renovate[bot]
31c4e773c0
chore(deps): update dependency awssdk.secretsmanager to 4.0.100.15 ( #385 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 16:27:23 +00:00
renovate[bot]
ab68ffdcbf
chore(deps): update dependency awssdk.extensions.netcore.setup to 4.0.102.1 ( #383 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 16:26:53 +00:00
renovate[bot]
49687cbe90
chore(deps): update dependency awssdk.s3 to 4.0.104.1 ( #384 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 16:26:04 +00:00
renovate[bot]
988b2f98c4
chore(deps): update dependency awssdk.dynamodbv2 to 4.0.107 ( #382 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-05 16:25:44 +00:00
renovate[bot]
6692bbe896
chore(deps): update dependency axios to v1.20.0 [security] ( #380 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-10-01 16:32:25 +00:00
dependabot[bot]
4d0ffdcf10
chore(deps): bump undici ( #379 )
...
Bumps the npm_and_yarn group with 1 update in the /web directory: [undici](https://github.com/nodejs/undici ).
Updates `undici` from 8.9.0 to 8.11.2
- [Release notes](https://github.com/nodejs/undici/releases )
- [Commits](https://github.com/nodejs/undici/compare/v8.9.0...v8.11.2 )
---
updated-dependencies:
- dependency-name: undici
dependency-version: 8.11.2
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 16:28:24 +00:00
renovate[bot]
c87e156074
chore(deps): update postgres:18-alpine docker digest to 77f5851 ( #377 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-28 16:06:29 +00:00
renovate[bot]
7bd0627e6a
chore(deps): update dependency awssdk.dynamodbv2 to 4.0.105 ( #378 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-28 16:06:24 +00:00
Adam Moussa
e728152961
docs(agents): drop security review gates ( #376 )
...
Agents no longer treat a security review or a cross-family review as a merge gate.
2026-09-26 17:17:54 -04:00
dependabot[bot]
112464a9c5
chore(deps): bump rubyzip ( #375 )
...
Bumps the bundler group with 1 update in the /mobile directory: [rubyzip](https://github.com/rubyzip/rubyzip ).
Updates `rubyzip` from 2.4.1 to 3.4.0
- [Release notes](https://github.com/rubyzip/rubyzip/releases )
- [Changelog](https://github.com/rubyzip/rubyzip/blob/main/Changelog.md )
- [Commits](https://github.com/rubyzip/rubyzip/compare/v2.4.1...v3.4.0 )
---
updated-dependencies:
- dependency-name: rubyzip
dependency-version: 3.4.0
dependency-type: indirect
dependency-group: bundler
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-26 20:19:01 +00:00
Adam Moussa
fe4069a535
chore(ci): remove unused Mergify stub ( #374 )
2026-09-22 18:41:46 +00:00
renovate[bot]
c0c7c51e59
chore(deps): update dependency awssdk.dynamodbv2 to 4.0.103.8 ( #370 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:44:09 +00:00
renovate[bot]
67c4fedf7f
chore(deps): update dependency awssdk.extensions.netcore.setup to 4.0.101.4 ( #371 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:44:08 +00:00
renovate[bot]
a685376efb
chore(deps): update dependency awssdk.s3 to 4.0.103.3 ( #372 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:43:49 +00:00
renovate[bot]
80cff6e050
chore(deps): update dependency awssdk.secretsmanager to 4.0.100.14 ( #373 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 15:43:40 +00:00
dependabot[bot]
769faaff8c
chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates ( #369 )
...
Bumps the npm_and_yarn group with 5 updates in the /mobile directory:
| Package | From | To |
| --- | --- | --- |
| [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping ) | `2.10.42` | `2.11.24` |
| [browserslist](https://github.com/browserslist/browserslist ) | `4.28.5` | `4.29.0` |
| [decode-uri-component](https://github.com/SamVerschueren/decode-uri-component ) | `0.2.2` | `removed` |
| [joi](https://github.com/hapijs/joi ) | `17.13.4` | `17.13.8` |
| [js-yaml](https://github.com/nodeca/js-yaml ) | `4.3.1` | `4.3.2` |
Updates `baseline-browser-mapping` from 2.10.42 to 2.11.24
- [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases )
- [Commits](https://github.com/web-platform-dx/baseline-browser-mapping/compare/v2.10.42...v2.11.24 )
Updates `browserslist` from 4.28.5 to 4.29.0
- [Release notes](https://github.com/browserslist/browserslist/releases )
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md )
- [Commits](https://github.com/browserslist/browserslist/compare/4.28.5...4.29.0 )
Removes `decode-uri-component`
Updates `joi` from 17.13.4 to 17.13.8
- [Commits](https://github.com/hapijs/joi/compare/v17.13.4...v17.13.8 )
Updates `js-yaml` from 4.3.1 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/compare/4.3.1...4.3.2 )
---
updated-dependencies:
- dependency-name: baseline-browser-mapping
dependency-version: 2.11.24
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: browserslist
dependency-version: 4.29.0
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: decode-uri-component
dependency-version:
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: joi
dependency-version: 17.13.8
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: js-yaml
dependency-version: 4.3.2
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 17:21:37 +00:00
renovate[bot]
ea36104ccc
chore(deps): update dependency awssdk.s3 to 4.0.103.2 ( #364 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 17:17:24 +00:00
renovate[bot]
f6c1d0a7a9
chore(deps): update dependency awssdk.secretsmanager to 4.0.100.13 ( #365 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 17:09:54 +00:00
renovate[bot]
5b531d9161
chore(deps): update dependency awssdk.dynamodbv2 to 4.0.103.7 ( #366 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 17:03:00 +00:00
dependabot[bot]
ebd8f38b8f
chore(deps-dev): bump qs ( #363 )
...
Bumps the npm_and_yarn group with 1 update in the /mobile directory: [qs](https://github.com/ljharb/qs ).
Updates `qs` from 6.15.3 to 6.16.0
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md )
- [Commits](https://github.com/ljharb/qs/compare/v6.15.3...v6.16.0 )
---
updated-dependencies:
- dependency-name: qs
dependency-version: 6.16.0
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-16 16:58:23 +00:00
renovate[bot]
6521588a7f
chore(deps): update dependency awssdk.extensions.netcore.setup to 4.0.101.3 ( #367 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 16:58:11 +00:00
renovate[bot]
6c230e4dad
chore(deps): update dependency awssdk.simpleemailv2 to 4.0.104.2 ( #368 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 16:58:07 +00:00
renovate[bot]
e788401f94
chore(deps): update dependency awssdk.dynamodbv2 to 4.0.103.5 ( #361 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 22:42:02 +00:00
renovate[bot]
32a7ce8d9a
chore(deps): update dependency awssdk.extensions.netcore.setup to 4.0.101.1 ( #362 )
...
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 22:41:30 +00:00
renovate[bot]
9ac50567f2
chore(deps): update dependency awssdk.dynamodbv2 to v4 ( #335 )
2026-08-25 17:07:19 +00:00
renovate[bot]
140e14f82e
chore(deps): update dependency typescript to v7 ( #353 )
2026-08-25 17:01:13 +00:00
renovate[bot]
2a21e63bbf
chore(deps): update dependency swashbuckle.aspnetcore to v10 ( #352 )
2026-08-25 16:55:45 +00:00
Adam Moussa
9cb9952a39
chore(deps): remove dependabot version updates ( #360 )
...
Renovate is the version-update bot on this Interactive repo. GitHub Dependabot alerts stay.
2026-08-25 11:51:07 -04:00
renovate[bot]
0e675e86d7
fix(deps): update dependency react-native-haptic-feedback to v3 ( #356 )
2026-08-25 14:50:58 +00:00
renovate[bot]
42898c3303
fix(deps): update dependency react-native-keychain to v10 ( #358 )
2026-08-25 14:45:25 +00:00
renovate[bot]
bfbdd8c846
fix(deps): update dependency react-native-share to v12 ( #359 )
2026-08-25 00:57:03 +00:00
renovate[bot]
1eed50c245
chore(deps): update dependency dotnet-sdk to v10 ( #342 )
2026-08-25 00:49:29 +00:00
renovate[bot]
03c1233760
chore(deps): update postgres docker tag to v18 ( #354 )
2026-08-25 00:44:25 +00:00
renovate[bot]
5021873ba4
fix(deps): update dependency @react-native-async-storage/async-storage to v3 ( #355 )
2026-08-25 00:39:13 +00:00
renovate[bot]
622a30d505
fix(deps): update dependency react-native-image-picker to v8 ( #357 )
2026-08-25 00:31:19 +00:00
renovate[bot]
73e27e3c54
chore(deps): update dependency coverlet.collector to v10 ( #341 )
2026-08-25 00:25:16 +00:00
renovate[bot]
6747d05738
chore(deps): update dependency fluentvalidation to v12 ( #344 )
2026-08-24 23:59:41 +00:00
renovate[bot]
6b89f4d502
chore(deps): update dependency fluentassertions to v8 ( #343 )
2026-08-24 23:47:11 +00:00
renovate[bot]
c8aec2f1e8
fix(deps): update npm minor and patch ( #334 )
2026-08-24 22:57:35 +00:00
renovate[bot]
dbd403c30c
chore(deps): update pip minor and patch ( #333 )
2026-08-24 22:44:26 +00:00
renovate[bot]
fb51152ff5
chore(deps): pin postgres docker tag to fe0737b ( #329 )
2026-08-24 22:37:16 +00:00
renovate[bot]
c9cefe0f60
chore(deps): update github actions ( #332 )
2026-08-24 22:27:03 +00:00
renovate[bot]
8847cb3ee1
chore(deps): update dependency dotnet-sdk to v8.0.424 ( #331 )
2026-08-24 22:19:34 +00:00
renovate[bot]
d7e895ab1d
chore(deps): update dependency amazon.lambda.aspnetcoreserver.hosting to 2.2.1 ( #330 )
2026-08-24 22:10:46 +00:00
dependabot[bot]
942a73f657
chore(deps): update boto3 requirement in /lambdas/pdf-generate ( #322 )
2026-08-24 19:56:46 +00:00
Adam Moussa
63c5c697b9
chore(ci): remove pr policy workflow caller ( #327 )
2026-08-24 15:12:28 -04:00
Adam Moussa
8007c7af71
chore(ci): switch auto-merge from seahaven-bot to Mergify ( #326 )
2026-08-24 13:53:25 -04:00
Adam Moussa
78990cd44f
ci: enable squash auto-merge on ready PRs (PLAT-108) ( #314 )
...
* ci: enable squash auto-merge on ready PRs
* fix(ci): serialize auto-merge enable and ignore already-enabled
2026-08-21 23:34:35 +00:00
Adam Moussa
18792e0749
ci: add merge_group trigger for required ci / ci ( #313 )
2026-08-21 17:42:09 -04:00
Adam Moussa
9e579f84e2
fix(web,api): pin nanoid and sanitize auth logs (SEC-29) ( #312 )
...
* fix: bump nanoid to 3.3.16 and postcss to 8.5.26
Bump nanoid from 3.3.16 to 3.3.18 in web/
Bump postcss from 8.5.25 to 8.5.26 in web/
Closes [Dependabot 47] (https://github.com/Sea-Haven-Industries/proposal-system/security/dependabot/47 )
* fix(api): sanitize request path in internal API key logs (SEC-29)
Strip CR/LF from Request.Path before logging invalid-key and disallowed-path warnings so CodeQL alerts 4 and 5 close without changing 401/403 behavior.
* fix(api): log user id instead of email on cognito role sync (SEC-29)
Keep AuthResponse.Email unchanged so CodeQL alert 1 closes without altering the callback payload.
* fix(api): use sanitized path on both internal key logs (SEC-29)
The 401 branch referenced an out-of-scope identifier and the 403 branch skipped SanitizeForLog. Cover newline-in-path logs and Cognito role-sync user-id logging with tests.
2026-08-20 12:38:29 -04:00