feat: #3614681 Add Varbase Patches to the composer requirements
Issue: https://www.drupal.org/project/horizonaid/issues/3614681
What changed
Adds one Composer requirement to the Horizon Aid recipe:
"vardot/varbase-patches": "~11.0.0"Why
scripts/drupal-cms-wiring.php, scripts/assets/drupal-cms.composer.json, scripts/assets/drupal-libraries.package.json and scripts/README.md already shipped in 1.0.0-alpha1, and the wiring script writes the patch allowlist that permits vardot/varbase-patches and vardot/drupal-core-patches to apply their patches. The allowlist only permits those patches, it does not pull the package in, and nothing else in the dependency chain required it — so a project that installed the recipe from the released tag never pulled Varbase Patches, and the curated Drupal core patches the template relies on (notably the fix for #2741429, without which the Drupal CMS install dies in drupal_cms_search display cloning) were absent.
~11.0.0 matches the constraint the two sibling site templates carry: Varbase Starter (#3614678, MR !14 (merged)) and Educare (#3614680). Horizon Aid 1.0.0-alpha1 shipped with no x-dev pins, and vardot/varbase-patches publishes stable releases (latest 11.0.38), so a caret-free tilde constraint resolves without a pre-release floor.
Inserted in the existing alphabetical order (it sorts after every drupal/* entry). composer validate --no-check-all --no-check-publish passes on the result.
AI-Generated: Yes
Checkpoints:
- File an issue
- Addition/Change/Update/Fix
- Testing to ensure no regression
- Automated unit testing coverage
- Automated functional testing coverage
- UX/UI designer responsibilities
- Readability
- Accessibility
- Performance
- Security
- Developer Documentation
- User Guide Documentation
- Reviewed by human
- Code review by maintainers
- Full testing and approval
- Credit contributors
- Review with the product owner
- Release notes snippet
- Release