Problem/Motivation

The two documented install paths for Varbase Starter install different versions of the same theme, and an accessibility fix released in that theme reaches only one of them.

Both paths were run verbatim from the commands published on the Varbase Starter project page, in a DDEV workspace, on 23 September 2026:

  • Drupal CMS base (ddev composer create-project drupal/cms, then ddev composer require drupal/varbase_starter): installs drupal/vartheme_bs5 5.0.4, indicator gap 1rem, the WCAG 2.5.8 fix is present.
  • Varbase project base (ddev composer create-project drupal/varbase_project:~11): installs drupal/vartheme_bs5 5.0.3, indicator gap 0.5rem, the WCAG 2.5.8 fix is absent.

Both resolve the same constraint, drupal/vartheme_bs5: ~5.0.0, which accepts 5.0.4. The difference is that varbase_project ships a committed composer.lock of 24523 lines, so composer create-project installs the locked 5.0.3 rather than resolving the range. The Drupal CMS path has no lock at that point, resolves the range, and gets 5.0.4.

Verified by reading the installed file in each build, web/themes/contrib/vartheme_bs5/components/organisms/hero-slider-container/hero-slider-container.css, the .carousel-indicators rule: gap: 1rem on the Drupal CMS path, gap: 0.5rem on the Varbase project path.

The fix in question is #3625192, released in vartheme_bs5 5.0.4. It makes the hero slider carousel indicators meet WCAG 2.2 Success Criterion 2.5.8 Target Size (Minimum) by spacing adjacent target centres at least 24 CSS px apart. On 5.0.3 they are 16 px apart and the criterion fails.

varbase_starter 1.0.3 has just been tagged and will hit the same split once packaged: the Drupal CMS path will pick it up, the Varbase project path will not until the lock is refreshed.

This is not a defect in the theme release, and not a defect in locking. Shipping a committed lock is a deliberate choice here: it makes installs deterministic and reproducible, which is the point of it. The gap is that the lock is not refreshed when a dependency releases a fix, so the Varbase install path silently trails the Drupal CMS one.

There is a policy question attached, and the answer is the maintainers' to make. The options worth naming:

  • Refresh the lock as part of each site-template or theme release the project depends on.
  • Refresh it on a schedule, accepting a known lag.
  • Do not ship a lock in the project template at all, accepting non-deterministic installs.

Steps to reproduce

  1. Build the Drupal CMS path: ddev composer create-project drupal/cms, then ddev composer require drupal/varbase_starter.
  2. Build the Varbase project path: ddev composer create-project drupal/varbase_project:~11.
  3. In each build, read the installed theme version: ddev composer show drupal/vartheme_bs5.
  4. In each build, open web/themes/contrib/vartheme_bs5/components/organisms/hero-slider-container/hero-slider-container.css and read the gap value on the .carousel-indicators rule.

Result: 5.0.4 with gap: 1rem on the first, 5.0.3 with gap: 0.5rem on the second.

Proposed resolution

Regenerate composer.lock and patches.lock.json in varbase_project through DDEV so the Varbase path picks up vartheme_bs5 5.0.4 and, once packaged, varbase_starter 1.0.3, then release.

11.0.8 was released today and its lock predates both, so a new release is needed for this to reach users.

Alongside that, decide which of the three refresh policies above the project follows, so the lag is a known quantity rather than a surprise.

Remaining tasks

  • ✅ File an issue
  • ✅ Addition/Change/Update/Fix
  • ✅ Testing to ensure no regression
  • ➖ Automated unit testing coverage
  • ➖ Automated functional testing coverage
  • ➖ UX/UI designer responsibilities
  • ➖ Readability
  • ❌ Accessibility
  • ➖ Performance
  • ➖ Security
  • ➖ Developer Documentation
  • ➖ User Guide Documentation
  • ❌ Reviewed by human
  • ❌ Code review by maintainers
  • ❌ Full testing and approval
  • ❌ Credit contributors
  • ❌ Review with the product owner
  • ✅ Release notes snippet
  • ✅ Release

User interface changes

  • None directly. Once the lock is refreshed, new Varbase project installs render the hero slider carousel indicators with the 5.0.4 spacing.

API changes

  • N/A

Data model changes

  • N/A

Release notes snippet

  • Refreshed the committed composer.lock and patches.lock.json so a new install picks up vartheme_bs5 5.0.5 and varbase_starter 1.0.4.

AI-Generated: Yes

Comments

rajab natshah created an issue. See original summary.

rajab natshah’s picture

Issue summary: View changes
Status: Active » Fixed
Issue tags: +varbase_project-11.0.10

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.