loader from loading.io

Talking Drupal #567 - Common Vulnerabilities & Exposures

Talking Drupal

Release Date: 08/27/2026

Talking Drupal #569 - Site Templates show art Talking Drupal #569 - Site Templates

Talking Drupal

On today's show we are talking about Site Templates, What they do, and How you can use them with guests Tim Lehnen & Adam Globus-Hoenich. We’ll also cover Haven as our module of the week. For show notes visit: Topics MOTW: Haven What Site Templates Are Canvas Components Included Promoting Templates Beyond Drupal Templates vs Distributions Who Benefits from Templates Template Types and Adoption Where to Find Templates Featured vs Installer List Free vs Paid Templates Recipes vs Templates Distributions and Themes Empowering Site Builders Exporting a Template Designing for Users Releases...

info_outline
Talking Drupal #568 - Off The Cuff #12 show art Talking Drupal #568 - Off The Cuff #12

Talking Drupal

Today we are talking about Drupal Performance, Rapid Development, and Drupal Canvas Maturity with our hosts. We’ll also cover Microsoft 365 FullCalendar as our module of the week. For show notes visit: Topics Deprecating Module Theme Files Migrating Hooks to Classes Why This Change Matters Drupal Performance Gains Performance Audits and Lighthouse Automating Checks and Spreadsheet Rant AI Spreadsheet Cautionary Tale Privacy Concerns with AI Freelancer Pressure Rapid Change Reality Canvas Release Risks Community Support Needed AI For Documentation Canvas Production Readiness Canvas...

info_outline
Talking Drupal #567 - Common Vulnerabilities & Exposures show art Talking Drupal #567 - Common Vulnerabilities & Exposures

Talking Drupal

Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We’ll also cover Security Scanner as our module of the week. For show notes visit: Topics What Are CVEs CVE Lifecycle and Disclosure AI Era Security Challenges What CVE Program Excludes Patch Fast Reality Global Security Signals CVE Timing Judgment KEV Flags Explained CVE Updates Link Rot Who Decides CVE Sneaky Patch Dangers ADP Program Fixes Small Team Triage Vulnerability Tsunami AI Autonomous Security Future Legal Pressure Budgets Resources Guests David Welch - Hosts Nic...

info_outline
Talking Drupal #566 - DrupalEasy: Responsible Drupal AI show art Talking Drupal #566 - DrupalEasy: Responsible Drupal AI

Talking Drupal

Today we are talking about Drupal, AI, and learning to use it responsibly with guest Mike Anello. We’ll also cover Entity Mesh as our module of the week. For show notes visit: Topics Course overview Fast moving modules Inside vs outside AI No code approach Keeping curriculum current Essentials vs add ons Chat Claude Code setup Inside vs Outside AI Rules and Provider Calls Guardrails in Drupal UI Model QA and Testing Local Models and Costs Token Budgets and Logging Course Use Cases Overview RAG and Vector Basics Class Schedule and Pricing AI Predictions and Wrap Resources Guests...

info_outline
Talking Drupal #565 - That Geerling Guy show art Talking Drupal #565 - That Geerling Guy

Talking Drupal

Today we are talking about Open Source sustainability, becoming your own content creation machine, and how drupal influenced some of that with guest Jeff Geerling. We’ll also cover AI Metering as our module of the week. For show notes visit: Topics Jeff’s Timekeeping Icebreaker Jeff’s Drupal Origin Story From Drupal to Hardware Tinkering Staying Motivated on YouTube What Conferences Are Really About DrupalCon Memories and Community Why Jeff Moved to Hugo PSA Tornado Warning Detour Keeping Up with Drupal CMS PHP Perception Shift Fast Drupal Setup COVID Streaming Boom Picking Video...

info_outline
Talking Drupal #564 - Approachable Open Source show art Talking Drupal #564 - Approachable Open Source

Talking Drupal

Today we are talking about Maintaining NodeJS, Patternlab, Writing Books, and Open Source with guest Brian Muenzenmeyer. We’ll also cover AI Webform Generator as our module of the week. For show notes visit: Topics Brian Open Source Origins Pattern Lab Node Journey Maintaining and Moving On Writing Approachable Open Source Who the Book Is For Beyond Code Contributions All Things Open Book Signing Choosing Conferences to Attend Pitching Open Source at Work Misconceptions and Starting Small Avoiding Maintainer Burnout Handling AI Noise and Low Effort PRs DCO and Licensing Basics Better...

info_outline
TD Cafe #020 - AI & Development Teams show art TD Cafe #020 - AI & Development Teams

Talking Drupal

How should development teams adopt AI without sacrificing code quality or collaboration? In this Talking Drupal Cafe, Stephen Cross is joined by Mike Miles and Jim Birch to discuss practical strategies for integrating AI into Drupal development teams. They explore AI coding assistants, team policies, code review, agent workflows, governance, and real-world lessons from using tools like Claude Code and GitHub Copilot in production environments. For show notes visit: Topics Why AI Matters Now Team Introductions From Experiments to Workflows Standards and Guardrails Skills and Automation...

info_outline
Talking Drupal #563 - Drupito: More Than a Marketplace show art Talking Drupal #563 - Drupito: More Than a Marketplace

Talking Drupal

Today we are talking about Drupito, its Business model, and Marketplaces with guest Ashraf Abed. We’ll also cover Generate (Social Media) Image as our module of the week. For show notes visit: Topics Meet Drupalito and the Mission Platform Layers and Roadmap Pricing and New Markets Marketplace Success Stories Exportability and Vendor Lock In Growing the Drupal Ecosystem Derivatives and Recurring Revenue Rebuilding on Drupedo Funding Drupal Association Global Community Check In Migrating Sites to Drupedo Marketplace Vision Shift Maintenance and Incentives Safe Updates Blue Green Testing...

info_outline
Talking Drupal #562 - Acquia Fair Trade Initiative show art Talking Drupal #562 - Acquia Fair Trade Initiative

Talking Drupal

Today we are talking about Supporting Open Source, Acquia, and The Acquia Fair Trade Initiative with guest James Sims. We’ll also cover Image Effects as our module of the week. For show notes visit: Topics Fair Trade Initiative Explained How the Program Started Why Fair Trade Matters Adoption and Open Framework Agency and Freelancer Benefits Partner Funded Giving Who Can Be Makers Tracking Participation Tax Deduction Questions Community Shaped Program Money Counts Too Early Challenges Timeline And Launch Sustainability Built In How To Get Involved Defining Success Origins Of Fair Trade ...

info_outline
TD Cafe #019 - From Drupal to FIRST Robotics show art TD Cafe #019 - From Drupal to FIRST Robotics

Talking Drupal

Michael Kinnunen and Steve Wirt share how they each got started with Drupal through higher-ed jobs and stayed for the communit. They compare those community values to FIRST Robotics, explaining FIRST’s K–12 programs (FRC, FTC, and FIRST LEGO League), kickoff-style challenges, and the “coopertition” culture where teams help competitors with parts and repairs. Both mentor highschool robotics teams in the US. For show notes visit: Topics Cafe Catch Up Drupal Origin Stories Why Drupal Community What Is FIRST Mentoring Journeys Team Names Numbers Kickoff Build Sprint Coopertition In...

info_outline
 
More Episodes

Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We’ll also cover Security Scanner as our module of the week.

For show notes visit:
https://www.talkingDrupal.com/567

Topics

  • What Are CVEs
  • CVE Lifecycle and Disclosure
  • AI Era Security Challenges
  • What CVE Program Excludes
  • Patch Fast Reality
  • Global Security Signals
  • CVE Timing Judgment
  • KEV Flags Explained
  • CVE Updates Link Rot
  • Who Decides CVE
  • Sneaky Patch Dangers
  • ADP Program Fixes
  • Small Team Triage
  • Vulnerability Tsunami AI
  • Autonomous Security Future
  • Legal Pressure Budgets

Resources

Guests

David Welch - github: dwelch2344 dwelch2344

Hosts

Nic Laflin - nLighteneddevelopment.com nicxvan
John Picozzi - epam.com johnpicozzi
JD Flynn - dorficus

MOTW

Correspondent

Martin Anderson-Clutz - mandclu.com mandclu

  • Brief description:
    • Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that.
  • Module name/project name:
  • Brief history
    • How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia
    • Versions available: 1.0.0, which works with Drupal 10.3 and 11
  • Maintainership
    • Actively maintained — created and shipped its first stable this summer, with steady development right through late July
    • Security coverage
    • Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories
    • Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG
    • Number of open issues: 1 issue, not a bug
  • Usage stats:
    • 2 sites (it's brand new)
  • Module features and usage
    • Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review
    • It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, missing CSRF tokens, unserialize() on untrusted data, hardcoded secrets
    • Then there's an optional deep pass: with the Psalm static analysis scanning engine installed, it'll trace untrusted input across functions and files to catch cross-function issues. And it's honest about state — the report always says whether that deep pass ran, was skipped, or failed, so a failure never gets mistaken for a clean scan
    • One nice detail under the hood: a tokenizer-backed "code map" that knows whether a match is real code, a comment, or a string — so it won't flag the word "unserialize" sitting in a doc comment. That kills the single biggest source of false positives
    • The checks are regression-tested against real Drupal advisories (Drupalgeddon, Drupalgeddon2, the 2019 unserialize bug, etc) so a pattern that caused an actual CVE can't quietly come back in your custom code
    • Output comes in three flavors: a readable table, JSON for CI and AI agents, and SARIF — which means findings show up as annotations right on your GitHub or GitLab merge-request diff instead of buried in a job log
    • For adopting it on an existing codebase there's a baseline file — you fingerprint the findings you've reviewed, with a required reason on each, and they stop failing the build but never go invisible; every run still counts them
    • It exits non-zero on error-level findings, so it drops straight into CI or a pre-commit hook
    • And it's extensible — checks are Drupal plugins with a #[SecurityCheck] attribute, so any module can add its own or alter the ones that ship
    • Big caveat, and the module says this itself: a finding means "review this," not "this is broken." Static analysis has false positives, and a clean scan doesn't prove the code is secure — access-control logic especially still needs human review
    • I first heard about this module over beverages at Drupalcamp Asheville, so I know that this module was largely vibe-coded, after having an AI agent ingest every single Drupal security team CVE. So I like to think of this module as security pattern recognition tool, but of course it does even more