Recent improvements to the packaging system will enable many Drupal distributions to move back home onto Drupal.org and allow other distributions to develop and flourish.
Several sources are publishing a supposed vulnerability in Drupal. One source is the security site Packet Storm Security. This post is a response to that issue.
The Drupal Security team has concluded that this does not constitute a valid vulnerability. The attack depends on a "Man In the Middle" attack or sniffing software, which is outside of Drupal and presents a much bigger problem.
The Drupal Security team provides an easy way to report issues by sending emails to security@drupal.org, and we will credit researchers with all issues they report in this manner. No formal report of this issue was filed directly with our team. We encourage all researchers to follow the practice of coordinated disclosure, and report directly to our team to ensure both that we can provide public credit for authentic vulnerabilities, and keep our users as secure as possible.
We are also happy to announce that automatic exporting of patterns configuration from the database is finally working. At least partially, we are still testing this feature.
Please give us feedback, open bug issues, features requests and so on!
iHubbub is working with Acquia on a few initiatives and one of them is to grow a list of Drupal Developers to a brand new page on our site http://ihubbub.com/drupal-developers so the devs are able to promote their services to our home business and online business audience.
Two of the Drupal Association's 2012 priorities are to make Drupal.org awesome: both for site builders and for developers. We want to hear from you about what improvements you'd most like to see on Drupal.org.
Please let us know your thoughts at http://drupal-association.ideascale.com/. You can propose new ideas, vote on existing ideas, and also leave comments. When we have the more discrete list of things we plan to cover in 2012 and when, we'll share it with the community for feedback.
Important things to note:
Please don't limit yourself only to big things. The more high-impact, "low hanging fruit" we can fix, the better! :) All suggestions must have a correlating URL on *.drupal.org with more information.
Voting on an idea here does **not** necessarily mean it will get implemented, even if it's one of the highest (or even *the* highest) thing in the list. We are using this tool as a barometer to find out more about what our contributor community thinks is important, so we can factor this into our prioritization process.