Saltar al contenido
PodcastsTecnologíaTalking Drupal

Talking Drupal

Talking Drupal Hosts
Talking Drupal
Último episodio

595 episodios

  • Talking Drupal

    Talking Drupal #571 - GovHub

    24/09/2026 | 1 h 5 min
    Today we are talking about GovHub, Drupal in Government, and Why Governments Love Drupal with guest Jasmyne Epps. We'll also cover Convivial Gov Site Template as our module of the week.
    For show notes visit:
    https://www.talkingDrupal.com/571
    Topics
    GovHub Origins and Goals
    Feature Requests and Governance
    Why Government Chooses Drupal
    Team Structure and Release Cadence
    Accessibility and Compliance Strategy
    Hosting Model and Multisite
    Structured Content and Microcontent
    Syndication and Emergency Alerts
    Orchard Design System Explained
    Training and Onboarding Editors
    Gov Talks Conference
    Logo Specs and Releases
    Ticket Prioritization PRICE
    QA Workflow with Tugboat
    Handling Traffic Spikes
    Drupal 11 Performance Talk
    Drupal 11 Upgrade Gotchas
    Getting Users Excited
    Translation Strategy Limits
    Why Government Loves Drupal
    Resources
    GovHub
    The Bug Stops Here — The State of Georgia Shifts Left (GovCon 2025 presentation with Jasmyne Epps and James Sansbury)
    Accelerating an ambitious migration and development project (GovHub + Tugboat migration story)
    Logo page
    Public facing knowledge base
    Orchard design system
    (P)Rice (P)olitics - (R)each - (I)mpact - (C)onfidence - (E)ffort

    Luma
    Guests
    Jasmyne Epps - jasmyneepps.com jasmyneepps
    Hosts
    Nic Laflin - nLighteneddevelopment.com nicxvan
    John Picozzi - epam.com johnpicozzi
    Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)
    MOTW
    Correspondent
    Martin Anderson-Clutz - mandclu.com mandclu
    Brief description: Have you ever wanted to stand up a polished, accessible government website in Drupal (with components, content types, SEO, and cookie consent all wired up) without writing any code? There's a site template for that.

    Module name/project name: Convivial Gov

    Brief history Created in March 2026 by Morpht, the shop behind the Convivial family — with Ivan Zugec leading the maintainer team.
    Versions available: 1.3.3, which works with Drupal 11

    Maintainership Actively maintained: release just last week, on September 16th
    Security coverage
    Test coverage: functional tests for install and validation, plus a kernel requirements test.
    Documentation there's a full handbook over at docs.morpht.com, and a live demo at gov.convivial.io
    Open issues: none?

    Site template features and usage Like the Haven site template we talked about a couple of weeks ago, Convivial Gov gives you a curated stack plus demo content, and in this case hands you a robust, ready-to-customize government site.
    Because it's built on Drupal CMS, you get all the latest Drupal tooling: Canvas for visual page building, Single Directory Components, and Recipes.
    The front end is Morpht's Morphos theme, built on Tailwind and DaisyUI, so you get dark mode, multiple colour palettes, and a big library of editor-friendly components out of the box. It's worth mentioning that using the Morphos theme on a production site requires a paid license
    The provided components are sorted into six buckets: container, content, child, element, background, and behavior. They include fun ones like scroll reveal and a colour palette switching behavior
    The content model is broad. You get seven content types: Page, Section, Article, Publication, Resource, Topic, and Audience. And, they come with a stack of teaser and card view modes to display them.
    The whole point is no-code: a site builder can compose sophisticated pages in Canvas without ever touching a template.
    One thing to watch: the default timezone is Australia/Sydney out of the box
    It's also worth comparing Convivial Gov to another site template called Local. Both dropped in March 2026, both are Canvas-based Drupal CMS site templates for the public sector, and both lean on ECA for automation — so there's real common ground. The difference is scope and mechanism. Local, from Annertech, is narrowly purpose-built for local councils and community-service directories: it ships a specific service information architecture — Service and Service Landing content types — with ECA wired so section pages stay in sync when service pages get published or updated, taking its cues from the gov.uk design system. Convivial Gov goes the other way — it's design-system-led and general-purpose, a broad component library and content model meant for any government, agency, or marketing site rather than one particular workflow.
  • Talking Drupal

    Talking Drupal #570 - Laravel & Marketing PHP

    17/09/2026 | 1 h 13 min
    Today we are talking about Laravel, Marketing, and The PHP Foundation with guest Matt Stauffer. We'll also cover Formdazzle as our module of the week.
    For show notes visit:
    https://www.talkingDrupal.com/570
    Topics
    What Is Laravel
    Writing Laravel Books
    AI and Technical Writing
    Laravel Versus CMS
    Drupal as Framework
    Integrating Laravel and CMS
    Laravel and Symfony
    Marketing Modern PHP
    Laravel Community Marketing
    Jigsaw and Onramp
    Drupal Marketing Lessons
    Onboarding Focus in Laravel
    Laravel BDFL Changes
    Onboarding And Docs
    Drupal Framework Perception
    What PHP Foundation Does
    Marketing PHP Vs Laravel
    AI Answers And Positioning
    Cross Ecosystem Collaboration
    Resources
    Jigsaw
    Onramp
    Native php
    Alpine
    Tailwind
    Vue
    Laravel herd
    php.new
    Blog post on how to contribute to php
    Laracon talk
    Kent C. Dodds The Last Software Engineer (how in the AI era, we need to all become Product Engineers)
    Guests
    Matt Stauffer - mattstauffer.com
    Hosts
    Nic Laflin - nLighteneddevelopment.com nicxvan
    John Picozzi - epam.com johnpicozzi
    Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)
    MOTW
    Correspondent
    Bernardo Martinez - bernardm28
    Brief description: This week's module is Formdazzle, a developer tool that makes theming Drupal forms easier.
    Drupal's Form API is a powerful abstraction, but when you want to target one specific field, label, button, or form wrapper, the default Twig template suggestions can be limited.
    The module works by taking information Drupal already knows about the form, like the form ID, element type, and element name, and using that to generate more targeted Twig template suggestions.
    For example, in a Drupal View with exposed filters, you may want to style the Reset button differently from the Submit button. By default, Drupal renders both buttons through the same input–submit.html.twig template, which makes it difficult to customize them independently. This module lets you assign different templates to individual form buttons—such as Submit, Reset, or Filter—based on their action, type, and other properties.
    This module has no configuration. Just enable the module and it starts working and look at the twig debug comments including extra template suggestions.

    Module name/project name: formdazzle

    Brief history How old: created in 13 September 2019 by johnalbin
    Versions available: ^10.1 ^11 ^12

    Maintainership Actively maintained
    Last release was 1 September 2026, currently the module has two maintainers Stephen Mustgrave and John Albin.
    The module includes both test and security coverage.

    Usage stats: 3,956 according to drupal.org

    Module features and usage There's no configuration. Just enable the module and it starts working, including with Views exposed forms and Webform.
    Formdazzle automatically adds more specific theme suggestions based on the form ID, element type, and element name.
  • Talking Drupal

    Talking Drupal #569 - Site Templates

    10/09/2026 | 1 h 14 min
    On today's show we are talking about Site Templates, What they do, and How you can use them with guests Tim Lehnen & Adam Globus-Hoenich. We'll also cover Haven as our module of the week.
    For show notes visit:
    https://www.talkingDrupal.com/569
    Topics
    MOTW: Haven
    What Site Templates Are
    Canvas Components Included
    Promoting Templates Beyond Drupal
    Templates vs Distributions
    Who Benefits from Templates
    Template Types and Adoption
    Where to Find Templates
    Featured vs Installer List
    Free vs Paid Templates
    Recipes vs Templates
    Distributions and Themes
    Empowering Site Builders
    Exporting a Template
    Designing for Users
    Releases Without Upgrades
    Best Practices and AI
    How to Contribute
    Resources
    Webinar: Drupal Canvas and Agentic Content Management: What Enterprise Teams Need to Know
    Drupal Site Templates
    Tim's book - Fog & Fireflies
    Guests
    Tim Lehnen - @TimLehnen hestenet
    Adam Globus-Hoenich - @PhenaProxima phenaproxima
    Hosts
    Nic Laflin - nLighteneddevelopment.com nicxvan
    Stephen Cross - SecondSginalMedia.com [stephencross]](https://www.drupal.org/u/stephencross)
    Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)
    Module of the Week
    Correspondent
    Martin Anderson-Clutz - mandclu.com mandclu
    Haven - Site Template - Designed for non-profit sites, this template features a bright, warm design that can be adapted for many use cases. It comes pre-confifgured with blog, projects and people profiles, as well as newsletter signup, donation add-ons and more.
  • Talking Drupal

    Talking Drupal #568 - Off The Cuff #12

    03/09/2026 | 1 h 20 min
    Today we are talking about Drupal Performance, Rapid Development, and Drupal Canvas Maturity with our hosts. We'll also cover Microsoft 365 FullCalendar as our module of the week.
    For show notes visit:
    https://www.talkingDrupal.com/568
    Topics
    Deprecating Module Theme Files
    Migrating Hooks to Classes
    Why This Change Matters
    Drupal Performance Gains
    Performance Audits and Lighthouse
    Automating Checks and Spreadsheet Rant
    AI Spreadsheet Cautionary Tale
    Privacy Concerns with AI
    Freelancer Pressure
    Rapid Change Reality
    Canvas Release Risks
    Community Support Needed
    AI For Documentation
    Canvas Production Readiness
    Canvas Architecture Debate
    AI For Voting Research
    LLM Bias And Sources
    Resources
    Rebrickable
    Webpagetest
    Lighthouse
    Tugboat
    Drupal canvas
    Guests
    Martin Anderson-Clutz - mandclu.com mandclu
    Hosts
    Nic Laflin - nLighteneddevelopment.com nicxvan
    John Picozzi - epam.com johnpicozzi
    Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz)
    MOTW
    Correspondent
    Martin Anderson-Clutz - mandclu.com mandclu
    Brief description: Have you ever wanted your users' own Outlook calendars to show up right alongside your Drupal content in a calendar view? There's a module for that.

    Module name/project name: Microsoft 365 FullCalendar

    Brief history How old: created just last month, August 19 2026, by fabianderijk of Finalist
    Versions available: 1.0.0, which works with Drupal 11

    Maintainership Brand new — the first and only release is from last month, and the whole commit history is basically launch day
    Security coverage: brand new, so not yet
    Test coverage: yes, both unit tests and kernel tests
    Documentation: a genuinely thorough README — it walks through privacy, the config guard rails, and three different ways to customize event output
    Open issues: none yet, it's less than two weeks old

    Usage stats: Too new for a site count

    Module features and usage With this installed, it adds the signed-in user's Microsoft 365, or Outlook, calendar as an extra event source on a FullCalendar view — so their personal appointments sit right next to the Drupal content the view already renders
    It leans on the Microsoft 365 Connector module and its SSO submodule, plus the FullCalendar module. Each user must have signed in through Microsoft 365 SSO: anyone who hasn't just sees no events, which is a clean fallback
    It uses lazy loading, so it only fetches events in the date range the calendar is currently showing, not your whole calendar
    Privacy is baked in: anything marked private or confidential in Outlook is masked, so it shows up as just "Busy", with no title, location, or meeting link, unless the site builder deliberately turns masking off
    The response itself is per-user and marked private, no-store, so it never lands in a shared or CDN cache
    There's a clever server-side cache too: it stores the raw Graph response before masking, so a single fetch can serve several displays that each have different masking settings
    You get guard rails you can tune with Drush or an admin form: max events, max date range, cache lifetime, and a separate, shorter failure cache
    That failure cache is a nice touch — if there's no active Microsoft session, or Graph errors out, it caches the empty result briefly so a broken connection doesn't get re-polled on every single calendar click
    Under the hood it calls Graph's calendarView endpoint rather than /me/events, which means recurring meetings get expanded into their individual occurrences — exactly what a calendar grid needs
    Every event carries CSS classes for its status — busy, free, tentative, out-of-office, working elsewhere, cancelled — so you can style them however you want
    And if CSS isn't enough, there's a server-side alter hook and a JavaScript pre-build event for fully custom rendering. Nice detail: the hook is explicitly guarded so you can't use it to put back a title or location that masking just stripped out
    Clearly this will be more useful for edge cases, for example an intranet, but I think this is a really interesting example of the power of Drupal as an integration layer, or as some like to put it, the "glass" through which a user can interact with multiple systems
  • Talking Drupal

    Talking Drupal #567 - Common Vulnerabilities & Exposures

    27/08/2026 | 1 h 16 min
    Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We'll also cover Security Scanner as our module of the week.
    For show notes visit:
    https://www.talkingDrupal.com/567
    Topics
    What Are CVEs
    CVE Lifecycle and Disclosure
    AI Era Security Challenges
    What CVE Program Excludes
    Patch Fast Reality
    Global Security Signals
    CVE Timing Judgment
    KEV Flags Explained
    CVE Updates Link Rot
    Who Decides CVE
    Sneaky Patch Dangers
    ADP Program Fixes
    Small Team Triage
    Vulnerability Tsunami AI
    Autonomous Security Future
    Legal Pressure Budgets
    Resources
    Psalm PHP Static Analysis Tool
    SARIF format
    PHP ecosystem
    Council of roots
    How AI Broke Open Source Security: End-of-Life Software Is the Most Exposed
    CVE podcast
    Vulncon
    PSIRT
    Guests
    David Welch - github: dwelch2344 dwelch2344
    Hosts
    Nic Laflin - nLighteneddevelopment.com nicxvan
    John Picozzi - epam.com johnpicozzi
    JD Flynn - dorficus
    MOTW
    Correspondent
    Martin Anderson-Clutz - mandclu.com mandclu
    Brief description: Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that.

    Module name/project name: Security Scanner

    Brief history How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia
    Versions available: 1.0.0, which works with Drupal 10.3 and 11

    Maintainership Actively maintained — created and shipped its first stable this summer, with steady development right through late July
    Security coverage
    Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories
    Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG
    Number of open issues: 1 issue, not a bug

    Usage stats: 2 sites (it's brand new)

    Module features and usage Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review
    It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, missing CSRF tokens, unserialize() on untrusted data, hardcoded secrets
    Then there's an optional deep pass: with the Psalm static analysis scanning engine installed, it'll trace untrusted input across functions and files to catch cross-function issues. And it's honest about state — the report always says whether that deep pass ran, was skipped, or failed, so a failure never gets mistaken for a clean scan
    One nice detail under the hood: a tokenizer-backed "code map" that knows whether a match is real code, a comment, or a string — so it won't flag the word "unserialize" sitting in a doc comment. That kills the single biggest source of false positives
    The checks are regression-tested against real Drupal advisories (Drupalgeddon, Drupalgeddon2, the 2019 unserialize bug, etc) so a pattern that caused an actual CVE can't quietly come back in your custom code
    Output comes in three flavors: a readable table, JSON for CI and AI agents, and SARIF — which means findings show up as annotations right on your GitHub or GitLab merge-request diff instead of buried in a job log
    For adopting it on an existing codebase there's a baseline file — you fingerprint the findings you've reviewed, with a required reason on each, and they stop failing the build but never go invisible; every run still counts them
    It exits non-zero on error-level findings, so it drops straight into CI or a pre-commit hook
    And it's extensible — checks are Drupal plugins with a #[SecurityCheck] attribute, so any module can add its own or alter the ones that ship
    Big caveat, and the module says this itself: a finding means "review this," not "this is broken." Static analysis has false positives, and a clean scan doesn't prove the code is secure — access-control logic especially still needs human review
    I first heard about this module over beverages at Drupalcamp Asheville, so I know that this module was largely vibe-coded, after having an AI agent ingest every single Drupal security team CVE. So I like to think of this module as security pattern recognition tool, but of course it does even more
Más podcasts de Tecnología
Acerca de Talking Drupal
Talking Drupal is a weekly chat about web design and development by a group of people with one thing in common: We Love Drupal. With hosts John Picozzi, Nic Laflin, and Martin Anderson-Clutz
Sitio web del podcast

Escucha Talking Drupal, Desde el reloj y muchos más podcasts de todo el mundo con la aplicación de radio.es

Descarga la app gratuita: radio.es

  • Añadir radios y podcasts a favoritos
  • Transmisión por Wi-Fi y Bluetooth
  • Carplay & Android Auto compatible
  • Muchas otras funciones de la app