ci: #3625828 Keep the CI build below Twig 3.30

Issue: https://www.drupal.org/i/3625828

Changes

varbase-e2e-test went red on 1.0.x (https://git.drupalcode.org/project/admin_audit_trail/-/pipelines/976774) because Composer picked up Twig 3.30.0, released minutes before, and nothing else changed. Twig 3.30.0 compiles core's drupal_escape filter into a direct runtime call, so every page render fails:

TypeError: Twig\Runtime\EscaperRuntime::escape(): Argument #4 ($autoescape) must be of type bool, null given

This adds twig/twig:<3.30 to the CI composer build only, via .composer-base, and the same constraint to .gitlab-ci-local.yml. The module's composer.json is untouched. Remove it once a fixed Twig is out. The yarn.lock change (!52 (merged)) was not the cause: the 500 happens before Node is installed.

Testing

gitlab-ci-local, drupalci PHP 8.3 Apache image, templates build scripts: 1.0.x fails 58/58 scenarios, this branch passes 58/58 on core 11.4.6 and 11.4.7. The slim .gitlab-ci-local.yml passes too. Swapping only Twig 3.29.0 and 3.30.0 on one site flips /user/login between 200 and 500.

AI-Generated: Yes

Checkpoints:

  • File an issue
  • Addition/Change/Update/Fix
  • Testing to ensure no regression
  • Automated unit testing coverage
  • Automated functional testing coverage
  • UX/UI designer responsibilities
  • Readability
  • Accessibility
  • Performance
  • Security
  • Developer Documentation
  • User Guide Documentation
  • Reviewed by human
  • Code review by maintainers
  • Full testing and approval
  • Credit contributors
  • Review with the product owner
  • Release notes snippet
  • Release

🤖 Generated with Claude Code

Merge request reports

Loading
Loading