Commit graph

10 commits

Author SHA1 Message Date
Adam Moussa
405f4bbfab
fix(infra): distinct Aurora construct ID; group + unpause Dependabot (#129)
* fix(infra): give the Aurora cluster a distinct construct ID

The RDS->Aurora swap (PR3 #125) kept construct ID 'Database', so CloudFormation
saw the same logical ID change from AWS::RDS::DBInstance to AWS::RDS::DBCluster and
rejected the changeset ('Update of resource type is not permitted'). Renaming the
construct to 'AuroraCluster' gives the cluster a new logical ID, so CFN does a clean
replace (remove old DBInstance, add new DBCluster) instead of an in-place type change.

* chore(deps): group Dependabot minor/patch updates per ecosystem

Add a group to each update entry so weekly minor/patch bumps land as a
single PR per ecosystem/directory instead of one PR per package. Major
bumps remain individual PRs so breaking changes get isolated review.

Grouping takes effect when open-pull-requests-limit is raised above 0
(version updates are still paused during development, #109).

* chore(deps): unpause Dependabot version updates

Raise open-pull-requests-limit from 0 to 10 across all ecosystems,
re-enabling weekly version updates (paused during development, #109).
With grouping now in place, minor/patch bumps land as one grouped PR
per ecosystem; the limit caps outstanding major-bump PRs.
2026-06-18 13:57:15 -04:00
Adam Moussa
a6dd20d66d
chore(deps): re-pause Dependabot version updates during development (#109)
Some checks failed
Deploy / Deploy to AWS (push) Has been cancelled
Restores the deliberate dev-pause from #86. The 2026-06-05 audit
remediation raised these limits to 5 without knowing the pause was
intentional; the resulting 14 version-update PRs were closed unmerged.
Security updates are unaffected by this setting. Re-raise at V1.
2026-06-08 18:29:20 -04:00
Adam Moussa
32c2d03c4c
chore(deps): remove blanket aws-cdk-lib dependabot ignore (#107)
Some checks are pending
Deploy / Deploy to AWS (push) Waiting to run
Per handbook Pinning Principle: exact pins are kept current by Dependabot version updates gated by CI + dependency review. Blanket ignores let pins rot (see today's fast-uri incident).
2026-06-05 13:59:51 -04:00
Adam Moussa
a342465036
fix(deps): pin aws-cdk-lib to ==2.257.0 (#90)
Some checks are pending
Deploy / Deploy to AWS (push) Waiting to run
* fix(deps): re-pin aws-cdk-lib to ==2.253.1

* fix(deps): pin aws-cdk-lib to 2.257.0 (exact)
2026-06-05 13:20:09 -04:00
Adam Moussa
1722b1b760
fix(deps): enable Dependabot PRs (#88)
Raise open-pull-requests-limit from 0 (disabled) to 5 for all 11
package ecosystems so Dependabot can open update PRs.
2026-06-05 12:51:45 -04:00
Adam Moussa
610c3ba339
Pause Dependabot version updates while in development (#86)
Some checks failed
Deploy / Deploy to AWS (push) Has been cancelled
Set open-pull-requests-limit to 0 on all 11 ecosystem entries so Dependabot
stops opening version-update PRs (which were being closed unactioned during
active development). Security updates are unaffected — they ignore this limit.

Revert the limits (or raise them) once the repo stabilizes.
2026-06-02 20:02:46 -04:00
Adam Moussa
7dd66caf61 Add missing dependabot entry for lambdas/suggestions 2026-05-18 18:12:02 -04:00
Adam Moussa
ef8a3b5f48 Clean up oss-index-creator: remove debug logging, update docs
- Remove verbose print statements from Lambda handler
- Add dependabot pip entry for oss-index-creator
- Update README with new Lambda and deployed stack state
2026-05-18 18:10:35 -04:00
Adam Moussa
7426d9a538
Add iOS CD pipeline and refactor workflows to org reusable callers (#24)
* Add iOS native project for React Native mobile app

Xcode project with bundle ID com.seahavenind.proposals,
CocoaPods configuration, and app scaffolding.

* Add Fastlane configuration for iOS builds and TestFlight distribution

Configures match with S3 storage (seahaven-ios-certificates bucket)
for code signing and a beta lane for automated TestFlight uploads.

* Add mobile CI job and iOS CD workflow (disabled)

CI: adds mobile typecheck job on PRs.
CD: deploy-mobile.yaml builds and uploads to TestFlight via
Fastlane on a macOS runner with OIDC auth for match S3 access.
Currently workflow_dispatch only — activate for V1 release.

* Refactor workflows to thin wrappers calling org reusable workflows

CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam
from the org repo. Deploy calls cd-cdk with post-deploy script
for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios.
Adds deploy concurrency groups to both deploy workflows.

* Add mobile Dependabot entries and remove assignees

Add npm and bundler ecosystems for mobile/. Remove assignees
from all entries — convention no longer in use.

* Add comprehensive README for the proposal-system monorepo

* Fix mobile TypeScript errors and add package-lock.json

Fix tsconfig.json (remove rootDir/outDir, add noEmit), fix useRef
type error, fix navigation type cast, add @types/react-native-vector-icons,
and generate package-lock.json for CI.

* Add .npmrc for mobile to resolve peer dependency conflicts

react-native-screens@4.x requires react-native >= 0.82 but the
project uses 0.79. legacy-peer-deps allows installation until
the next React Native upgrade.
2026-05-18 15:30:30 -04:00
0b055b3ad9 Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model
Phase 0 of proposal-system: complete project setup including:
- CDK infrastructure (3 stacks: foundation, compute, frontend)
- .NET 8 solution with Clean Architecture (Domain, Application, Infrastructure, Api)
- EF Core data model (PostgreSQL) with all entities
- Python Lambda placeholders (pdf-extract, pdf-generate, library-ingest)
- React 19 web frontend scaffold (Vite + MUI)
- React Native mobile placeholder
- Shared TypeScript API contracts
- GitHub Actions CI/CD (ci.yaml + deploy.yaml)
- OIDC deploy role (githubdeploy-proposal-system)
- Dependabot configuration
- Cognito User Pool with Google OAuth, PKCE clients, groups
2026-05-16 18:40:46 -04:00