* fix(infra): give the Aurora cluster a distinct construct ID
The RDS->Aurora swap (PR3 #125) kept construct ID 'Database', so CloudFormation
saw the same logical ID change from AWS::RDS::DBInstance to AWS::RDS::DBCluster and
rejected the changeset ('Update of resource type is not permitted'). Renaming the
construct to 'AuroraCluster' gives the cluster a new logical ID, so CFN does a clean
replace (remove old DBInstance, add new DBCluster) instead of an in-place type change.
* chore(deps): group Dependabot minor/patch updates per ecosystem
Add a group to each update entry so weekly minor/patch bumps land as a
single PR per ecosystem/directory instead of one PR per package. Major
bumps remain individual PRs so breaking changes get isolated review.
Grouping takes effect when open-pull-requests-limit is raised above 0
(version updates are still paused during development, #109).
* chore(deps): unpause Dependabot version updates
Raise open-pull-requests-limit from 0 to 10 across all ecosystems,
re-enabling weekly version updates (paused during development, #109).
With grouping now in place, minor/patch bumps land as one grouped PR
per ecosystem; the limit caps outstanding major-bump PRs.
Restores the deliberate dev-pause from #86. The 2026-06-05 audit
remediation raised these limits to 5 without knowing the pause was
intentional; the resulting 14 version-update PRs were closed unmerged.
Security updates are unaffected by this setting. Re-raise at V1.
Per handbook Pinning Principle: exact pins are kept current by Dependabot version updates gated by CI + dependency review. Blanket ignores let pins rot (see today's fast-uri incident).
Set open-pull-requests-limit to 0 on all 11 ecosystem entries so Dependabot
stops opening version-update PRs (which were being closed unactioned during
active development). Security updates are unaffected — they ignore this limit.
Revert the limits (or raise them) once the repo stabilizes.
- Remove verbose print statements from Lambda handler
- Add dependabot pip entry for oss-index-creator
- Update README with new Lambda and deployed stack state
* Add iOS native project for React Native mobile app
Xcode project with bundle ID com.seahavenind.proposals,
CocoaPods configuration, and app scaffolding.
* Add Fastlane configuration for iOS builds and TestFlight distribution
Configures match with S3 storage (seahaven-ios-certificates bucket)
for code signing and a beta lane for automated TestFlight uploads.
* Add mobile CI job and iOS CD workflow (disabled)
CI: adds mobile typecheck job on PRs.
CD: deploy-mobile.yaml builds and uploads to TestFlight via
Fastlane on a macOS runner with OIDC auth for match S3 access.
Currently workflow_dispatch only — activate for V1 release.
* Refactor workflows to thin wrappers calling org reusable workflows
CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam
from the org repo. Deploy calls cd-cdk with post-deploy script
for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios.
Adds deploy concurrency groups to both deploy workflows.
* Add mobile Dependabot entries and remove assignees
Add npm and bundler ecosystems for mobile/. Remove assignees
from all entries — convention no longer in use.
* Add comprehensive README for the proposal-system monorepo
* Fix mobile TypeScript errors and add package-lock.json
Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef
type error, fix navigation type cast, add @types/react-native-vector-icons,
and generate package-lock.json for CI.
* Add .npmrc for mobile to resolve peer dependency conflicts
react-native-screens@4.x requires react-native >= 0.82 but the
project uses 0.79. legacy-peer-deps allows installation until
the next React Native upgrade.