I see Security update related alerts on the Developer Portal and Pantheon. Thing is I applied all the updates available in Pantheon but I am still getting alerts for some modules.
I referred to following existing issues logged by other community user, but have further questions
https://community.apigee.com/questions/30224/developer-portal-updates.html
https://community.apigee.com/questions/22929/should-customers-using-pantheon-hosted-drupal-appl.html
The Developer portal shows updates for two modules in my case: Legal and Media. These modules are already present in both Profiles/ and Sites/ location. The Profiles/ location modules are getting updated (though not the July updates) but are not effective because they are being overridden by the Sites/ modules. I don’t believe we have added these modules to the Sites/ location. So, I have the following questions:
-
In case of Legal module, the version in Profiles/ matches the recommended version as per Security alert. So can I remove the module from Sites/ ?
-
In case of Media module, the version in Profiles/ folder is 7.x-2.8 (older) which is newer that Sites/ but older than the recommended version 7.x-2.9 per the Security alert. So, should I get the latest recommended version and place that in Sites/ folder?
In such case, how do we manage our long term approach because security vulnerabilities may us to place the modules in Sites/ folder and then these module may end up not getting updated through Pantheon because the Sites/ folder module is overriding the Profiles/ folder module.


