Release 10.6.15 from 2026-08-06 to today.
| Issue | Title | Category | Component | Version | Comments | Followers | Created |
|---|---|---|---|---|---|---|---|
| All issues opened and fixed during this release window | |||||||
| #3615396 | Update PHP_CodeSniffer to 3.13.6 | Task | composer | 10.6.x-dev | 16 | 4 | |
| #3615238 | Drupal core not updated to latest version | Support | composer | 10.6.x-dev | 12 | 3 | |
| All other issues fixed during this release window | |||||||
| #3614340 | Update to Twig 3.28 | Task | composer | 10.6.x-dev | 27 | 5 | |
| #3607797 | Potential XSS in block.admin.js | Bug | block.module | 10.6.x-dev | 15 | 6 | |
| #3605792 | SQL injection via unvalidated operator in case-insensitive entity query array conditions | Bug | postgresql db driver | 10.6.x-dev | 26 | 12 | |
| #3575821 | locale.check_translation route is not protected against CSRF | Bug | locale.module | 10.6.x-dev | 19 | 9 | |
| #3566351 | Throwing AccessDeniedException without a route causes PHP errors | Bug | base system | 10.6.x-dev | 32 | 9 | |
| #3380334 | user_update_10000 fails on role with no data | Bug | user.module | 10.6.x-dev | 20 | 10 | |