Commit graph

54 commits

Author SHA1 Message Date
55a689b5c8
docs(agents): drop security review gates
Agents no longer treat a security review or a cross-family review as a merge gate.
2026-09-26 17:00:06 -04:00
Adam Moussa
3073c30922
chore(ci): remove unused Mergify stub (#44) 2026-09-22 18:41:31 +00:00
renovate[bot]
0d9d445141
chore(deps): update pip minor and patch (#43)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 16:15:20 +00:00
renovate[bot]
2dda1e09c3
chore(deps): update dependency httpx2 to v2.12.0 [security] (#40)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 17:00:48 +00:00
renovate[bot]
dd0364ccb3
chore(deps): update pip minor and patch (#41)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 16:58:26 +00:00
renovate[bot]
ec872a28a4
chore(deps): update sea-haven-industries/.github action to v1.0.11 (#42)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 16:46:03 +00:00
renovate[bot]
d549fe8619
chore(deps): update dependency httpx2 to v2.11.0 [security] (#39)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-09 18:47:25 +00:00
Adam Moussa
223ef4ae1f
chore(deps): remove dependabot version updates (#36)
Renovate is the version-update bot. GitHub Dependabot alerts stay.
2026-08-25 11:51:47 -04:00
Adam Moussa
f09fcfdedc
chore(ci): remove pr policy workflow caller (#35) 2026-08-24 15:12:19 -04:00
Adam Moussa
ad9c6bf421
chore(ci): switch auto-merge from seahaven-bot to Mergify (#34) 2026-08-24 13:53:32 -04:00
Adam Moussa
200848d2c3
ci: enable squash auto-merge on ready PRs (PLAT-108) (#32)
* ci: enable squash auto-merge on ready PRs

* fix(ci): serialize auto-merge enable and ignore already-enabled
2026-08-21 23:34:31 +00:00
Adam Moussa
e456800d19
ci: add merge_group trigger for required ci / ci (#31) 2026-08-21 17:42:16 -04:00
dependabot[bot]
6c9848bff9
chore(deps): bump httpx2 from 2.9.1 to 2.10.0 (#30)
Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.9.1 to 2.10.0.
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](https://github.com/pydantic/httpx2/compare/v2.9.1...v2.10.0)

---
updated-dependencies:
- dependency-name: httpx2
  dependency-version: 2.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 15:16:01 +00:00
dependabot[bot]
152a7d72a8
chore(deps): bump uvicorn from 0.52.1 to 0.52.3 (#29)
Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.52.1 to 0.52.3.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.52.1...0.52.3)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.52.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 15:08:05 +00:00
dependabot[bot]
99488e0f18
chore(deps): bump callable-dependency-review.yaml (#28)
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 10:57:34 -04:00
dependabot[bot]
889af4238d
chore(deps): bump callable-labeler.yaml (#27)
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 14:56:05 +00:00
dependabot[bot]
24360e01a2
chore(deps): bump callable-pr-policy.yaml (#26)
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 14:53:37 +00:00
dependabot[bot]
7ecf79a792
chore(deps): bump ci-python-app.yaml (#25)
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml](https://github.com/sea-haven-industries/.github) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-19 14:52:00 +00:00
dependabot[bot]
e327ef5b74
chore(deps): bump callable-labeler.yaml (#24)
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) from 1.0.3 to 1.0.6.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 15:55:27 +00:00
dependabot[bot]
490d62a0cb
chore(deps): bump callable-pr-policy.yaml (#22)
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github) from 1.0.5 to 1.0.6.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](9c1ecf9428...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 15:53:51 +00:00
dependabot[bot]
53eee8056c
chore(deps): bump callable-dependency-review.yaml (#21)
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github) from 1.0.3 to 1.0.6.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 15:52:33 +00:00
dependabot[bot]
a2ac6bd932
chore(deps): bump ci-python-app.yaml (#23)
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml](https://github.com/sea-haven-industries/.github) from 1.0.3 to 1.0.6.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 11:51:13 -04:00
dependabot[bot]
f7811f9e88
chore(deps): bump uvicorn from 0.51.0 to 0.52.1 (#20)
Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.51.0 to 0.52.1.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.51.0...0.52.1)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.52.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 18:30:03 -04:00
dependabot[bot]
7097a6d9ed
chore(deps): bump fastapi from 0.140.13 to 0.141.1 (#19)
Bumps [fastapi](https://github.com/fastapi/fastapi) from 0.140.13 to 0.141.1.
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.140.13...0.141.1)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 15:32:19 -04:00
Adam Moussa
34bf979c8c
ci: add org PR policy caller (#18)
Refs: PLAT-62
2026-08-04 11:56:21 -04:00
Adam Moussa
c071c5cc17
ci: declare read-only permissions in ci and dependency-review workflows (#17) 2026-07-29 11:41:20 -04:00
Adam Moussa
2580eed3b4
Merge pull request #16 from Sea-Haven-Industries/dependabot/pip/fastapi-0.140.13 2026-07-29 08:21:58 -04:00
dependabot[bot]
7b2daba6ce
chore(deps): bump fastapi from 0.139.2 to 0.140.13
Bumps [fastapi](https://github.com/fastapi/fastapi) from 0.139.2 to 0.140.13.
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.139.2...0.140.13)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.140.13
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 12:21:11 +00:00
Adam Moussa
f6faba0c0d
Merge pull request #15 from Sea-Haven-Industries/dependabot/pip/httpx2-2.9.1 2026-07-29 08:19:39 -04:00
dependabot[bot]
4f4754b7bc
chore(deps): bump httpx2 from 2.7.0 to 2.9.1
Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.7.0 to 2.9.1.
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](https://github.com/pydantic/httpx2/compare/v2.7.0...v2.9.1)

---
updated-dependencies:
- dependency-name: httpx2
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 12:18:50 +00:00
Adam Moussa
5e9093d6fc
Merge pull request #14 from Sea-Haven-Industries/dependabot/github_actions/Sea-Haven-Industries/dot-github/dot-github/workflows/callable-labeler.yaml-1.0.3 2026-07-29 08:17:02 -04:00
dependabot[bot]
74e32bb6c9
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 12:16:15 +00:00
Adam Moussa
db48f357dc
Merge pull request #13 from Sea-Haven-Industries/dependabot/github_actions/Sea-Haven-Industries/dot-github/dot-github/workflows/ci-python-app.yaml-1.0.3 2026-07-29 08:15:56 -04:00
dependabot[bot]
0ca839625f
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 12:15:12 +00:00
Adam Moussa
a60d9b98cd
Merge pull request #12 from Sea-Haven-Industries/dependabot/github_actions/Sea-Haven-Industries/dot-github/dot-github/workflows/callable-dependency-review.yaml-1.0.3 2026-07-29 08:14:11 -04:00
dependabot[bot]
fd6a410078
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 07:23:52 +00:00
Adam Moussa
8c65272cf0
Merge pull request #11 from Sea-Haven-Industries/chore/repin-central-workflows-v1.0.0
chore(ci): pin central workflow refs to v1.0.0
2026-07-28 17:29:06 -04:00
1b0b5eb01d
chore(ci): move the central workflow pin to v1.0.2
v1.0.0 and v1.0.1 predate the fix for multi-job reusable concurrency
groups, which cancelled ci / lint through ci-python-app.yaml. v1.0.2
carries it.
2026-07-28 17:26:56 -04:00
f8cc6d9e6c
chore(ci): pin central workflow refs to v1.0.0
The three refs pointed at fd60e4c9 with a trailing '# main' comment. That
comment names a branch, not a version, and Sea-Haven-Industries/.github had
no tags, so Dependabot's github-actions updater had nothing to resolve a
newer SHA against.

That repo now tags releases. Repoints all three at 2fbfb2e (v1.0.0) and
replaces the comment with the version.
2026-07-28 17:16:23 -04:00
dependabot[bot]
425f9149f1
Bump fastapi from 0.139.0 to 0.139.2 (#7)
Bumps [fastapi](https://github.com/fastapi/fastapi) from 0.139.0 to 0.139.2.
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.139.0...0.139.2)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.139.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 13:06:30 -04:00
dependabot[bot]
4caf4dbf80
Bump uvicorn from 0.50.2 to 0.51.0 (#5)
Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.50.2 to 0.51.0.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.50.2...0.51.0)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 13:37:38 -04:00
dependabot[bot]
997a3e0870
Bump httpx2 from 2.5.0 to 2.7.0 (#6)
Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.5.0 to 2.7.0.
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](https://github.com/pydantic/httpx2/compare/v2.5.0...v2.7.0)

---
updated-dependencies:
- dependency-name: httpx2
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 12:49:59 -04:00
dependabot[bot]
12bd7eb573
Bump uvicorn from 0.49.0 to 0.50.2 (#4)
Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.49.0 to 0.50.2.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.49.0...0.50.2)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.50.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 10:49:50 -04:00
Adam Moussa
8b53da8f99
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#3) 2026-07-06 18:27:15 -04:00
Adam Moussa
c4d1827c50
docs: add README status badges (INFRA-137) (#2) 2026-07-06 17:41:12 -04:00
Adam Moussa
6500bc85aa
chore(ci): add org dependency-review caller (INFRA-125) (#1) 2026-07-06 17:40:57 -04:00
138d300048
Add sidebar quick buttons and Dependabot review rendering
Add Expand all / Collapse all controls and a Dependabot-only filter to the
top of the queue sidebar. Render the dependency-risk assessment in the
detail view (update-type and risk badges, packages, reasons, title and
description notes) reusing the post, revise, and auto-merge controls, and
show a risk chip on Dependabot rows in the queue. Reviews without a "_kind"
fall back to the code-review layout.
2026-07-01 19:46:15 -04:00
667afd73f9
Assess Dependabot PRs for merge risk instead of code review
Dependabot dependency-update PRs do not benefit from BLOCK/FIX/NIT/QUESTION
code notes. Route them to a dependency-risk assessment instead: the semver
update type, a safe/low_risk/risky/breaking call, the packages bumped, and
reasons, grounded in the Sea Haven Dependabot merge policy (patch/minor
generally safe; majors need changelog review; grouped PRs assessed at the
riskiest package). Feedback focuses on PR title/description quality.

review() dispatches on the author to a dependabot or code path, each
stamping a "_kind" so consumers can tell the shapes apart (missing "_kind"
reads as code, keeping older cached reviews valid). Enum fields are clamped
to allowlists with cautious defaults so a hallucinated or injected value
cannot reach the posted event. The handbook distillation also captures the
dependency policy, though the prompt carries it regardless.
2026-07-01 19:46:15 -04:00
d60efeca28
Bump pytest to 9.1.1 for CVE-2025-71176
The pre-push security scanner flagged pytest 8.3.4 (CVE-2025-71176).
Dev/test-only dependency, not shipped, but bump to the patched release.
Suite passes on 9.x unchanged.
2026-07-01 19:12:45 -04:00
26f0558589
Group PRs by repo in the sidebar and add auto-merge
Group the review queue into a collapsible section per repo (collapse
state persisted in localStorage), with PRs ordered oldest to newest by
creation date, so a large multi-repo queue is easier to scan.

Add an optional per-PR auto-merge control: a method choice (squash by
default per handbook, merge, or rebase) enables GitHub auto-merge via a
GraphQL mutation, so the PR merges once required checks pass. It only
fires when clicked; nothing merges automatically.

Back this with created_at and node_id from the PR search, two new
nullable store columns added via an idempotent PRAGMA-guarded migration,
and a cheap-gate metadata backfill so already-cached PRs gain node_id
without being re-reviewed. New endpoint POST /api/automerge.
2026-07-01 19:11:09 -04:00