What to expect from the review process

Last updated on
4 May 2025

First and foremost it is strongly recommended that you review other applications according to Review bonus.

Reviewers will basically follow the pattern described in Application checklist.

For detailed information on what to expect during the process, applicants are encouraged to read through the reviewer documentation section of this handbook. For the sake of convenience, the workflow steps are repeated below.

Application Workflow

  1. Applications are submitted to the Drupal.org security advisory coverage applications issue queue, complete with a link to the project which will contain the module or theme code.

  2. When the applicants have fully prepared the code and the supporting materials, they should change the status of the issue to Needs review.

  3. The project files will be then reviewed.

If any issue is found

  • The reviewers will leave a comment in the issue thread, identifying the issue (and preferably explaining what needs to be done to address it), and set the issue status to Needs work.
  • The applicants should make the appropriate changes to the project (or answer any questions that are asked) and change the issue status back to Needs review.
  • The reviewers will validate the changes/response and repeat the process if they identify any new issue and/or question.

Once there are no issues in the project's files

  • The reviewers will change the status of the issue to Reviewed & tested by the community.
  • After that, a project moderator will validate the review, granting the applicants the role to be able to opt projects into security advisory coverage, and changing the status of the application to Fixed. If new issues are identified, the status could be set back to Needs work.

Application Review Timelines

Unfortunately, the application queue does occasionally experience a large backlog, and applications may sit in the queue up to a year before getting reviewed. You can avoid that by taking part in the review bonus program. In the event that your application has held a status of needs review for a certain length of time, applicants or reviewers may elevate the priority of the application. Once a reviewer has responded according to Application workflow and the application review process proceeds the application priority should return to normal.

Help improve this page

Page status: No known problems

You can: