dependabot[bot]
c558520a79
build(deps-dev): bump aws-cdk in /infra in the infra group ( #169 )
...
Bumps the infra group in /infra with 1 update: [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk ).
Updates `aws-cdk` from 2.1128.0 to 2.1128.1
- [Release notes](https://github.com/aws/aws-cdk-cli/releases )
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.1/packages/aws-cdk )
---
updated-dependencies:
- dependency-name: aws-cdk
dependency-version: 2.1128.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: infra
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 20:07:17 +00:00
Adam Moussa
36fc1120bf
build(deps): upgrade MUI to v9 (material + icons) and group @mui/* in Dependabot ( #168 )
...
Bump @mui/material and @mui/icons-material 7.3.1 -> ^9.1.1 together in
/web. They must move in lockstep (icons peer-depends on material), so
Dependabot's separate per-package PRs (#145/#146) could never go green
individually (ERESOLVE). Adds a 'mui' Dependabot group so future @mui/*
updates — including majors — are raised as one PR.
MUI v9 migration fixes (v7->v9 spans two majors):
- ListItemText: primaryTypographyProps -> slotProps.primary; fontSize
moved into sx (Typography system props removed in v9).
- Autocomplete renderInput: params.InputProps -> params.slotProps.input;
spread ...params.slotProps to retain inputLabel/htmlInput slots.
- Icons: @mui/icons-material/ErrorOutline -> ErrorOutlined (the plain
ErrorOutline export was removed in v9).
- vitest: inline @mui/material + react-transition-group so Vite resolves
v9's Transition.mjs directory import (native ESM loader can't).
Verified locally on Node 24: npm ci, npm run build, and npm test
(26 tests, 3 suites) all pass.
2026-06-22 16:02:43 -04:00
dependabot[bot]
433198c4e8
Bump xunit.runner.visualstudio from 2.8.2 to 3.1.5 ( #162 )
...
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 19:47:23 +00:00
dependabot[bot]
b1a330e916
Bump Microsoft.NET.Test.Sdk from 17.14.1 to 18.6.0 ( #160 )
...
---
updated-dependencies:
- dependency-name: Microsoft.NET.Test.Sdk
dependency-version: 18.6.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 19:40:47 +00:00
dependabot[bot]
4db44777a7
chore(deps): bump concurrent-ruby from 1.3.6 to 1.3.7 in /mobile ( #166 )
...
Bumps [concurrent-ruby](https://github.com/ruby-concurrency/concurrent-ruby ) from 1.3.6 to 1.3.7.
- [Release notes](https://github.com/ruby-concurrency/concurrent-ruby/releases )
- [Changelog](https://github.com/ruby-concurrency/concurrent-ruby/blob/master/CHANGELOG.md )
- [Commits](https://github.com/ruby-concurrency/concurrent-ruby/compare/v1.3.6...v1.3.7 )
---
updated-dependencies:
- dependency-name: concurrent-ruby
dependency-version: 1.3.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 15:33:50 -04:00
Adam Moussa
091a5da385
chore: disable auto-deploy workflows (manual dispatch only) ( #167 )
...
Remove push-to-main triggers from deploy.yaml (backend/CDK) and
deploy-mobile.yaml (iOS/TestFlight), leaving workflow_dispatch only.
CDK is not yet deployed; pausing auto-deploy until ready. Revert this
PR to re-enable.
2026-06-22 14:48:04 -04:00
dependabot[bot]
dce5979046
chore(deps-dev): bump @babel/core from 7.29.0 to 7.29.7 in /web ( #165 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core ) from 7.29.0 to 7.29.7.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v7.29.7/packages/babel-core )
---
updated-dependencies:
- dependency-name: "@babel/core"
dependency-version: 7.29.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:55:36 -04:00
dependabot[bot]
25c74bac34
chore(deps): bump undici from 7.26.0 to 7.28.0 in /web ( #164 )
...
Bumps [undici](https://github.com/nodejs/undici ) from 7.26.0 to 7.28.0.
- [Release notes](https://github.com/nodejs/undici/releases )
- [Commits](https://github.com/nodejs/undici/compare/v7.26.0...v7.28.0 )
---
updated-dependencies:
- dependency-name: undici
dependency-version: 7.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:50:02 -04:00
dependabot[bot]
7a3827b130
chore(deps): bump form-data from 4.0.5 to 4.0.6 in /web ( #163 )
...
Bumps [form-data](https://github.com/form-data/form-data ) from 4.0.5 to 4.0.6.
- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md )
- [Commits](https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6 )
---
updated-dependencies:
- dependency-name: form-data
dependency-version: 4.0.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:45:02 -04:00
dependabot[bot]
63adfdf816
Bump AWSSDK.SimpleEmailV2 from 3.7.500 to 3.7.509.10 ( #155 )
...
---
updated-dependencies:
- dependency-name: AWSSDK.SimpleEmailV2
dependency-version: 3.7.509.10
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:39:27 -04:00
dependabot[bot]
15e9eb9f9c
chore(deps): update boto3 requirement in /lambdas/pdf-extract ( #154 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.32...1.43.34 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.34
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:31:45 -04:00
dependabot[bot]
b117f1d65f
chore(deps): update boto3 requirement in /lambdas/pdf-generate ( #153 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.32...1.43.34 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.34
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:25:57 -04:00
dependabot[bot]
0c90452f17
chore(deps): update boto3 requirement in /lambdas/suggestions ( #152 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.32...1.43.34 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.34
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:20:31 -04:00
dependabot[bot]
59e2d48fb9
chore(deps): update boto3 requirement in /lambdas/library-ingest ( #151 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.32...1.43.34 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.34
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:15:07 -04:00
dependabot[bot]
3c17c33c16
Bump Amazon.Lambda.AspNetCoreServer.Hosting and 14 others ( #149 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Bumps Amazon.Lambda.AspNetCoreServer.Hosting from 1.7.2 to 1.10.0
Bumps AWSSDK.DynamoDBv2 from 3.7.400 to 3.7.513.4
Bumps AWSSDK.Extensions.NETCore.Setup from 3.7.400 to 3.7.400.2
Bumps AWSSDK.S3 from 3.7.405 to 3.7.511.8
Bumps AWSSDK.SecretsManager from 3.7.500 to 3.7.504.43
Bumps AWSSDK.SQS from 3.7.500 to 3.7.502.57
Bumps FluentAssertions from 7.2.0 to 7.2.2
Bumps FluentValidation from 11.11.0 to 11.12.0
Bumps Microsoft.AspNetCore.Authentication.JwtBearer from 8.0.27 to 8.0.28
Bumps Microsoft.EntityFrameworkCore from 8.0.27 to 8.0.28
Bumps Microsoft.EntityFrameworkCore.Design from 8.0.11 to 8.0.28
Bumps Microsoft.EntityFrameworkCore.InMemory from 8.0.11 to 8.0.28
Bumps Microsoft.EntityFrameworkCore.Sqlite from 8.0.11 to 8.0.28
Bumps Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore from 8.0.27 to 8.0.28
Bumps Microsoft.NET.Test.Sdk from 17.12.0 to 17.14.1
---
updated-dependencies:
- dependency-name: Amazon.Lambda.AspNetCoreServer.Hosting
dependency-version: 1.10.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: api
- dependency-name: AWSSDK.DynamoDBv2
dependency-version: 3.7.513.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: AWSSDK.Extensions.NETCore.Setup
dependency-version: 3.7.400.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: AWSSDK.S3
dependency-version: 3.7.511.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: AWSSDK.SecretsManager
dependency-version: 3.7.504.43
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: AWSSDK.SQS
dependency-version: 3.7.502.57
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: FluentValidation
dependency-version: 11.12.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: api
- dependency-name: Microsoft.AspNetCore.Authentication.JwtBearer
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.EntityFrameworkCore
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.EntityFrameworkCore.Design
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: FluentAssertions
dependency-version: 7.2.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.EntityFrameworkCore.InMemory
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.EntityFrameworkCore.Sqlite
dependency-version: 8.0.28
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: api
- dependency-name: Microsoft.NET.Test.Sdk
dependency-version: 17.14.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: api
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 16:13:33 -04:00
dependabot[bot]
c83570c07c
build(deps-dev): bump @types/node from 22.19.19 to 25.9.3 in /infra ( #141 )
...
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) from 22.19.19 to 25.9.3.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.9.3
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 15:43:46 -04:00
dependabot[bot]
4e056f8fd6
build(deps): update reportlab requirement in /lambdas/pdf-generate ( #135 )
...
Updates the requirements on [reportlab](https://www.reportlab.com/ ) to permit the latest version.
---
updated-dependencies:
- dependency-name: reportlab
dependency-version: 5.0.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 15:38:14 -04:00
dependabot[bot]
19acd81b8c
build(deps): bump actions/checkout from 6 to 7 ( #134 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 15:32:31 -04:00
dependabot[bot]
9c7ff41cb0
build(deps): bump the mobile-npm group across 1 directory with 10 updates ( #147 )
...
Deploy / Deploy to AWS (push) Waiting to run
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Has been cancelled
Bumps the mobile-npm group with 10 updates in the /mobile directory:
| Package | From | To |
| --- | --- | --- |
| [@react-navigation/bottom-tabs](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/bottom-tabs ) | `7.16.1` | `7.18.2` |
| [@react-navigation/native](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native ) | `7.2.5` | `7.3.3` |
| [@react-navigation/native-stack](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native-stack ) | `7.15.1` | `7.17.5` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.100.10` | `5.101.0` |
| [axios](https://github.com/axios/axios ) | `1.16.1` | `1.18.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react ) | `19.2.6` | `19.2.7` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react ) | `19.2.15` | `19.2.17` |
| [react-native](https://github.com/facebook/react-native/tree/HEAD/packages/react-native ) | `0.85.3` | `0.86.0` |
| [@react-native/babel-preset](https://github.com/facebook/react-native ) | `0.85.3` | `0.86.0` |
| [@react-native/metro-config](https://github.com/facebook/react-native/tree/HEAD/packages/metro-config ) | `0.85.3` | `0.86.0` |
Updates `@react-navigation/bottom-tabs` from 7.16.1 to 7.18.2
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/bottom-tabs@7.18.2/packages/bottom-tabs/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/bottom-tabs@7.18.2/packages/bottom-tabs )
Updates `@react-navigation/native` from 7.2.5 to 7.3.3
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native@7.3.3/packages/native/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native@7.3.3/packages/native )
Updates `@react-navigation/native-stack` from 7.15.1 to 7.17.5
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native-stack@7.17.5/packages/native-stack/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native-stack@7.17.5/packages/native-stack )
Updates `@tanstack/react-query` from 5.100.10 to 5.101.0
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.101.0/packages/react-query )
Updates `axios` from 1.16.1 to 1.18.0
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.16.1...v1.18.0 )
Updates `react` from 19.2.6 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react )
Updates `@types/react` from 19.2.15 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
Updates `react-native` from 0.85.3 to 0.86.0
- [Release notes](https://github.com/facebook/react-native/releases )
- [Changelog](https://github.com/react/react-native/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react-native/commits/v0.86.0/packages/react-native )
Updates `@react-native/babel-preset` from 0.85.3 to 0.86.0
- [Release notes](https://github.com/facebook/react-native/releases )
- [Changelog](https://github.com/react/react-native/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react-native/compare/v0.85.3...v0.86.0 )
Updates `@react-native/metro-config` from 0.85.3 to 0.86.0
- [Release notes](https://github.com/facebook/react-native/releases )
- [Changelog](https://github.com/react/react-native/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react-native/commits/v0.86.0/packages/metro-config )
Updates `@types/react` from 19.2.15 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
---
updated-dependencies:
- dependency-name: "@react-native/babel-preset"
dependency-version: 0.86.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@react-native/metro-config"
dependency-version: 0.86.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@react-navigation/bottom-tabs"
dependency-version: 7.18.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@react-navigation/native"
dependency-version: 7.3.3
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@react-navigation/native-stack"
dependency-version: 7.17.5
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@tanstack/react-query"
dependency-version: 5.101.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: "@types/react"
dependency-version: 19.2.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: "@types/react"
dependency-version: 19.2.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: axios
dependency-version: 1.18.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
- dependency-name: react
dependency-version: 19.2.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: react-native
dependency-version: 0.86.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-npm
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:54:02 -04:00
dependabot[bot]
d2318b122b
build(deps): bump the web group across 1 directory with 7 updates ( #144 )
...
Bumps the web group with 7 updates in the /web directory:
| Package | From | To |
| --- | --- | --- |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.100.14` | `5.101.0` |
| [axios](https://github.com/axios/axios ) | `1.16.1` | `1.18.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react ) | `19.2.6` | `19.2.7` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react ) | `19.2.15` | `19.2.17` |
| [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom ) | `19.2.6` | `19.2.7` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom ) | `7.16.0` | `7.18.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ) | `4.1.7` | `4.1.9` |
Updates `@tanstack/react-query` from 5.100.14 to 5.101.0
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.101.0/packages/react-query )
Updates `axios` from 1.16.1 to 1.18.0
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.16.1...v1.18.0 )
Updates `react` from 19.2.6 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react )
Updates `@types/react` from 19.2.15 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
Updates `react-dom` from 19.2.6 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react-dom )
Updates `react-router-dom` from 7.16.0 to 7.18.0
- [Release notes](https://github.com/remix-run/react-router/releases )
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.0/packages/react-router-dom/CHANGELOG.md )
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.0/packages/react-router-dom )
Updates `@types/react` from 19.2.15 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
Updates `vitest` from 4.1.7 to 4.1.9
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.9/packages/vitest )
---
updated-dependencies:
- dependency-name: "@tanstack/react-query"
dependency-version: 5.101.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: web
- dependency-name: "@types/react"
dependency-version: 19.2.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: web
- dependency-name: "@types/react"
dependency-version: 19.2.17
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: web
- dependency-name: axios
dependency-version: 1.18.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: web
- dependency-name: react
dependency-version: 19.2.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: web
- dependency-name: react-dom
dependency-version: 19.2.7
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: web
- dependency-name: react-router-dom
dependency-version: 7.18.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: web
- dependency-name: vitest
dependency-version: 4.1.9
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: web
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:45:35 -04:00
dependabot[bot]
96166a0485
build(deps): update pdfplumber requirement in /lambdas/pdf-extract ( #143 )
...
Updates the requirements on [pdfplumber](https://github.com/jsvine/pdfplumber ) to permit the latest version.
- [Release notes](https://github.com/jsvine/pdfplumber/releases )
- [Changelog](https://github.com/jsvine/pdfplumber/blob/stable/CHANGELOG.md )
- [Commits](https://github.com/jsvine/pdfplumber/compare/v0.11.9...v0.11.10 )
---
updated-dependencies:
- dependency-name: pdfplumber
dependency-version: 0.11.10
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:39:05 -04:00
dependabot[bot]
2f3e1681e0
build(deps): update boto3 requirement in /lambdas/pdf-extract ( #142 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.18...1.43.32 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.32
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:33:37 -04:00
dependabot[bot]
43c46d1a6c
build(deps): bump the infra group across 1 directory with 2 updates ( #140 )
...
Bumps the infra group with 2 updates in the /infra directory: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib ) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk ).
Updates `aws-cdk-lib` from 2.257.0 to 2.260.0
- [Release notes](https://github.com/aws/aws-cdk/releases )
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md )
- [Commits](https://github.com/aws/aws-cdk/commits/v2.260.0/packages/aws-cdk-lib )
Updates `aws-cdk` from 2.1126.0 to 2.1128.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases )
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.0/packages/aws-cdk )
---
updated-dependencies:
- dependency-name: aws-cdk
dependency-version: 2.1128.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: infra
- dependency-name: aws-cdk-lib
dependency-version: 2.260.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: infra
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:27:21 -04:00
dependabot[bot]
42a5e90fc4
build(deps): update boto3 requirement in /lambdas/suggestions ( #139 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.18...1.43.32 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.32
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:21:14 -04:00
dependabot[bot]
c86cce8fd1
build(deps): update boto3 requirement in /lambdas/library-ingest ( #138 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.18...1.43.32 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.32
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:15:36 -04:00
dependabot[bot]
208188f0c6
build(deps): update boto3 requirement in /lambdas/pdf-generate ( #137 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.18...1.43.32 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.32
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:09:56 -04:00
dependabot[bot]
e725722b6c
build(deps): bump fastlane in /mobile in the mobile-bundler group ( #136 )
...
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Waiting to run
Deploy / Deploy to AWS (push) Waiting to run
Bumps the mobile-bundler group in /mobile with 1 update: [fastlane](https://github.com/fastlane/fastlane ).
Updates `fastlane` from 2.235.0 to 2.236.1
- [Release notes](https://github.com/fastlane/fastlane/releases )
- [Changelog](https://github.com/fastlane/fastlane/blob/master/CHANGELOG.latest.md )
- [Commits](https://github.com/fastlane/fastlane/compare/fastlane/2.235.0...fastlane/2.236.1 )
---
updated-dependencies:
- dependency-name: fastlane
dependency-version: 2.236.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: mobile-bundler
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-18 14:04:41 -04:00
Adam Moussa
405f4bbfab
fix(infra): distinct Aurora construct ID; group + unpause Dependabot ( #129 )
...
* fix(infra): give the Aurora cluster a distinct construct ID
The RDS->Aurora swap (PR3 #125 ) kept construct ID 'Database', so CloudFormation
saw the same logical ID change from AWS::RDS::DBInstance to AWS::RDS::DBCluster and
rejected the changeset ('Update of resource type is not permitted'). Renaming the
construct to 'AuroraCluster' gives the cluster a new logical ID, so CFN does a clean
replace (remove old DBInstance, add new DBCluster) instead of an in-place type change.
* chore(deps): group Dependabot minor/patch updates per ecosystem
Add a group to each update entry so weekly minor/patch bumps land as a
single PR per ecosystem/directory instead of one PR per package. Major
bumps remain individual PRs so breaking changes get isolated review.
Grouping takes effect when open-pull-requests-limit is raised above 0
(version updates are still paused during development, #109 ).
* chore(deps): unpause Dependabot version updates
Raise open-pull-requests-limit from 0 to 10 across all ecosystems,
re-enabling weekly version updates (paused during development, #109 ).
With grouping now in place, minor/patch bumps land as one grouped PR
per ecosystem; the limit caps outstanding major-bump PRs.
2026-06-18 13:57:15 -04:00
Adam Moussa
5d84399a0d
feat: pricing library — curated priced items feed the RAG corpus ( #127 )
...
Deploy / Deploy to AWS (push) Waiting to run
Adds a managed pricing library so admins can seed/curate reference priced items
directly, instead of the corpus being populated only by ingesting Sent proposals.
v1 PR5.
API:
- PricingLibraryItem entity + migration; /api/pricing-library CRUD (admin), with
GET {id} reachable by internal Lambda callers (admins role via internal key).
- Create/update publish an ADDITIVE library-ingest SQS job {pricingLibraryItemId},
wrapped so a publish failure never rolls back the save.
Lambda (library-ingest):
- Additive event-shape branch: pricingLibraryItemId -> fetch item, format markdown,
upload to pricing-library/{category}/{id}.md, trigger KB sync. The existing
proposalId path is byte-for-byte unchanged. Explicit error when neither id present;
warns when both present.
Web:
- Pricing Library management page (/admin/pricing-library): list / create / edit / delete.
GPT-4.1 cross-review on the event-shape change: no BLOCK (neither/both-id handling
applied). Verified: api 159 tests; web tsc + 26 tests; lambdas ruff + 37 pytest.
2026-06-18 12:49:47 -04:00
Adam Moussa
1fca0fa978
feat: proposal delivery — email customers the PDF on Mark as Sent ( #126 )
...
* feat: proposal delivery — email customers the PDF on "Mark as Sent"
Makes the system's namesake feature real: marking a proposal Sent now emails the
customer an expiring link to the branded PDF, and customers are managed (with
contact emails) instead of hardcoded. v1 PR4.
API:
- Customer.ContactEmail + migration; Customer list/update endpoints. Search stays
additive at GET /api/customers?query= (frozen-mobile + web compat); new paginated
list at GET /api/customers/list (admin).
- IEmailService (SesEmailService v2 / DevEmailService, dev-gated). MarkSentAsync
resolves the customer's email, presigns the latest PDF (7d), and sends via SES.
Email/presign failures are caught + audited and NEVER roll back the Sent transition.
- Startup EF migration guarded by a Postgres advisory lock (concurrency-safe).
Infra:
- SES email identity (proposals@seahavenind.com ); least-privilege ses:SendEmail/
SendRawEmail scoped to the identity ARN + ses:FromAddress condition; SES_FROM_ADDRESS
env. SES starts in sandbox — production access needed for unverified recipients.
Web:
- Customer management page (/admin/customers): list / create / edit incl. contact email.
- New-proposal form searches real customers (free-solo) instead of a hardcoded value.
- Mark-as-Sent dialog notes the PDF will be emailed to the customer.
GPT-4.1 cross-review (SES IAM): no BLOCK (ses:FromAddress condition applied).
Verified: api build + 121 tests; web tsc + 26 tests; infra tsc; ruff clean.
* Potential fix for pull request finding 'CodeQL / Exposure of private information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* Potential fix for pull request finding 'CodeQL / Exposure of private information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* Potential fix for pull request finding 'CodeQL / Exposure of private information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
---------
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-06-18 12:40:55 -04:00
dependabot[bot]
bddb3f0c37
build(deps): bump the npm_and_yarn group across 1 directory with 4 updates ( #132 )
...
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Has been cancelled
Bumps the npm_and_yarn group with 4 updates in the /mobile directory: [js-yaml](https://github.com/nodeca/js-yaml ), [ws](https://github.com/websockets/ws ), [form-data](https://github.com/form-data/form-data ) and [launch-editor](https://github.com/vitejs/launch-editor ).
Updates `js-yaml` from 4.1.1 to 4.2.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/commits )
Updates `ws` from 6.2.3 to 6.2.4
- [Release notes](https://github.com/websockets/ws/releases )
- [Commits](https://github.com/websockets/ws/compare/6.2.3...6.2.4 )
Updates `form-data` from 4.0.5 to 4.0.6
- [Release notes](https://github.com/form-data/form-data/releases )
- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md )
- [Commits](https://github.com/form-data/form-data/compare/v4.0.5...v4.0.6 )
Updates `launch-editor` from 2.13.2 to 2.14.1
- [Commits](https://github.com/vitejs/launch-editor/compare/v2.13.2...v2.14.1 )
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.2.0
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: ws
dependency-version: 6.2.4
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: form-data
dependency-version: 4.0.6
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: launch-editor
dependency-version: 2.14.1
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-17 11:20:48 -04:00
dependabot[bot]
4cb8189354
build(deps): bump the npm_and_yarn group across 1 directory with 2 updates ( #131 )
...
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Waiting to run
Bumps the npm_and_yarn group with 2 updates in the /mobile directory: [js-cookie](https://github.com/js-cookie/js-cookie ) and [shell-quote](https://github.com/ljharb/shell-quote ).
Updates `js-cookie` from 2.2.1 to 3.0.8
- [Release notes](https://github.com/js-cookie/js-cookie/releases )
- [Commits](https://github.com/js-cookie/js-cookie/compare/v2.2.1...v3.0.8 )
Updates `shell-quote` from 1.8.3 to 1.8.4
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md )
- [Commits](https://github.com/ljharb/shell-quote/compare/v1.8.3...v1.8.4 )
---
updated-dependencies:
- dependency-name: js-cookie
dependency-version: 3.0.8
dependency-type: indirect
dependency-group: npm_and_yarn
- dependency-name: shell-quote
dependency-version: 1.8.4
dependency-type: indirect
dependency-group: npm_and_yarn
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-16 17:27:20 -04:00
Adam Moussa
aff38a11ae
feat(infra): migrate Bedrock KB vector store to Aurora pgvector ( #125 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Replaces OpenSearch Serverless with Aurora PostgreSQL Serverless v2 + pgvector as
the Bedrock Knowledge Base vector store (v1 PR3). Bedrock KB requires Aurora SSv2
(RDS Data API), not a plain RDS instance — so the DB engine moves to Aurora.
- foundation: rds.DatabaseInstance (PG15) -> rds.DatabaseCluster Aurora SSv2
(0.5-4 ACU, enableDataApi). RDS alarms: free-storage -> freeable-memory.
- compute: delete all AOSS (collection, policies, VPC endpoint, index-creator);
add bedrock_user secret + KB role (scoped rds-data + secret read); repoint
CfnKnowledgeBase to RDS storage (bedrock_integration.bedrock_kb, vector(1024)).
- lambdas: oss-index-creator -> aurora-pgvector-init (bootstrap schema/table/
indexes/role via RDS Data API; transient-error retry; password guard).
- ADR 0001 documents the decision.
Eliminates the ~$175-350/mo AOSS OCU floor. NAT kept (egress still needed).
GPT-4.1 cross-review: no BLOCK (FIX applied). tsc clean; foundation synth shows
Aurora cluster with Data API enabled; 23 pytest pass.
2026-06-12 18:44:42 -04:00
Adam Moussa
bbd185b280
feat(infra): parameterize stacks for multi-env (prod/staging) ( #123 )
...
Adds an env config layer resolved from CDK context (`-c env=staging`, default prod)
and threads it through all three stacks so a fully isolated staging environment can
be deployed in the same AWS account.
prod is byte-identical: the prod config reproduces the deployed values exactly and
stackSuffix='' keeps every construct ID, stack name, and physical resource name
unchanged. Verified via synth — prod foundation keeps proposal-system-db /
-uploads / db-credentials / -auth / seahaven; staging suffixes all of them.
- config.ts: EnvConfig (prod + staging, same account) + resolveConfig
- app.ts: env-aware stack naming + config passthrough
- foundation/compute/frontend: ~40 physical names suffixed with config.stackSuffix;
CORS, Cognito domain/callbacks, alarms email from config; RETAIN / deletionProtection
gated on config.retainData so staging can be torn down
- cdk.json: register `env` context (default prod)
- post-deploy.sh: STACK_SUFFIX for dynamic stack-name lookup (default prod)
Note: automated staging CI deploy needs a one-line `cdk-context` input added to the
org reusable cd-cdk.yaml (companion change). prod deploy is unaffected (default prod).
2026-06-12 18:04:53 -04:00
Adam Moussa
3d050bcf8e
fix(lambdas): SigV4-sign internal API calls and bundle Lambda dependencies ( #122 )
...
Deploy / Deploy to AWS (push) Waiting to run
The .NET API Lambda Function URL uses authType=AWS_IAM, but the four workload
Lambdas (suggestions, pdf-extract, pdf-generate, library-ingest) sent unsigned
requests with only X-Internal-Api-Key -> every internal call 403s. They also
used bare fromAsset() with no pip bundling -> ImportError at cold start. Both
made the SQS->Lambda->API pipeline non-functional when deployed (v1 pre-flight).
- Add _sign_request_headers (botocore SigV4Auth, service "lambda"); serialize the
JSON body once and send via httpx content= so the signed payload hash matches
the bytes sent; preserve X-Internal-Api-Key for the app-layer check. Sign per
retry attempt to avoid SigV4 timestamp expiry on slow retries.
- Add CDK pip bundling (--platform manylinux2014_aarch64 --only-binary=:all:) to
all four Lambdas so ARM64 wheels (reportlab, Pillow, pdfplumber) ship.
- Converge _retry_request across all four (fixes possibly-undefined return in
pdf-extract/pdf-generate).
- Add SigV4 signing regression tests.
Verified: ruff clean, infra tsc clean, aarch64 wheels resolve for all four,
23 pytest pass. GPT-4.1 cross-family review: no BLOCK (FIX + NIT applied).
2026-06-12 17:13:08 -04:00
252e52546e
chore: gitignore .NET publish output and tsbuildinfo
...
Deploy / Deploy to AWS (push) Waiting to run
Build artifacts (api/publish/, *.tsbuildinfo) were untracked-but-committable;
.NET publish output can include appsettings.*.json. Flagged by sh-build-review.
2026-06-12 16:06:47 -04:00
f502f8afc2
feat(web): apply Sea Haven Ops design system re-theme and layout fixes
...
Re-theme the MUI app from teal (#0B5A73) to the Sea Haven Ops neutral-navy
structure (#111827 ) with action-blue (#2563EB) as the sole brand accent, driven
through the theme tokens so all screens update consistently. Cards become
border-driven (no shadow); table headers gray-50; status/priority chips aligned
to design-system token values.
Layout fixes:
- Topbar: square bottom corners (was inheriting MuiPaper radius)
- Sidebar: remove duplicate user tag (already shown in topbar)
- Main: drop redundant ml that double-counted the persistent drawer width
- New Proposal form: center the constrained container (mx: auto)
2026-06-12 16:06:47 -04:00
2549ce3afc
Repo hygiene: PR labeler + README badges (INFRA-56/57)
2026-06-11 14:02:35 -04:00
Adam Moussa
a6dd20d66d
chore(deps): re-pause Dependabot version updates during development ( #109 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Restores the deliberate dev-pause from #86 . The 2026-06-05 audit
remediation raised these limits to 5 without knowing the pause was
intentional; the resulting 14 version-update PRs were closed unmerged.
Security updates are unaffected by this setting. Re-raise at V1.
2026-06-08 18:29:20 -04:00
Adam Moussa
38aebb5ebd
chore(ci): add aggregator job reporting the org-required 'ci / ci' context ( #108 )
...
Deploy / Deploy to AWS (push) Has been cancelled
proposal-system's seven CI jobs have distinct names, so the org ruleset's
required 'ci / ci' status check never reported here. The aggregator needs
all real CI jobs and fails if any failed or was cancelled. NOTE: this
check will be red until the pre-existing Python Lint/Tests failures
(INFRA-55) are fixed — it reports CI state honestly.
2026-06-05 15:11:48 -04:00
Adam Moussa
32c2d03c4c
chore(deps): remove blanket aws-cdk-lib dependabot ignore ( #107 )
...
Deploy / Deploy to AWS (push) Waiting to run
Per handbook Pinning Principle: exact pins are kept current by Dependabot version updates gated by CI + dependency review. Blanket ignores let pins rot (see today's fast-uri incident).
2026-06-05 13:59:51 -04:00
Adam Moussa
a342465036
fix(deps): pin aws-cdk-lib to ==2.257.0 ( #90 )
...
Deploy / Deploy to AWS (push) Waiting to run
* fix(deps): re-pin aws-cdk-lib to ==2.253.1
* fix(deps): pin aws-cdk-lib to 2.257.0 (exact)
2026-06-05 13:20:09 -04:00
Adam Moussa
1722b1b760
fix(deps): enable Dependabot PRs ( #88 )
...
Raise open-pull-requests-limit from 0 (disabled) to 5 for all 11
package ecosystems so Dependabot can open update PRs.
2026-06-05 12:51:45 -04:00
Adam Moussa
8b0eab00d7
chore(ci): bump actions/checkout to v6 ( #87 )
...
Bump all actions/checkout references to @v6 (org target). v4 runs on a
node runtime version that is being deprecated; v6 is the verified org
standard alongside configure-aws-credentials@v6.
Ref: engineering-handbook cicd.md (workflow standardization).
2026-06-05 12:42:19 -04:00
Adam Moussa
610c3ba339
Pause Dependabot version updates while in development ( #86 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Set open-pull-requests-limit to 0 on all 11 ecosystem entries so Dependabot
stops opening version-update PRs (which were being closed unactioned during
active development). Security updates are unaffected — they ignore this limit.
Revert the limits (or raise them) once the repo stabilizes.
2026-06-02 20:02:46 -04:00
dependabot[bot]
c07f644e08
build(deps-dev): bump tmp from 0.2.5 to 0.2.7 in /mobile ( #66 )
...
Deploy Mobile (iOS) / Build & Upload to TestFlight (push) Has been cancelled
Deploy / Deploy to AWS (push) Has been cancelled
Bumps [tmp](https://github.com/raszi/node-tmp ) from 0.2.5 to 0.2.7.
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md )
- [Commits](https://github.com/raszi/node-tmp/compare/v0.2.5...v0.2.7 )
---
updated-dependencies:
- dependency-name: tmp
dependency-version: 0.2.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:36:26 +00:00
dependabot[bot]
2959f7bc41
build(deps): bump @tanstack/react-query in /web ( #80 )
...
Bumps [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) from 5.100.11 to 5.100.14.
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.100.14/packages/react-query )
---
updated-dependencies:
- dependency-name: "@tanstack/react-query"
dependency-version: 5.100.14
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:34:11 +00:00
dependabot[bot]
ebcece420e
build(deps): bump @react-navigation/native in /mobile ( #81 )
...
Bumps [@react-navigation/native](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native ) from 7.2.4 to 7.2.5.
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native@7.2.5/packages/native/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native@7.2.5/packages/native )
---
updated-dependencies:
- dependency-name: "@react-navigation/native"
dependency-version: 7.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:34:08 +00:00
dependabot[bot]
987f3314bd
build(deps): bump react-router-dom from 7.15.1 to 7.16.0 in /web ( #78 )
...
Bumps [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom ) from 7.15.1 to 7.16.0.
- [Release notes](https://github.com/remix-run/react-router/releases )
- [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md )
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.16.0/packages/react-router-dom )
---
updated-dependencies:
- dependency-name: react-router-dom
dependency-version: 7.16.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:34:00 +00:00
dependabot[bot]
ba1b6bc22b
build(deps): update boto3 requirement in /lambdas/pdf-generate ( #76 )
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.14...1.43.18 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.18
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-30 04:33:57 +00:00