Let's add a job that verifies the commited vendor/ directory (in mediawiki/vendor.git) matches what composer generates from scratch.
This will make commits much easier to verify and will catch any mistakes, undocumented patches or sloppy conflicts.
We'd take the proposed patch, remove composer's artefacts (*/, autoload.php), run composer install with the appropriate arguments (I think we use --optimize-autoloader), apply any patches (maybe from a patches/00*.diff pattern), and verify the git working copy is clean / same as it was.