This is a patch (bugfix) release of Drupal 11 and is ready for use on production sites. Learn more about Drupal 11.
Drupal 11.0.x will receive security coverage until June 2025.
The Twig templating library has issued a security advisory. Drupal core is not vulnerable, but previous versions of the drupal/core-recommended package only allowed insecure versions of Twig to be installed. This patch release upgrades Twig to 3.14.0 as a public security hardening.
Known issues
- [#3471741] conflicts with Menu Trail by Path, Entity Manager and Gin Toolbar modules.
Important update information
- If you are updating from Drupal 10, refer to Preparing your site to upgrade to a newer major version for tools you can use to check the Drupal 11 compatibility of modules, themes and sites. Then, upgrade from Drupal 10 to 11. You should also check the Drupal 11.0.0 release notes.
- If you are updating from 10.2.x or earlier and have the CKEditor font module installed, you should consider switching to CKEditor5 Plugin pack for a more up-to-date version of the plugin which is compatible with the CKEditor5 version shipped with Drupal 10.3.
All changes in this release
- Issue #2386195 by dawehner, samit.310@gmail.com, voleger, daffie, smustgrave, mile23: State has no dedicated test coverage
- Issue #3473195 by longwave, catch, jurgenhaas, naveenvalecha, quietone: twig/twig has a possible sandbox bypass
- Issue #3472092 by nicxvan, smustgrave: Remove references to ApcClassLoader (removed in Symfony 4)
- Issue #3471741 by mstrelan, bbrala, kristiaanvandeneynde: Fix null $cid in CacheCollector classes
- Issue #3469309 by mstrelan, smustgrave, moshe weitzman: Use one-time login link instead of user login form in BrowserTestBase tests
- Revert "Issue #3469309 by mstrelan, smustgrave, moshe weitzman: Use one-time login link instead of user login form in BrowserTestBase tests"
- Issue #3469309 by mstrelan, smustgrave, moshe weitzman: Use one-time login link instead of user login form in BrowserTestBase tests
- Issue #3454507 by hablat, catch: Aggregated asset generation causes uncacheable assets
- Issue #3436526 by skaught, plopesc, kostyashupenko, m4olivei, quietone, godotislate, catch, ckrina, KeyboardCowboy, nod_, longwave: Adjust custom navigation logo dimensions on upload
- Issue #3471977 by grimreaper: Drupal.dialog openDialog should use event settings
- Back to dev.
VCS Label
11.0.3
Short description
Actively maintained with new features and backwards-compatible improvements every six months. Use this version for the best compatibility with future releases.
Packaged Git sha1
a724e435f67db428241d7bbd0220394ee77f81c9
Release files
d7353192e32b8c2d1457c93f3e98838b
Release file SHA-1 hash
d73805a6e48c5eb68add056d9c2f2e0d041427de
Release file SHA-256 hash
1df750e5aa143dead7bf3765deb15296ce60b23334310473dbacb0fe382ff953
a62c4647d2840b384da0ad68de64a365
Release file SHA-1 hash
6943b796ce4f23b6e0c374d453db18f8cd1f403d
Release file SHA-256 hash
c4accf25b5cb60355199837a84d8f36c11fab58723a37c32551545c66b07024b