Talking Drupal

Talking Drupal Hosts

Talking Drupal is a weekly chat about web design and development by a group of people with one thing in common: We Love Drupal. With hosts John Picozzi, Nic Laflin, and Martin Anderson-Clutz

  1. 5d ago

    Talking Drupal #572 - The PHP Foundation

    Today we are talking about PHP, Open Source, and Sustainability with guest Elizabeth Barron. We'll also cover AI Image Classification as our module of the week. For show notes visit: https://www.talkingDrupal.com/572 Topics What is the PHP Foundation Language Health Challenges Paid Core Developers Release Infrastructure Foundation Role and Perception Docs and Onboarding Elizabeth Open Source Journey Future of PHP Ecosystem Listener Elephant Question Ecosystem Security Hub Advisory Board Limits Modernizing Mailing Lists Foundation Awareness Push PHP Ambassadors Strategy State of PHP Survey Five Year Vision Community Hour Podcast php.net Design Refresh Resources The PHP Foundation Derek Rethans xdebug Infrastructure https://github.com/derickr Drupal advocacy Link to community hour podcast Php 8.5 Contribute to php article Guests Elizabeth Barron - thephp.foundation elizabethbarron Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Tim Sharp - tea-sharp MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted the images in your Drupal media library to be automatically given alt text, a rich description, and a set of tags, using AI? There's a recipe for that. Module name/project name: AI Image Classification Brief history How old: created in Sep 2025 by Artem Dmitriiev (a.dmitriiev) of 1xINTERNET Versions available: 1.1.1, which requires Drupal 11.2 or newer Maintainership Actively maintained, latest release and commit just two weeks ago Security coverage Number of open issues: 9 open issues, 4 of which are bugs Usage stats: No usage data reported Module features and usage This recipe applies core's image media type recipe, then adds a description field and a tags field to image media, with tags in a new "Image Classification" vocabulary Editors get a "Generate Alt Text" button right on the image field, using the Field Widget Actions module, with a prompt written like an accessibility expert: under 100 characters, no "image of", flag logos and graphics On save, a vision model writes a description of up to eight sentences: colours, photo versus illustration, people, mood, and key objects, using the media name for context Tagging is chained off that description rather than the image itself, picking or creating up to five short, general terms, and reusing similar existing tags where it can It also adds bulk actions to the media admin view, so you can run description and tagging across an existing library, not just new uploads Description and tag filters are added to the media library, including the widget, so editors can search for "sunny summer day" right in the image picker The stated bigger goal is making images discoverable by RAG and other AI search, so good descriptions become a foundation for future AI features. In fact, this recipe is a dependency for the Canvas AI Image Search recipe, which is still a work in progress Under the hood, images get scaled to 400px wide and converted to PNG before they're sent to the model, which keeps things faster and cheaper One caveat: your site needs an AI provider with a default "chat with image vision" model, and the recipe checks for that when it's applied Also worth a look: the description prompt asks the model to describe people's age, gender, and ethnicity, and even name them if it can, so you may want to review that prompt for your privacy policies, and adjust accordingly Like any recipe, it provides a robust starting point for some compelling features, and every prompt and setting can be tweaked after you apply it Lastly, I wanted to mention that in today's Driesnote in here in Rotterdam, Dries demoed being able to use MCP to search images on his own site. A recipe like this could help you make sure the images in your media library have sufficient metadata to make that work reliably

  2. Sep 24

    Talking Drupal #571 - GovHub

    Today we are talking about GovHub, Drupal in Government, and Why Governments Love Drupal with guest Jasmyne Epps. We'll also cover Convivial Gov Site Template as our module of the week. For show notes visit: https://www.talkingDrupal.com/571 Topics GovHub Origins and Goals Feature Requests and Governance Why Government Chooses Drupal Team Structure and Release Cadence Accessibility and Compliance Strategy Hosting Model and Multisite Structured Content and Microcontent Syndication and Emergency Alerts Orchard Design System Explained Training and Onboarding Editors Gov Talks Conference Logo Specs and Releases Ticket Prioritization PRICE QA Workflow with Tugboat Handling Traffic Spikes Drupal 11 Performance Talk Drupal 11 Upgrade Gotchas Getting Users Excited Translation Strategy Limits Why Government Loves Drupal Resources GovHub The Bug Stops Here — The State of Georgia Shifts Left (GovCon 2025 presentation with Jasmyne Epps and James Sansbury) Accelerating an ambitious migration and development project (GovHub + Tugboat migration story) Logo page Public facing knowledge base Orchard design system (P)Rice (P)olitics - (R)each - (I)mpact - (C)onfidence - (E)ffort Luma Guests Jasmyne Epps - jasmyneepps.com jasmyneepps Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz) MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted to stand up a polished, accessible government website in Drupal (with components, content types, SEO, and cookie consent all wired up) without writing any code? There's a site template for that. Module name/project name: Convivial Gov Brief history Created in March 2026 by Morpht, the shop behind the Convivial family — with Ivan Zugec leading the maintainer team. Versions available: 1.3.3, which works with Drupal 11 Maintainership Actively maintained: release just last week, on September 16th Security coverage Test coverage: functional tests for install and validation, plus a kernel requirements test. Documentation there's a full handbook over at docs.morpht.com, and a live demo at gov.convivial.io Open issues: none? Site template features and usage Like the Haven site template we talked about a couple of weeks ago, Convivial Gov gives you a curated stack plus demo content, and in this case hands you a robust, ready-to-customize government site. Because it's built on Drupal CMS, you get all the latest Drupal tooling: Canvas for visual page building, Single Directory Components, and Recipes. The front end is Morpht's Morphos theme, built on Tailwind and DaisyUI, so you get dark mode, multiple colour palettes, and a big library of editor-friendly components out of the box. It's worth mentioning that using the Morphos theme on a production site requires a paid license The provided components are sorted into six buckets: container, content, child, element, background, and behavior. They include fun ones like scroll reveal and a colour palette switching behavior The content model is broad. You get seven content types: Page, Section, Article, Publication, Resource, Topic, and Audience. And, they come with a stack of teaser and card view modes to display them. The whole point is no-code: a site builder can compose sophisticated pages in Canvas without ever touching a template. One thing to watch: the default timezone is Australia/Sydney out of the box It's also worth comparing Convivial Gov to another site template called Local. Both dropped in March 2026, both are Canvas-based Drupal CMS site templates for the public sector, and both lean on ECA for automation — so there's real common ground. The difference is scope and mechanism. Local, from Annertech, is narrowly purpose-built for local councils and community-service directories: it ships a specific service information architecture — Service and Service Landing content types — with ECA wired so section pages stay in sync when service pages get published or updated, taking its cues from the gov.uk design system. Convivial Gov goes the other way — it's design-system-led and general-purpose, a broad component library and content model meant for any government, agency, or marketing site rather than one particular workflow.

  3. Sep 17

    Talking Drupal #570 - Laravel & Marketing PHP

    Today we are talking about Laravel, Marketing, and The PHP Foundation with guest Matt Stauffer. We'll also cover Formdazzle as our module of the week. For show notes visit: https://www.talkingDrupal.com/570 Topics What Is Laravel Writing Laravel Books AI and Technical Writing Laravel Versus CMS Drupal as Framework Integrating Laravel and CMS Laravel and Symfony Marketing Modern PHP Laravel Community Marketing Jigsaw and Onramp Drupal Marketing Lessons Onboarding Focus in Laravel Laravel BDFL Changes Onboarding And Docs Drupal Framework Perception What PHP Foundation Does Marketing PHP Vs Laravel AI Answers And Positioning Cross Ecosystem Collaboration Resources Jigsaw Onramp Native php Alpine Tailwind Vue Laravel herd php.new Blog post on how to contribute to php Laracon talk Kent C. Dodds The Last Software Engineer (how in the AI era, we need to all become Product Engineers) Guests Matt Stauffer - mattstauffer.com Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz) MOTW Correspondent Bernardo Martinez - bernardm28 Brief description: This week's module is Formdazzle, a developer tool that makes theming Drupal forms easier. Drupal's Form API is a powerful abstraction, but when you want to target one specific field, label, button, or form wrapper, the default Twig template suggestions can be limited. The module works by taking information Drupal already knows about the form, like the form ID, element type, and element name, and using that to generate more targeted Twig template suggestions. For example, in a Drupal View with exposed filters, you may want to style the Reset button differently from the Submit button. By default, Drupal renders both buttons through the same input–submit.html.twig template, which makes it difficult to customize them independently. This module lets you assign different templates to individual form buttons—such as Submit, Reset, or Filter—based on their action, type, and other properties. This module has no configuration. Just enable the module and it starts working and look at the twig debug comments including extra template suggestions. Module name/project name: formdazzle Brief history How old: created in 13 September 2019 by johnalbin Versions available: ^10.1 ^11 ^12 Maintainership Actively maintained Last release was 1 September 2026, currently the module has two maintainers Stephen Mustgrave and John Albin. The module includes both test and security coverage. Usage stats: 3,956 according to drupal.org Module features and usage There's no configuration. Just enable the module and it starts working, including with Views exposed forms and Webform. Formdazzle automatically adds more specific theme suggestions based on the form ID, element type, and element name.

  4. Sep 10

    Talking Drupal #569 - Site Templates

    On today's show we are talking about Site Templates, What they do, and How you can use them with guests Tim Lehnen & Adam Globus-Hoenich. We'll also cover Haven as our module of the week. For show notes visit: https://www.talkingDrupal.com/569 Topics MOTW: Haven What Site Templates Are Canvas Components Included Promoting Templates Beyond Drupal Templates vs Distributions Who Benefits from Templates Template Types and Adoption Where to Find Templates Featured vs Installer List Free vs Paid Templates Recipes vs Templates Distributions and Themes Empowering Site Builders Exporting a Template Designing for Users Releases Without Upgrades Best Practices and AI How to Contribute Resources Webinar: Drupal Canvas and Agentic Content Management: What Enterprise Teams Need to Know Drupal Site Templates Tim's book - Fog & Fireflies Guests Tim Lehnen - @TimLehnen hestenet Adam Globus-Hoenich - @PhenaProxima phenaproxima Hosts Nic Laflin - nLighteneddevelopment.com nicxvan Stephen Cross - SecondSginalMedia.com [stephencross]](https://www.drupal.org/u/stephencross) Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz) Module of the Week Correspondent Martin Anderson-Clutz - mandclu.com mandclu Haven - Site Template - Designed for non-profit sites, this template features a bright, warm design that can be adapted for many use cases. It comes pre-confifgured with blog, projects and people profiles, as well as newsletter signup, donation add-ons and more.

  5. Sep 3

    Talking Drupal #568 - Off The Cuff #12

    Today we are talking about Drupal Performance, Rapid Development, and Drupal Canvas Maturity with our hosts. We'll also cover Microsoft 365 FullCalendar as our module of the week. For show notes visit: https://www.talkingDrupal.com/568 Topics Deprecating Module Theme Files Migrating Hooks to Classes Why This Change Matters Drupal Performance Gains Performance Audits and Lighthouse Automating Checks and Spreadsheet Rant AI Spreadsheet Cautionary Tale Privacy Concerns with AI Freelancer Pressure Rapid Change Reality Canvas Release Risks Community Support Needed AI For Documentation Canvas Production Readiness Canvas Architecture Debate AI For Voting Research LLM Bias And Sources Resources Rebrickable Webpagetest Lighthouse Tugboat Drupal canvas Guests Martin Anderson-Clutz - mandclu.com mandclu Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi Amber Matz - tugboatqa.com [amber himes matz](https://www.drupal.org/u/amber himes matz) MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted your users' own Outlook calendars to show up right alongside your Drupal content in a calendar view? There's a module for that. Module name/project name: Microsoft 365 FullCalendar Brief history How old: created just last month, August 19 2026, by fabianderijk of Finalist Versions available: 1.0.0, which works with Drupal 11 Maintainership Brand new — the first and only release is from last month, and the whole commit history is basically launch day Security coverage: brand new, so not yet Test coverage: yes, both unit tests and kernel tests Documentation: a genuinely thorough README — it walks through privacy, the config guard rails, and three different ways to customize event output Open issues: none yet, it's less than two weeks old Usage stats: Too new for a site count Module features and usage With this installed, it adds the signed-in user's Microsoft 365, or Outlook, calendar as an extra event source on a FullCalendar view — so their personal appointments sit right next to the Drupal content the view already renders It leans on the Microsoft 365 Connector module and its SSO submodule, plus the FullCalendar module. Each user must have signed in through Microsoft 365 SSO: anyone who hasn't just sees no events, which is a clean fallback It uses lazy loading, so it only fetches events in the date range the calendar is currently showing, not your whole calendar Privacy is baked in: anything marked private or confidential in Outlook is masked, so it shows up as just "Busy", with no title, location, or meeting link, unless the site builder deliberately turns masking off The response itself is per-user and marked private, no-store, so it never lands in a shared or CDN cache There's a clever server-side cache too: it stores the raw Graph response before masking, so a single fetch can serve several displays that each have different masking settings You get guard rails you can tune with Drush or an admin form: max events, max date range, cache lifetime, and a separate, shorter failure cache That failure cache is a nice touch — if there's no active Microsoft session, or Graph errors out, it caches the empty result briefly so a broken connection doesn't get re-polled on every single calendar click Under the hood it calls Graph's calendarView endpoint rather than /me/events, which means recurring meetings get expanded into their individual occurrences — exactly what a calendar grid needs Every event carries CSS classes for its status — busy, free, tentative, out-of-office, working elsewhere, cancelled — so you can style them however you want And if CSS isn't enough, there's a server-side alter hook and a JavaScript pre-build event for fully custom rendering. Nice detail: the hook is explicitly guarded so you can't use it to put back a title or location that masking just stripped out Clearly this will be more useful for edge cases, for example an intranet, but I think this is a really interesting example of the power of Drupal as an integration layer, or as some like to put it, the "glass" through which a user can interact with multiple systems

  6. Aug 27

    Talking Drupal #567 - Common Vulnerabilities & Exposures

    Today we are talking about Security, Vulnerabilities, and how to avoid exposure with guest Dave Welch. We'll also cover Security Scanner as our module of the week. For show notes visit: https://www.talkingDrupal.com/567 Topics What Are CVEs CVE Lifecycle and Disclosure AI Era Security Challenges What CVE Program Excludes Patch Fast Reality Global Security Signals CVE Timing Judgment KEV Flags Explained CVE Updates Link Rot Who Decides CVE Sneaky Patch Dangers ADP Program Fixes Small Team Triage Vulnerability Tsunami AI Autonomous Security Future Legal Pressure Budgets Resources Psalm PHP Static Analysis Tool SARIF format PHP ecosystem Council of roots How AI Broke Open Source Security: End-of-Life Software Is the Most Exposed CVE podcast Vulncon PSIRT Guests David Welch - github: dwelch2344 dwelch2344 Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi JD Flynn - dorficus MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted a fast way to catch the security mistakes that slip into custom Drupal code — especially the code your AI assistant just wrote — before it ships? There's a module for that. Module name/project name: Security Scanner Brief history How old: created in July 2026 by Mayank Gupta (mayankguptadotcom) of Acquia Versions available: 1.0.0, which works with Drupal 10.3 and 11 Maintainership Actively maintained — created and shipped its first stable this summer, with steady development right through late July Security coverage Test coverage — and it's strong: unit and kernel tests, including a regression corpus built from real Drupal core advisories Documentation? In-depth README with a full check table and CI recipes, plus a CHANGELOG Number of open issues: 1 issue, not a bug Usage stats: 2 sites (it's brand new) Module features and usage Provide a Drush command, has no UI — you point drush security:scan at a module or any path, it reads the code statically, and prints a prioritized, OWASP-mapped list of things to review It's built for the age of AI-written code — the checks target the classes AI assistants keep reintroducing: routes with no access check, #markup and |raw XSS, missing CSRF tokens, unserialize() on untrusted data, hardcoded secrets Then there's an optional deep pass: with the Psalm static analysis scanning engine installed, it'll trace untrusted input across functions and files to catch cross-function issues. And it's honest about state — the report always says whether that deep pass ran, was skipped, or failed, so a failure never gets mistaken for a clean scan One nice detail under the hood: a tokenizer-backed "code map" that knows whether a match is real code, a comment, or a string — so it won't flag the word "unserialize" sitting in a doc comment. That kills the single biggest source of false positives The checks are regression-tested against real Drupal advisories (Drupalgeddon, Drupalgeddon2, the 2019 unserialize bug, etc) so a pattern that caused an actual CVE can't quietly come back in your custom code Output comes in three flavors: a readable table, JSON for CI and AI agents, and SARIF — which means findings show up as annotations right on your GitHub or GitLab merge-request diff instead of buried in a job log For adopting it on an existing codebase there's a baseline file — you fingerprint the findings you've reviewed, with a required reason on each, and they stop failing the build but never go invisible; every run still counts them It exits non-zero on error-level findings, so it drops straight into CI or a pre-commit hook And it's extensible — checks are Drupal plugins with a #[SecurityCheck] attribute, so any module can add its own or alter the ones that ship Big caveat, and the module says this itself: a finding means "review this," not "this is broken." Static analysis has false positives, and a clean scan doesn't prove the code is secure — access-control logic especially still needs human review I first heard about this module over beverages at Drupalcamp Asheville, so I know that this module was largely vibe-coded, after having an AI agent ingest every single Drupal security team CVE. So I like to think of this module as security pattern recognition tool, but of course it does even more

  7. Aug 20

    Talking Drupal #566 - DrupalEasy: Responsible Drupal AI

    Today we are talking about Drupal, AI, and learning to use it responsibly with guest Mike Anello. We'll also cover Entity Mesh as our module of the week. For show notes visit: https://www.talkingDrupal.com/566 Topics Course overview Fast moving modules Inside vs outside AI No code approach Keeping curriculum current Essentials vs add ons Chat Claude Code setup Inside vs Outside AI Rules and Provider Calls Guardrails in Drupal UI Model QA and Testing Local Models and Costs Token Budgets and Logging Course Use Cases Overview RAG and Vector Basics Class Schedule and Pricing AI Predictions and Wrap Resources New DrupalEasy class: Responsible Drupal AI Basics Training at orlando amazee ai Jrockowitz losing my skill AI module ecosystem AI browser provider (LLM in Google Chrome) amazee.ai Private AI Provider Derecho Guests Mike Anello - drupaleasy.com ultimike Hosts Nic Laflin - nLighteneddevelopment.com nicxvan John Picozzi - epam.com johnpicozzi JD Flynn - dorficus MOTW Correspondent Martin Anderson-Clutz - mandclu.com mandclu Brief description: Have you ever wanted a way to analyze and visualize the ways in which the content on your Drupal site is interlinked? There's a module for that. Module name/project name: Entity Mesh Brief history How old: created in Jan 2025 by Jorge Tutor (gedur) of Metadrop Versions available: 2.1.0 and 2.0.3, both of which work with Drupal 11 Maintainership Actively maintained, latest release last month, and a commit just yesterday Security coverage Test coverage Documentation? Project page is pretty descriptive Number of open issues: 13 open issues, 4 of which are bugs, but 2 of those were marked fixed in the past week Usage stats: 437 sites Module features and usage With Entity Mesh installed, the module will analyze the rendered output of your nodes using a chosen account, looking for links to other content That means it will find not just links in entity relationship fields, but also links within formatted text, menus, and more The results can be visualized in a D3.js 3D visualization, displayed as a table, or exported as a CSV The report also exposes a set of Views-style filters, to help you narrow down to the specific set of information you want to understand Entity Mesh analyzes the DOM of your rendered nodes, looking for links, iframes, and images. Internal paths are further analyzed and categorized, for example based on whether the specified path redirects, is broken, points to something that is access-denied, and so on From a marketing perspective, that allows you to understand the paths available to navigate from a source page to a target page, the content linked to or from a specific page, and will also augment the content deletion confirmation form to advise the user of any existing links to the content being deleted There are obvious SEO advantages to being able to find redirect chain, broken or access denied links, and there are GDPR compliance implications for being able to identify iframes that might load third-party cookies The project page also mentions that this module could be very useful to run after a content migration, for QA The actual analysis of your site content be triggered by drush, an admin form, or by cron, and you can set limits on the size of the batch to run, because of the weight it puts on your site by rendering every node it analyzes The current versions Entity Mesh also depend on the Entity Registry and Entity Render Context modules, that have essentially the same maintainers, so if there's only part of Entity Mesh that you really need, you could also give those a look Back in episode #321 we covered Entity Usage, and there are some definite similarities, but also some differences. While they both provide reporting on content relationships, Entity Usage does so by examining structured field values at save time. So, the information gathered is different, and collects data that can be displayed in views or custom code.

  8. Aug 13

    Talking Drupal #565 - That Geerling Guy

    Today we are talking about Open Source sustainability, becoming your own content creation machine, and how drupal influenced some of that with guest Jeff Geerling. We'll also cover AI Metering as our module of the week. For show notes visit: https://www.talkingDrupal.com/565 Topics Jeff's Timekeeping Icebreaker Jeff's Drupal Origin Story From Drupal to Hardware Tinkering Staying Motivated on YouTube What Conferences Are Really About DrupalCon Memories and Community Why Jeff Moved to Hugo PSA Tornado Warning Detour Keeping Up with Drupal CMS PHP Perception Shift Fast Drupal Setup COVID Streaming Boom Picking Video Projects Decommissioning Builds YouTube Algorithm Risk Vintage Time Server Creator Starter Tips Supporting Maintainers Books and Crohns Local Control Trends AI Workflow Boundaries Timing Obsession Kind Drupal Culture Guests Jeff Geerling - jeffgeerling.com geerlingguy Hosts Nic Laflin - nLighteneddevelopment.com nicxvan Mike Anello - drupaleasy.com ultimike JD Flynn - dorficus MOTW Correspondent Mike Anello - drupaleasy.com ultimike Brief description: AI Metering module - helps keep track of your users' AI token usage on the site. Includes cost estimation, token limits, and local LLM fallback options. Module name/project name: AI Metering Brief history How old: created in June 1 2026 by Jérôme Tchania (codeitwisely) Versions available: 1.0.1 Maintainership Actively maintained - yes Co-maintained by Carlos Ospina (camoa) Security coverage - yes Test coverage - yes Documentation - yes Number of open issues: 9 open issues, 4 of which are bugs against the current branch Usage stats: Sites: 78 Module features and usage Obtains token costs for all modules from LiteLLM Can be configured to send email when the token limit is being approached. Per user and per role reports. LLM fallback to Ollama

4.9
out of 5
28 Ratings

About

Talking Drupal is a weekly chat about web design and development by a group of people with one thing in common: We Love Drupal. With hosts John Picozzi, Nic Laflin, and Martin Anderson-Clutz

You Might Also Like