Active
Project:
Drupal core
Version:
main
Component:
recipe system
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
1 Sep 2026 at 16:30 UTC
Updated:
1 Sep 2026 at 16:32 UTC
Jump to comment: Most recent
It's right there in black-and-white, my friends: https://git.drupalcode.org/project/drupal/-/blob/main/core/lib/Drupal/Co...
If we're in the middle of a site installation, a recipe's installed config is not validated. This means you can sneak bad config into a site via a recipe that is out of date (or, worst-case scenario, actively malicious).
We need to validate config when installing from a recipe.
We can't really do it whilst applying the recipe, because config is shifting around us. But we could maybe do it a separate, specific step of a recipe-based installation.
Comments
Comment #2
phenaproxima