Security blocks on Twig versions for Drupal 9

Created on 20 December 2025, about 2 months ago

Problem/Motivation

The Composer (previous major) job in the d9-basic branch has just started to fail with security blocks in Drupal 9.5

Problem 1
    - Root composer.json requires drupal/core-recommended ^9.5 -> satisfiable by drupal/core-recommended[9.5.x-dev].
    - drupal/core-recommended 9.5.x-dev requires twig/twig ~v2.15.4 -> found twig/twig[v2.15.4, v2.15.5, v2.15.6] but these were not loaded, because they are affected by security advisories. To ignore the advisories, add ("PKSA-yhcn-xrg3-68b1", "PKSA-2wrf-1xmk-1pky", "PKSA-6319-ffpf-gx66") to the audit "ignore" config. To turn the feature off entirely, you can set "block-insecure" to false in your "audit" config.

This must be a relatively new discovery, because the scheduled pipeline on 17th December was OK
https://git.drupalcode.org/project/gitlab_templates_downstream/-/pipelin...

Steps to reproduce

Proposed resolution

Remaining tasks

📌 Task
Status

Active

Component

Composer

Created by

🇬🇧United Kingdom jonathan1055

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

  • Pipeline finished with Success
    about 1 month ago
    Total: 278s
    #696600
  • Pipeline finished with Success
    about 1 month ago
    Total: 289s
    #696607
  • Pipeline finished with Success
    about 1 month ago
    Total: 2462s
    #697508
  • Pipeline finished with Success
    about 1 month ago
    Total: 4878s
    #698172
  • Pipeline finished with Success
    about 1 month ago
    Total: 123s
    #699669
  • Pipeline finished with Failed
    28 days ago
    Total: 48s
    #703022
  • Pipeline finished with Success
    28 days ago
    Total: 51s
    #703025
  • Pipeline finished with Success
    28 days ago
    Total: 7891s
    #703030
  • Pipeline finished with Success
    28 days ago
    Total: 1281s
    #703221
  • Pipeline finished with Failed
    27 days ago
    Total: 7914s
    #703874
Production build 0.71.5 2024