Problem/Motivation
I have that when I try to maitain up to date my Drupal:
drupal/csp 2.2.2 2.2.3 Provide Content-Security-Policy headers
$ cat composer.json | grep csp
"drupal/csp": "^2.0",
$ composer why-not drupal/csp 2.2.3
drupal/csp 2.2.3 requires drupal/core (^11.2 || ^12)
drupal/recommended-project - does not require drupal/core (but 10.6.7 is installed)
Not finding what you were looking for? Try calling `composer require "drupal/csp:2.2.3" --dry-run` to get another view on the problem.
Tableau des versions de Drupal et leurs dates de fin de vie
Version de Drupal Date de sortie Date de fin de vie (EOL)
Drupal 8 19 novembre 2015 2 novembre 2021
Drupal 9 3 juin 2020 1er novembre 2023
Drupal 10 14 décembre 2022 9 décembre 2026
Drupal 11 Juin 2025 (stable) Décembre 2027 (estimé)
Proposed resolution
The maintainers could (should) have pushed a new major version for this, since they chose to drop support for Drupal <11.2
Thanks.
Comments
Comment #2
sidgrafix commentedAgree 100%, having a warning on the status page for out of date module that isn't compatible for a Drupal installation should not be and is really annoying! Considering CSP 2.2.2 had support for Drupal ^10.2, I would think the logical step would be to continue Drupal 10 support but perhaps up the core version requirement to it's latest 10.x (^10.6) when continuing the 2.x branch. CSP going to 3.x branch dropping support for Drupal 10 should have been the approach.
Comment #3
gappleope! I rushed the release and missed that the core version bump had been committed on the 2.x branch and made the tag from there, instead of cherry-picking the bug fix to the 2.2.x branch that was already created 🤦.
The 2.3.x release will drop support for D10, but 2.2.x will continue to be maintained with bug fixes while D10 is still supported.