ci: #3625828 Keep the CI build below Twig 3.30
Issue: https://www.drupal.org/i/3625828
Changes
varbase-e2e-test went red on 1.0.x (https://git.drupalcode.org/project/admin_audit_trail/-/pipelines/976774) because Composer picked up Twig 3.30.0, released minutes before, and nothing else changed. Twig 3.30.0 compiles core's drupal_escape filter into a direct runtime call, so every page render fails:
TypeError: Twig\Runtime\EscaperRuntime::escape(): Argument #4 ($autoescape) must be of type bool, null given
This adds twig/twig:<3.30 to the CI composer build only, via .composer-base, and the same constraint to .gitlab-ci-local.yml. The module's composer.json is untouched. Remove it once a fixed Twig is out. The yarn.lock change (!52 (merged)) was not the cause: the 500 happens before Node is installed.
Testing
gitlab-ci-local, drupalci PHP 8.3 Apache image, templates build scripts: 1.0.x fails 58/58 scenarios, this branch passes 58/58 on core 11.4.6 and 11.4.7. The slim .gitlab-ci-local.yml passes too. Swapping only Twig 3.29.0 and 3.30.0 on one site flips /user/login between 200 and 500.
AI-Generated: Yes
Checkpoints:
- File an issue
- Addition/Change/Update/Fix
- Testing to ensure no regression
- Automated unit testing coverage
- Automated functional testing coverage
- UX/UI designer responsibilities
- Readability
- Accessibility
- Performance
- Security
- Developer Documentation
- User Guide Documentation
- Reviewed by human
- Code review by maintainers
- Full testing and approval
- Credit contributors
- Review with the product owner
- Release notes snippet
- Release