spring was something else.
The Drop Times: Mike Gifford Says Accessibility Must Be Built Into Workflows Before AI Scales Bad Patterns
Très Bien Blog: Visualization of Drupal Core Change records over the years
How many Drupal Core change records (CR) has there been over the years? Is it a manageable amount for contrib maintainers? How many are about something new or deprecated? This is what it looks like since 2018. For visual effect I grouped CRs in 4 buckets:
theodore May 22, 20261xINTERNET blog: AI Content Intelligence at Estate Scale
AI is accelerating content creation, making estate-scale governance critical. Learn the 5 dimensions of content governance and why it must live natively in your CMS.
The Drop Times: Accessibility Contributors Discuss Continuity, Governance, and AI Ahead of GAAD
PreviousNext: Keywords to Context: Semantic Search and Retrieval-Augmented Generation with OpenSearch
PreviousNext: PreviousNext wins four Splash Awards and a third consecutive Best in Show at DrupalSouth Wellington 2026
Security advisories: Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
Drupal core includes a database abstraction API to ensure that queries executed against the database are sanitized to prevent SQL injection attacks.
A vulnerability in this API allows an attacker to send specially crafted requests, resulting in arbitrary SQL injection for sites using PostgreSQL databases. This can lead to information disclosure, and in some cases privilege escalation, remote code execution, or other attacks.
This vulnerability can be exploited by anonymous users.
This vulnerability only affects sites using PostgreSQL. However, the dependency updates in this release apply to all sites.
Upstream security advisoriesThe Drupal releases for supported branches (11.3, 11.2, 10.6, and 10.5) in this advisory also include security updates for Symfony and Twig. Those projects have released important Security Advisories that were coordinated with this Drupal release, and Drupal is affected by some of the vulnerabilities.
Depending on your site configuration and contrib modules, you may be vulnerable to one or more of these upstream issues, so updating these dependencies is highly recommended whether the SQL Injection vulnerability affects you or not. It is also recommended to review which user roles have the ability to update Twig templates, for example via Views or contributed modules.
Solution:Install the latest version.
The following releases will be available as soon as automated release packaging is complete. You may receive a 404 in the interim. The updates may also be available on Packagist sooner.
Drupal 11- If you use Drupal 11.3.x, update to Drupal 11.3.10.
- If you use Drupal 11.2.x, update to Drupal 11.2.12.
- If you use Drupal 11.1.x or 11.0.x, update to Drupal 11.1.10.
- If you use Drupal 10.6.x, update to Drupal 10.6.9.
- If you use Drupal 10.5.x, update to Drupal 10.5.10.
- If you use Drupal 10.4.x or earlier, update to Drupal 10.4.10.
- If you use any version of Drupal 9, try manually applying the Drupal 9.5 patch for this issue.
- If you use Drupal 8.9, try manually applying the Drupal 8.9 patch for this issue.
Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.) Due to this issue's severity, the unsupported releases and patches for unsupported versions are provided as a best effort. Those unsupported versions will still have other, previously disclosed security vulnerabilities.
Reported By: Fixed By:- Björn Brala (bbrala)
- Benji Fisher (benjifisher) of the Drupal Security Team
- catch (catch) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Anna Kalata (akalata) of the Drupal Security Team
- Benji Fisher (benjifisher) of the Drupal Security Team
- catch (catch) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Heine Deelstra (heine) of the Drupal Security Team
- Tim Hestenes Lehnen (hestenet)
- Dave Long (longwave) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Cathy Theys (yesct) of the Drupal Security Team
HPE Server G10 - Grundeinstellungen falsch?
VMware ESXi-8 - NIC Passthrough VM als Uplink
- « erste Seite
- ‹ vorherige Seite
- …
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- …
- nächste Seite ›
- letzte Seite »