Critical · 342,248 sites report using it · 20 security fixes
This module allows you to build forms to collect data and send it to other systems.
20 security fixes in one update. Webform fixed 20 separate security bugs this week: 10 cross site scripting, 8 access bypass, 1 remote code execution, 1 denial of service. One update covers all of them. The most serious, SA-CONTRIB-2026-175, is explained here and the full list is at the end of the card.
Anyone without logging in could submit data that runs as code when the form is viewed. They could read the entire database and change the underlying website code. They could not do this on forms that do not use special formatting tags.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if a form is set up with a custom multiple value format that includes submission value tags.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Webform to 6.2.12 or 6.3.1, whichever branch you are on.
For developers: what the fix changed
This release carries 20 security fixes. The summary below is for SA-CONTRIB-2026-175, the most serious of them.
Adds the missing `#` prefix to `#format_items_html` and `#format_items_text` in `WebformElementBase.php` to properly exclude multiple-value item formats from token replacement.
Also in this release The release also includes numerous other security fixes, such as XSS mitigations in JavaScript, SSRF protections for remote CSV imports, path traversal prevention in exports, and stricter access controls for remote post handlers and file downloads.
6.2.11 to 6.2.12 27 commits, 75 files including 33 tests.
.gitlab-ci.yml +1 −1
composer.json +1 −0
includes/webform.query.inc +8 −0
js/webform.announce.js +1 −1
js/webform.dialog.js +1 −1
js/webform.element.ajax.js +18 −7
js/webform.element.color.js +6 −2
js/webform.element.counter.js +18 −0
js/webform.element.help.js +1 −1
js/webform.element.rating.js +53 −2
js/webform.tooltip.js +2 −2
js/webform.xss.js +133 −0
Full diff, 6.2.11 to 6.2.12 · Full diff, 6.3.0 to 6.3.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
All 20 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.
Critical · 15,894 sites report using it · SA-CONTRIB-2026-178 · on drupal.org
This module lets site builders find and install new features directly from the website interface.
Anyone without logging in could trick an administrator into installing new features. They could view private site configurations and add unwanted modules to the site. They could not do this without tricking a logged in administrator.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Project Browser to 2.1.5 or 2.0.3, whichever branch you are on.
For developers: what the fix changed
Adds `_csrf_token: 'TRUE'` to the `project_browser.activate` and `project_browser.uninstall` routes in `project_browser.routing.yml` and introduces a `CsrfTokenPath` service to properly generate and inject CSRF tokens into URLs used by the frontend.
Also in this release Fixed an issue where an un-instantiable applied recipe would blank the entire catalog.
2.1.4 to 2.1.5 2 commits, 21 files including 9 tests.
.cspell-project-words.txt +1 −0
project_browser.routing.yml +2 −0 fix
project_browser.services.yml +3 −0 fix
src/Activator/RecipeActivator.php +22 −2
src/Controller/InstallerController.php +3 −21 fix
src/CsrfTokenPath.php +58 −0 fix
src/Element/ProjectBrowser.php +5 −0 fix
src/ProjectBrowser/Normalizer.php +5 −1 fix
sveltejs/public/build/bundle.js +0 −0
sveltejs/public/build/bundle.js.map +0 −0
sveltejs/src/InstallListProcessor.js +7 −5 fix
sveltejs/src/constants.js +1 −0 fix
Full diff, 2.1.4 to 2.1.5 · Full diff, 2.0.2 to 2.0.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · 767 sites report using it · SA-CONTRIB-2026-184 · on drupal.org
This module adds a live chat feature to the website.
Anyone without logging in could trick a logged in user into performing actions they did not intend to do. They could read private chat logs and alter the chat settings. They could not take full control of the web server.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Tawk.to - Live chat application to 3.0.4.
For developers: what the fix changed
The fix adds CSRF token requirements and restricts methods to POST for the `set_widget` and `remove_widget` routes in `tawk_to.routing.yml`. It also updates `TawkToWidgetController` to generate URLs with CSRF tokens and modifies `tawk-to-iframe.html.twig` to use these secure URLs when making requests.
Also in this release The release replaces jQuery with vanilla JavaScript in the iframe template, improves autoescaping in templates, and adds entity decoding for user details in `TawkToEmbedRender`.
3.0.3 to 3.0.4 1 commit, 5 files.
src/Controller/TawkToWidgetController.php +75 −7 fix
src/Service/TawkToEmbedRender.php +5 −4
tawk_to.routing.yml +4 −0 fix
templates/tawk-to-iframe.html.twig +55 −37 fix
templates/tawk-to.html.twig +3 −1
Full diff, 3.0.3 to 3.0.4
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Critical · no install count published · 2 security fixes
This module lets users manage their external server infrastructure directly from the website.
2 security fixes in one update. Cloud fixed 2 separate security bugs this week: 2 remote code execution. One update covers all of them. The most serious, SA-CONTRIB-2026-177, is explained here and the full list is at the end of the card.
An administrator account could run dangerous operating system commands on the web server by entering malicious web addresses. They could read any file on the server and change the core website code. They could not do this without the access right to add or edit server templates.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if the Kubernetes feature is turned on and the attacker has the access right to launch server templates.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Cloud to 7.0.1.
For developers: what the fix changed
This release carries 2 security fixes. The summary below is for SA-CONTRIB-2026-177, the most serious of them.
It is unclear where the exact sanitisation occurs in the module's code, but the fix appears to rely on updating the `cloud_orchestrator` Docker image version to 7.0.1 in the Kubernetes deployment configuration files.
The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.
Also in this release The release also adds new AWS region locations, updates type hints for PHP 8.4 compatibility, and removes 'default_argument_skip_url' from various view configurations.
7.0.0 to 7.0.1 25 commits, 772 files including 77 tests.
.gitlab-ci.yml +6 −4
README.md +3 −3
cloud.doxyfile +1 −1
cloud.info.yml +1 −1
cloud.install +31 −4
cloud.module +5 −5
config/install/field.storage.cloud_config.field_self_signed_cert_path.yml +1 −4
config/install/views.view.cloud_launch_template.yml +0 −1
deployments/cfn/nested/cloud_orchestrator_full.yaml +2 −1
deployments/cfn/nested/cloud_orchestrator_full_manual_vpc.yaml +2 −1
deployments/cfn/nested/cloud_orchestrator_single.yaml +2 −1
deployments/cfn/nested/cloud_orchestrator_single_ami.yaml +2 −1
Full diff, 7.0.0 to 7.0.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.
Moderately critical · 31,786 sites report using it · SA-CONTRIB-2026-185 · on drupal.org
This module runs an automatic accessibility checker that gives live feedback to editors as they work.
An ordinary account on the site could edit or delete the accessibility checker data because an access right was set up incorrectly. They could remove important accessibility warnings. They could not read any restricted content.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Editoria11y Accessibility Checker to 2.2.23 or 3.0.9, whichever branch you are on.
For developers: what the fix changed
Updates the title and description of the 'view editoria11y checker' permission in editoria11y.permissions.yml to clarify its purpose and effect.
2.2.22 to 2.2.23 1 commit, 1 file.
editoria11y.permissions.yml +2 −2 fix
Full diff, 2.2.22 to 2.2.23 · Full diff, 3.0.8 to 3.0.9
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 1,665 sites report using it · SA-CONTRIB-2026-182 · on drupal.org
This module adds an extra layer of security to the data feeds on your website.
Anyone without logging in could bypass the security checks for some data feed requests. They could read private information from the data feed. They could not modify or delete any of that information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate REST & JSON API Authentication for Drupal to 3.2.0.
For developers: what the fix changed
The fix updates `RestAPI::applies()` in `src/Authentication/Provider/RestAPI.php` and `DisallowAPIRequests::check()` in `src/PageCache/DisallowAPIRequests.php` to use `$request->getPathInfo()` instead of `$request->getRequestUri()` for path matching. It also replaces a literal string check for `?_format=` with `$request->query->has('_format')` to prevent attackers from bypassing authentication by reordering query parameters.
Also in this release The release also added GitLab CI configuration and a new functional test.
3.1.0 to 3.2.0 1 commit, 4 files including 1 test.
.gitlab-ci.yml +18 −0
src/Authentication/Provider/RestAPI.php +8 −3 fix
src/PageCache/DisallowAPIRequests.php +2 −2 fix
Full diff, 3.1.0 to 3.2.0
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 470 sites report using it · SA-CONTRIB-2026-187 · on drupal.org
This module lets content editors use artificial intelligence to write or fix text in the text editor.
An ordinary account on the site could use special template commands to extract confidential system data. They could view secret server details. They could not modify any content or settings.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate AI CKEditor to 1.4.3.
For developers: what the fix changed
The fix prevents Twig template injection by rendering the Twig template before replacing placeholders with user input in the `Tone` and `Translate` plugins.
Also in this release The release also adds cleanup logic for CKEditor settings when the module is uninstalled, along with a warning on the uninstall confirmation form.
1.4.2 to 1.4.3 4 commits, 9 files including 1 test.
ai_ckeditor.install +37 −0
ai_ckeditor.module +10 −0
ai_ckeditor.services.yml +3 −0
package-lock.json +2 −2
package.json +1 −1
src/Hook/AiCKEditorHooks.php +81 −0
src/Plugin/AiCKEditor/Tone.php +9 −6 fix
src/Plugin/AiCKEditor/Translate.php +8 −6 fix
Full diff, 1.4.2 to 1.4.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 349 sites report using it · SA-CONTRIB-2026-190 · on drupal.org
This module shows different content blocks to visitors based on their browser settings.
Anyone without logging in could view restricted content blocks by asking the server for them directly. They could see hidden text meant for other users. They could not alter any information on the site.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if a site has placed a restricted block inside a display blocks reaction.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Smart Content to 3.2.1.
For developers: what the fix changed
The fix updates the `DisplayBlocks` reaction plugin to correctly call `isAllowed()` on the block access result object in `modules/smart_content_block/src/Plugin/smart_content/Reaction/DisplayBlocks.php`, rather than just checking if the object itself evaluates to true.
Also in this release The release also includes Drupal 11 compatibility updates and PHP 8.2 deprecation fixes.
3.1.0 to 3.2.1 4 commits, 18 files including 5 tests.
modules/smart_content_block/smart_content_block.info.yml +1 −1
modules/smart_content_block/src/EventSubscriber/LayoutBuilderComponentRenderArray.php +1 −1
modules/smart_content_block/src/Plugin/smart_content/Reaction/DisplayBlocks.php +2 −1 fix
modules/smart_content_browser/smart_content_browser.info.yml +1 −1
smart_content.info.yml +1 −1
src/Condition/ConditionTypeConfigurableBase.php +2 −1
src/Condition/ConditionsHelperTrait.php +1 −1
src/Condition/Type/ConditionTypeBase.php +14 −0
src/Condition/Type/ConditionTypeInterface.php +9 −0
src/Decision/DecisionBase.php +1 −1
src/Plugin/DataType/DecisionData.php +16 −0
src/Plugin/Field/FieldType/DecisionItem.php +2 −1
Full diff, 3.1.0 to 3.2.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 304 sites report using it · SA-CONTRIB-2026-180 · on drupal.org
This module lets you add diagrams to a piece of content or display them in a pop up window.
An ordinary account on the site could view diagram content in a pop up window without the correct access rights. They could see hidden charts meant for other users. They could not alter the diagrams.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the pop up display option is turned on for the diagram field or if the attacker knows the exact web address of the pop up.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Mermaid Diagram Field to 1.0.10.
For developers: what the fix changed
The fix changes MermaidModalController::build in src/Controller/MermaidModalController.php to load the default revision instead of the latest revision and adds explicit view access checks for the entity and the field.
Also in this release Added a hook for CSV export in mermaid_diagram_field.module.
1.0.9 to 1.0.10 2 commits, 2 files.
mermaid_diagram_field.module +54 −0
src/Controller/MermaidModalController.php +10 −3 fix
Full diff, 1.0.9 to 1.0.10
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 282 sites report using it · SA-CONTRIB-2026-191 · on drupal.org
This module adds a sliding image gallery that can be set up directly without custom code.
An ordinary account on the site could add hidden scripts to the slide descriptions. They could read private user details and change the text on the page. They could not take over the entire website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies to sites that use a formatted text field for the slide description and have enabled the allow HTML description option.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Diba carousel slider to 3.0.2.
For developers: what the fix changed
The fix applies text format filtering or admin XSS filtering to the description in `src/Plugin/Block/DibaCarousel.php` when HTML is allowed, and removes the `|raw` filter from variables in `templates/block--diba-carousel.html.twig`.
Also in this release Updated GitLab CI configuration.
3.0.1 to 3.0.2 2 commits, 3 files.
.gitlab-ci.yml +70 −36
src/Plugin/Block/DibaCarousel.php +15 −2 fix
templates/block--diba-carousel.html.twig +4 −4 fix
Full diff, 3.0.1 to 3.0.2
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 147 sites report using it · SA-CONTRIB-2026-183 · on drupal.org
This module blocks people from logging in as the main administrator to protect against lost passwords.
An administrator account could bypass the login block by using alternative authentication methods. They could view all private user details and change any site settings. They could not bypass the block without a valid administrator password.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if an attacker has a valid administrator password and uses a less common login method.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Stop administrator login to 8.x-1.6.
For developers: what the fix changed
The fix transitions the module from using `hook_form_alter` to using an event subscriber (`AuthenticationCheckSubscriber`) and a service decorator (`UserAuthentication`) to enforce login restrictions across all authentication mechanisms. It also introduces a `LoginPolicy` service to centralise the restriction logic.
Also in this release Updated core version requirements to Drupal 10.3 and 11, updated documentation, and added test coverage.
8.x-1.5 to 8.x-1.6 1 commit, 17 files including 9 tests.
README.md +44 −6
src/EventSubscriber/AuthenticationCheckSubscriber.php +94 −0 fix
src/Form/StopAdminConfigForm.php +1 −3
src/LoginPolicy.php +62 −0 fix
src/UserAuthentication.php +64 −0 fix
stop_admin.info.yml +1 −1
stop_admin.module +34 −43 fix
stop_admin.services.yml +13 −0 fix
Full diff, 8.x-1.5 to 8.x-1.6
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 50 sites report using it · SA-CONTRIB-2026-188 · on drupal.org
This module lets you combine multiple image designs into a single image.
Anyone without logging in could force the server to generate many new images without the right security token. They could not view any hidden files and they could not alter any existing images.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Combined image style to 1.0.7.
For developers: what the fix changed
The fix adds validation in `ImageStyleDownloadController::deliverCombined()` to throw a `NotFoundHttpException` if the requested image style names do not fully resolve. It also updates `CombinedImageStyle::getPathToken()` to return a random string instead of an empty string when there are no image styles, preventing empty tokens from bypassing validation.
Also in this release Added functional tests for combined image style delivery.
1.0.6 to 1.0.7 1 commit, 3 files including 1 test.
src/Controller/ImageStyleDownloadController.php +23 −1 fix
src/Entity/CombinedImageStyle.php +9 −0 fix
Full diff, 1.0.6 to 1.0.7
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 26 sites report using it · SA-CONTRIB-2026-179 · on drupal.org
This module provides data feeds that allow other systems to create shop orders remotely.
Anyone without logging in could send unsafe order details to the remote order creation data feed. They could add false items to a shopping basket. They could not view other peoples orders.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Commerce Decoupled Checkout to 8.x-1.8.
For developers: what the fix changed
The fix introduces an allowlist for order fields in `OrderCreateResource::validateInput()` to reject unexpected properties, and updates `validateEntity()` to enforce all field constraints. It also adds a settings form in `SettingsForm.php` to configure permitted custom order fields.
8.x-1.7 to 8.x-1.8 1 commit, 8 files.
README.md +14 −0
commerce_decoupled_checkout.install +20 −0
commerce_decoupled_checkout.links.menu.yml +5 −0
commerce_decoupled_checkout.routing.yml +7 −0
config/install/commerce_decoupled_checkout.settings.yml +1 −0
config/schema/commerce_decoupled_checkout.schema.yml +10 −0
src/Form/SettingsForm.php +106 −0 fix
src/Plugin/rest/resource/OrderCreateResource.php +99 −12 fix
Full diff, 8.x-1.7 to 8.x-1.8
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 12 sites report using it · SA-CONTRIB-2026-189 · on drupal.org
This module lets a design scanner send usage measurements to the site so administrators can see real page statistics.
Anyone without logging in could send fake design measurements to the site. They could add false statistics to the administrator reports. They could not view any private information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate CSS Usage Analyzer to 1.0.2.
For developers: what the fix changed
The fix introduces a new permission in css_usage_analyzer.routing.yml to restrict access to the save endpoint. It also implements flood control and URL validation in the ajaxSave method of src/Controller/CssUsageAnalyzerController.php to prevent forged or repeated submissions.
Also in this release The release also adds an update hook and updates the README file to document the new permission.
1.0.1 to 1.0.2 2 commits, 6 files.
README.md +15 −2
css_usage_analyzer.install +7 −0
css_usage_analyzer.module +1 −1 fix
css_usage_analyzer.permissions.yml +5 −0 fix
css_usage_analyzer.routing.yml +6 −3 fix
src/Controller/CssUsageAnalyzerController.php +46 −0 fix
Full diff, 1.0.1 to 1.0.2
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Moderately critical · 3 sites report using it · SA-CONTRIB-2026-181 · on drupal.org
This module helps site owners comply with privacy laws by showing information about cookie usage.
An administrator account could save malicious scripts in the settings form which would then run on the site. They could read private session details and alter the cookie banner text. They could not do this without administrator access rights.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if an attacker has the access right to manage the cookie settings.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate CookieCuttr to 2.0.3.
For developers: what the fix changed
The fix applies Xss::filterAdmin to the configuration variables in the cookiecuttr_settings function within cookiecuttr.module to prevent cross site scripting.
Also in this release The release also updates the core version requirement to include Drupal 12.
2.0.2 to 2.0.3 2 commits, 2 files.
cookiecuttr.info.yml +1 −1
cookiecuttr.module +2 −1 fix
Full diff, 2.0.2 to 2.0.3
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.
Less critical · 7,867 sites report using it · SA-CONTRIB-2026-186 · on drupal.org
This module lets other systems read and submit forms on your site over a data feed.
An ordinary account on the site could view form fields and submissions without the right access rights. They could read personal details submitted by other people. They could not edit or delete those submissions.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this less critical. Fix it with the next routine update.
Tell your developerUpdate Webform REST to 4.2.1.
For developers: what the fix changed
Adds access checks to `WebformCompleteSubmissionResource`, `WebformElementsResource`, and `WebformFieldsResource` to ensure the current user has permission to view the webform and its submissions.
Also in this release Fixed PHPCS warnings, updated GitLab CI configuration, corrected typos in error messages, and made REST GET endpoints cacheable by replacing ModifiedResourceResponse with ResourceResponse.
4.2.0 to 4.2.1 7 commits, 15 files including 4 tests.
.gitlab-ci.yml +20 −3
src/Event/WebformSubmitReturnEvent.php +13 −2
src/Form/WebformRestForm.php +8 −35
src/Plugin/rest/resource/WebformCompleteSubmissionResource.php +58 −13 fix
src/Plugin/rest/resource/WebformElementsResource.php +32 −6 fix
src/Plugin/rest/resource/WebformFieldsResource.php +24 −8 fix
src/Plugin/rest/resource/WebformSubmissionResource.php +22 −21
src/Plugin/rest/resource/WebformSubmitResource.php +21 −23
webform_rest.install +3 −2
webform_rest.permissions.yml +1 −1
webform_rest.routing.yml +1 −1
Full diff, 4.2.0 to 4.2.1
The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.