Talking Drupal

Talking Drupal #567 - Common Vulnerabilities & Exposures

August 27, 2026·1h 16m
Episode Description from the Publisher

Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We'll also cover Security Scanner as our module of the week. For show notes visit: https://www.talkingDrupal.com/567 Topics What Are CVEs CVE Lifecycle and Disclosure AI Era Security Challenges What CVE Program Excludes Patch Fast Reality Global Security Signals CVE Timing Judgment KEV Flags Explained CVE Updates Link Rot Who Decides CVE Sneaky Patch Dangers ADP Program Fixes Small Team Triage Vulnerability Tsunami AI Autonomous Security Future Legal Pressure Budgets Resources Psalm PHP Static Analysis Tool SARIF format PHP ecosystem Council of roots How AI Broke Open Source Security: End-of-Life Software Is the Most Exposed CVE podcast Vulncon PSIRT Guests David Welch - github: dwelch2344 dwelch2344 Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi JD Flynn - dorficus MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that. Module name/project name: Security Scanner Brief history How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia Versions available: 1.0.0, which works with Drupal 10.3 and 11 Maintainership Actively maintained — created and shipped its first stable this summer, with steady development right through late July Security coverage Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG Number of open issues: 1 issue, not a bug Usage stats: 2 sites (it's brand new) Module features and usage Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, mis

Podzilla Summary coming soon

Sign up to get notified when the full AI-powered summary is ready.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.

Listen to This Episode

Get summaries like this every morning.

Free AI-powered recaps of Talking Drupal and your other favorite podcasts, delivered to your inbox.

Get Free Summaries →

Free forever for up to 3 podcasts. No credit card required.