<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>security</title><description/><link>https://kevinquillen.com</link><language>en</language><item><title>Keep Secrets secure outside of configuration in Drupal with the Key module</title><link>https://kevinquillen.com/keep-secrets-secure-outside-configuration-drupal-key-module</link><guid isPermaLink="false">375 at https://kevinquillen.com</guid><description>
&lt;span property=&quot;schema:name&quot;&gt;Keep Secrets secure outside of configuration in Drupal with the Key module&lt;/span&gt;

            &lt;div property=&quot;schema:text&quot; class=&quot;text-content clearfix field field--name-body field--type-text-with-summary field--label-hidden field__item&quot;&gt;&lt;p&gt;Security is a paramount feature of any modern CMS. Drupal has a well defined authentication and &lt;a href=&quot;https://en.wikipedia.org/wiki/Role-based_access_control&quot;&gt;RBAC (role based access control)&lt;/a&gt; system limiting the scope of what users can or cannot do. Soon we will even have &lt;a href=&quot;https://www.drupal.org/project/drupal/issues/3371246&quot;&gt;PBAC (policy based access control)&lt;/a&gt; in Drupal core. But what about securing other things, like API tokens, SSL certificates or secrets that are used to authenticate with external services that enable features that require authorization?&lt;/p&gt;&lt;/div&gt;
      
&lt;span rel=&quot;schema:author&quot;&gt;&lt;span lang about=&quot;https://kevinquillen.com/user/1&quot; typeof=&quot;schema:Person&quot; property=&quot;schema:name&quot; datatype&gt;Kevin&lt;/span&gt;&lt;/span&gt;

&lt;span property=&quot;schema:dateCreated&quot; content=&quot;2023-11-09T18:29:47+00:00&quot;&gt;&lt;time datetime=&quot;2023-11-09T13:29:47-05:00&quot; title=&quot;Thursday, November 9, 2023 - 13:29&quot;&gt;November 9th, 2023&lt;/time&gt;
&lt;/span&gt;
</description><pubDate>Thu, 09 Nov 2023 18:29:47 GMT</pubDate><dc:creator>Kevin</dc:creator></item><item><title>Automatically update Drupal core, Drupal modules, and Docker images with Renovate</title><link>https://kevinquillen.com/automatically-update-drupal-core-drupal-modules-and-docker-images-renovate</link><guid isPermaLink="false">361 at https://kevinquillen.com</guid><description>
&lt;span property=&quot;schema:name&quot;&gt;Automatically update Drupal core, Drupal modules, and Docker images with Renovate&lt;/span&gt;

            &lt;div property=&quot;schema:text&quot; class=&quot;text-content clearfix field field--name-body field--type-text-with-summary field--label-hidden field__item&quot;&gt;&lt;p&gt;As promised in the last post, &lt;a href=&quot;//www.velir.com/ideas/2022/10/20/how-to-automate-dependency-updates-with-renovate&quot;&gt;here is a new article&lt;/a&gt; over on the Velir blog. It is an in-depth introduction to using &lt;a href=&quot;https://github.com/renovatebot/renovate&quot;&gt;Renovate&lt;/a&gt;&amp;nbsp;to keep your projects updated automatically and stay ahead of security issues - no matter if you are using Drupal, PHP, Go, NPM, Docker, Ruby or Rust (and many more).&lt;/p&gt;&lt;/div&gt;
      
&lt;span rel=&quot;schema:author&quot;&gt;&lt;span lang about=&quot;https://kevinquillen.com/user/1&quot; typeof=&quot;schema:Person&quot; property=&quot;schema:name&quot; datatype&gt;Kevin&lt;/span&gt;&lt;/span&gt;

&lt;span property=&quot;schema:dateCreated&quot; content=&quot;2022-10-21T12:01:30+00:00&quot;&gt;&lt;time datetime=&quot;2022-10-21T08:01:30-04:00&quot; title=&quot;Friday, October 21, 2022 - 08:01&quot;&gt;October 21st, 2022&lt;/time&gt;
&lt;/span&gt;
</description><pubDate>Fri, 21 Oct 2022 12:01:30 GMT</pubDate><dc:creator>Kevin</dc:creator></item></channel></rss>