task: #3624092 Update composer.lock and patches.lock.json for Drupal core 11.4.7

Update the locks of Varbase Project 11.0.x to Drupal core 11.4.7, for the 11.0.9 release, on issue #3624092.

What this changes

  • composer.json: version from 11.0.x-dev to 11.0.9, and vardot/varbase + vardot/varbase-patches from 11.0.x-dev to the released ~11.0.0 constraints.
  • composer.lock regenerated in DDEV against that composer.json and committed, so the tag installs from the lock with no solve.
  • patches.lock.json regenerated alongside it.
  • CHANGELOG.md: 11.0.9 section.
  • README.md: version badge to 11.0.9.

Dependency moves since 11.0.8

Package 11.0.8 11.0.9
drupal/core 11.4.6 11.4.7 (SA-CORE-2026-013)
vardot/varbase-patches 11.0.43 11.0.46
vardot/drupal-core-patches 11.4.0.6 11.4.0.7
drupal/vartheme_bs5 5.0.2 5.0.3
drupal/varbase_webform_base 1.0.0 1.0.2
drupal/canvas_override 1.0.0 1.0.1
drupal/ai 1.4.8 1.4.9
drupal/eca 3.1.7 3.1.8
drupal/entity_usage 2.2.0 2.3.0
drupal/schemata 1.0.0 1.1.0

Plus patch-level moves in the drupal/core-* companions, symfony/* 7.4.19, ckeditor5_plugin_pack, ckeditor5_premium_features, config_language_lock, modeler_api, tagify, htmlpurifier, oauth2-client, php-parser and openai-php/client. vardot/varbase stays at 11.0.0. 406 packages, unchanged in count.

Patches

patches.lock.json goes from 68 patches on 36 packages to 66 on 34.

  • Added: the Drupal core patch for #3622837 (MR !17111), from vardot/drupal-core-patches 11.4.0.7.
  • Dropped: drupal/canvas #3567225, drupal/schemata #3523349 and neilime/php-css-lint #3498301, no longer carried by vardot/varbase-patches 11.0.46.

Testing notes

Verified:

  • ddev composer update -W exits 0 with exit-on-patch-failure on.
  • A clean ddev composer install from the committed lock exits 0, with every patch applied.
  • composer validate passes.

CI on this merge request is green. Pipeline 965808 passed all 33 of its jobs, none of them allowed to fail: composer, Cspell, YAML lint, ESLint, Stylelint, PHPCS, PHPStan, 📦 Install Varbase, 📖 Storybook build and the full 24-job varbase-e2e matrix, from 01-website-base-requirements through 17-search, including 09-drupal-canvas, 13-varbase-recipes, 14-ai and 15-quality.

That matrix installs Varbase from this lock and drives the result in a real browser, so the install and the browser run are covered by CI rather than by a manual run. The earlier caveat about no browser install no longer stands.

Still not covered:

  • No PHPUnit job runs in this pipeline, so this change has no unit-test evidence behind it.

AI-Generated: Yes

Checkpoints:

  • File an issue
  • Addition/Change/Update/Fix
  • Testing to ensure no regression
  • Automated unit testing coverage
  • Automated functional testing coverage
  • UX/UI designer responsibilities
  • Readability
  • Accessibility
  • Performance
  • Security
  • Developer Documentation
  • User Guide Documentation
  • Reviewed by human
  • Code review by maintainers
  • Full testing and approval
  • Credit contributors
  • Review with the product owner
  • Release notes snippet
  • Release

🤖 Generated with Claude Code

Edited by Rajab Natshah

Merge request reports

Loading
Loading