En

Drupal官网安全更新(2022-12-06)

来源:Drupal官网 发布日期:2022-12-06 阅读次数:3172 评论:0

基本信息

发布日期:2022-12-06(官方当地时间)

更新类型:安全更新

更新版本:10.0.0-rc2

感知时间:2022-12-06 18:20:05

风险等级:未知

情报贡献:TSRC

更新标题

drupal 10.0.0-rc2

更新详情

RC2 outline
This is a release candidate for the next major version of Drupal. Release candidates are not supported for production sites, but they are intended for widespread testing in preparation for the upcoming stable release. More information on release candidates.

Refer to Preparing your site to upgrade to a newer major version for tools you can use to check the Drupal 10 compatibility of modules, themes, and sites. For more information on 10.0.x development, see #3118143: [meta] Release Drupal 10 on December 14, 2022.
The 10.0.x branch also includes all the latest commits that will be backported to 9.5.x and earlier branches. 10.0.x will be nearly identical to 9.5.x except that:

Deprecated code will be removed, including entire deprecated modules.
Dependencies will be updated to new major versions as appropriate.

For all other changes, refer to the 9.5.x branch.
Important changes since 10.0.0-rc1


The requirement for PostgreSQL is now version 12 or higher. An error allowed Drupal 10.0.0-rc1 and earlier versions to use PostgreSQL 10. This is now fixed. Sites will no longer be able to run on PostgreSQL 10 databases.


The default robots.txt file has been updated to disallow indexing of oEmbed media links.


Drupal 10 now supports contributed module testing against PHP 8.2.


PHP dependency changes


Symfony has been updated to the latest 6.2.0 stable release.


PHP dependencies have been updated to the latest releases.


Frontend dependency changes


CKEditor 5 has been updated to the latest 35.3.2 release. This fixes a critical accessibility issue for dictation users. Drupal core's CKEditor 5 integration is now ready for production use!


Most JavaScript dependencies have been updated to the latest releases.


Development dependency changes
Known issues

#3324062: [Regression] Changes to Drupal.ajax in 9.5.x have caused regressions in paragraphs_features module

All changes since Drupal 10.0.0-rc1
Change log

Issue #3279725 by rpayanm, DeepaliJ, jasonfelix, quietone, mherchel, larowlan, Kristen Pol: Default article content type form display should have image above body to match display
Issue #2314645 by herom, jsobiecki, Pawelgorski87, quietone, ashutoshsngh, zaporylie: Correct the type of $pattern in DateFormat
Issue #3266004 by quietone, longwave: Update UPDATE.txt for Drupal 10
Issue #3325295 by daffie, Arantxio: Update minumum version for PostgreSQL in code
Issue #3294914 by Spokje, quietone, bbrala, longwave, Gábor Hojtsy, benjifisher, dww, xjm, rkoller: Create dedicated error section for missing removed core modules/themes on update
Issue #3324723 by Spokje: Update to the latest cspell version (6.15.1)
Issue #2779321 by nedjo, Akram Khan, smustgrave, catch, Meenakshi_j, pooja saraah, Berdir, alexpott: Submitting empty block layout form results in breakage for all block entities
Issue #3319173 by longwave: Remove vendor specific prefixes from keyframes CSS
Issue #3265724 by ravi.shankar, nevergone, alexpott, quietone: Remove unused help text in UserViewsData
Issue #3319426 by longwave, catch, andypost: Update to a stable Symfony 6.2 release
Issue #3032746 by mfb, O'Briat, Anybody: Improve documentation for reverse proxy addresses setting
Issue #3303329 by DieterHolvoet: Referenced method in NoCorrespondingEntityClassException docblock does not exist
Issue #3324540 by alexpott, longwave: PHPCS fails on Drupal 10 & 9
Issue #3322989 by andypost, quietone, effulgentsia: Update dependencies for Drupal 10.0.0 rc2
Issue #3174108 by _pratik_, asad_ahmed, rivimey, NivethaSubramaniyan, longwave: FieldableEntityNormalizerTrait::extractBundleData() has incorrect return type
Issue #3273532 by Dom., smustgrave, Wim Leers, bnjmnm, marcvangend: Better discovery of DX CKE5 debug documentation
Issue #3324213 by Spokje, andypost: upgrade Symfony dependencies to RC2
Issue #3314632 by andypost, Gábor Hojtsy: upgrade phpspec/prophecy to 1.16.0 to support PHP 8.2
Issue #3049525 by longwave, fougere, larowlan, kim.pepper, AaronBauman, Wim Leers, Charlie ChX Negyesi, geek-merlin: Enable service autowiring by adding interface aliases to core service definitions
Issue #3268818 by ravi.shankar, quietone: Fix class comment doc blocks in non tests 'Drupal.Commenting.DocComment.ShortSingleLine'
Issue #3196619 by Shashwat Purav, larowlan, paulocs, Elin Yordanov: Typo in the machine name for Container field in ForumController::addForum
Issue #3159842 by smustgrave, andypost, longwave: Fix wording in BROWSERTEST_OUTPUT_BASE_URL comment
Issue #3319582 by mondrake, Spokje, longwave, mallezie: Fix calls to methods with too many parameters passed in
Issue #3324215 by andypost: Upgrade composer/pcre to 3.1.0
Issue #3320240 by solideogloria, tobiasb, smustgrave, alexpott: Entity count query returns a string instead of int
Issue #2898903 by tetranz, alexpott, smustgrave, immaculatexavier, prasanth_kp, timmillwood, catch, vinaymahale, rajandro: Terms lose as the parent when editing
Revert "Issue #2898903 by tetranz, alexpott, smustgrave, immaculatexavier, prasanth_kp, timmillwood, vinaymahale, rajandro: Terms lose as the parent when editing"
Issue #2888872 by dagmar, brentg, yogeshmpawar, ravi.shankar, anacolautti, larowlan, alexpott: Hide type filter form in dblog view when there are no logs
Issue #3067024 by amateescu, hchonov, plach: Add test coverage for uninstalling revisionable entity types whose code doesn't exist anymore
Issue #2514582 by Mile23, joachim, sahil.goyal, jhodgdon, Fabianx, dawehner: Document lazy services and fix script doxygen
Issue #2779321 by nedjo, Akram Khan, smustgrave, Meenakshi_j, pooja saraah, alexpott: Submitting empty block layout form results in breakage for all block entities
Issue #2898903 by tetranz, alexpott, smustgrave, immaculatexavier, prasanth_kp, timmillwood, vinaymahale, rajandro: Terms lose as the parent when editing
Issue #2894269 by droplet, Akram Khan, _pratik_, dylf, nod_, Cottser: `bool` in JSDoc should be `boolean`
Issue #3259751 by rodrigoaguilera, smustgrave, nod_: Add ability to pass cli arguments to chromedriver
Issue #3312089 by longwave: Run phpcs in parallel in commit-code-check.sh
Issue #3323057 by Arti Anil Pattewar, Pasqualle: Invalid PHPDoc comments
Issue #3301288 by balintpekker, mondrake, mglaman: Deprecated getStatus() in DrupalTestBrowser
Issue #3323855 by benjifisher: Improve class comment for Drupal\Core\Menu\MenuLinkTreeElement
Issue #3283929 by eleonel, smustgrave: Fix comment with a plural possessive typo in jsonapi.api.php
Issue #3323944 by Spokje: Update JavaScript dependencies for Drupal 10, except Shepherd.js and Nightwatch
Issue #3205578 by Taran2L, kevinn, Charlie ChX Negyesi, longwave: Source code disclosure with /core/scripts/transliteration_data.php.txt
Issue #3323741 by andypost, Spokje, catch, longwave: upgrade Symfony dependencies to RC1
Issue #3322485 by anneke_vde: EntityInterface::toLink() $text documented as string|null actually also accepts an render array
Issue #3318108 by Lendude, rreedy: Views Roles Contextual Filters Multiple Option not saving
Issue #2862922 by smustgrave, NitinLama, zaporylie, rpayanm, DanielVeza, pooja saraah, ranjith_kumar_k_u, Abhijith S, bnjmnm, Kristen Pol, alexpott, ameymudras, murilohp: Set #maxlength for TelephoneDefaultWidget to the one specified in TelephoneItem plugin
Issue #2927407 by Akram Khan, anmolgoyal74, droplet, Pooja Ganjage, Tom Konda, nod_, alexpott: Follow-up: remove unnecessary returns in ajax.js
Issue #3319791 by Cyberwolf, Chi, longwave: ContainerAwareEventDispatcher should not expect the dispatched event to be stopable
Issue #3323260 by Spokje, longwave: Remove usage of node_revision_load() and friends
Issue #2925297 by Spokje, mpp, paulvandenburg, anmolgoyal74, gobinathm, catch, mmrares, shubhangi1995, Martijn de Wit: Fatal error on config form with translation enabled when config is missing
Issue #3322961 by mondrake: Fix WebAssert since PHPStan can now check the number of arguments passed to methods
Issue #3304267 by donquixote, nod_: Mark {Drupal~behaviorDetach} as optional in jsdoc
Issue #3323036 by mondrake, mallezie: Remove $group parameter from AssertContentTrait methods
Issue #3283802 by Wim Leers, bnjmnm, effulgentsia, mgifford: Update CKEditor 5 to 35.3.2 to fix voice control/IME on some platforms
Issue #3322986 by mondrake: Missed removing a $group parameter from AssertMailTrait
Issue #3322984 by andypost: upgrade Symfony dependencies
Issue #3322182 by longwave, Spokje, catch: Ignore sites directory in PHPStan
Issue #3322763 by Spokje: Fix PHPStan L2 error "PHPDoc tag @return with type Foo is incompatible with native type void."
Issue #3226117 by MegaChriz, marthinal, longwave, sinn, dcam, ankithashetty, itaran, catch: Uncaught RfcComplianceException when email From name contains a comma
Issue #2689923 by pradhumanjainOSL, johnrosswvsu, WagnerMelo, leoneldiaz02, Anchal_gupta, sk33lz, apaderno, smustgrave, alexpott, jhodgdon: hook_views_pre_view incorrect documentation example
Issue #3032078 by jrglasgow, dagomar, Berdir, nikitagupta, catch, anmolgoyal74, technoveltyco, idebr, ndf, jonas139, nod_: Multiple webheads can cause infinite growth of Twig cache
Issue #3321004 by longwave: Remove IE11 hack from fieldset.css
Issue #3266243 by mfb, longwave, catch: Views tries to call trigger_error() with E_WARNING which throws a ValueError
Issue #3163123 by Spokje, anmolgoyal74, andypost, guilhermevp, Niklan, Hardik_Patel_12, quietone, larowlan: Error: Class 'ZipArchive' not found in Drupal\Core\Archiver\Zip->__construct() (line 30 of core/lib/Drupal/Core/Archiver/Zip.php)
Issue #3266688 by yassermussa, ankithashetty, Medha Kumari, pooja saraah, ravi.shankar, joachim, xjm: class docs for TestRunnerKernel are incorrect
Issue #3308369 by JeroenT, cilefen: Block access to yarn.lock and package.json
Revert "Issue #3260173 by andregp, joachim, tstoeckler, nod_: Media should set the owner field to anonymous if no explicit owner is set"
Issue #3260175 by jsricardo, andregp, joachim, nod_, alexpott: Saving media entity without an owner crashes
Issue #3260173 by andregp, joachim, tstoeckler, nod_: Media should set the owner field to anonymous if no explicit owner is set
Issue #3321771 by Wim Leers, Chi: CKEditor 5 Duplicated constants in assert statement
Issue #3321945 by Spokje: Remove PHP < 5.4.0 checks
Issue #3321779 by Spokje, longwave, mondrake: Update PHPStan to 1.9.2
Issue #3321425 by Spokje: Update cspell drupal dictionary after cspell update
Issue #3321955 by neclimdul, phenaproxima: DefaultMenuLinkTreeManipulatorsTest cache context assertions are broken
Issue #3260401 by idebr, Spokje, Akram Khan, mcdruid, longwave, alexpott: Google is abandoning FLoC - so remove the header
Issue #3164428 by DonAtt, longwave, sahil.goyal, Anchal_gupta, alexpott: Use cacheBackend->setMultiple in ContentEntityStorageBase::setPersistentCache
Back to dev.

Release type: Bug fixesNew features

软件描述

Drupal是使用PHP语言编写的开源内容管理框架(CMF),它由内容管理系统(CMS)和PHP开发框架(Framework)共同构成。

CVE编号

TSRC分析

暂无

业界资讯

暂无

评论

提交评论 您输入的评论有误,请重新输入