Change record status: 
Project: 
Introduced in branch: 
9.4.x
Introduced in version: 
9.4.0
Description: 

The Update Manager included with Drupal Core now provides a 'View update notifications' permission. This controls which users should see notifications about missing security updates on most administration pages (nearly everything under /admin/*). Previously, these messages were displayed to any user with the 'Administer site configuration' permission, although in many cases, those users do not have permission to install available updates and resolve the warnings.

A post update function (update_post_update_add_view_update_notifications_permission()) is provided to automatically add the new 'View update notifications' permission to any role that has 'Administer site configuration'. Existing sites (after upgrading and visiting update.php or running drush updb) will see no change in behavior, but site builders are invited to reconsider what role(s) should have the 'View update notifications' permission.

Impacts: 
Site builders, administrators, editors