Reply to comment

Two-sided coin

I'm amazed at and grateful for everything that Drupal does for a website maintainer, but I find that keeping up with security patches is one of the downsides to using Drupal (the other is juggling the various module dependencies). I would imagine that these two 'problems' apply to any open source app that has a large and active user base, however.

Roy, are you on the Drupal security bulletin email list (http://drupal.org/security)? The security team is excellent, but it is unfortunate that so many XSS and SQL injection bugs get into the code.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote>
  • Lines and paragraphs break automatically.
  • You may post code using <code>...</code> (generic) or <?php ... ?> (highlighted PHP) tags.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.