Releases: govCMS/GovCMS
2.9.0 Release
GovCMS 2.9.0 Release Notes
Advice
GovCMS released the Drupal 9 (D9) distribution on Monday 31 January 2022. Deployment is scheduled to commence from Tuesday 1 February 2022 and will be conducted throughout the daytime and into the evening.
It addresses a recent security advisory issued by Drupal.org. GovCMS assessed the moderately critical risks as they applied to D9 distribution, subsequently the security risks remained moderately critical.
No outages are expected to websites during the deployment process.
What is included in the update?
- Drupal Core from 9.2.10 to 9.2.11
https://www.drupal.org/project/drupal/releases/9.2.11
https://www.drupal.org/sa-core-2022-001 - Layout Builder Restrictions module from 2.11.0 to 2.12.0
https://www.drupal.org/project/layout_builder_restrictions/releases/8.x-2.12 - Migrate Plus module from 5.1 to 5.2.0
https://www.drupal.org/project/migrate_plus/releases/8.x-5.2 - Migrate Tools module from 5.0 to 5.1.0
https://www.drupal.org/project/migrate_tools/releases/8.x-5.1 - Password Policy module from 3.0 to 3.1.0
https://www.drupal.org/project/password_policy/releases/8.x-3.1 - Redirect module from 1.6 to 1.7.0
https://www.drupal.org/project/redirect/releases/8.x-1.7 - Search API Attachments module from 1.0.0-beta18 to 9.0.0
https://www.drupal.org/project/search_api_attachments/releases/9.0.0 - Shield module from 1.4 to 1.5.0
https://www.drupal.org/project/shield/releases/8.x-1.5 - Simple Sitemap module from 3.10.0 to 4.0.1
https://www.drupal.org/project/simple_sitemap/releases/4.0.1
What modules are added/removed in the distribution?
Nothing was added/removed from the distribution
What support will be provided after these update?
The D9 distribution will continue to be supported after this update.
What actions must my organisation do now?
- SaaS customers
All customers will need to check their site after the deployment to ensure there aren’t any issues.
❗Important notice for customers with configuration management enabled
Once the deployment is completed you will need to export the new configurations files and commit them back to master. Deployments to master branch of all websites should be completed by 10am Wednesday 2 February 2022, you can confirm this at https://status.govcms.support - PaaS customers
If you use the GovCMS D9 distribution. You should aim to apply this update to your distribution as soon as possible.
Updated files released on Monday 31 January 2022 and are available from https://github.com/govCMS/GovCMS/releases/tag/2.9.0
More information
- If you have any concerns, raise a ticket at https://www.govcms.support
- Stay up to date by subscribing for notifications at https://status.govcms.support/
2.8.0 Release
GovCMS 2.8.0 Release Notes
Advice
GovCMS released the Drupal 9 (D9) distribution on Friday 21 January 2022. Deployment is scheduled to commence from Monday 24 January 2022 and will be conducted throughout the daytime and into the evening.
It addresses a recent security advisory issued by Drupal.org. GovCMS assessed the moderately critical risks as they applied to D9 distribution, subsequently the security risks remained moderately critical.
No outages are expected to websites during the deployment process.
What is included in the update?
- Drupal Core from 9.2.9 to 9.2.10 - https://www.drupal.org/project/drupal/releases/9.2.10
- Simple OAuth module from 5.0.5 to 5.2.0 - https://www.drupal.org/project/simple_oauth/releases/5.2.0 https://www.drupal.org/sa-contrib-2022-002
- Devel module from 4.1.1 to 4.1.3 - https://www.drupal.org/project/devel/releases/4.1.3
- Honeypot module from 2.0.1 to 2.0.2 - https://www.drupal.org/project/honeypot/releases/2.0.2
- Key module from 1.14 to 1.15.0 - https://www.drupal.org/project/key/releases/8.x-1.15
- Layout Builder Restrictions module from 2.9 to 2.11.0 - https://www.drupal.org/project/layout_builder_restrictions/releases/8.x-2.11
- Search API module from 1.20.0 to 1.21.0 - https://www.drupal.org/project/search_api/releases/8.x-1.21
- Swiftmailer module from 2.0.0 to 2.2.0 - https://www.drupal.org/project/swiftmailer/releases/8.x-2.2
- Swiftmailer library from 6.2.7 to 6.3.0 - https://github.com/swiftmailer/swiftmailer/releases/tag/v6.3.0
- Token module from 1.9.0. to 1.10.0 - https://www.drupal.org/project/token/releases/8.x-1.10
What modules are added/removed in the distribution?
Noting was added/removed from the distribution
What support will be provided after these update?
The D9 distribution will continue to be supported after this update.
More information
- If you have any concerns, raise a ticket at https://www.govcms.support
- Stay up to date by subscribing for notifications at https://status.govcms.support/
2.7.0 Release
GovCMS 2.7.0 Release Notes
Advice
Over the weekend (11 December), a zero-day exploit (Log4Shell) in the popular Java logging library log4j was discovered that results in Remote Code Execution (RCE) by logging a certain string. See https://www.lunasec.io/docs/blog/log4j-zero-day/ and GHSA-jfh8-c2jp-5v3q for more background.
GovCMS is currently prioritising this Zero Day CVE (See CVE-2021-44228 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228). An urgent hotfix has been applied to temporarily mitigate the issue across the platform, until the D9 deployment tomorrow. There is no further action for D9 SaaS projects.
D9 PaaS customers will need to patch your projects ASAP. If you use the GovCMS base images, you will need to redeploy your projects for the change to take effect. If you don’t use the GovCMS base images you will need to take action to patch SOLR7 in your project as it pertains to your codebase.
Actions
-
❗ Important notice for SaaS customers with configuration management enabled
Once the deployment is completed you will need to export the new configurations files and commit them back to master. Deployments to all websites should be completed by 12pm Thursday 16 December 2021, you can confirm this at https://status.govcms.support/. -
D9 PaaS customers will need to patch your projects ASAP
If you use the GovCMS D9 distribution:
**If you have any projects running on Solr 7 or above, there is a temporary mitigation in place for existing environments, but you should upgrade to https://github.com/uselagoon/lagoon-images/releases/tag/21.12.0 base images as soon as practical (so newly created environments receive protection)
**You should prioritise this update to your distribution. Updated files released on Monday 13 December 2021 and are available from https://github.com/govCMS/GovCMS/releases/tag/2.7.0 -
If you don’t use the GovCMS D9 distribution:
** If you have any projects running on Solr 7 or above, immediately apply the SOLR7 patch as it pertains to your codebase
Release Information
- Distribution was updated on Monday 13 December 2021
- Deployments are scheduled to commence on Tuesday 14 December 2021
- Deployments will be conducted throughout the daytime and into the evening.
- No modules have been added/removed from the distribution
- No outages are expected to websites during the deployment process.
- The D9 distribution will continue to be supported after this update.
Module Update
- Drupal Core from 9.2.7 to 9.2.9 (https://www.drupal.org/project/drupal/releases/9.2.9)
- Webform module from 6.0.5 to 6.1.2 (https://www.drupal.org/project/webform/releases/6.1.2)
More information
If you have any concerns, raise a ticket at https://www.govcms.support, alternatively subscribe to https://status.govcms.support/ for information on updates to the GovCMS platform
2.6.0
Who is affected: GovCMS Drupal 9 (D9) community
Advice
- Distribution was updated on Friday 12 November 2021
- Deployments were originally scheduled to commence on Monday 15 November 2021 and had to be postponed.
- Deployments are now rescheduled to commence on Wednesday 17 November 2021
- Deployments will be conducted throughout the daytime and into the evening.
- ❗ Important notice for SaaS customers with configuration management enabled
Once the deployment is completed you will need to export the new configurations files and commit them back to master. Deployments to all websites should be completed by 9am Friday 19 November 2021, you can confirm this at https://status.govcms.support/. - PaaS customers, review the detailed information about this update.
If you use the GovCMS D9 distribution. You should aim to apply this update to your distribution as soon as possible. Updated files will be available from: https://github.com/govCMS/GovCMS/releases/tag/2.6.0 - No outages are expected to websites during the deployment process.
- The D9 distribution will continue to be supported after this update.
What is included in the update?
- Drupal Core from 9.2.6 to 9.2.7 (https://www.drupal.org/project/drupal/releases/9.2.7 )
- Add Address 1.9 (https://www.drupal.org/project/address/releases/8.x-1.9 )
- Admin toolbar from 3.0.2 to 3.0.3 (https://www.drupal.org/project/admin_toolbar/releases/3.0.3 )
- Linkit from 6.0.0-beta2 to 6.0.0-beta3 (https://www.drupal.org/sa-contrib-2021-042; https://www.drupal.org/project/linkit/releases/6.0.0-beta3 )
- Enhancements/Bug Fixes: Webform signature field (#329)
What modules are added/removed in the distribution?
Address module has been added to the distribution.
More information
If you have any concerns, raise a ticket at https://www.govcms.support.
1.21.0 Release
GovCMS updated the Drupal 8 (D8) distribution on Monday 25 October 2021
What is included in the update?
Linkit module from 6.0-beta2 to 6.0-beta3 - https://www.drupal.org/sa-contrib-2021-042
What does the update remove from the distribution?
Nothing will be removed from the D8 distribution in this update.
What support will be provided after these update?
The D8 distribution will be supported until 2nd November 2021
Drupal 8 end-of-life on November 2, 2021 - https://www.drupal.org/psa-2021-2021-06-29
More information
If you have any concerns, raise a ticket at https://www.govcms.support, alternatively subscribe to https://status.govcms.support/ for information on updates to the GovCMS platform
2.5.0
Advice
- Distribution was updated on Thursday 7 October 2021
- Deployments are scheduled to commence on Monday 11 October 2021
- Deployments will be conducted throughout the daytime and into the evening.
- Deployments to all websites should be completed by 9am Tuesday 12 October 2021
- No outages are expected to websites during the deployment process.
- The D9 distribution will continue to be supported after this update.
Module update
- Drupal Core from 9.2.4 to 9.2.6 (https://www.drupal.org/project/drupal/releases/9.2.6)
Cross Site Request Forgery (https://www.drupal.org/sa-core-2021-006 ; https://www.drupal.org/sa-core-2021-007)
Access bypass (https://www.drupal.org/sa-core-2021-008 ; https://www.drupal.org/sa-core-2021-009 ; https://www.drupal.org/sa-core-2021-010) - Dropzone from 5.7.2 to 5.9.3 (https://asset-packagist.org/package/bower-asset/dropzone)
- Context from 4.0.0-beta6 to 4.1.0 (https://www.drupal.org/project/context/releases/8.x-4.1)
- Entity_embed from 1.1 to 1.2.0 (https://www.drupal.org/project/entity_embed/releases/8.x-1.2)
- Field_group from 3.1 to 3.2.0 (https://www.drupal.org/project/field_group/releases/8.x-3.2)
- Search_api from 1.19.0 to 1.20.0 (https://www.drupal.org/project/search_api/releases/8.x-1.20)
- Search_api_attachments from 1.0-beta17 to 1.0.0-beta18 (https://www.drupal.org/project/search_api_attachments/releases/8.x-1.0-beta18)
- Simple_oauth requirement from 5.0.4 to 5.0.5 (https://www.drupal.org/project/simple_oauth/releases/5.0.5)
- TFA from 1.0.0-alpha7 to 1.0.0-alpha8 (https://www.drupal.org/project/tfa/releases/8.x-1.0-alpha8)
- Swiftmailer from 6.2.3 to 6.2.7 (https://github.com/swiftmailer/swiftmailer/releases/tag/v6.2.7)
Modules added/removed/ deprecated
Nothing will be added/removed from the D9 distribution in this update.
Important reminder for projects with configuration management enabled
Do not import any out of date configurations of these modules. This will cause fatal errors to your websites. Once the deployment is completed you will need to export the new configurations files and commit them back to master. Deployments to all websites should be completed by 9am Tuesday 12 October 2021, you can confirm this at https://status.govcms.support/.
More information
If you have any concerns, raise a ticket at https://www.govcms.support, alternatively subscribe to https://status.govcms.support/ for information on updates to the GovCMS platform
1.20.0 Release
GovCMS updated the Drupal 8 (D8) distribution on Tuesday 28 September 2021.
Deployment is scheduled to commence from Wednesday 29 September 2021 and will be conducted throughout the daytime and into the evening.
It addresses a recent security advisory issued by Drupal.org. GovCMS assessed this moderately critical risk as it applied to D8 distribution, subsequently the security risk remained moderately critical.
No outages are expected to websites during the deployment process.
What is included in the update?
Drupal Core from 8.9.18 to 8.9.19
Cross Site Request Forgery
https://www.drupal.org/sa-core-2021-006
https://www.drupal.org/sa-core-2021-007
Access bypass
https://www.drupal.org/sa-core-2021-008
https://www.drupal.org/sa-core-2021-009
https://www.drupal.org/sa-core-2021-010
Admin Toolbar from 8.x-2.3 to 8.x-2.5
https://www.drupal.org/sa-contrib-2021-025
Webform from 8.x-5.25 to 8.x-5.28
https://www.drupal.org/sa-contrib-2021-026
Entity Embed from 8.x-1.1 to 8.x-1.2
https://www.drupal.org/sa-contrib-2021-028
What does the update remove from the distribution?
Nothing will be removed from the D8 distribution in this update.
What support will be provided after these update?
The D8 distribution will be supported until November 2021.
More information
If you have any concerns, raise a ticket at https://www.govcms.support, alternatively subscribe to https://status.govcms.support/ for information on updates to the GovCMS platform
2.4.0 Release
GovCMS 2.4.0 Release Notes
Advice
- D9 Distribution was updated on Tuesday 7 September 2021.
- Deployments are scheduled to commence on Wednesday 8 September 2021.
- Deployments be conducted throughout the daytime and into the evening.
- No outages are expected to websites during the deployment process.
- The D9 distribution will continue to be supported after this update.
Modules added
- Layout Builder Modal https://www.drupal.org/project/layout_builder_modal
- Layout Builder Restrictions https://www.drupal.org/project/layout_builder_restrictions
Module update
- Drupal Core from 9.2.2 to 9.2.4 https://www.drupal.org/sa-core-2021-005 https://www.drupal.org/project/drupal/releases/9.2.4
- Admin Toolbar from 3.0.1 to 3.0.2 https://www.drupal.org/SA-CONTRIB-2021-025 https://www.drupal.org/project/admin_toolbar/releases/3.0.2
- Webform from 6.0.4 to 6.0.5 https://www.drupal.org/SA-CONTRIB-2021-026 https://www.drupal.org/project/webform/releases/6.0.5
- Devel from 4.0.1 to 4.1.1 https://www.drupal.org/project/devel/releases/4.1.1
- Dropzonejs from 2.3.0 to 2.5.0 https://www.drupal.org/project/dropzonejs/releases/8.x-2.5
- Display Suite from 3.9.0 to 3.13.0 https://www.drupal.org/project/ds/releases/8.x-3.13
- Dynamic Entity Reference from 1.11.0 to 1.12.0 https://www.drupal.org/project/dynamic_entity_reference/releases/8.x-1.12
- Entity Browser from 2.5.0 to 2.6.0 https://www.drupal.org/project/entity_browser/releases/8.x-2.6
- Environment Indicator from 4.0.1 to 4.0.3 https://www.drupal.org/project/environment_indicator/releases/4.0.3
- Features from 3.11.0 to 3.12.0 https://www.drupal.org/project/features/releases/8.x-3.12
- Menu Block from 1.6.0 to 1.7.0 https://www.drupal.org/project/menu_block/releases/8.x-1.7
- Metatag from 1.14.0 to 1.16.0 https://www.drupal.org/project/metatag/releases/8.x-1.16
- Password Policy from 3.0.0-beta1 to 3.0.0 https://www.drupal.org/project/password_policy/releases/8.x-3.0
- Scheduled Transitions from 2.0.0 to 2.1.0 https://www.drupal.org/project/scheduled_transitions/releases/2.1.0
- Search API Solr from 4.1.11 to 4.2.1 https://www.drupal.org/project/search_api_solr/releases/4.2.1
- Token from 1.7.0 to 1.9.0 https://www.drupal.org/project/token/releases/8.x-1.9
- Bug fixes to Two-factor Authentication
Modules deprecated/removed
Nothing will be removed from the D9 distribution in this update.
Important reminder for projects with configuration management enabled
Do not import any out of date configurations of these modules. This will cause fatal errors to your websites. Once the deployment is completed you will need to export the new configurations files and commit them back to master. Deployments to all websites should be completed by 9am Thursday 9 September 2021, you can confirm this at https://status.govcms.support/.
More information
If you have any concerns, raise a ticket at https://www.govcms.support, alternatively subscribe to https://status.govcms.support/ for information on updates to the GovCMS platform
1.19.0
Module update
Drupal Core from 8.9.17 to 8.9.18 https://www.drupal.org/project/drupal/releases/8.9.18
Important reminder for projects with configuration management enabled
Do not import any out of date configurations of these modules. This will cause fatal errors to your websites. Once the deployment is completed you will need to export the new configurations files and commit them back to master. Deployments to all websites should be completed by 8am Friday 10 September 2021, you can confirm this at https://status.govcms.support/.
More information
If you have any concerns, raise a ticket at https://www.govcms.support, alternatively subscribe to https://status.govcms.support/ for information on updates to the GovCMS platform
2.3.0 Release
Module and core update
- Drupal Core From 9.2.0 to 9.2.2 https://www.drupal.org/project/drupal/releases/9.2.2 https://www.drupal.org/sa-core-2021-004
- migrate_tools from 4.5 to 5.0
- admin_toolbar from 2.4.0 to 3.0.1
- components from 2.2.0 to 2.4.0
- ctools from 3.6.0 to 3.7.0
- entity_reference_revisions from 1.8.0 to 1.9.0
- simple_oauth from 5.0.2 to 5.0.4
- simple_sitemap from 3.7.0 to 3.10.0
- username_enumeration_prevention from 1.1.0 to 1.2.0
- webform from 6.0.2 to 6.0.4
Modules deprecated/removed
Nothing will be removed from the D9 distribution in this update.
Deployment information
-
Deployments are also scheduled to commence from Monday 16 August 2021 and will be conducted throughout the daytime and into the evening.
-
No outages are expected to websites during the deployment process.
-
The D9 distribution will continue to be supported after this update.
Important reminder for projects with configuration management enabled
Do not import any out of date configurations of these modules. This will cause fatal errors to your websites. Once the deployment is completed you will need to export the new configurations files and commit them back to master. Deployments to all websites should be completed by 8am Tuesday 17 August 2021, you can confirm this at https://status.govcms.support/.
More information
If you have any concerns, raise a ticket at https://www.govcms.support, alternatively subscribe to https://status.govcms.support/ for information on updates to the GovCMS platform