task: #3624092 Update composer.lock and patches.lock.json for Drupal core 11.4.7
Update the locks of Varbase Project 11.0.x to Drupal core 11.4.7, for the 11.0.9 release, on issue #3624092.
What this changes
composer.json:versionfrom11.0.x-devto11.0.9, andvardot/varbase+vardot/varbase-patchesfrom11.0.x-devto the released~11.0.0constraints.composer.lockregenerated in DDEV against thatcomposer.jsonand committed, so the tag installs from the lock with no solve.patches.lock.jsonregenerated alongside it.CHANGELOG.md:11.0.9section.README.md: version badge to11.0.9.
Dependency moves since 11.0.8
| Package | 11.0.8 | 11.0.9 |
|---|---|---|
drupal/core |
11.4.6 | 11.4.7 (SA-CORE-2026-013) |
vardot/varbase-patches |
11.0.43 | 11.0.46 |
vardot/drupal-core-patches |
11.4.0.6 | 11.4.0.7 |
drupal/vartheme_bs5 |
5.0.2 | 5.0.3 |
drupal/varbase_webform_base |
1.0.0 | 1.0.2 |
drupal/canvas_override |
1.0.0 | 1.0.1 |
drupal/ai |
1.4.8 | 1.4.9 |
drupal/eca |
3.1.7 | 3.1.8 |
drupal/entity_usage |
2.2.0 | 2.3.0 |
drupal/schemata |
1.0.0 | 1.1.0 |
Plus patch-level moves in the drupal/core-* companions, symfony/* 7.4.19, ckeditor5_plugin_pack, ckeditor5_premium_features, config_language_lock, modeler_api, tagify, htmlpurifier, oauth2-client, php-parser and openai-php/client. vardot/varbase stays at 11.0.0. 406 packages, unchanged in count.
Patches
patches.lock.json goes from 68 patches on 36 packages to 66 on 34.
- Added: the Drupal core patch for #3622837 (MR !17111), from
vardot/drupal-core-patches11.4.0.7. - Dropped:
drupal/canvas#3567225,drupal/schemata#3523349 andneilime/php-css-lint#3498301, no longer carried byvardot/varbase-patches11.0.46.
Testing notes
Verified:
ddev composer update -Wexits 0 with exit-on-patch-failure on.- A clean
ddev composer installfrom the committed lock exits 0, with every patch applied. composer validatepasses.
CI on this merge request is green. Pipeline 965808 passed all 33 of its jobs, none of them allowed to fail: composer, Cspell, YAML lint, ESLint, Stylelint, PHPCS, PHPStan, 📦 Install Varbase, 📖 Storybook build and the full 24-job varbase-e2e matrix, from 01-website-base-requirements through 17-search, including 09-drupal-canvas, 13-varbase-recipes, 14-ai and 15-quality.
That matrix installs Varbase from this lock and drives the result in a real browser, so the install and the browser run are covered by CI rather than by a manual run. The earlier caveat about no browser install no longer stands.
Still not covered:
- No PHPUnit job runs in this pipeline, so this change has no unit-test evidence behind it.
AI-Generated: Yes
Checkpoints:
- File an issue
- Addition/Change/Update/Fix
- Testing to ensure no regression
- Automated unit testing coverage
- Automated functional testing coverage
- UX/UI designer responsibilities
- Readability
- Accessibility
- Performance
- Security
- Developer Documentation
- User Guide Documentation
- Reviewed by human
- Code review by maintainers
- Full testing and approval
- Credit contributors
- Review with the product owner
- Release notes snippet
- Release