drupal 7.31

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcement:

No other fixes are included.

drupal 6.33

Security update
Insecure

Maintenance and security release of the Drupal 6 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcement:

No other fixes are included.

drupal 8.0.x-dev

Bug fixes
New features

The Drupal core repository is now open for the forthcoming 8.0.x series. This is a development snapshot release for the 8.0.x series. This is not stable, and production sites should not run this code. However, users wishing to help test and develop the next version of Drupal are encouraged to use this for test sites.

drupal 8.1.x-dev

This is a development snapshot release for the 8.1.x series. This is not stable, and production sites should not run this code. However, users wishing to help test and develop the next version of Drupal are encouraged to use this for test sites.

drupal 7.30

Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes bug fixes only, including a fix for regressions introduced in Drupal 7.29.

No security fixes are included in this release.

Besides documentation fixes, no changes have been made to the .htaccess, web.config, robots.txt or default settings.php files in this release, so upgrading custom versions of those files is not necessary.

Known issues:

None.

drupal 7.29

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcement:

No other fixes are included.

drupal 6.32

Security update
Insecure

Maintenance and security release of the Drupal 6 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

drupal 7.28

Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes bug fixes and small API/feature improvements only (no major new functionality); significant new features are only being added to the forthcoming Drupal 8.0 release.

No security fixes are included in this release.

No changes have been made to the .htaccess, web.config, robots.txt or default settings.php files in this release, so upgrading custom versions of those files is not necessary.

drupal 7.27

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

drupal 6.31

Security update
Insecure

Maintenance and security release of the Drupal 6 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

drupal 7.26

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

drupal 6.30

Security update
Insecure

Maintenance and security release of the Drupal 6 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

Only minor documentation fixes are included on top of the security fix.

drupal 7.25

Bug fixes
New features
Insecure

Maintenance release of the Drupal 7 series. Includes bug fixes and small API/feature improvements only (no major new functionality); significant new features are only being added to the forthcoming Drupal 8.0 release.

No security fixes are included in this release.

drupal 8.0-alpha6

Bug fixes
Insecure

This is a hot-fix to alpha5 in order to fix problems on Windows. It also includes the initial migrate in core patch.

Changes since 8.0-alpha5:

drupal 7.24

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

drupal 6.29

Security update
Insecure

Maintenance and security release of the Drupal 6 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

drupal 7.23

Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes bug fixes and small API/feature improvements only (no major new functionality); significant new features are only being added to the forthcoming Drupal 8.0 release.

No security fixes are included in this release.

As with any release, sites should run update.php after updating the code, but for this release it is particularly important to do so due to database changes in the Image module. In addition, sites which perform updates using Drush (rather than via the user interface) may need to run an explicit cache clear after the updates have run to avoid Image module errors.

Besides documentation fixes, no changes have been made to the robots.txt or default settings.php files in this release, so upgrading custom versions of those files is not necessary.

There are two changes to the .htaccess file in this release:

  1. A change to add support for HTTP authorization in CGI environments (see #670454).
  2. A fix for a regression in Drupal 7.22 that caused internal server errors for sites running on very old Apache 1.x web servers (see #1962780).

There is also one change to the web.config file for IIS servers in this release:

drupal 8.0-alpha2

Insecure

Note that we did not make a release out of Drupal 8.0-alpha1, so this is the first tagged release of Drupal 8. Later on we needed to remove the 8.0-alpha1 tag from our git repository due to infrastructure reasons. If you are looking for Drupal 8.0-alpha1, the commit hash for the tag was 6718550cda5757d511a4f8e541cdaaaaa0f1422d.

Changes since 8.0-alpha1:

drupal 7.22

Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes bugfixes and small API/feature improvements only (no major new functionality); significant new features are only being added to the forthcoming Drupal 8.0 release.

No security fixes are included in this release.

Besides documentation fixes, no changes have been made to the robots.txt or default settings.php files in this release, so upgrading custom versions of those files is not necessary. There are two changes to the .htaccess file in this release:

  1. An improvement to the default rewrite rules to help avoid man-in-the-middle attacks on sites which are accessed over HTTP and HTTPS (see #1733476).
  2. A change to the list of file extensions which are blocked by .htaccess, to prevent temporary files created by text editors from being accessed (see #1907704). Note: This change may cause issues for sites running very old versions of the Apache web server (1.x); see the "Known issues" section below.

Upgrading custom versions of the .htaccess file is recommended.

Known issues:

drupal 7.21

Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes fixes for incompatibilities introduced in the Drupal 7.20 security release only.

No security fixes are included in this release; however, sites which were unable to upgrade to Drupal 7.20 (or upgraded but made modifications to disable the security fixes included within it) should upgrade to Drupal 7.21 to obtain additional security protection.

No changes have been made to the .htaccess, robots.txt or settings.php files in this release, so upgrading custom versions of those files is not necessary.

If you have already upgraded to Drupal 7.20 with no problems this release does not provide any new functionality. You can upgrade to Drupal 7.21 at your leisure, without reading the notes below.

Important update notes:

Drupal 7.20 fixed a fundamental security flaw in the Drupal core Image module and therefore introduced incompatibilities with a number of contributed modules and sites (see the Drupal 7.20 release notes). To help mitigate the effect of these changes, an optional 'image_allow_insecure_derivatives' variable was provided, which sites could use to turn off the security fix.

drupal 7.20

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

No changes have been made to the .htaccess, robots.txt or settings.php files in this release, so upgrading custom versions of those files is not necessary.

Important update notes (and known issues):

If you encountered difficulties upgrading to Drupal 7.20 as described below, try upgrading to Drupal 7.21 and following the instructions there.

The security fixes in this release change all image derivative URLs generated by Drupal to append a token as a query string. ("Image derivatives" are copies of images which the Drupal Image module automatically creates based on configured image styles; for example, thumbnail, medium, large, etc.)

drupal 7.19

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

No changes have been made to the .htaccess, robots.txt or settings.php files in this release, so upgrading custom versions of those files is not necessary.

drupal 6.28

Security update
Insecure

Maintenance and security release of the Drupal 6 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

No changes have been made to the .htaccess, robots.txt or settings.php files in this release, so upgrading custom versions of those files is not necessary.

drupal 7.18

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

No changes have been made to the .htaccess, robots.txt or settings.php files in this release, so upgrading custom versions of those files is not necessary.

drupal 6.27

Security update
Insecure

Maintenance and security release of the Drupal 6 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

No changes have been made to the .htaccess, robots.txt or settings.php files in this release, so upgrading custom versions of those files is not necessary.

drupal 7.17

Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes bugfixes and small API/feature improvements only (no major new functionality); significant new features are only being added to the forthcoming Drupal 8.0 release.

No security fixes are included in this release.

No changes have been made to the .htaccess or robots.txt files in this release, so upgrading custom versions of those files is not necessary. Changes to the default settings.php file in this release include documentation fixes, additional (optional) configuration settings, and a new default value of the '404_fast_html' configuration setting. Upgrading custom versions of this file is not necessary, but may be useful if you want to take advantage of the new configuration settings.

Note that Drupal 7.17 makes a change to the Update Manager module to allow Drupal.org to collect usage statistics for individual modules and themes, rather than only for entire projects. The usage statistics will remain anonymous. (For more information on how usage statistics are collected from your site, see the online handbook entry for the Update Manager module.)

Known issues:

drupal 7.16

Security update
Insecure

Maintenance and security release of the Drupal 7 series.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

No other fixes are included.

No changes have been made to the .htaccess, robots.txt or settings.php files in this release, so upgrading custom versions of those files is not necessary.

drupal 7.15

Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes bugfixes and small API/feature improvements only (no major new functionality); significant new features are only being added to the forthcoming Drupal 8.0 release.

No security fixes are included in this release.

Besides documentation fixes, no changes have been made to the .htaccess, robots.txt or settings.php files in this release, so upgrading custom versions of those files is not necessary.

Known issues:

Major changes since 7.14:

drupal 7.14

Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes bugfixes only (no new functionality), plus the security fixes from Drupal 7.13 which was released alongside Drupal 7.14.

Major changes since 7.13:

- Fixed "integrity constraint" fatal errors when rebuilding registry.
- Fixed custom logo and favicon functionality referencing incorrect paths.
- Fixed DB Case Sensitivity: Allow BINARY attribute in MySQL.
- Split field_bundle_settings out per bundle.
- Improve UX for machine names for fields (UI change).
- Fixed User pictures are not removed properly.
- Fixed HTTPS sessions not working in all cases.
- Fixed Regression: Required radios throw illegal choice error when none selected.
- Fixed allow autocompletion requests to include slashes.
- Eliminate $user->cache and {session}.cache in favor of $_SESSION['cache_expiration'][$bin] (Performance).
- Fixed focus jumps to tab when pressing enter on a form element within tab.
- Fixed race condition in locale() - duplicates in {locales_source}.
- Fixed Missing "Default image" per field instance.
- Quit clobbering people's work when they click the filter tips link
- Form API #states: Fix conditionals to allow OR and XOR constructions.
- Fixed Focus jumps to tab when pressing enter on a form element within tab. (Accessibility)
- Improved performance of node_access queries.

drupal 7.13

Security update
Insecure

Maintenance and security release of the Drupal 7 series. Only fixes for security vulnerabilities have been committed. New features are only being added to the forthcoming Drupal 8.0 release.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

drupal 6.26

Bug fixes
Insecure

The twentysixth maintenance release of the Drupal 6 series. Only bugfixes have been committed. No security fixes are included in this release. New features are only being added to the forthcoming Drupal 8.0 release.

Drupal 6.26 builds on top of Drupal 6.25 and includes all the previous bugfixes and security improvements. The complete list of changes committed since Drupal 6.25 are as follows:

  • #1145700 by jbrown, mr.baileys, joachim: harden link display on dblogoverview screen in case the link might be dependent on user input with any contrib module
  • #183435 by TR, gregmac: make drupal_http_request() more tolerant of faulty newlines in the response headers
  • #341588 by voxpelli, mikl, Albert Volkman, dawehner: use the right JSON MIME type in drupal_json()
  • #1352272 by Albert Volkman, sven.lauer, LSU_JBob: fix phpdoc for system_settings_overview()
  • #260934 by catch, ShawnClark, Jody Lynn, Island Usurper, joshmiller, anrikun, roychri, pdrake, Dave Cohen, sun, plach, bjaspan: When drupal_execute()ing multiple forms with same form_id in a page request, only the first one was validated.
  • #784864 by Niklas Fiekas, kbgordon7, rdrh555, lisarex: Link in update.php instructions was pointing to an outdated handbook page. Update it.
  • #655048 by Gábor Hojtsy, gumanist, intuited, Albert Volkman: Plural formula information was blanked when importing a poorly-formed .po file.
  • #751578 by xamanu, sanduhrs, Gábor Hojtsy: OpenID realm should not be language dependent.
  • #800968 by JacobSingh, ksenzee, Big Z: Tabledrag.js should not use for...in to iterate over an array.
  • #1446372 by Heine, bserem, champlin: Invalid Unicode code range in PREG_CLASS_UNICODE_WORD_BOUNDARY fails with PCRE 8.30.
  • #736556 by Albert Volkman, daniels220, jeckman: Improve theme_links() documentation.
  • #300279 by achton, pillarsdotnet, unknownguy: Improve db_query_temporary() documentation to apply even if persistent database connections are used.
  • #1441852 by chris.leversuch, cafuego: Better return value documentation for db_query().
  • #1436074 by Pat Redmond, tstoeckler, fureigh: Minor documentation fix in the batch_set() docs.
  • #1432708 by scorchio, mkalkbrenner: Expand drupal_goto() documentation for query argument.
  • #1416212 by pontus_nilsson, ibot: Documentation cleanup for _user_mail_notify().
  • #1421330 by Albert Volkman, heyrocker: Crosslink cache_set() and cache_get() documentation with @see.

drupal 6.25

Bug fixes
Insecure

The twentyfifth maintenance release of the Drupal 6 series. Only bugfixes have been committed. No security fixes are included in this release. New features are only being added to the forthcoming Drupal 8.0 release.

Drupal 6.25 builds on top of Drupal 6.24 and includes all the previous bugfixes and security improvements The complete list of changes committed since Drupal 6.24 are as follows:

drupal 7.12

New features
Bug fixes
Insecure

Maintenance release of the Drupal 7 series. Includes bugfixes only (no new functionality), plus the security fixes from Drupal 7.11 which was released alongside Drupal 7.12.

All changes committed since Drupal 7.10 are as follows:

  • #336483 by brianV, catch: Fixed Performance: SELECT MAX(comment_count()) FROM node_comment_statistics() does full table scan.
  • #289504 by catch, mikeryan, moshe weitzman: Fixed user_delete() performance: index comment uid columns.
  • #1326482 by ryanissamson: Clean up minor code style issues in archiver.inc.
  • #996236 by fago, sun, pillarsdotnet, xjm: Fixed drupal_flush_all_caches() does not clear entity info cache.
  • Rollback of Issue #1280792 by andypost: Key length too long error.
  • #569076 by rocket_nova, wamilton, alonpeer: Test that taxonomy term page contains a link to parent terms in the breadcrumbs.
  • #1367000 by chris.leversuch, oriol_e9g, David_Rothstein: Clean up API docs for php module.
  • #1421330 by heyrocker: Fixed Add @see for cache_set() and cache_get() .

drupal 6.24

Bug fixes
Insecure

The twentyfourth maintenance release of the Drupal 6 series. Only bugfixes have been committed. No security fixes are included in this release. New features are only being added to the forthcoming Drupal 8.0 release.

This release includes the security fixes from Drupal 6.23 which was released alongside Drupal 6.24. No additional security fixes are included.

The complete list of changes committed since Drupal 6.22 are as follows:

  • #879270 by Ben Coleman: query in taxonomy_node_get_terms() needs the v.weight field added to the SELECT because it was already present in the ORDER BY; improved PostgreSQL compatibility
  • #12274 by markoshust, DamienMcKenna, seanbfuller, cburschka, aufumy: do not accept email addresses with dots at the end as valid
  • #600836 by tim.cosgrove, dww, naxoc, Dave Reid: prevent batches from going indefinitely if their 'finished' value becomes bigger than 1
  • #289504 by mikeryan, catch, moshe weitzman: backport indexes from Drupal 7 on comments and node_comment_statistics to improve performance of mass-user operations such as deleting users en masse

drupal 7.11

Security update
Insecure

Important!! It was discovered post-release that this version of Drupal only includes bug fixes from Drupal 7.9, not Drupal 7.10! Users are encouraged to use Drupal 7.12 instead. Discussion is happening at #1430404: Drupal 7.11 is missing all the bug fixes from Drupal 7.10

drupal 6.23

Security update
Insecure

The twentythird maintenance and security release of the Drupal 6 series. Only fixes for security vulnerabilities have been committed. New features are only being added to the forthcoming Drupal 8.0 release.

This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the security announcement:

drupal 7.10

New features
Bug fixes
Insecure

Highlights

  • Fixed Content-Language HTTP header to not cause issues with Drush 5.x.
  • Reduce memory usage of theme registry (performance).
  • Fixed PECL upload progress bar for FileField
  • Fixed running update.php doesn't always clear the cache.
  • Fixed PDO exceptions on long titles.
  • Fixed Overlay redirect does not include query string.
  • Fixed D6 modules satisfy D7 module dependencies.
  • Fixed the ordering of module hooks when using module_implements_alter().
  • Fixed "floating" submit buttons during AJAX requests.
  • Fixed timezone selected on install not propogating to admin account.
  • Added msgctx context to JS translation functions, for feature parity with t().
  • Profiles' .install files now available during hook_install_tasks().
  • Added test coverage of 7.0 -> 7.x upgrade path.
  • Numerous notice fixes.
  • Numerous documentation improvements.
  • Additional automated test coverage.

Update notes

  • None at this time.

Known issues

  • None at this time.

Full list of changes since 7.9:

  • #1318316 by xjm: AssertTaxonomyPage is missing documentation.

drupal 7.9

New features
Bug fixes
Insecure

Highlights

  • Critical fixes to OpenID to spec violations that could allow for impersonation in certain scenarios. Existing OpenID users should see http://drupal.org/node/1323342 for more information on transitioning.
  • Fixed files getting lost when adding multiple files to multiple file fields at the same time.
  • Improved usability of the clean URL test screens.
  • Restored height/width attributes on images run through the theme system.
  • Fixed usability bug with first password field being pre-filled by certain browser plugins.
  • Fixed file_usage_list() so that it can return more than one result.
  • Fixed bug preventing preview of private images on node form.
  • Fixed PDO error when inserting an aggregator title longer than 255 characters.
  • Spelled out what TRADITIONAL means in MySQL sql_mode.
  • Deprecated "!=" operator for DBTNG; should be "<>".
  • Added two new API functions (menu_tree_set_path()/menu_tree_get_path()) were added in order to enable setting the active menu trail for dynamically generated menu paths.
  • Added new "fast 404" capability in settings.php to bypass Drupal bootstrap when serving 404 pages for certain file types.

drupal 7.8

Bug fixes
Insecure

The eighth maintenance release of the Drupal 7 series. Only bugfixes and small API improvements have been committed. No security fixes are included in this release. New features are only being added to the forthcoming Drupal 8.0 release.

Important note about Drupal 6 -> 7.7 upgrade path for multilingual sites

If you:

  • upgraded from Drupal 6 to Drupal 7.7
  • had Locale module enabled
  • had created any content after enabling it

...then you would have run across issue #1164852: Inconsistencies in field language handling and found that your node bodies went missing. This issue has been fixed in 7.8. Restore your Drupal 6 backup and re-run the upgrade path to 7.8, and everything should work.

If you cannot roll back, there is an experimental script at http://drupal.org/files/issues/tf_reset-1164852-42.php_.txt which removes language information from every field value and disables language support for every field to address the issue. Some users have reported success with this script, but it is not supported officially and may result in future upgrade issues with field data.

Changes since 7.7:

  • #1262360 by larowlan: Add larowlan as forum maintainer.
  • #1008580 by sun, xjm, Jeff Burnz, tim.plunkett: Fixed image references in forum.css.

Pages

Subscribe with RSS Subscribe to Releases for Drupal core