Problem/Motivation

vardot/varbase-patches is a Composer patch-applier plugin, not a Drupal recipe/module dependency. The Varbase Starter recipe ("type": "drupal-recipe") currently declares it in composer.json require ("vardot/varbase-patches": "~11.0.0"). That forces the plugin in as a recipe requirement before the project's config.allow-plugins and extra.composer-patches allowlist exist, and couples the site-template recipe to build-time patch tooling. The wiring script already owns the surrounding patch config (allow-plugins for cweagans/composer-patches + vardot/varbase-patches + oomphinc/composer-installers-extender, and the default-deny allowed-dependency-patches allowlist), so it should own the requirement itself. Keeping it in the recipe also means a bare composer require drupal/varbase_starter drags the plugin in before the wiring permits it.

Related: #3614678: Add Varbase Patches to the composer requirements and a Drupal CMS wiring script.

Steps to reproduce

  1. Inspect composer.json of the varbase_starter recipe: "vardot/varbase-patches": "~11.0.0" sits among the Drupal recipe requirements.
  2. Inspect scripts/drupal-cms-wiring.php + scripts/assets/drupal-cms.composer.json: the allow-plugins and allowed-dependency-patches for varbase-patches are already wired there, and scripts/README.md notes "vardot/varbase-patches arrives as a requirement of this recipe, so it does not need requiring separately".

Proposed resolution

  1. Remove "vardot/varbase-patches": "~11.0.0" from composer.json require.
  2. Add vardot/varbase-patches to the wiring asset scripts/assets/drupal-cms.composer.json so the wiring script writes the requirement into the project-root composer.json (the plugin is then required at the project level, where allow-plugins + the patches allowlist already land).
  3. Update scripts/README.md: the "arrives as a requirement of this recipe" note and the require step, so it reflects the wiring-script-only ownership.

Remaining tasks

  • ✅ File an issue
  • ❌ Addition/Change/Update/Fix
  • ❌ Testing to ensure no regression
  • ➖ Automated unit/functional testing coverage
  • ➖ Developer Documentation support
  • ➖ User Guide Documentation support
  • ➖ UX/UI designer responsibilities
  • ➖ Accessibility and Readability
  • ❌ Reviewed by a human
  • ❌ Code review by maintainers
  • ❌ Full testing and approval
  • ❌ Credit contributors
  • ❌ Review with the product owner
  • ❌ Update Release Notes
  • ❌ Release

User interface changes

  • N/A

API changes

  • N/A

Data model changes

  • N/A

Release notes snippet

  • Move vardot/varbase-patches out of the Varbase Starter recipe composer.json; the drupal-cms wiring script now owns the requirement alongside the allow-plugins and patches allowlist it already sets.
Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

rajab natshah created an issue. See original summary.

  • rajab natshah committed 0311e8ec on 1.0.x
    refactor: #3618246 Move vardot/varbase-patches out of the recipe...

  • rajab natshah committed 4c3edfe2 on 1.0.x
    refactor: #3618246 Remove the Drupal CMS wiring script and inline the...
rajab natshah’s picture

Assigned: Unassigned » josebc
Status: Active » Needs review
rajab natshah’s picture

Title: refactor: Move vardot/varbase-patches out of the recipe composer.json to the wiring script only » refactor: Stop shipping vardot/varbase-patches and the Drupal CMS wiring script in the recipe (wire inline in CI)
rajab natshah’s picture

Assigned: josebc » Unassigned
rajab natshah’s picture

Status: Needs review » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.