One Webform Release, Twenty Advisories: Audit Every Drupal Site
A critical Webform release is a reminder to audit every Drupal codebase, configuration and deployment—not just the main production website.
A critical Webform release is a reminder to audit every Drupal codebase, configuration and deployment—not just the main production website.
Twelve production websites on one server, each with its own Composer dependency tree, and the oldest question in hosting: are they up to date, and is it safe to make them so? The dependency-currency gate answers it weekly and automatically — it inventories every vhost, checks each dependency tree against the PHP version that site's web server actually runs, queues the semver-safe updates for approval, and reports the breaking ones instead of applying them.
GrN.dk — server fleet (12 production vhosts)
Drupal 12 arrives as Drupal 10 support ends in December 2026. Moving to Drupal 11.3+ first keeps two mandatory upgrades manageable.
Drupal’s June security fixes reveal where update routines fail. A practical guide to Composer checks, supported versions, staging, and dependable deployment.
Drupal 10 reaches end of life on December 9, 2026. Use this practical inventory to scope Drupal 11 readiness, Composer debt, modules, and custom code.
The legacy Drupal update API is gone. Choose a supported update path, check Composer and hosting constraints, and rehearse safer Drupal releases.
A practical 2026 guide to auditing a legacy Drupal 9 site, using Drupal 10 as a controlled bridge, and deciding whether to upgrade to Drupal 11 or rebuild.
Diagnose Drush, Symfony, Composer and PHP conflicts safely, choose a supported Drupal toolchain, and prevent repeat deployment failures.
Make PHP dependency changes easier to review with Composer Normalize. Set explicit plugin trust, keep the lock file in sync, and catch drift in CI.
Written recommendations from Trafik og Veje, Aarhus Municipality (2011) and AgroTech (2010).