Problem/Motivation
vardot/varbase-patches is a Composer patch-applier plugin, not a Drupal recipe/module dependency. The Varbase Starter recipe ("type": "drupal-recipe") currently declares it in composer.json require ("vardot/varbase-patches": "~11.0.0"). That forces the plugin in as a recipe requirement before the project's config.allow-plugins and extra.composer-patches allowlist exist, and couples the site-template recipe to build-time patch tooling. The wiring script already owns the surrounding patch config (allow-plugins for cweagans/composer-patches + vardot/varbase-patches + oomphinc/composer-installers-extender, and the default-deny allowed-dependency-patches allowlist), so it should own the requirement itself. Keeping it in the recipe also means a bare composer require drupal/varbase_starter drags the plugin in before the wiring permits it.
Related: #3614678: Add Varbase Patches to the composer requirements and a Drupal CMS wiring script.
Steps to reproduce
- Inspect
composer.jsonof the varbase_starter recipe:"vardot/varbase-patches": "~11.0.0"sits among the Drupal recipe requirements. - Inspect
scripts/drupal-cms-wiring.php+scripts/assets/drupal-cms.composer.json: the allow-plugins and allowed-dependency-patches for varbase-patches are already wired there, andscripts/README.mdnotes "vardot/varbase-patches arrives as a requirement of this recipe, so it does not need requiring separately".
Proposed resolution
- Remove
"vardot/varbase-patches": "~11.0.0"fromcomposer.jsonrequire. - Add
vardot/varbase-patchesto the wiring assetscripts/assets/drupal-cms.composer.jsonso the wiring script writes the requirement into the project-rootcomposer.json(the plugin is then required at the project level, where allow-plugins + the patches allowlist already land). - Update
scripts/README.md: the "arrives as a requirement of this recipe" note and the require step, so it reflects the wiring-script-only ownership.
Remaining tasks
- ✅ File an issue
- ❌ Addition/Change/Update/Fix
- ❌ Testing to ensure no regression
- ➖ Automated unit/functional testing coverage
- ➖ Developer Documentation support
- ➖ User Guide Documentation support
- ➖ UX/UI designer responsibilities
- ➖ Accessibility and Readability
- ❌ Reviewed by a human
- ❌ Code review by maintainers
- ❌ Full testing and approval
- ❌ Credit contributors
- ❌ Review with the product owner
- ❌ Update Release Notes
- ❌ Release
User interface changes
- N/A
API changes
- N/A
Data model changes
- N/A
Release notes snippet
- Move vardot/varbase-patches out of the Varbase Starter recipe composer.json; the drupal-cms wiring script now owns the requirement alongside the allow-plugins and patches allowlist it already sets.
Issue fork varbase_starter-3618246
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #6
rajab natshahComment #7
rajab natshahComment #8
rajab natshahComment #9
rajab natshah