Path to this page:
Subject: CVS commit: pkgsrc/www/drupal8
From: Wen Heping
Date: 2019-03-16 14:15:03
Message id: 20190316131503.51B78FB16@cvs.NetBSD.org
Log Message:
Update to 8.6.12
Upstream changes:
8.6.12
The third-party Twig library, which powers Drupal 8's theme system, recently \
released new versions (Twig 1.38.0 and 1.38.1) that introduced a fatal error for \
Drupal 8 sites using Composer. Drupal 8.6.11 was released yesterday with an \
update to Twig 1.38.2 in order to resolve that error. However, this update also \
led to a different regression for certain Drupal 8 themes that use Twig {% embed \
%} tags. This release hotfixes Drupal 8 to resolve that regression. No other \
changes are included.
8.6.11
This release resolves two critical issues affecting Drupal 8 site updates:
The third-party Twig library, which powers Drupal 8's theme system, recently \
released a new minor version (1.38.0) that introduced a fatal error when used \
with Drupal 8. As a result, Drupal 8 sites managed with Composer encountered \
this fatal error when updating Twig to version 1.38.0 or 1.38.1. This release \
updates Drupal to require Twig 1.38.2, which resolves the fatal error.
The recent releases for SA-CORE-2019-003 introduced a serialized data \
integrity issue affecting some contributed and custom modules, including the \
Default Content and Paragraphs modules. This release resolves the issue for \
affected sites.
Additionally, this release resolves an administrator-only access bypass with the \
Layout Builder module. Previously, users who didn't have access to view \
individual entities were still granted access to configure the layout for that \
entity (if per-entity layout configuration was enabled) and therefore could view \
its content. This implicit access has been removed. Site owners should ensure \
that all content editor roles have access to view the content for which they are \
configuring the layout.
Files: