1 comment

[ 2.3 ms ] story [ 21.1 ms ] thread
Is this a common practice in the wider security community?

Since Drupageddon i kind of see the necessity of such an Pre-Announcement, but this seems like a horribly broken process if the only way to ensure an critical security update to a submodule gets installed is to tell everyone to get their mousecursor over the update button so you can be quick enough...