Drupal Association members fund grants that make connections all over the world.
Avoid Twig's sandbox security issue.
Maintenance and security release of the Drupal 8 series.
This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcements:
No other fixes are included.
Bug fixes updates:
Update for Coder - Highly Critical - Remote Code Execution - SA-CONTRIB-2016-039
Please see the Updating Open Atrium guide!
IMPORTANT : Make a BACKUP of your database before applying any updates.
NOTE: : When running updates, it is normal to see "oa_core_update_7236" run many times depending on the amount of content on your site. Do not abort the update process, allow it to complete.
Changes since 7.x-2.5:
In addition to the news page and sub-tabs, all security announcements are posted to an email list. To subscribe to email: log in, go to your user profile page and subscribe to the security newsletter on the Edit » My newsletters tab.
You can also get rss feeds for core, contrib, or public service announcements or follow @drupalsecurity on Twitter.
In order to report a security issue, or to learn more about the security team, please see the Security team handbook page.
If you are a Drupal developer, please read the handbook section on Writing secure code.
Drupal is a registered trademark of Dries Buytaert.