Taken from the Naked Security Blog:
What Drupal badly needs but doesn't have is an automatic updater that rolls out security updates by default.
Drupal can automatically update modules automatically but it can only warn administrators that new core updates are available - it won't install them automatically.
There are lots of good reasons for not forcing updates on people but the reality is that without them there will be many millions of site owners who either update too late or who never update at all.
Every Drupal 7 site that was unpatched after 23:00 (UTC) on 15 October 2014 is now a potential "sleeper agent" for cybercrooks.
WordPress, the most popular content management system in the world, took the plunge and rolled out automatic updates a year ago.
It's time for Drupal to follow suit.
http://nakedsecurity.sophos.com/2014/10/30/millions-of-drupal-websites-a...
This is likely a duplicate, but can't seem to find it.
It may be difficult to implement, but there are a number of related calls for this and so should at least be able to point folks to a common space.
How did the WP folks do it?
Comments
Comment #1
mgiffordComment #2
klausiDuplicate of #2367319: Implement automatic background updates for highly critical security issues.