

DRUPAL SECURITY RELEASE LEVELS UPDATE
Really this security update is no different from the many that happen in contrib every year. I'd love to hear how you deal with these potentially tough conversations, and what you've learned from them. Here's a link to the official announcement: Thank you for your understanding and continuing business! Please feel free to contact me should you have any questions. The recent high profile Sony Playstation Network security breach being a potent example of what can go wrong. If your site were not built using Drupal, it's likely that this issue would have gone undetected and could have resulted in significant financial cost. I feel strongly that this update should be viewed as a showcases the value of Drupal and Open Source projects.

If you need us to address any issues, they will be addressed on a T&M basis. There should be no downtime associated with the patch, but you may wish you review the site for possible issues/changes. We're currently estimating this task as a 1 hour line-item billed at your normal hourly rate, however should complications arise it's possible that it could take more time.
DRUPAL SECURITY RELEASE LEVELS PATCH
Please let us know if you will be able to schedule a software update within the next few weeks yourself, or we can implement the patch on a time and materials basis. Since this represents a significant danger to the data on your site and machines within our hosting environment we are considering this update to be mandatory. Since you currently have an Extended Service Agreement with us, we're recommending scheduling the fix as part of our monthly allotment of hours.ī. We're currently recommending implementing this ASAP patch to avoid any issues.Ī. There was a significant security flaw identified in the version of Drupal your site is running that was fixed in a security patch that was released released on May 25. Here's the email that we drafted up and shared with our customers (please feel free to use it, rewrite and share if it proves useful): While I feel strongly this is illustrates the value of Drupal and Open Source, it can be a significant challenge to talk to your customers about this. With the recent release of versions 7.2 and 6.22, a significant Drupal security flaw in 6.x has been identified and fixed.
