Commit graph

31 commits

Author SHA1 Message Date
dependabot[bot]
7097a6d9ed
chore(deps): bump fastapi from 0.140.13 to 0.141.1 (#19)
Bumps [fastapi](https://github.com/fastapi/fastapi) from 0.140.13 to 0.141.1.
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.140.13...0.141.1)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 15:32:19 -04:00
Adam Moussa
34bf979c8c
ci: add org PR policy caller (#18)
Refs: PLAT-62
2026-08-04 11:56:21 -04:00
Adam Moussa
c071c5cc17
ci: declare read-only permissions in ci and dependency-review workflows (#17) 2026-07-29 11:41:20 -04:00
Adam Moussa
2580eed3b4
Merge pull request #16 from Sea-Haven-Industries/dependabot/pip/fastapi-0.140.13 2026-07-29 08:21:58 -04:00
dependabot[bot]
7b2daba6ce
chore(deps): bump fastapi from 0.139.2 to 0.140.13
Bumps [fastapi](https://github.com/fastapi/fastapi) from 0.139.2 to 0.140.13.
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.139.2...0.140.13)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.140.13
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 12:21:11 +00:00
Adam Moussa
f6faba0c0d
Merge pull request #15 from Sea-Haven-Industries/dependabot/pip/httpx2-2.9.1 2026-07-29 08:19:39 -04:00
dependabot[bot]
4f4754b7bc
chore(deps): bump httpx2 from 2.7.0 to 2.9.1
Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.7.0 to 2.9.1.
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](https://github.com/pydantic/httpx2/compare/v2.7.0...v2.9.1)

---
updated-dependencies:
- dependency-name: httpx2
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 12:18:50 +00:00
Adam Moussa
5e9093d6fc
Merge pull request #14 from Sea-Haven-Industries/dependabot/github_actions/Sea-Haven-Industries/dot-github/dot-github/workflows/callable-labeler.yaml-1.0.3 2026-07-29 08:17:02 -04:00
dependabot[bot]
74e32bb6c9
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 12:16:15 +00:00
Adam Moussa
db48f357dc
Merge pull request #13 from Sea-Haven-Industries/dependabot/github_actions/Sea-Haven-Industries/dot-github/dot-github/workflows/ci-python-app.yaml-1.0.3 2026-07-29 08:15:56 -04:00
dependabot[bot]
0ca839625f
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 12:15:12 +00:00
Adam Moussa
a60d9b98cd
Merge pull request #12 from Sea-Haven-Industries/dependabot/github_actions/Sea-Haven-Industries/dot-github/dot-github/workflows/callable-dependency-review.yaml-1.0.3 2026-07-29 08:14:11 -04:00
dependabot[bot]
fd6a410078
chore(deps): bump Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
Bumps [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github) from 1.0.2 to 1.0.3.
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-29 07:23:52 +00:00
Adam Moussa
8c65272cf0
Merge pull request #11 from Sea-Haven-Industries/chore/repin-central-workflows-v1.0.0
chore(ci): pin central workflow refs to v1.0.0
2026-07-28 17:29:06 -04:00
1b0b5eb01d
chore(ci): move the central workflow pin to v1.0.2
v1.0.0 and v1.0.1 predate the fix for multi-job reusable concurrency
groups, which cancelled ci / lint through ci-python-app.yaml. v1.0.2
carries it.
2026-07-28 17:26:56 -04:00
f8cc6d9e6c
chore(ci): pin central workflow refs to v1.0.0
The three refs pointed at fd60e4c9 with a trailing '# main' comment. That
comment names a branch, not a version, and Sea-Haven-Industries/.github had
no tags, so Dependabot's github-actions updater had nothing to resolve a
newer SHA against.

That repo now tags releases. Repoints all three at 2fbfb2e (v1.0.0) and
replaces the comment with the version.
2026-07-28 17:16:23 -04:00
dependabot[bot]
425f9149f1
Bump fastapi from 0.139.0 to 0.139.2 (#7)
Bumps [fastapi](https://github.com/fastapi/fastapi) from 0.139.0 to 0.139.2.
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.139.0...0.139.2)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.139.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-22 13:06:30 -04:00
dependabot[bot]
4caf4dbf80
Bump uvicorn from 0.50.2 to 0.51.0 (#5)
Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.50.2 to 0.51.0.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.50.2...0.51.0)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 13:37:38 -04:00
dependabot[bot]
997a3e0870
Bump httpx2 from 2.5.0 to 2.7.0 (#6)
Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.5.0 to 2.7.0.
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](https://github.com/pydantic/httpx2/compare/v2.5.0...v2.7.0)

---
updated-dependencies:
- dependency-name: httpx2
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 12:49:59 -04:00
dependabot[bot]
12bd7eb573
Bump uvicorn from 0.49.0 to 0.50.2 (#4)
Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.49.0 to 0.50.2.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.49.0...0.50.2)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.50.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 10:49:50 -04:00
Adam Moussa
8b53da8f99
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#3) 2026-07-06 18:27:15 -04:00
Adam Moussa
c4d1827c50
docs: add README status badges (INFRA-137) (#2) 2026-07-06 17:41:12 -04:00
Adam Moussa
6500bc85aa
chore(ci): add org dependency-review caller (INFRA-125) (#1) 2026-07-06 17:40:57 -04:00
138d300048
Add sidebar quick buttons and Dependabot review rendering
Add Expand all / Collapse all controls and a Dependabot-only filter to the
top of the queue sidebar. Render the dependency-risk assessment in the
detail view (update-type and risk badges, packages, reasons, title and
description notes) reusing the post, revise, and auto-merge controls, and
show a risk chip on Dependabot rows in the queue. Reviews without a "_kind"
fall back to the code-review layout.
2026-07-01 19:46:15 -04:00
667afd73f9
Assess Dependabot PRs for merge risk instead of code review
Dependabot dependency-update PRs do not benefit from BLOCK/FIX/NIT/QUESTION
code notes. Route them to a dependency-risk assessment instead: the semver
update type, a safe/low_risk/risky/breaking call, the packages bumped, and
reasons, grounded in the Sea Haven Dependabot merge policy (patch/minor
generally safe; majors need changelog review; grouped PRs assessed at the
riskiest package). Feedback focuses on PR title/description quality.

review() dispatches on the author to a dependabot or code path, each
stamping a "_kind" so consumers can tell the shapes apart (missing "_kind"
reads as code, keeping older cached reviews valid). Enum fields are clamped
to allowlists with cautious defaults so a hallucinated or injected value
cannot reach the posted event. The handbook distillation also captures the
dependency policy, though the prompt carries it regardless.
2026-07-01 19:46:15 -04:00
d60efeca28
Bump pytest to 9.1.1 for CVE-2025-71176
The pre-push security scanner flagged pytest 8.3.4 (CVE-2025-71176).
Dev/test-only dependency, not shipped, but bump to the patched release.
Suite passes on 9.x unchanged.
2026-07-01 19:12:45 -04:00
26f0558589
Group PRs by repo in the sidebar and add auto-merge
Group the review queue into a collapsible section per repo (collapse
state persisted in localStorage), with PRs ordered oldest to newest by
creation date, so a large multi-repo queue is easier to scan.

Add an optional per-PR auto-merge control: a method choice (squash by
default per handbook, merge, or rebase) enables GitHub auto-merge via a
GraphQL mutation, so the PR merges once required checks pass. It only
fires when clicked; nothing merges automatically.

Back this with created_at and node_id from the PR search, two new
nullable store columns added via an idempotent PRAGMA-guarded migration,
and a cheap-gate metadata backfill so already-cached PRs gain node_id
without being re-reviewed. New endpoint POST /api/automerge.
2026-07-01 19:11:09 -04:00
c07e4397aa
Harden review JSON parsing against reasoning models
Some Fireworks models emit chain-of-thought before the JSON review, and
that preamble can contain stray "{". The old first-"{"-to-last-"}" span
then grabbed reasoning braces and failed to parse (seen live on a real
PR). Scan each "{" and return the first substring that actually decodes
to an object instead, so a preamble or trailing prose no longer breaks
the review.
2026-07-01 19:11:09 -04:00
89494c1710
Ground reviews in the engineering-handbook
Feed the reviewer a distilled digest of the Sea Haven engineering-handbook
so findings reflect our naming, commit, PR, secrets, and IaC conventions
instead of generic code-review judgment.

A new handbook module keeps an app-managed shallow clone of the (private)
handbook, distills the review-relevant pages into a compact conventions
checklist via the Fireworks model once a day, caches it under ~/.cache,
and hands it to the reviewer to inject into every review's system prompt.
The refresh runs in-process at the start of each worker cycle; failures
keep the last good digest and back off, so a handbook outage never blocks
reviews. Set HANDBOOK_ENABLED=false to disable.

Extract a shared fireworks_complete helper used by both the reviewer and
the distiller, so the handbook provider needs no reviewer reference and
the guidance callable is set once at construction. Clone auth uses a
Basic http.extraHeader (GitHub git-over-HTTPS rejects Bearer), and the
distiller wraps its answer in delimiters to strip a reasoning model's
chain-of-thought preamble. Adds GET /api/handbook and a header status
line. Stdlib-only, no new dependencies.
2026-07-01 17:08:21 -04:00
15a52bff40
Add background auto-review worker with SQLite cache
Pre-compute PR reviews so they are ready the moment a PR is opened in
the queue, instead of waiting on an on-demand Fireworks call each time.

A daemon worker polls the queue every POLL_INTERVAL and reviews new or
changed non-draft PRs into a local SQLite cache (gitignored). Change
detection is two-level: skip when the PR's updated_at is unchanged, and
even when it moved, skip the model call when the diff's SHA-256 matches,
so comment-only bumps do not burn tokens. Failed reviews retry up to
MAX_REVIEW_ATTEMPTS with 429 backoff; departed PRs are closed with a
grace window before purge.

Singletons are initialized eagerly in the FastAPI lifespan before the
worker thread starts to avoid an init race; all cache writes are
serialized. New endpoints GET /api/reviews and POST /api/refresh back a
dashboard that polls for status (reviewing/ready/error) and opens a
ready review instantly. Nothing is posted automatically; the human
still decides. Stdlib-only, so no new runtime or test dependencies.
2026-07-01 14:28:11 -04:00
46cd856fb3
Add pr-reviewer local PR review tool
A single-user local dashboard that pulls open PRs from the
Sea-Haven-Industries org, reviews each with a Fireworks model in the
BLOCK/FIX/NIT/QUESTION format, and posts the review to GitHub as the
token owner. Runs only on localhost; secrets stay in a gitignored .env
and never reach the browser.

Structured as an app/ package plus a static/ frontend so the module
imports and static mount resolve. HTTP uses httpx2 (the runtime lib
starlette's TestClient now prefers), pinned in requirements.txt.

Includes a stdlib-only pytest suite (network mocked, no extra test
deps so CI needs only pytest) with a skip-by-default live Fireworks
test, and CI wired to the org ci-python-app reusable workflow to lint
app and tests and run the mocked suite fully offline. Dependabot covers
pip and github-actions.
2026-07-01 13:48:10 -04:00