dependabot[bot]
3c17c33c16
Bump Amazon.Lambda.AspNetCoreServer.Hosting and 14 others ( #149 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Bumps Amazon.Lambda.AspNetCoreServer.Hosting from 1.7.2 to 1.10.0
Bumps AWSSDK.DynamoDBv2 from 3.7.400 to 3.7.513.4
Bumps AWSSDK.Extensions.NETCore.Setup from 3.7.400 to 3.7.400.2
Bumps AWSSDK.S3 from 3.7.405 to 3.7.511.8
Bumps AWSSDK.SecretsManager from 3.7.500 to 3.7.504.43
Bumps AWSSDK.SQS from 3.7.500 to 3.7.502.57
Bumps FluentAssertions from 7.2.0 to 7.2.2
Bumps FluentValidation from 11.11.0 to 11.12.0
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 8.0.27 to 8.0.28
Bumps Microsoft.EntityFrameworkCore from 8.0.27 to 8.0.28
Bumps Microsoft.EntityFrameworkCore.Design from 8.0.11 to 8.0.28
Bumps Microsoft.EntityFrameworkCore.InMemory from 8.0.11 to 8.0.28
Bumps Microsoft.EntityFrameworkCore.Sqlite from 8.0.11 to 8.0.28
Bumps Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore from 8.0.27 to 8.0.28
Bumps Microsoft.NET.Test.Sdk from 17.12.0 to 17.14.1
---
updated-dependencies:
- dependency-name: Amazon.Lambda.AspNetCoreServer.Hosting
dependency-version: 1.10.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: api
- dependency-name: AWSSDK.DynamoDBv2
dependency-version: 3.7.513.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: AWSSDK.Extensions.NETCore.Setup
dependency-version: 3.7.400.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: AWSSDK.S3
dependency-version: 3.7.511.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: AWSSDK.SecretsManager
dependency-version: 3.7.504.43
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: AWSSDK.SQS
dependency-version: 3.7.502.57
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: FluentValidation
dependency-version: 11.12.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: api
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.EntityFrameworkCore
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.EntityFrameworkCore.Design
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: FluentAssertions
dependency-version: 7.2.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.EntityFrameworkCore.InMemory
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.NET.Test.Sdk
dependency-version: 17.14.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: api
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 16:13:33 -04:00
dependabot[bot]
c83570c07c
build(deps-dev): bump @types/node from 22.19.19 to 25.9.3 in /infra ( #141 )
...
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) from 22.19.19 to 25.9.3.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.9.3
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 15:43:46 -04:00
dependabot[bot]
4e056f8fd6
build(deps): update reportlab requirement in /lambdas/pdf-generate ( #135 )
...
Updates the requirements on [reportlab](https://www.reportlab.com/ ) to permit the latest version.
---
updated-dependencies:
- dependency-name: reportlab
dependency-version: 5.0.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 15:38:14 -04:00
dependabot[bot]
19acd81b8c
build(deps): bump actions/checkout from 6 to 7 ( #134 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 15:32:31 -04:00
dependabot[bot]
9c7ff41cb0
build(deps): bump the mobile-npm group across 1 directory with 10 updates ( #147 )
...
Deploy / Deploy to AWS (push) Waiting to run
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Has been cancelled
Bumps the mobile-npm group with 10 updates in the /mobile directory:
| Package | From | To |
| --- | --- | --- |
| [@react-navigation/bottom-tabs](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/bottom-tabs ) | `7.16.1` | `7.18.2` |
| [@react-navigation/native](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native ) | `7.2.5` | `7.3.3` |
| [@react-navigation/native-stack](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native-stack ) | `7.15.1` | `7.17.5` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.100.10` | `5.101.0` |
| [axios](https://github.com/axios/axios ) | `1.16.1` | `1.18.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react ) | `19.2.6` | `19.2.7` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react ) | `19.2.15` | `19.2.17` |
| [react-native](https://github.com/facebook/react-native/tree/HEAD/packages/react-native ) | `0.85.3` | `0.86.0` |
| [@react-native/babel-preset](https://github.com/facebook/react-native ) | `0.85.3` | `0.86.0` |
| [@react-native/metro-config](https://github.com/facebook/react-native/tree/HEAD/packages/metro-config ) | `0.85.3` | `0.86.0` |
Updates `@react-navigation/bottom-tabs` from 7.16.1 to 7.18.2
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/bottom-tabs@7.18.2/packages/bottom-tabs/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/bottom-tabs@7.18.2/packages/bottom-tabs )
Updates `@react-navigation/native` from 7.2.5 to 7.3.3
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native@7.3.3/packages/native/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native@7.3.3/packages/native )
Updates `@react-navigation/native-stack` from 7.15.1 to 7.17.5
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native-stack@7.17.5/packages/native-stack/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native-stack@7.17.5/packages/native-stack )
Updates `@tanstack/react-query` from 5.100.10 to 5.101.0
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.101.0/packages/react-query )
Updates `axios` from 1.16.1 to 1.18.0
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.16.1...v1.18.0 )
Updates `react` from 19.2.6 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react )
Updates `@types/react` from 19.2.15 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
Updates `react-native` from 0.85.3 to 0.86.0
- [Release notes](https://github.com/facebook/react-native/releases )
- [Changelog](https://github.com/react/react-native/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react-native/commits/v0.86.0/packages/react-native )
Updates `@react-native/babel-preset` from 0.85.3 to 0.86.0
- [Release notes](https://github.com/facebook/react-native/releases )
- [Changelog](https://github.com/react/react-native/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react-native/compare/v0.85.3...v0.86.0 )
Updates `@react-native/metro-config` from 0.85.3 to 0.86.0
- [Release notes](https://github.com/facebook/react-native/releases )
- [Changelog](https://github.com/react/react-native/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react-native/commits/v0.86.0/packages/metro-config )
Updates `@types/react` from 19.2.15 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
---
updated-dependencies:
- dependency-name: "@react-native/babel-preset"
dependency-version: 0.86.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@react-native/metro-config"
dependency-version: 0.86.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@react-navigation/bottom-tabs"
dependency-version: 7.18.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@react-navigation/native"
dependency-version: 7.3.3
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@react-navigation/native-stack"
dependency-version: 7.17.5
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@tanstack/react-query"
dependency-version: 5.101.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@types/react"
dependency-version: 19.2.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: "@types/react"
dependency-version: 19.2.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: axios
dependency-version: 1.18.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: react
dependency-version: 19.2.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: react-native
dependency-version: 0.86.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:54:02 -04:00
dependabot[bot]
d2318b122b
build(deps): bump the web group across 1 directory with 7 updates ( #144 )
...
Bumps the web group with 7 updates in the /web directory:
| Package | From | To |
| --- | --- | --- |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.100.14` | `5.101.0` |
| [axios](https://github.com/axios/axios ) | `1.16.1` | `1.18.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react ) | `19.2.6` | `19.2.7` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react ) | `19.2.15` | `19.2.17` |
| [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom ) | `19.2.6` | `19.2.7` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom ) | `7.16.0` | `7.18.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ) | `4.1.7` | `4.1.9` |
Updates `@tanstack/react-query` from 5.100.14 to 5.101.0
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.101.0/packages/react-query )
Updates `axios` from 1.16.1 to 1.18.0
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.16.1...v1.18.0 )
Updates `react` from 19.2.6 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react )
Updates `@types/react` from 19.2.15 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
Updates `react-dom` from 19.2.6 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react-dom )
Updates `react-router-dom` from 7.16.0 to 7.18.0
- [Release notes](https://github.com/remix-run/react-router/releases )
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.0/packages/react-router-dom/CHANGELOG.md )
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.0/packages/react-router-dom )
Updates `@types/react` from 19.2.15 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
Updates `vitest` from 4.1.7 to 4.1.9
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.9/packages/vitest )
---
updated-dependencies:
- dependency-name: "@tanstack/react-query"
dependency-version: 5.101.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: web
- dependency-name: "@types/react"
dependency-version: 19.2.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: web
- dependency-name: "@types/react"
dependency-version: 19.2.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: web
- dependency-name: axios
dependency-version: 1.18.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: web
- dependency-name: react
dependency-version: 19.2.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: web
- dependency-name: react-dom
dependency-version: 19.2.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: web
- dependency-name: react-router-dom
dependency-version: 7.18.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: web
- dependency-name: vitest
dependency-version: 4.1.9
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: web
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:45:35 -04:00
dependabot[bot]
96166a0485
build(deps): update pdfplumber requirement in /lambdas/pdf-extract ( #143 )
...
Updates the requirements on [pdfplumber](https://github.com/jsvine/pdfplumber ) to permit the latest version.
- [Release notes](https://github.com/jsvine/pdfplumber/releases )
- [Changelog](https://github.com/jsvine/pdfplumber/blob/stable/CHANGELOG.md )
- [Commits](https://github.com/jsvine/pdfplumber/compare/v0.11.9...v0.11.10 )
---
updated-dependencies:
- dependency-name: pdfplumber
dependency-version: 0.11.10
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:39:05 -04:00
dependabot[bot]
2f3e1681e0
build(deps): update boto3 requirement in /lambdas/pdf-extract ( #142 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.18...1.43.32 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.32
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:33:37 -04:00
dependabot[bot]
43c46d1a6c
build(deps): bump the infra group across 1 directory with 2 updates ( #140 )
...
Bumps the infra group with 2 updates in the /infra directory: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib ) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk ).
Updates `aws-cdk-lib` from 2.257.0 to 2.260.0
- [Release notes](https://github.com/aws/aws-cdk/releases )
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md )
- [Commits](https://github.com/aws/aws-cdk/commits/v2.260.0/packages/aws-cdk-lib )
Updates `aws-cdk` from 2.1126.0 to 2.1128.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases )
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.0/packages/aws-cdk )
---
updated-dependencies:
- dependency-name: aws-cdk
dependency-version: 2.1128.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: infra
- dependency-name: aws-cdk-lib
dependency-version: 2.260.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: infra
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:27:21 -04:00
dependabot[bot]
42a5e90fc4
build(deps): update boto3 requirement in /lambdas/suggestions ( #139 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.18...1.43.32 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.32
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:21:14 -04:00
dependabot[bot]
c86cce8fd1
build(deps): update boto3 requirement in /lambdas/library-ingest ( #138 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.18...1.43.32 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.32
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:15:36 -04:00
dependabot[bot]
208188f0c6
build(deps): update boto3 requirement in /lambdas/pdf-generate ( #137 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.18...1.43.32 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.32
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:09:56 -04:00
dependabot[bot]
e725722b6c
build(deps): bump fastlane in /mobile in the mobile-bundler group ( #136 )
...
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Waiting to run
Deploy / Deploy to AWS (push) Waiting to run
Bumps the mobile-bundler group in /mobile with 1 update: [fastlane](https://github.com/fastlane/fastlane ).
Updates `fastlane` from 2.235.0 to 2.236.1
- [Release notes](https://github.com/fastlane/fastlane/releases )
- [Changelog](https://github.com/fastlane/fastlane/blob/master/CHANGELOG.latest.md )
- [Commits](https://github.com/fastlane/fastlane/compare/fastlane/2.235.0...fastlane/2.236.1 )
---
updated-dependencies:
- dependency-name: fastlane
dependency-version: 2.236.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-bundler
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:04:41 -04:00
Adam Moussa
405f4bbfab
fix(infra): distinct Aurora construct ID; group + unpause Dependabot ( #129 )
...
* fix(infra): give the Aurora cluster a distinct construct ID
The RDS->Aurora swap (PR3 #125 ) kept construct ID 'Database', so CloudFormation
saw the same logical ID change from AWS::RDS::DBInstance to AWS::RDS::DBCluster and
rejected the changeset ('Update of resource type is not permitted'). Renaming the
construct to 'AuroraCluster' gives the cluster a new logical ID, so CFN does a clean
replace (remove old DBInstance, add new DBCluster) instead of an in-place type change.
* chore(deps): group Dependabot minor/patch updates per ecosystem
Add a group to each update entry so weekly minor/patch bumps land as a
single PR per ecosystem/directory instead of one PR per package. Major
bumps remain individual PRs so breaking changes get isolated review.
Grouping takes effect when open-pull-requests-limit is raised above 0
(version updates are still paused during development, #109 ).
* chore(deps): unpause Dependabot version updates
Raise open-pull-requests-limit from 0 to 10 across all ecosystems,
re-enabling weekly version updates (paused during development, #109 ).
With grouping now in place, minor/patch bumps land as one grouped PR
per ecosystem; the limit caps outstanding major-bump PRs.
2026-06-18 13:57:15 -04:00
Adam Moussa
5d84399a0d
feat: pricing library — curated priced items feed the RAG corpus ( #127 )
...
Deploy / Deploy to AWS (push) Waiting to run
Adds a managed pricing library so admins can seed/curate reference priced items
directly, instead of the corpus being populated only by ingesting Sent proposals.
v1 PR5.
API:
- PricingLibraryItem entity + migration; /api/pricing-library CRUD (admin), with
GET {id} reachable by internal Lambda callers (admins role via internal key).
- Create/update publish an ADDITIVE library-ingest SQS job {pricingLibraryItemId},
wrapped so a publish failure never rolls back the save.
Lambda (library-ingest):
- Additive event-shape branch: pricingLibraryItemId -> fetch item, format markdown,
upload to pricing-library/{category}/{id}.md, trigger KB sync. The existing
proposalId path is byte-for-byte unchanged. Explicit error when neither id present;
warns when both present.
Web:
- Pricing Library management page (/admin/pricing-library): list / create / edit / delete.
GPT-4.1 cross-review on the event-shape change: no BLOCK (neither/both-id handling
applied). Verified: api 159 tests; web tsc + 26 tests; lambdas ruff + 37 pytest.
2026-06-18 12:49:47 -04:00
Adam Moussa
1fca0fa978
feat: proposal delivery — email customers the PDF on Mark as Sent ( #126 )
...
* feat: proposal delivery — email customers the PDF on "Mark as Sent"
Makes the system's namesake feature real: marking a proposal Sent now emails the
customer an expiring link to the branded PDF, and customers are managed (with
contact emails) instead of hardcoded. v1 PR4.
API:
- Customer.ContactEmail + migration; Customer list/update endpoints. Search stays
additive at GET /api/customers?query= (frozen-mobile + web compat); new paginated
list at GET /api/customers/list (admin).
- IEmailService (SesEmailService v2 / DevEmailService, dev-gated). MarkSentAsync
resolves the customer's email, presigns the latest PDF (7d), and sends via SES.
Email/presign failures are caught + audited and NEVER roll back the Sent transition.
- Startup EF migration guarded by a Postgres advisory lock (concurrency-safe).
Infra:
- SES email identity (proposals@seahavenind.com ); least-privilege ses:SendEmail/
SendRawEmail scoped to the identity ARN + ses:FromAddress condition; SES_FROM_ADDRESS
env. SES starts in sandbox — production access needed for unverified recipients.
Web:
- Customer management page (/admin/customers): list / create / edit incl. contact email.
- New-proposal form searches real customers (free-solo) instead of a hardcoded value.
- Mark-as-Sent dialog notes the PDF will be emailed to the customer.
GPT-4.1 cross-review (SES IAM): no BLOCK (ses:FromAddress condition applied).
Verified: api build + 121 tests; web tsc + 26 tests; infra tsc; ruff clean.
* Potential fix for pull request finding 'CodeQL / Exposure of private information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* Potential fix for pull request finding 'CodeQL / Exposure of private information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* Potential fix for pull request finding 'CodeQL / Exposure of private information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
---------
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-06-18 12:40:55 -04:00
dependabot[bot]
bddb3f0c37
build(deps): bump the npm_and_yarn group across 1 directory with 4 updates ( #132 )
...
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Has been cancelled
Bumps the npm_and_yarn group with 4 updates in the /mobile directory: [js-yaml](https://github.com/nodeca/js-yaml ), [ws](https://github.com/websockets/ws ), [form-data](https://github.com/form-data/form-data ) and [launch-editor](https://github.com/vitejs/launch-editor ).
Updates `js-yaml` from 4.1.1 to 4.2.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/commits )
Updates `ws` from 6.2.3 to 6.2.4
- [Release notes](https://github.com/websockets/ws/releases )
- [Commits](https://github.com/websockets/ws/compare/6.2.3...6.2.4 )
Updates `form-data` from 4.0.5 to 4.0.6
- [Release notes](https://github.com/form-data/form-data/releases )
- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md )
- [Commits](https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6 )
Updates `launch-editor` from 2.13.2 to 2.14.1
- [Commits](https://github.com/vitejs/launch-editor/compare/v2.13.2...v2.14.1 )
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.2.0
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: ws
dependency-version: 6.2.4
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: form-data
dependency-version: 4.0.6
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: launch-editor
dependency-version: 2.14.1
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-17 11:20:48 -04:00
dependabot[bot]
4cb8189354
build(deps): bump the npm_and_yarn group across 1 directory with 2 updates ( #131 )
...
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Waiting to run
Bumps the npm_and_yarn group with 2 updates in the /mobile directory: [js-cookie](https://github.com/js-cookie/js-cookie ) and [shell-quote](https://github.com/ljharb/shell-quote ).
Updates `js-cookie` from 2.2.1 to 3.0.8
- [Release notes](https://github.com/js-cookie/js-cookie/releases )
- [Commits](https://github.com/js-cookie/js-cookie/compare/v2.2.1...v3.0.8 )
Updates `shell-quote` from 1.8.3 to 1.8.4
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md )
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4 )
---
updated-dependencies:
- dependency-name: js-cookie
dependency-version: 3.0.8
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: shell-quote
dependency-version: 1.8.4
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-16 17:27:20 -04:00
Adam Moussa
aff38a11ae
feat(infra): migrate Bedrock KB vector store to Aurora pgvector ( #125 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Replaces OpenSearch Serverless with Aurora PostgreSQL Serverless v2 + pgvector as
the Bedrock Knowledge Base vector store (v1 PR3). Bedrock KB requires Aurora SSv2
(RDS Data API), not a plain RDS instance — so the DB engine moves to Aurora.
- foundation: rds.DatabaseInstance (PG15) -> rds.DatabaseCluster Aurora SSv2
(0.5-4 ACU, enableDataApi). RDS alarms: free-storage -> freeable-memory.
- compute: delete all AOSS (collection, policies, VPC endpoint, index-creator);
add bedrock_user secret + KB role (scoped rds-data + secret read); repoint
CfnKnowledgeBase to RDS storage (bedrock_integration.bedrock_kb, vector(1024)).
- lambdas: oss-index-creator -> aurora-pgvector-init (bootstrap schema/table/
indexes/role via RDS Data API; transient-error retry; password guard).
- ADR 0001 documents the decision.
Eliminates the ~$175-350/mo AOSS OCU floor. NAT kept (egress still needed).
GPT-4.1 cross-review: no BLOCK (FIX applied). tsc clean; foundation synth shows
Aurora cluster with Data API enabled; 23 pytest pass.
2026-06-12 18:44:42 -04:00
Adam Moussa
bbd185b280
feat(infra): parameterize stacks for multi-env (prod/staging) ( #123 )
...
Adds an env config layer resolved from CDK context (`-c env=staging`, default prod)
and threads it through all three stacks so a fully isolated staging environment can
be deployed in the same AWS account.
prod is byte-identical: the prod config reproduces the deployed values exactly and
stackSuffix='' keeps every construct ID, stack name, and physical resource name
unchanged. Verified via synth — prod foundation keeps proposal-system-db /
-uploads / db-credentials / -auth / seahaven; staging suffixes all of them.
- config.ts: EnvConfig (prod + staging, same account) + resolveConfig
- app.ts: env-aware stack naming + config passthrough
- foundation/compute/frontend: ~40 physical names suffixed with config.stackSuffix;
CORS, Cognito domain/callbacks, alarms email from config; RETAIN / deletionProtection
gated on config.retainData so staging can be torn down
- cdk.json: register `env` context (default prod)
- post-deploy.sh: STACK_SUFFIX for dynamic stack-name lookup (default prod)
Note: automated staging CI deploy needs a one-line `cdk-context` input added to the
org reusable cd-cdk.yaml (companion change). prod deploy is unaffected (default prod).
2026-06-12 18:04:53 -04:00
Adam Moussa
3d050bcf8e
fix(lambdas): SigV4-sign internal API calls and bundle Lambda dependencies ( #122 )
...
Deploy / Deploy to AWS (push) Waiting to run
The .NET API Lambda Function URL uses authType=AWS_IAM, but the four workload
Lambdas (suggestions, pdf-extract, pdf-generate, library-ingest) sent unsigned
requests with only X-Internal-Api-Key -> every internal call 403s. They also
used bare fromAsset() with no pip bundling -> ImportError at cold start. Both
made the SQS->Lambda->API pipeline non-functional when deployed (v1 pre-flight).
- Add _sign_request_headers (botocore SigV4Auth, service "lambda"); serialize the
JSON body once and send via httpx content= so the signed payload hash matches
the bytes sent; preserve X-Internal-Api-Key for the app-layer check. Sign per
retry attempt to avoid SigV4 timestamp expiry on slow retries.
- Add CDK pip bundling (--platform manylinux2014_aarch64 --only-binary=:all:) to
all four Lambdas so ARM64 wheels (reportlab, Pillow, pdfplumber) ship.
- Converge _retry_request across all four (fixes possibly-undefined return in
pdf-extract/pdf-generate).
- Add SigV4 signing regression tests.
Verified: ruff clean, infra tsc clean, aarch64 wheels resolve for all four,
23 pytest pass. GPT-4.1 cross-family review: no BLOCK (FIX + NIT applied).
2026-06-12 17:13:08 -04:00
252e52546e
chore: gitignore .NET publish output and tsbuildinfo
...
Deploy / Deploy to AWS (push) Waiting to run
Build artifacts (api/publish/, *.tsbuildinfo) were untracked-but-committable;
.NET publish output can include appsettings.*.json. Flagged by sh-build-review.
2026-06-12 16:06:47 -04:00
f502f8afc2
feat(web): apply Sea Haven Ops design system re-theme and layout fixes
...
Re-theme the MUI app from teal (#0B5A73) to the Sea Haven Ops neutral-navy
structure (#111827 ) with action-blue (#2563EB) as the sole brand accent, driven
through the theme tokens so all screens update consistently. Cards become
border-driven (no shadow); table headers gray-50; status/priority chips aligned
to design-system token values.
Layout fixes:
- Topbar: square bottom corners (was inheriting MuiPaper radius)
- Sidebar: remove duplicate user tag (already shown in topbar)
- Main: drop redundant ml that double-counted the persistent drawer width
- New Proposal form: center the constrained container (mx: auto)
2026-06-12 16:06:47 -04:00
2549ce3afc
Repo hygiene: PR labeler + README badges (INFRA-56/57)
2026-06-11 14:02:35 -04:00
Adam Moussa
a6dd20d66d
chore(deps): re-pause Dependabot version updates during development ( #109 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Restores the deliberate dev-pause from #86 . The 2026-06-05 audit
remediation raised these limits to 5 without knowing the pause was
intentional; the resulting 14 version-update PRs were closed unmerged.
Security updates are unaffected by this setting. Re-raise at V1.
2026-06-08 18:29:20 -04:00
Adam Moussa
38aebb5ebd
chore(ci): add aggregator job reporting the org-required 'ci / ci' context ( #108 )
...
Deploy / Deploy to AWS (push) Has been cancelled
proposal-system's seven CI jobs have distinct names, so the org ruleset's
required 'ci / ci' status check never reported here. The aggregator needs
all real CI jobs and fails if any failed or was cancelled. NOTE: this
check will be red until the pre-existing Python Lint/Tests failures
(INFRA-55) are fixed — it reports CI state honestly.
2026-06-05 15:11:48 -04:00
Adam Moussa
32c2d03c4c
chore(deps): remove blanket aws-cdk-lib dependabot ignore ( #107 )
...
Deploy / Deploy to AWS (push) Waiting to run
Per handbook Pinning Principle: exact pins are kept current by Dependabot version updates gated by CI + dependency review. Blanket ignores let pins rot (see today's fast-uri incident).
2026-06-05 13:59:51 -04:00
Adam Moussa
a342465036
fix(deps): pin aws-cdk-lib to ==2.257.0 ( #90 )
...
Deploy / Deploy to AWS (push) Waiting to run
* fix(deps): re-pin aws-cdk-lib to ==2.253.1
* fix(deps): pin aws-cdk-lib to 2.257.0 (exact)
2026-06-05 13:20:09 -04:00
Adam Moussa
1722b1b760
fix(deps): enable Dependabot PRs ( #88 )
...
Raise open-pull-requests-limit from 0 (disabled) to 5 for all 11
package ecosystems so Dependabot can open update PRs.
2026-06-05 12:51:45 -04:00
Adam Moussa
8b0eab00d7
chore(ci): bump actions/checkout to v6 ( #87 )
...
Bump all actions/checkout references to @v6 (org target). v4 runs on a
node runtime version that is being deprecated; v6 is the verified org
standard alongside configure-aws-credentials@v6.
Ref: engineering-handbook cicd.md (workflow standardization).
2026-06-05 12:42:19 -04:00
Adam Moussa
610c3ba339
Pause Dependabot version updates while in development ( #86 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Set open-pull-requests-limit to 0 on all 11 ecosystem entries so Dependabot
stops opening version-update PRs (which were being closed unactioned during
active development). Security updates are unaffected — they ignore this limit.
Revert the limits (or raise them) once the repo stabilizes.
2026-06-02 20:02:46 -04:00
dependabot[bot]
c07f644e08
build(deps-dev): bump tmp from 0.2.5 to 0.2.7 in /mobile ( #66 )
...
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Has been cancelled
Deploy / Deploy to AWS (push) Has been cancelled
Bumps [tmp](https://github.com/raszi/node-tmp ) from 0.2.5 to 0.2.7.
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md )
- [Commits](https://github.com/raszi/node-tmp/compare/v0.2.5...v0.2.7 )
---
updated-dependencies:
- dependency-name: tmp
dependency-version: 0.2.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:36:26 +00:00
dependabot[bot]
2959f7bc41
build(deps): bump @tanstack/react-query in /web ( #80 )
...
Bumps [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) from 5.100.11 to 5.100.14.
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.100.14/packages/react-query )
---
updated-dependencies:
- dependency-name: "@tanstack/react-query"
dependency-version: 5.100.14
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:34:11 +00:00
dependabot[bot]
ebcece420e
build(deps): bump @react-navigation/native in /mobile ( #81 )
...
Bumps [@react-navigation/native](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native ) from 7.2.4 to 7.2.5.
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native@7.2.5/packages/native/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native@7.2.5/packages/native )
---
updated-dependencies:
- dependency-name: "@react-navigation/native"
dependency-version: 7.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:34:08 +00:00
dependabot[bot]
987f3314bd
build(deps): bump react-router-dom from 7.15.1 to 7.16.0 in /web ( #78 )
...
Bumps [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom ) from 7.15.1 to 7.16.0.
- [Release notes](https://github.com/remix-run/react-router/releases )
- [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md )
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.16.0/packages/react-router-dom )
---
updated-dependencies:
- dependency-name: react-router-dom
dependency-version: 7.16.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:34:00 +00:00
dependabot[bot]
ba1b6bc22b
build(deps): update boto3 requirement in /lambdas/pdf-generate ( #76 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.14...1.43.18 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.18
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:57 +00:00
dependabot[bot]
a9b0df54da
build(deps): update boto3 requirement in /lambdas/pdf-extract ( #73 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.14...1.43.18 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.18
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:50 +00:00
dependabot[bot]
4f724531bf
build(deps): bump react-native-app-auth from 8.3.0 to 8.4.0 in /mobile ( #79 )
...
Bumps [react-native-app-auth](https://github.com/FormidableLabs/react-native-app-auth ) from 8.3.0 to 8.4.0.
- [Release notes](https://github.com/FormidableLabs/react-native-app-auth/releases )
- [Commits](https://github.com/FormidableLabs/react-native-app-auth/compare/react-native-app-auth@8.3.0...react-native-app-auth@8.4.0 )
---
updated-dependencies:
- dependency-name: react-native-app-auth
dependency-version: 8.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:42 +00:00
dependabot[bot]
a71b07db4d
build(deps): update boto3 requirement in /lambdas/library-ingest ( #77 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.14...1.43.18 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.18
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:40 +00:00
dependabot[bot]
a330eb39c2
build(deps): update boto3 requirement in /lambdas/suggestions ( #74 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.14...1.43.18 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.18
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:37 +00:00
dependabot[bot]
57cd85e4c2
build(deps): bump fastlane from 2.234.0 to 2.235.0 in /mobile ( #75 )
...
Bumps [fastlane](https://github.com/fastlane/fastlane ) from 2.234.0 to 2.235.0.
- [Release notes](https://github.com/fastlane/fastlane/releases )
- [Changelog](https://github.com/fastlane/fastlane/blob/master/CHANGELOG.latest.md )
- [Commits](https://github.com/fastlane/fastlane/compare/fastlane/2.234.0...fastlane/2.235.0 )
---
updated-dependencies:
- dependency-name: fastlane
dependency-version: 2.235.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:34 +00:00
dependabot[bot]
d3347333b2
build(deps-dev): bump @types/react from 19.2.14 to 19.2.15 in /web ( #72 )
...
Bumps [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react ) from 19.2.14 to 19.2.15.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
---
updated-dependencies:
- dependency-name: "@types/react"
dependency-version: 19.2.15
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:29 +00:00
dependabot[bot]
8691c8a205
build(deps-dev): bump aws-cdk from 2.1124.1 to 2.1125.0 in /infra ( #71 )
...
Bumps [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk ) from 2.1124.1 to 2.1125.0.
- [Release notes](https://github.com/aws/aws-cdk-cli/releases )
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1125.0/packages/aws-cdk )
---
updated-dependencies:
- dependency-name: aws-cdk
dependency-version: 2.1125.0
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:26 +00:00
dependabot[bot]
b23c4be81c
build(deps): bump react-native-paper from 5.15.2 to 5.15.3 in /mobile ( #70 )
...
Bumps [react-native-paper](https://github.com/callstack/react-native-paper ) from 5.15.2 to 5.15.3.
- [Release notes](https://github.com/callstack/react-native-paper/releases )
- [Commits](https://github.com/callstack/react-native-paper/compare/v5.15.2...v5.15.3 )
---
updated-dependencies:
- dependency-name: react-native-paper
dependency-version: 5.15.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:20 +00:00
Adam Moussa
ae3ad9d823
fix: CORS, JWT auth, useBlocker crash, and auto-migration for production deploy
...
Deploy / Deploy to AWS (push) Has been cancelled
- Add CloudFront origin to API Gateway CORS preflight and .NET CORS policy
- Replace HttpMethod.ANY with explicit methods so OPTIONS preflight doesn't
hit the JWT authorizer (was causing 403 on all API calls)
- Return Cognito ID token instead of access token from auth callback
(access tokens lack the aud claim required by API Gateway JWT authorizer)
- Add CloudFront callback URI to allowed redirect list
- Remove identity_provider=Google from login URL to show Cognito hosted UI
- Replace useBlocker (requires data router) with state-based navigation guard
to fix crash on AdminWorkspace with BrowserRouter
- Add auto-migration on Lambda cold start
- Enable Swagger in production
2026-05-27 19:20:29 -04:00
Adam Moussa
da783d48cd
fix(web): restore WEB-C1/M4 fixes reverted by rebase conflict resolution
...
Deploy / Deploy to AWS (push) Waiting to run
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Has been cancelled
- client.ts: localStorage → sessionStorage (WEB-C1 critical fix)
- proposals.ts: re-add 'Other' to ServiceCategory (WEB-M4)
- ProposalListPage.tsx: STATUS_COLORS → STATUS_CHIP_STYLES (visual design)
2026-05-27 18:21:03 -04:00
Adam Moussa
f9081fabf4
docs: Phase 6 cleanup — update AUDIT-REPORT, README, remove stale docs
...
- AUDIT-REPORT.md: mark all Phase 6 findings fixed (API-M2/M5/M7/M9/M10/M12/M13,
WEB-M3/M4/M8/M9/M11, LAM-M2/M3/M6/M9, INF-M1/M2/M9), update test count to 149
- README.md: Function URL NONE→AWS_IAM, add Testing and Security sections,
expand CI table with test jobs, note SQS encryption/OpenSearch VPC/access logging
- Remove stale session docs (AUDIT-2026-05-20, HANDOFF, RETROSPECTIVE, CHATGPT prompt)
- Add .claude/agents/ to .gitignore
- Remove empty-state placeholder from SimilarProposalsPanel
2026-05-27 18:18:44 -04:00
Adam Moussa
ab9569d7a9
test: add ProposalNumberGenerator, LineItemService state guard, and API client interceptor tests
...
- ProposalNumberGenerator tests (8 tests): format validation (SHI-YYYY-NNNN),
sequence incrementing, revision skipping, year boundary isolation, uniqueness,
zero-padding, high sequence rollover. Uses SQLite in-memory with Postgres
function stubs to support ExecuteSqlRawAsync.
- LineItemService state guard tests (18 tests): verifies line items cannot be
created/bulk-updated/deleted on Approved or Sent proposals (QA-C2), confirms
operations succeed on InReview and Revised statuses, validates
KeyNotFoundException on missing proposals, verifies audit logging.
- API client interceptor tests (14 tests): request interceptor attaches Bearer
token from sessionStorage (WEB-C1), handles missing/malformed token data,
response interceptor dispatches Redux logout on 401 (WEB-M2), returns friendly
messages for 403/404, extracts server error details, handles network errors.
- DbContextFactory updated to suppress InMemoryEventId.TransactionIgnoredWarning
so BulkUpdateAsync tests work with in-memory provider.
- Added SqliteDbContextFactory for tests requiring relational features.
- Added Microsoft.EntityFrameworkCore.Sqlite to test project dependencies.
Total: 104 .NET tests (was 77), 26 web tests (was 12). CI already wired.
2026-05-27 18:18:44 -04:00
Adam Moussa
8d73e66a17
fix(api): API-M2, M5, M7, M9, M10, M12, M13 — Medium audit findings
...
- API-M2: Add comment for fail-loud auth config guard (already implemented)
- API-M5: Add FluentValidation validators for VendorProposal, GeneratedPdf,
and SimilarReference DTOs; move request records to Application DTOs
- API-M7: Add AsNoTracking() to all read-only queries in ProposalService,
LineItemService, AdminController, UsersController, FilesController
- API-M9: Log stderr from dev PDF generation instead of returning to client
- API-M10: Return generic "Authentication service unavailable" in auth
callbacks instead of leaking Cognito/DevMode configuration state
- API-M12: Enrich audit logging with before/after values for status changes,
proposal edits, and line item operations using structured JSON
- API-M13: Log previous role alongside new role on user role changes in
both UsersController and Cognito-synced role updates in AuthController
2026-05-27 18:18:44 -04:00
Adam Moussa
15570d24db
docs: update AUDIT-REPORT.md for WEB-M3, M4, M8, M9, M11 fixes
2026-05-27 18:18:44 -04:00