UT Drupal Kit 2.12.1 Security Release

ITS has posted a patch-level release of the UT Drupal Kit in order to address the critical security vulnerability in Drupal core announced on February 21, 2018 (View the complete security advisory on Drupal.org).

It is recommended that all users of the UT Drupal Kit update their sites with this latest version as soon as practicable.

How to Update the UT Drupal Kit

Complete instructions for updating a UT Drupal Kit site are available on the documentation wiki.

Please review the release notes thoroughly, and always make backups of your code, files, and database before proceeding with an update!

UT Drupal Kit 2.12 Release

ITS is happy to announce the immediate availability of UT Drupal Kit 2.12, the twelth maintenance release for our University distribution since the inclusion of the Forty Acres theme and the Page Builder module.

The 2.12 release includes two minor bug fixes and a change to the default site installtion behavior. There are no updates to Drupal core or contrib modules, or the “Page Builder” custom module.


PLEASE NOTE: The following issue does NOT apply to users of the packaged zip file version of the UT Drupal Kit, and is specific to users of the Pantheon upstream repository.

For users of the UT Drupal Kit upstream repository on Pantheon, the 2.11 release introduced an unintentional change within the profiles/utexas/themes/forty_acres/fonts and profiles/utexas/themes/forty_acres/src/fonts directories in which some font directory and filenames were all-lowercase and others were mixed-case. The intended change was for all of these directories and filenames to be all-lowercase.

This issue has been resolved in the 2.12 release, but developers with local clones of their Pantheon site repo should re-clone in order to ensure that their local version of the codebase is fixed. More details, including resolution steps, can be found in the special release notes for the 2.12 release.


With the change to the Libre Franklin sans-serif font in the 2.11 release, the required footer link for the UT Accessibility Policy started breaking onto a second line. This has been fixed in the latest version of the Forty Acres theme.


A recent phishing attempt against Drupal sites around the globe attempted to leverage the fact that the default username for the “superuser” or UID 1 user that is created during site installation is “admin” by sending password reset requests for the username “admin” to many sites.

No UT Drupal Kit sites were compromised as a result of this attempted exploit, but in order to provide an extra measure of protection against similar future attempts, we have updated the UT Drupal Kit installation profile with a custom value for the default username on the UID 1 account.

Site owners may still select a different value during or after installation as desired. Please note that this change does NOT affect existing sites. However, we do recommend changing the username of the UID 1 account to something other than “admin” on existing sites.

More details can be found in the special release notes for the 2.12 release.


Complete instructions and download links for updating a UT Drupal Kit site are available on the documentation wiki. Pantheon site dashboards that use the UT Drupal Kit distribution should see the upstream updates available now; see the Pantheon documentation for more information on applying upstream updates.

Please review the changelog and special release notes thoroughly, and always make backups of your code, files, and database before proceeding with an update!


The UT Drupal Kit is released on bi-monthly maintenance release schedule, with releases targeted for the second Tuesday of the month. The next planned release for this year is UT Drupal Kit 7.x-2.13, due on April 10, 2018.

If you have questions or concerns about the UT Drupal Kit, please feel free to email us at drupal-kit-support@utlists.utexas.edu.