-
Notifications
You must be signed in to change notification settings - Fork 239
Open
Description
Drupal.conf should be updated to block access to Markdown (.md) and YAML (.yml) files by default. With many modules transitioning to README.md etc instead of README.txt, this change is important for security. Tools like Droopescan can automatically search a site for exposed files to discover which modules are enabled.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels