Adam Moussa
dfaee830f7
feat(contracts): shared api-contracts adoption, zod schemas, ProblemDetails codes ( #222 )
...
* feat(web): adopt SHOC design system and shell layout (ADR 0003)
Port shoc-frontend-new dev's design system with its CSS-variable
single-token-source mechanism:
- src/styles/theme.css: SHOC token file ported verbatim (Montserrat/
DM Sans/JetBrains Mono, primary #1c75bc, navy #262262 , full radius/
shadow/sidebar/header token layers); fonts self-hosted via @fontsource
- src/lib/theme/{css-vars,mui-theme}.ts: getCssVar -> createTheme
adapter mirroring SHOC's mui-theme.ts (palette, typography, shadows
tuple, component overrides; MUI v9 slot renames expressed as class
selectors); theme.ts is now a re-export
- Shell: SHOC composition (sidebar column + sticky gradient topbar +
scrolling main); sidebar 244px/76px collapse with brand header row,
grouped nav, SHOC active treatment (white card + 3px accent bar);
topbar 100-degree gradient, surface hamburger, gradient avatar pill
- Brand: SeahavenMark + BrandLockup ported (Tailwind re-expressed as
sx; wordmark subtitle localized to PROPOSAL SYSTEM)
- Login: SHOC auth-card treatment (centered 384px card on #f9fafb)
- Old "Sea Haven Ops" Inter/#2563EB theme and Nunito remnants removed;
remaining hardcoded hexes replaced with tokens; lucide-react for
shell/nav icons per SHOC convention
Verify: tsc clean, 26/26 vitest, vite build OK; Playwright screenshots
pixel-sampled against the extracted SHOC spec (all hard values exact,
no blocking deviations).
* feat(contracts): adopt shared api-contracts in web, add zod schemas and ProblemDetails codes
Closes WEB-M5 (web hand-duplicated wire types, standing drift risk):
- shared/api-contracts: rewritten as the authoritative superset of the
.NET DTOs (ProposalListItem/ProposalDetail with poNumber and
submittedByName, line item requests, customers, pricing library,
dashboard, audit, sites, auth, presigned upload, ApiProblem); stale
Proposal/UpdateLineItemsRequest shapes removed
- shared/api-contracts/src/schemas.ts: zod runtime schemas coupled to
every wire type via `satisfies z.ZodType<T>` (schema/type drift is now
a compile error); separate entrypoint so type-only consumers (mobile)
never pull zod
- web: imports @proposal-system/api-contracts (file: dep + tsconfig
paths + vite preserveSymlinks); all 7 lib/api modules re-export shared
types so page imports stay stable; enum unions tightened
(PricingLibraryPage form state now ServiceCategory-typed)
- fix(web): customer create/update sent a singular `address` field the
API silently dropped (contract is addresses: string[], CustomerDtos.cs)
- addresses now round-trip, extra addresses preserved on edit
- api: ProblemDetails responses carry a machine-readable top-level
`code` (SHOC error-code vocabulary): ValidationFailed,
InvalidStateTransition, NotFound, Unauthorized, InternalError; new
BusinessRuleException(code, message) maps to 422 with its code;
GlobalExceptionHandlerTests cover the full mapping (wire contract)
Cross-checked .NET DTOs vs TS types vs zod schemas with the
orchestrator scanner (Gemini): core domains consistent; internal-only
DTOs (FileDtos vendor/lambda surface, SimilarProposalDtos, UserDtos
admin surface) intentionally uncovered.
Verify: dotnet 166/166, web tsc + vitest 26/26 + build, mobile tsc,
shared tsc all green.
* fix(web): install shared api-contracts deps via postinstall
Web Frontend Check failed on PR #222 : tsc compiles
shared/api-contracts/src/schemas.ts through the tsconfig path alias,
and module resolution for its zod import walks up from shared/, never
reaching web/node_modules. CI only ran npm ci in web/, so the shared
package's deps were absent. A postinstall hook installs them wherever
web's deps are installed (CI typecheck, web-test, deploy bundling).
Passed locally only because a stray repo-root node_modules/zod
satisfied the lookup.
2026-07-13 19:28:33 -04:00
Adam Moussa
8ce2a5cd8f
feat(web): adopt SHOC design system and shell layout (ADR 0003) ( #221 )
...
Port shoc-frontend-new dev's design system with its CSS-variable
single-token-source mechanism:
- src/styles/theme.css: SHOC token file ported verbatim (Montserrat/
DM Sans/JetBrains Mono, primary #1c75bc, navy #262262 , full radius/
shadow/sidebar/header token layers); fonts self-hosted via @fontsource
- src/lib/theme/{css-vars,mui-theme}.ts: getCssVar -> createTheme
adapter mirroring SHOC's mui-theme.ts (palette, typography, shadows
tuple, component overrides; MUI v9 slot renames expressed as class
selectors); theme.ts is now a re-export
- Shell: SHOC composition (sidebar column + sticky gradient topbar +
scrolling main); sidebar 244px/76px collapse with brand header row,
grouped nav, SHOC active treatment (white card + 3px accent bar);
topbar 100-degree gradient, surface hamburger, gradient avatar pill
- Brand: SeahavenMark + BrandLockup ported (Tailwind re-expressed as
sx; wordmark subtitle localized to PROPOSAL SYSTEM)
- Login: SHOC auth-card treatment (centered 384px card on #f9fafb)
- Old "Sea Haven Ops" Inter/#2563EB theme and Nunito remnants removed;
remaining hardcoded hexes replaced with tokens; lucide-react for
shell/nav icons per SHOC convention
Verify: tsc clean, 26/26 vitest, vite build OK; Playwright screenshots
pixel-sampled against the extracted SHOC spec (all hard values exact,
no blocking deviations).
2026-07-13 19:06:51 -04:00
Adam Moussa
a4b09eb0ad
docs: SHOC-alignment Phase 1 — ADRs, governance files, doc corrections ( #220 )
...
- Add ADR 0002 (SHOC merge boundary: separate backend services, shared
conventions) and ADR 0003 (adopt SHOC design system + UI/UX layout)
- Add CODEOWNERS (internal-dev) and PR template (Summary/Test plan/Jira/
docs-current checklist + contract-table convention)
- Fix stale facts in README/CLAUDE.md: MUI v7→v9, RN 0.85→0.86,
OpenSearch Serverless/oss-index-creator → Aurora pgvector/
aurora-pgvector-init (ADR 0001), test counts 149→186 (123 xUnit /
26 vitest / 37 pytest), deploy triggers are workflow_dispatch-only,
reusable workflow refs float on @main, aws-cdk-lib version claim
replaced with Dependabot-maintained note
2026-07-13 17:00:45 -04:00
Adam Moussa
536d440282
chore(security): add repo-local suppressions for adjudicated FPs ( #219 )
...
Moves proof-or-kill-verified false positives (Fastfile runtime PEM-assembly
boilerplate; Podfile.lock CocoaPods SPEC CHECKSUMs) from machine-level to a
tracked repo-local .security-review/suppressions.json so the Open SWE
daily-report automation resolves them. Justifications sanitized to avoid
reproducing the begin-marker literal. Machine-level copy retained until merge.
2026-07-13 14:30:51 -04:00
Adam Moussa
3960983956
Merge pull request #214 from Sea-Haven-Industries/dependabot/pip/lambdas/pdf-generate/boto3-gte-1.43.46-and-lt-2.0
2026-07-11 10:44:09 -04:00
Adam Moussa
e83a380382
Merge pull request #218 from Sea-Haven-Industries/dependabot/pip/lambdas/aurora-pgvector-init/boto3-gte-1.43.46-and-lt-2.0
2026-07-11 10:40:26 -04:00
Adam Moussa
67b304c20f
Merge pull request #217 from Sea-Haven-Industries/dependabot/pip/lambdas/library-ingest/boto3-gte-1.43.46-and-lt-2.0
2026-07-11 10:39:41 -04:00
Adam Moussa
fa0d22fbd7
Merge pull request #216 from Sea-Haven-Industries/dependabot/pip/lambdas/pdf-extract/boto3-gte-1.43.46-and-lt-2.0
2026-07-11 10:38:43 -04:00
Adam Moussa
1b5a2a666e
Merge pull request #215 from Sea-Haven-Industries/dependabot/pip/lambdas/suggestions/boto3-gte-1.43.46-and-lt-2.0
2026-07-11 10:37:59 -04:00
Adam Moussa
d3051b1dea
Merge branch 'main' into dependabot/pip/lambdas/pdf-generate/boto3-gte-1.43.46-and-lt-2.0
2026-07-11 10:36:52 -04:00
Adam Moussa
ae94960f5a
Merge pull request #213 from Sea-Haven-Industries/dependabot/npm_and_yarn/infra/infra-a5c93e662f
2026-07-11 10:36:38 -04:00
dependabot[bot]
71e0eb2e6d
build(deps): update boto3 requirement in /lambdas/aurora-pgvector-init
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.46
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:18 +00:00
dependabot[bot]
da3e87ab6b
build(deps): update boto3 requirement in /lambdas/library-ingest
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.46
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:08 +00:00
dependabot[bot]
8fb8800036
build(deps): update boto3 requirement in /lambdas/pdf-extract
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.46
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:06 +00:00
dependabot[bot]
e81593f3a9
build(deps): update boto3 requirement in /lambdas/suggestions
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.46
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:05 +00:00
dependabot[bot]
2288815607
build(deps): update boto3 requirement in /lambdas/pdf-generate
...
Updates the requirements on [boto3](https://github.com/boto/boto3 ) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases )
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46 )
---
updated-dependencies:
- dependency-name: boto3
dependency-version: 1.43.46
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:03 +00:00
dependabot[bot]
6a43d571cb
build(deps-dev): bump aws-cdk in /infra in the infra group
...
Bumps the infra group in /infra with 1 update: [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk ).
Updates `aws-cdk` from 2.1129.0 to 2.1130.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases )
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1130.0/packages/aws-cdk )
---
updated-dependencies:
- dependency-name: aws-cdk
dependency-version: 2.1130.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: infra
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:32:54 +00:00
Adam Moussa
bc4961f8bb
Merge pull request #212 from Sea-Haven-Industries/chore/bump-babel-core
...
chore: pin @babel/core >=7.29.6 in mobile and web
2026-07-10 16:25:09 -04:00
Adam Moussa
9e72f9f47e
chore: bump babel/core
...
Bump babel core to be > @babel/core@7.29.6 and @babel/core@8.0.0-rc.6 to satisfy CVE-2026-49356
2026-07-10 20:18:11 +00:00
Adam Moussa
605faebbd8
Merge pull request #211 from Sea-Haven-Industries/chore/combine-dependabot-prs
...
build(deps): combine open Dependabot updates into one PR
2026-07-08 16:55:21 -04:00
6692f856bc
fix(infra): run CDK app via tsx to support TypeScript 7
...
TypeScript 7.0.2 (the native-port build) no longer exposes the internal
compiler API (ts.sys) that ts-node@10.9.2 depends on, so
`npx ts-node bin/app.ts` fails during `cdk synth` with
"Cannot read properties of undefined (reading 'fileExists')".
Switch the CDK app runner to tsx (esbuild-based, version-agnostic — it
does not consume the typescript package's programmatic API), and pin tsx
as an infra devDependency. Verified `cdk synth` succeeds locally with
typescript 7.0.2 installed.
2026-07-08 16:51:54 -04:00
dd058f7170
build(deps): combine open Dependabot updates into one PR
...
Consolidates the 15 open Dependabot PRs (#195–#209) into a single branch.
Python (lambdas):
- boto3 -> >=1.43.43,<2.0 in suggestions, library-ingest, pdf-generate,
pdf-extract, aurora-pgvector-init (#203 , #205 , #206 , #208 , #204 )
- tests: pytest >=9.1.1 (#198 , major), pytest-mock >=3.15.1 (#197 ),
moto >=5.2.2 (#200 ), httpx >=0.28.1 (#195 )
npm:
- infra: @types/node ^25.9.5 (#196 ), typescript ~7.0.2 (#199 , major)
- web: vitest ^4.1.10 (#202 ), typescript ~7.0.2 (#207 , major)
- shared/api-contracts: typescript ~7.0.2 (#201 , major)
Ruby (mobile):
- bundler group: cocoapods 1.17.0, fastlane 2.237.0 + transitive (#209 )
Note: TypeScript 5.7 -> 7.0.2 and pytest 8 -> 9.1.1 are major bumps;
relying on CI to validate.
2026-07-08 16:46:43 -04:00
Adam Moussa
350ca2c3c1
Merge pull request #210 from Sea-Haven-Industries/dependabot/npm_and_yarn/mobile/mobile-npm-7d4fe87b33
...
build(deps): bump the mobile-npm group in /mobile with 5 updates
2026-07-08 16:42:09 -04:00
dependabot[bot]
07bdd6ac42
build(deps): bump the mobile-npm group in /mobile with 5 updates
...
Bumps the mobile-npm group in /mobile with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [@react-navigation/bottom-tabs](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/bottom-tabs ) | `7.18.7` | `7.18.8` |
| [@react-navigation/native](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native ) | `7.3.7` | `7.3.8` |
| [@react-navigation/native-stack](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native-stack ) | `7.17.9` | `7.17.10` |
| [amazon-cognito-identity-js](https://github.com/aws-amplify/amplify-js ) | `6.3.18` | `6.3.20` |
| [react-native-app-auth](https://github.com/FormidableLabs/react-native-app-auth ) | `8.4.0` | `8.4.1` |
Updates `@react-navigation/bottom-tabs` from 7.18.7 to 7.18.8
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/bottom-tabs@7.18.8/packages/bottom-tabs/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/bottom-tabs@7.18.8/packages/bottom-tabs )
Updates `@react-navigation/native` from 7.3.7 to 7.3.8
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native@7.3.8/packages/native/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native@7.3.8/packages/native )
Updates `@react-navigation/native-stack` from 7.17.9 to 7.17.10
- [Release notes](https://github.com/react-navigation/react-navigation/releases )
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native-stack@7.17.10/packages/native-stack/CHANGELOG.md )
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native-stack@7.17.10/packages/native-stack )
Updates `amazon-cognito-identity-js` from 6.3.18 to 6.3.20
- [Release notes](https://github.com/aws-amplify/amplify-js/releases )
- [Commits](https://github.com/aws-amplify/amplify-js/compare/amazon-cognito-identity-js@6.3.18...amazon-cognito-identity-js@6.3.20 )
Updates `react-native-app-auth` from 8.4.0 to 8.4.1
- [Release notes](https://github.com/FormidableLabs/react-native-app-auth/releases )
- [Commits](https://github.com/FormidableLabs/react-native-app-auth/compare/react-native-app-auth@8.4.0...react-native-app-auth@8.4.1 )
---
updated-dependencies:
- dependency-name: "@react-navigation/bottom-tabs"
dependency-version: 7.18.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: "@react-navigation/native"
dependency-version: 7.3.8
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: "@react-navigation/native-stack"
dependency-version: 7.17.10
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: amazon-cognito-identity-js
dependency-version: 6.3.20
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: mobile-npm
- dependency-name: react-native-app-auth
dependency-version: 8.4.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: mobile-npm
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-07-08 20:37:53 +00:00
Adam Moussa
367ba68dda
Merge pull request #194 from Sea-Haven-Industries/INFRA-130-dependabot-coverage
...
INFRA-130: repair Dependabot coverage
2026-07-08 16:35:46 -04:00
328ca575ec
ci: expand dependabot coverage (INFRA-130)
2026-07-08 16:31:26 -04:00
Adam Moussa
c5bbd238e2
Merge pull request #193 from Sea-Haven-Industries/feature/combine-vite-plugin-react-updates
2026-07-04 16:23:23 -04:00
amoussa1229
58a485c462
chore: re-trigger CI
2026-07-04 18:22:38 +00:00
dependabot[bot]
59a4c1d2fa
build(deps): bump the infra group in /infra with 3 updates ( #186 )
2026-07-04 14:11:31 -04:00
dependabot[bot]
d3761942e7
build(deps): update boto3 requirement in /lambdas/library-ingest ( #187 )
2026-07-04 14:11:07 -04:00
dependabot[bot]
0e342a2892
build(deps): bump the mobile-npm group in /mobile with 6 updates ( #190 )
2026-07-04 14:10:44 -04:00
dependabot[bot]
cac18d6b16
Bump the api group with 1 update ( #192 )
2026-07-04 14:10:10 -04:00
Adam Moussa
f5747d1154
Merge branch 'main' into feature/combine-vite-plugin-react-updates
2026-07-04 14:08:37 -04:00
dependabot[bot]
90183d94f7
build(deps): update boto3 requirement in /lambdas/pdf-extract ( #185 )
2026-07-04 13:55:09 +00:00
dependabot[bot]
0daf8182bf
build(deps): update boto3 requirement in /lambdas/suggestions ( #184 )
2026-07-04 13:46:56 +00:00
dependabot[bot]
63c8b9f877
build(deps): update boto3 requirement in /lambdas/pdf-generate ( #183 )
2026-07-04 13:42:07 +00:00
amoussa1229
65c4c01fb1
feat(deps): bump vite to 8.1.3 and @vitejs/plugin-react to 6.0.3
...
Update both packages together so peer dependencies are compatible:
@vitejs/plugin-react 6.x supports Vite 8, resolving the ERESOLVE
conflict from #191 where vite was upgraded alone.
2026-07-04 13:34:47 +00:00
dependabot[bot]
d88edd11e0
build(deps): bump the web group across 1 directory with 2 updates ( #188 )
2026-07-04 13:22:23 +00:00
dependabot[bot]
57e371e470
build(deps): bump the mui group in /web with 2 updates ( #182 )
2026-07-04 09:16:29 -04:00
dependabot[bot]
9c9b5a4947
build(deps): bump faraday from 1.10.5 to 1.10.6 in /mobile ( #181 )
...
Bumps [faraday](https://github.com/lostisland/faraday ) from 1.10.5 to 1.10.6.
- [Release notes](https://github.com/lostisland/faraday/releases )
- [Changelog](https://github.com/lostisland/faraday/blob/main/CHANGELOG.md )
- [Commits](https://github.com/lostisland/faraday/compare/v1.10.5...v1.10.6 )
---
updated-dependencies:
- dependency-name: faraday
dependency-version: 1.10.6
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 19:46:16 -04:00
Adam Moussa
63422608c7
chore(ci): track .github reusable workflows on @main ( #173 )
...
Switches all reusable-workflow references from the frozen SHA
c040bfaa (INF-M8 supply-chain pin) to @main, matching every other repo
in the org. This lets proposal-system pick up the actions/checkout v6->v7
bump (and future reusable-workflow changes) automatically instead of
staying frozen on the pre-bump commit.
Note: this intentionally reverses the INF-M8 SHA-pin hardening for
consistency with the rest of the org's @main convention.
2026-06-25 11:55:29 -04:00
dependabot[bot]
86c3dd6db9
build(deps): bump axios in /web in the web group across 1 directory ( #171 )
...
Bumps the web group with 1 update in the /web directory: [axios](https://github.com/axios/axios ).
Updates `axios` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.18.0...v1.18.1 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.18.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: web
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 20:17:11 +00:00
dependabot[bot]
63eb22a22a
build(deps): bump axios ( #170 )
...
Bumps the mobile-npm group with 1 update in the /mobile directory: [axios](https://github.com/axios/axios ).
Updates `axios` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.18.0...v1.18.1 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.18.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: mobile-npm
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 20:12:07 +00:00
dependabot[bot]
c558520a79
build(deps-dev): bump aws-cdk in /infra in the infra group ( #169 )
...
Bumps the infra group in /infra with 1 update: [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk ).
Updates `aws-cdk` from 2.1128.0 to 2.1128.1
- [Release notes](https://github.com/aws/aws-cdk-cli/releases )
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1128.1/packages/aws-cdk )
---
updated-dependencies:
- dependency-name: aws-cdk
dependency-version: 2.1128.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: infra
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 20:07:17 +00:00
Adam Moussa
36fc1120bf
build(deps): upgrade MUI to v9 (material + icons) and group @mui/* in Dependabot ( #168 )
...
Bump @mui/material and @mui/icons-material 7.3.1 -> ^9.1.1 together in
/web. They must move in lockstep (icons peer-depends on material), so
Dependabot's separate per-package PRs (#145/#146) could never go green
individually (ERESOLVE). Adds a 'mui' Dependabot group so future @mui/*
updates — including majors — are raised as one PR.
MUI v9 migration fixes (v7->v9 spans two majors):
- ListItemText: primaryTypographyProps -> slotProps.primary; fontSize
moved into sx (Typography system props removed in v9).
- Autocomplete renderInput: params.InputProps -> params.slotProps.input;
spread ...params.slotProps to retain inputLabel/htmlInput slots.
- Icons: @mui/icons-material/ErrorOutline -> ErrorOutlined (the plain
ErrorOutline export was removed in v9).
- vitest: inline @mui/material + react-transition-group so Vite resolves
v9's Transition.mjs directory import (native ESM loader can't).
Verified locally on Node 24: npm ci, npm run build, and npm test
(26 tests, 3 suites) all pass.
2026-06-22 16:02:43 -04:00
dependabot[bot]
433198c4e8
Bump xunit.runner.visualstudio from 2.8.2 to 3.1.5 ( #162 )
...
---
updated-dependencies:
- dependency-name: xunit.runner.visualstudio
dependency-version: 3.1.5
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 19:47:23 +00:00
dependabot[bot]
b1a330e916
Bump Microsoft.NET.Test.Sdk from 17.14.1 to 18.6.0 ( #160 )
...
---
updated-dependencies:
- dependency-name: Microsoft.NET.Test.Sdk
dependency-version: 18.6.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 19:40:47 +00:00
dependabot[bot]
4db44777a7
chore(deps): bump concurrent-ruby from 1.3.6 to 1.3.7 in /mobile ( #166 )
...
Bumps [concurrent-ruby](https://github.com/ruby-concurrency/concurrent-ruby ) from 1.3.6 to 1.3.7.
- [Release notes](https://github.com/ruby-concurrency/concurrent-ruby/releases )
- [Changelog](https://github.com/ruby-concurrency/concurrent-ruby/blob/master/CHANGELOG.md )
- [Commits](https://github.com/ruby-concurrency/concurrent-ruby/compare/v1.3.6...v1.3.7 )
---
updated-dependencies:
- dependency-name: concurrent-ruby
dependency-version: 1.3.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 15:33:50 -04:00
Adam Moussa
091a5da385
chore: disable auto-deploy workflows (manual dispatch only) ( #167 )
...
Remove push-to-main triggers from deploy.yaml (backend/CDK) and
deploy-mobile.yaml (iOS/TestFlight), leaving workflow_dispatch only.
CDK is not yet deployed; pausing auto-deploy until ready. Revert this
PR to re-enable.
2026-06-22 14:48:04 -04:00
dependabot[bot]
dce5979046
chore(deps-dev): bump @babel/core from 7.29.0 to 7.29.7 in /web ( #165 )
...
Deploy / Deploy to AWS (push) Has been cancelled
Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core ) from 7.29.0 to 7.29.7.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v7.29.7/packages/babel-core )
---
updated-dependencies:
- dependency-name: "@babel/core"
dependency-version: 7.29.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:55:36 -04:00