- Declare compatibility with drupal/commerce ^3 (#3540169). This only relaxes the Composer constraint. The Commerce 3 port is the 8.x-3.x branch.
- Declare compatibility with Drupal 11 (#3429423).
- Refactor webhooks so gate configuration is no longer required (#3378753).
- Support tokens with no expiration date (#3494324).
- Reorder payment methods in the backend.
- Bugfixes.
One new capability, for a kind of traffic no rule could describe before.
## Capping facet crawling
Bots walk a search or listing page through every combination of facets —
`?f[0]=type:article&f[1]=tag:a&f[2]=tag:b&f[3]=year:2026` — and each combination
is an uncacheable faceted search. People rarely apply more than two or three.
One new capability, for a kind of traffic no rule could describe before.
## Capping facet crawling
Bots walk a search or listing page through every combination of facets —
`?f[0]=type:article&f[1]=tag:a&f[2]=tag:b&f[3]=year:2026` — and each combination
is an uncacheable faceted search. People rarely apply more than two or three.
First beta of Advanced Comment Threads: threaded Drupal discussions with
progressive loading, inline replies, unread navigation, filtering, reader
preferences, and optional live refresh. Available as a comment field formatter
(including Layout Builder) and optional Canvas components.
### Changed
- https://www.drupal.org/project/file_gate/issues/3627119: Support the base module on Drupal 10.6/PHP 8.2 and Drupal 11.3/PHP 8.3. Older core uses a revision-aware file-reference backport; Drupal 11.4 retains the native resolver. Historical references, field authorization, download refusal and runtime security findings retain their existing rules. Optional submodule requirements remain unchanged.
- Documentation-only changes skip the full CI matrix. A change to the workflow file still runs the full matrix.
- The README install constraint is `drupal/postmark_webhooks:^1.2`.
### Fixed
- The dashboard's single "Keyed vs unkeyed" chart no longer fills the page. The chart grid uses fixed-width tracks, the Charts API element sets a 200px height, and canvas and SVG charts are capped at 200px tall.
Beta11 is about trust at the boundary: a declared access gate that runs before any caller input is processed, wire output that matches the advertised schema byte for byte, and messages that read the same whether a person or a model receives them.
The first stable release of File (Field) Paths for Drupal 10 and 11, with security advisory coverage. It requires Drupal 10.3 or 11 and PHP 8.2, and carries the three fixes made since 8.x-1.0-rc2: an image widget that showed the wrong thumbnail when two uploads shared a name, a redirect created on every new upload, and the PHP 8.2 minimum that rc2 needed but did not declare. Sites on PHP 8.1 should pin 8.x-1.0-rc1.
**Upgrade promptly if you use challenge rules.** This release raises the
required library version to pick up a security fix.
## The required kanopi/firewall version is now ^2.35.1
kanopi/firewall 2.35.1 fixes an open redirect on challenge solve. A redirect
target containing a raw tab could become `//evil.example` — a browser drops the
tab while working out the host, and PHP's own header check refuses carriage
return and newline but not tab. A visitor who solved a challenge could be sent
off-site.
**Upgrade promptly if you use challenge rules.** This release raises the
required library version to pick up a security fix.
## The required kanopi/firewall version is now ^2.35.1
kanopi/firewall 2.35.1 fixes an open redirect on challenge solve. A redirect
target containing a raw tab could become `//evil.example` — a browser drops the
tab while working out the host, and PHP's own header check refuses carriage
return and newline but not tab. A visitor who solved a challenge could be sent
off-site.
Updating from 1.0.0-alpha10 takes two steps, both straight away. Rebuild the cache (drush cr), because several services changed their constructor arguments and one was renamed, so the site fails until the container is rebuilt. Then install the new first_warned_at field on subject keys, which has no update hook since pdv has no beta release yet:
An update from 1.0.0-alpha13 or earlier needs a reinstall, and the audit data does not survive it. Five columns change size, and every existing secret carries an id this release no longer accepts for its bytes (see below).
This is a minor update to the memcache module, fixing all known bugs and introducing a few new features! This is the last version that will support Drupal 9.5, the next release will introduce Drupal 12 compatibility and drop support lower than 10.3.