Change record status: 
Project: 
Introduced in branch: 
8.8.x
Introduced in version: 
8.8.0
Description: 

The Vendor Hardening plugin is a new Composer plugin that will be used by Drupal 8.8.x sites that use Composer, but do not relocate the Drupal document root away from the project root. In this configuration, the vendor directory is vulnerable to direct inspection by the web server. The Vendor Hardening plugin mitigates this situation by removing unused testing directories, and by writing .htaccess and web.config files to block access to the vendor directory.

Due to a limitation in the way Composer manages autoloading for Composer plugins, the Vendor Hardening plugin is unable to find the file security class, which it needs in order to generate .htaccess and web.config files. To work around this limitation, the Vendor Hardening plugin now uses its own private copy of the File Security component relocated to its own namespace.

This change will not require any direct action on the part of site builders or administrators; just require drupal/core-vendor-hardening to use it.

Impacts: 
Site builders, administrators, editors