This is a patch (bugfix) release of Drupal 10 and is ready for use on production sites. Learn more about Drupal 10.

Drupal 10.3.x will receive security coverage until June 2025.

The Twig templating library has issued a security advisory. Drupal core is not vulnerable, but previous versions of the drupal/core-recommended package only allowed insecure versions of Twig to be installed. This patch release upgrades Twig to 3.14.0 as a public security hardening.

Known issues

  • [#3471741] conflicts with Menu Trail by Path, Entity Manager and Gin Toolbar modules.

Important update information

If you are updating from 10.2.x or earlier and have the CKEditor font module installed, you should consider switching to CKEditor5 Plugin pack for a more up-to-date version of the plugin which is compatible with the CKEditor5 version shipped with Drupal 10.3. If you are updating from Drupal 9, refer to Preparing your site to upgrade to a newer major version for tools you can use to check the Drupal 10 compatibility of modules, themes and sites. Then, upgrade from Drupal 9 to 10. You should also check the Drupal 10.0.0 release notes.

All changes in this release

VCS Label
10.3.4
Release type
Short description
Actively maintained with bugfixes and forwards compatibility backports every six months. Use this version if you already have a Drupal 10 site, until you're ready to update to 11.x
Packaged Git sha1
e51a2707783dc8c6453c7b1d231e5f0d97bbd687
Release files
a21b74c39d27226c6c2668ee52c45394
Release file SHA-1 hash
f75772ee99356ec8e2b665b2364bb8fb5b3a615e
Release file SHA-256 hash
150b3858e2e89ffedb38f6ac326e1a7305d5a73b6e9c4382fa56c8558c976fe8
42aa036b8c70cc243a49f71b8cfadde5
Release file SHA-1 hash
bcfd4146d8223261889f37a15e370e3e6ccdbfab
Release file SHA-256 hash
ac13cf3844b2802391c343446371d9645cd5078e32fec2df61b2bbf64807d15b