Commit graph

252 commits

Author SHA1 Message Date
e55f3fe1e6
docs: ADR 0004 (optimistic-concurrency convention) + README contract and deploy notes 2026-07-13 21:21:19 -04:00
9632c1048c
fix: resolve Phase 6c gate findings (2 high, 5 low) across api, web, lambda, mobile
Gemini scanner sweep (token-bypass), GPT-4.1 cross-review, and the
6-detector /sh-security-review fan-out ran against 6acfdab..HEAD; every
confirmed finding fixed:

HIGH (deployment blockers, logic detector):
- CONC-L1: suggestions lambda's bulk line-item PUT sent no
  proposalVersion — every AI suggestion job would 422 and be silently
  swallowed. Now fetches the proposal's rowVersion, echoes it, and
  retries once with a fresh token on 409. Pytest updated (38 green).
- CONC-L2: mobile admin surface (update/approve/send/revise, bulk line
  items) sent no tokens — the entire mobile admin workflow would 422.
  Tokens threaded through mobile api layer + workspace/line-item
  screens with 409 refetch handling. tsc clean.

MEDIUM-adjacent (scanner):
- VendorProposalsController: the VendorTotalCost write on Proposal now
  bumps Version (was a silent lost-update path bypassing the guard).
- FilesController: GeneratePDF audit staged into the same SaveChanges.

LOW (detectors):
- 409 envelope is schema-validated client-side
  (proposalConcurrencyConflictSchema.safeParse) and id-checked before
  seeding the react-query cache; malformed state degrades to
  invalidation (INJ-409-01/WEB-CONC-L1).
- ProposalConcurrencyException.CurrentState typed ProposalResponse?
  so an EF entity can never serialize into the 409 body (SC-1).
- Guard caller contract documented + GuardedEndpointAuthorizationTests
  reflection tripwire: guard-reaching endpoints must stay admin-gated
  (AUTHZ-CG-01).
- Pre-check currentState now loads display navigations so both 409
  paths return the same shape (CONC-L3).
- Save chain's trailing getById failure no longer misreports a
  committed save; falls back to invalidation (CONC-L4).

Also caught during fix verification: the handler's manual currentState
serialization lacked JsonStringEnumConverter — enums would serialize
as numbers, client schema validation would reject every guarded 409,
and the state would always be discarded. Now matches the MVC pipeline
and is pinned by a wire test.

193 xUnit / 70 vitest / 38 pytest green; mobile + shared tsc clean;
Playwright smoke 2/2.
2026-07-13 21:20:12 -04:00
d6404edefc
feat(contracts+web): thread concurrency tokens and 409 conflict handling through the domain layer
Phase 6b of the SHOC-alignment plan — client side of the optimistic-concurrency
wire contract shipped in 6a.

shared/api-contracts (additive):
- rowVersion: string on ProposalListItem, ProposalDetail, and LineItem
- proposalVersion?: string on UpdateProposalRequest and
  BulkUpdateLineItemsRequest; new ProposalVersionRequest
- ConcurrencyConflict<T> { message, currentState } — the SHOC ADR 0004
  409 envelope (guarded path; the unguarded fallback carries no state)
- matching zod schemas, all kept under the satisfies z.ZodType<T> coupling

web:
- lib/api/errors.ts: ConflictError carrying the server's reloaded
  currentState; client.ts interceptor throws it on 409 (WEB-M2 401
  handling untouched)
- guarded mutations read the token from the cached proposal detail at
  mutate time; the save flow chains rotated tokens (PUT response token
  into the bulk replace) and ends with a detail refetch so
  approve-after-save never sends a stale version
- 409 recovery in the admin use-cases: write currentState into the
  detail cache, invalidateProposalViews() (stale-queue invariant holds
  on the failure path too), and toast the conflict instead of the
  generic failure message
- e2e smoke mock payloads carry rowVersion; vitest coverage for the
  interceptor ConflictError paths, token threading/rotation, and 409
  cache recovery

Verified: shared typecheck, web tsc/vitest (69)/build/prettier/Playwright
smoke, mobile tsc (create-only, no changes needed).
2026-07-13 21:01:46 -04:00
a4e59040d6
test(api): concurrency, codec, 409 wire-shape, and audit-atomicity coverage
- ProposalConcurrencyTests (shared-connection SQLite, two competing
  writers): stale-token pre-check with embedded currentState, DB-level
  lost race reloading the winner's values, 422 token codes, version
  bump on success, bulk-update proposal-token guard, line-item create
  bumping the aggregate, audit rows never persisted on a lost race.
- GlobalExceptionHandlerTests: pin both SHOC 409 envelopes verbatim
  (guarded { message, currentState } incl. null state; fallback
  { status, message, code }) and assert shape exclusivity.
- RowVersionCodecTests: round-trip, SHOC-style token literal,
  malformed/wrong-length rejection.
- Existing suites threaded with live version tokens (Ver helper);
  audit assertions moved from LogAsync to Stage.

187 xUnit green (was 166).
2026-07-13 20:48:28 -04:00
85bca54e08
feat(api): optimistic concurrency on the proposal aggregate + atomic audit staging
Phase 6a of the SHOC-alignment plan (ADR 0004, wire contract extracted
verbatim from shoc-backend PRs #10/#13-#18).

Concurrency (SHOC double-guard, Postgres port):
- long Version on Proposal + LineItem, IsConcurrencyToken, additive
  migration AddProposalLineItemVersion (DEFAULT 1; Up/Down inspected —
  no drift, exactly two AddColumn/DropColumn).
- Tokens are opaque base64 strings on the wire (RowVersionCodec:
  8-byte big-endian long), rowVersion on responses, proposalVersion on
  guarded requests. Missing -> 422 ProposalVersionRequired; malformed
  -> 422 InvalidRowVersion (BusinessRuleException carrier).
- Guarded: update, approve, return-to-review, send, revise, and bulk
  line-item update (proposal-level token — bulk replaces the item set
  wholesale, so per-item tokens are meaningless; deviation from the
  plan documented). Creates/deletes unguarded per SHOC precedent but
  bump the aggregate version.
- Conflict -> 409 { message, currentState } (SHOC envelope, reloaded
  row embedded); bare DbUpdateConcurrencyException -> 409
  { status, message, code } fallback. Both non-ProblemDetails,
  emitted by GlobalExceptionHandler.

Audit atomicity (stage-then-single-SaveChanges):
- IAuditService.Stage adds to the shared context without saving;
  every proposal/line-item mutation stages before its own single
  SaveChangesAsync, so mutation + audit commit or fail together.
  LogAsync (self-saving) remains for standalone events (downloads,
  role changes, delivery).
2026-07-13 20:48:28 -04:00
6acfdabc8c
style(web): prettier format pass (mechanical)
npx prettier --write . with the new .prettierrc (singleQuote,
printWidth 100). No functional changes — enforced by format:check in
CI from this PR on.
2026-07-13 20:14:47 -04:00
191f710752
ci(web): Phase 5 — prettier check + Playwright smoke via org frontend workflow
Converts the web CI job from ci-typescript-cdk.yaml (typecheck only) to
ci-typescript-frontend.yaml: format:check, build (tsc -b included),
vitest, and a Playwright chromium smoke. Folds the standalone Web Tests
job into it (aggregator needs updated). Pure CI — no AWS secrets.

The smoke (e2e/smoke.spec.ts) drives dev-login → dashboard shell →
proposal list, plus the unauthenticated bounce, against a fully mocked
API (pathname-anchored route interception — a '**/api/**' glob would
swallow vite's /src/lib/api/* module URLs). Config mirrors SHOC's
playwright.config.ts (port 4173, chromium, dev-server webServer).

Prettier: singleQuote + printWidth 100 to match the existing codebase
style; lint intentionally not added (no ESLint config yet — run-lint
false, out of Phase 5 scope). rollback = revert this workflow file.
2026-07-13 20:14:41 -04:00
97cc26b03e
docs: web stack row reflects auth-context refactor (Redux removed, MUI v9) 2026-07-13 19:44:14 -04:00
5441836274
fix(web): harden auth session teardown per /sh-security-review findings
- AUTH-L1 (confirmed medium): logout() now clears the react-query cache —
  the singleton cache survived SPA logout, serving the previous
  principal's cached GETs to the next login in the same tab for up to
  staleTime with no server round-trip.
- AUTH-L3 (confirmed low): isTokenValid decodes base64url before atob —
  valid Cognito JWTs containing '-'/'_' in the payload segment were
  misclassified as expired (login lockout/loop; inherited from the old
  authSlice).
- AUTH-L2 (unverified, hardened anyway): 401 interceptor broadcasts
  AUTH_SESSION_CLEARED_EVENT so AuthProvider drops in-memory state
  synchronously, restoring the old Redux atomic-clear semantics.
- INJ-1 (unverified, hardened anyway): Authorization header only set
  when the stored token is a string.

Each fix pinned by a test; 63 vitest green, tsc clean.
2026-07-13 19:43:48 -04:00
8fbca7f780
refactor(web): fold Redux auth/ui slices into SHOC-shape auth context + storage module
Phase 4 tail of the SHOC-alignment plan. Matches SHOC's auth shape
(lib/auth storage module + providers/ context split) while keeping the
deliberate divergences:

- sessionStorage, not localStorage (WEB-C1 stands; SHOC's localStorage
  is on the SHOULD-NOT-ALIGN list)
- token acquisition stays in the auth pages (Cognito code exchange /
  dev-login) — the provider only owns session state
- 401 interceptor clears storage directly (WEB-M2 behavior preserved;
  full-page redirect resets provider state)

Sidebar open state moves to plain layout state in App passed down as
props (SHOC (protected)/_layout.tsx pattern), keeping localStorage
persistence. Drops @reduxjs/toolkit and react-redux.

Tests: authSlice tests replaced by authStorage + AuthProvider suites
(QA-C5 coverage preserved); client interceptor tests updated for the
storage-based 401 path. 59 vitest green, tsc clean, vite build OK.
Verified end-to-end headless: login redirect, seeded-session shell,
sidebar toggle persistence, logout, expired/malformed token handling,
RoleGuard bounce; recipe persisted as web/.claude/skills/verify.
2026-07-13 19:31:40 -04:00
1f55a59445
fix(web): apply Phase 4 code-review findings (10 correctness + 4 cleanup)
Correctness:
- State-transition mutations now invalidate every cached view via
  invalidateProposalViews (detail + line items + lists + stats + admin
  dashboard) — approving no longer leaves a stale queue for the
  5-minute staleTime
- Presigned S3 PUT moved to proposals/api.ts with res.ok check — a
  rejected upload is no longer confirmed as uploaded
- toCustomerRequest always sends contactEmail ('' clears); API create
  path normalizes empty->null to match the update path — customer
  emails can now be cleared from the UI
- Shared Number-based numeric form fields (domain/shared/formFields):
  '12abc' no longer silently coerces to 12 in the pricing library
- Customer create/update invalidate customersKeys.all so cached search
  autocompletes see new customers
- AdminWorkspace clears dirty right after a successful implicit save,
  before approve — no false unsaved-changes prompt when approve fails
- ProposalFormPage submit gate and missing-fields caption derive from
  ONE checks list (missing customer is now listed)
- Empty states gated on !err in ProposalListPage/AdminDashboard — no
  contradictory error + 'no proposals' UI
- VendorDataPanel migrated to useVendorProposals (kills the divergent
  ['vendorProposals', id] cache key and the inline apiClient query)
- useCustomerList/usePricingLibraryList get keepPreviousData — no
  TablePagination out-of-range flash on page change

Cleanup:
- Dead speculative hooks removed (useCreate/BulkUpdate/DeleteLineItem,
  useUpdateProposal, useProposalHistory/Audit, lineItemRowFormSchema,
  toUpdateLineItemEntry); tests moved to the live save path
  (useSaveProposalWorkspace)
- Shared useDebouncedValue hook replaces 4 drifted inline debounce
  copies (one leaked its timer on unmount, two hardcoded 300ms);
  DEBOUNCE_AUTOCOMPLETE=300 named
- Fix: WEB-H5 / WEB-H6 finding-ID markers restored at the relocated
  onError handlers (CLAUDE.md traceability)
- shared/api-contracts gains an exports map; /schemas resolver alias
  deduplicated from 3 copies to the tsconfig paths mapping

Verify: tsc clean, vitest 51/51 (tests updated to pin the new
invalidation/mapper behavior + new '12abc' rejection test),
vite build OK, dotnet 166/166.
2026-07-13 19:06:08 -04:00
2e1099a560
refactor(web): finish domain-layer integration — migrate straggler components, delete legacy api modules
- SimilarProposalsPanel -> useSimilarProposals (domain/admin); inline
  SimilarProposal type replaced by domain/admin/types (identical shape);
  query key joins the admin hierarchical key space
- LineItemEditor type imports -> domain/lineItems/types
- Delete now-orphaned lib/api/{proposals,lineItems,customers,
  pricingLibrary,admin,sites}.ts, constants/queryKeys.ts,
  hooks/usePaginatedList.ts (lib/api/client.ts + auth.ts stay per
  domain README rule 5)

Verify: tsc clean, vitest 52/52, build OK, Playwright smoke of the
authed shell renders on domain hooks.
2026-07-13 18:11:05 -04:00
f456006c30
test(web): domain use-case hook coverage 2026-07-13 18:08:52 -04:00
d1c7e812f6
refactor(web): dashboards on domain layer 2026-07-13 18:08:52 -04:00
b7c6386aca
refactor(web): pricing library on domain layer + react-hook-form 2026-07-13 18:08:52 -04:00
e0261f0cee
refactor(web): customer management on domain layer + react-hook-form 2026-07-13 18:08:52 -04:00
f1087aa82d
refactor(web): admin workspace on domain layer 2026-07-13 18:08:52 -04:00
97fa7f2b75
refactor(web): proposal pages on domain layer, proposal form on react-hook-form 2026-07-13 18:08:52 -04:00
e6e2c60c2f
feat(web): scaffold domain module layer (proposals, lineItems, customers, pricingLibrary, admin, sites)
Additive-only: pages still use lib/api/* and constants/queryKeys.ts until
the page-migration agents run. Each domain ships api.ts (HTTP moved from
lib/api), types.ts (contract re-exports + view types), schemas.ts (contract
schema re-exports + form schemas with toRequest mappers), and use-cases.ts
(TanStack Query v5 hooks + hierarchical query keys, mirroring current page
invalidations and toast-on-error behavior).

Adds an explicit vite/vitest alias for the
@proposal-system/api-contracts/schemas subpath (package has no exports map)
plus a schema/mapper smoke test suite.
2026-07-13 17:58:19 -04:00
924bfdd8f6
feat(web): domain-layer conventions doc + react-hook-form deps (Phase 4 prep) 2026-07-13 17:47:05 -04:00
8dc8f7814b
feat(contracts): adopt shared api-contracts in web, add zod schemas and ProblemDetails codes
Closes WEB-M5 (web hand-duplicated wire types, standing drift risk):

- shared/api-contracts: rewritten as the authoritative superset of the
  .NET DTOs (ProposalListItem/ProposalDetail with poNumber and
  submittedByName, line item requests, customers, pricing library,
  dashboard, audit, sites, auth, presigned upload, ApiProblem); stale
  Proposal/UpdateLineItemsRequest shapes removed
- shared/api-contracts/src/schemas.ts: zod runtime schemas coupled to
  every wire type via `satisfies z.ZodType<T>` (schema/type drift is now
  a compile error); separate entrypoint so type-only consumers (mobile)
  never pull zod
- web: imports @proposal-system/api-contracts (file: dep + tsconfig
  paths + vite preserveSymlinks); all 7 lib/api modules re-export shared
  types so page imports stay stable; enum unions tightened
  (PricingLibraryPage form state now ServiceCategory-typed)
- fix(web): customer create/update sent a singular `address` field the
  API silently dropped (contract is addresses: string[], CustomerDtos.cs)
  - addresses now round-trip, extra addresses preserved on edit
- api: ProblemDetails responses carry a machine-readable top-level
  `code` (SHOC error-code vocabulary): ValidationFailed,
  InvalidStateTransition, NotFound, Unauthorized, InternalError; new
  BusinessRuleException(code, message) maps to 422 with its code;
  GlobalExceptionHandlerTests cover the full mapping (wire contract)

Cross-checked .NET DTOs vs TS types vs zod schemas with the
orchestrator scanner (Gemini): core domains consistent; internal-only
DTOs (FileDtos vendor/lambda surface, SimilarProposalDtos, UserDtos
admin surface) intentionally uncovered.

Verify: dotnet 166/166, web tsc + vitest 26/26 + build, mobile tsc,
shared tsc all green.
2026-07-13 17:19:42 -04:00
42eedc1c49
feat(web): adopt SHOC design system and shell layout (ADR 0003)
Port shoc-frontend-new dev's design system with its CSS-variable
single-token-source mechanism:

- src/styles/theme.css: SHOC token file ported verbatim (Montserrat/
  DM Sans/JetBrains Mono, primary #1c75bc, navy #262262, full radius/
  shadow/sidebar/header token layers); fonts self-hosted via @fontsource
- src/lib/theme/{css-vars,mui-theme}.ts: getCssVar -> createTheme
  adapter mirroring SHOC's mui-theme.ts (palette, typography, shadows
  tuple, component overrides; MUI v9 slot renames expressed as class
  selectors); theme.ts is now a re-export
- Shell: SHOC composition (sidebar column + sticky gradient topbar +
  scrolling main); sidebar 244px/76px collapse with brand header row,
  grouped nav, SHOC active treatment (white card + 3px accent bar);
  topbar 100-degree gradient, surface hamburger, gradient avatar pill
- Brand: SeahavenMark + BrandLockup ported (Tailwind re-expressed as
  sx; wordmark subtitle localized to PROPOSAL SYSTEM)
- Login: SHOC auth-card treatment (centered 384px card on #f9fafb)
- Old "Sea Haven Ops" Inter/#2563EB theme and Nunito remnants removed;
  remaining hardcoded hexes replaced with tokens; lucide-react for
  shell/nav icons per SHOC convention

Verify: tsc clean, 26/26 vitest, vite build OK; Playwright screenshots
pixel-sampled against the extracted SHOC spec (all hard values exact,
no blocking deviations).
2026-07-13 16:47:17 -04:00
Adam Moussa
536d440282
chore(security): add repo-local suppressions for adjudicated FPs (#219)
Moves proof-or-kill-verified false positives (Fastfile runtime PEM-assembly
boilerplate; Podfile.lock CocoaPods SPEC CHECKSUMs) from machine-level to a
tracked repo-local .security-review/suppressions.json so the Open SWE
daily-report automation resolves them. Justifications sanitized to avoid
reproducing the begin-marker literal. Machine-level copy retained until merge.
2026-07-13 14:30:51 -04:00
Adam Moussa
3960983956
Merge pull request #214 from Sea-Haven-Industries/dependabot/pip/lambdas/pdf-generate/boto3-gte-1.43.46-and-lt-2.0 2026-07-11 10:44:09 -04:00
Adam Moussa
e83a380382
Merge pull request #218 from Sea-Haven-Industries/dependabot/pip/lambdas/aurora-pgvector-init/boto3-gte-1.43.46-and-lt-2.0 2026-07-11 10:40:26 -04:00
Adam Moussa
67b304c20f
Merge pull request #217 from Sea-Haven-Industries/dependabot/pip/lambdas/library-ingest/boto3-gte-1.43.46-and-lt-2.0 2026-07-11 10:39:41 -04:00
Adam Moussa
fa0d22fbd7
Merge pull request #216 from Sea-Haven-Industries/dependabot/pip/lambdas/pdf-extract/boto3-gte-1.43.46-and-lt-2.0 2026-07-11 10:38:43 -04:00
Adam Moussa
1b5a2a666e
Merge pull request #215 from Sea-Haven-Industries/dependabot/pip/lambdas/suggestions/boto3-gte-1.43.46-and-lt-2.0 2026-07-11 10:37:59 -04:00
Adam Moussa
d3051b1dea
Merge branch 'main' into dependabot/pip/lambdas/pdf-generate/boto3-gte-1.43.46-and-lt-2.0 2026-07-11 10:36:52 -04:00
Adam Moussa
ae94960f5a
Merge pull request #213 from Sea-Haven-Industries/dependabot/npm_and_yarn/infra/infra-a5c93e662f 2026-07-11 10:36:38 -04:00
dependabot[bot]
71e0eb2e6d
build(deps): update boto3 requirement in /lambdas/aurora-pgvector-init
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:18 +00:00
dependabot[bot]
da3e87ab6b
build(deps): update boto3 requirement in /lambdas/library-ingest
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:08 +00:00
dependabot[bot]
8fb8800036
build(deps): update boto3 requirement in /lambdas/pdf-extract
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:06 +00:00
dependabot[bot]
e81593f3a9
build(deps): update boto3 requirement in /lambdas/suggestions
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:05 +00:00
dependabot[bot]
2288815607
build(deps): update boto3 requirement in /lambdas/pdf-generate
Updates the requirements on [boto3](https://github.com/boto/boto3) to permit the latest version.
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](https://github.com/boto/boto3/compare/1.43.43...1.43.46)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:33:03 +00:00
dependabot[bot]
6a43d571cb
build(deps-dev): bump aws-cdk in /infra in the infra group
Bumps the infra group in /infra with 1 update: [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk` from 2.1129.0 to 2.1130.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1130.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk
  dependency-version: 2.1130.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: infra
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-11 04:32:54 +00:00
Adam Moussa
bc4961f8bb
Merge pull request #212 from Sea-Haven-Industries/chore/bump-babel-core
chore: pin @babel/core >=7.29.6 in mobile and web
2026-07-10 16:25:09 -04:00
Adam Moussa
9e72f9f47e chore: bump babel/core
Bump babel core to be > @babel/core@7.29.6 and @babel/core@8.0.0-rc.6 to satisfy CVE-2026-49356
2026-07-10 20:18:11 +00:00
Adam Moussa
605faebbd8
Merge pull request #211 from Sea-Haven-Industries/chore/combine-dependabot-prs
build(deps): combine open Dependabot updates into one PR
2026-07-08 16:55:21 -04:00
6692f856bc
fix(infra): run CDK app via tsx to support TypeScript 7
TypeScript 7.0.2 (the native-port build) no longer exposes the internal
compiler API (ts.sys) that ts-node@10.9.2 depends on, so
`npx ts-node bin/app.ts` fails during `cdk synth` with
"Cannot read properties of undefined (reading 'fileExists')".

Switch the CDK app runner to tsx (esbuild-based, version-agnostic — it
does not consume the typescript package's programmatic API), and pin tsx
as an infra devDependency. Verified `cdk synth` succeeds locally with
typescript 7.0.2 installed.
2026-07-08 16:51:54 -04:00
dd058f7170
build(deps): combine open Dependabot updates into one PR
Consolidates the 15 open Dependabot PRs (#195–#209) into a single branch.

Python (lambdas):
- boto3 -> >=1.43.43,<2.0 in suggestions, library-ingest, pdf-generate,
  pdf-extract, aurora-pgvector-init (#203, #205, #206, #208, #204)
- tests: pytest >=9.1.1 (#198, major), pytest-mock >=3.15.1 (#197),
  moto >=5.2.2 (#200), httpx >=0.28.1 (#195)

npm:
- infra: @types/node ^25.9.5 (#196), typescript ~7.0.2 (#199, major)
- web: vitest ^4.1.10 (#202), typescript ~7.0.2 (#207, major)
- shared/api-contracts: typescript ~7.0.2 (#201, major)

Ruby (mobile):
- bundler group: cocoapods 1.17.0, fastlane 2.237.0 + transitive (#209)

Note: TypeScript 5.7 -> 7.0.2 and pytest 8 -> 9.1.1 are major bumps;
relying on CI to validate.
2026-07-08 16:46:43 -04:00
Adam Moussa
350ca2c3c1
Merge pull request #210 from Sea-Haven-Industries/dependabot/npm_and_yarn/mobile/mobile-npm-7d4fe87b33
build(deps): bump the mobile-npm group in /mobile with 5 updates
2026-07-08 16:42:09 -04:00
dependabot[bot]
07bdd6ac42
build(deps): bump the mobile-npm group in /mobile with 5 updates
Bumps the mobile-npm group in /mobile with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [@react-navigation/bottom-tabs](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/bottom-tabs) | `7.18.7` | `7.18.8` |
| [@react-navigation/native](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native) | `7.3.7` | `7.3.8` |
| [@react-navigation/native-stack](https://github.com/react-navigation/react-navigation/tree/HEAD/packages/native-stack) | `7.17.9` | `7.17.10` |
| [amazon-cognito-identity-js](https://github.com/aws-amplify/amplify-js) | `6.3.18` | `6.3.20` |
| [react-native-app-auth](https://github.com/FormidableLabs/react-native-app-auth) | `8.4.0` | `8.4.1` |


Updates `@react-navigation/bottom-tabs` from 7.18.7 to 7.18.8
- [Release notes](https://github.com/react-navigation/react-navigation/releases)
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/bottom-tabs@7.18.8/packages/bottom-tabs/CHANGELOG.md)
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/bottom-tabs@7.18.8/packages/bottom-tabs)

Updates `@react-navigation/native` from 7.3.7 to 7.3.8
- [Release notes](https://github.com/react-navigation/react-navigation/releases)
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native@7.3.8/packages/native/CHANGELOG.md)
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native@7.3.8/packages/native)

Updates `@react-navigation/native-stack` from 7.17.9 to 7.17.10
- [Release notes](https://github.com/react-navigation/react-navigation/releases)
- [Changelog](https://github.com/react-navigation/react-navigation/blob/@react-navigation/native-stack@7.17.10/packages/native-stack/CHANGELOG.md)
- [Commits](https://github.com/react-navigation/react-navigation/commits/@react-navigation/native-stack@7.17.10/packages/native-stack)

Updates `amazon-cognito-identity-js` from 6.3.18 to 6.3.20
- [Release notes](https://github.com/aws-amplify/amplify-js/releases)
- [Commits](https://github.com/aws-amplify/amplify-js/compare/amazon-cognito-identity-js@6.3.18...amazon-cognito-identity-js@6.3.20)

Updates `react-native-app-auth` from 8.4.0 to 8.4.1
- [Release notes](https://github.com/FormidableLabs/react-native-app-auth/releases)
- [Commits](https://github.com/FormidableLabs/react-native-app-auth/compare/react-native-app-auth@8.4.0...react-native-app-auth@8.4.1)

---
updated-dependencies:
- dependency-name: "@react-navigation/bottom-tabs"
  dependency-version: 7.18.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: mobile-npm
- dependency-name: "@react-navigation/native"
  dependency-version: 7.3.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: mobile-npm
- dependency-name: "@react-navigation/native-stack"
  dependency-version: 7.17.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: mobile-npm
- dependency-name: amazon-cognito-identity-js
  dependency-version: 6.3.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: mobile-npm
- dependency-name: react-native-app-auth
  dependency-version: 8.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: mobile-npm
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-08 20:37:53 +00:00
Adam Moussa
367ba68dda
Merge pull request #194 from Sea-Haven-Industries/INFRA-130-dependabot-coverage
INFRA-130: repair Dependabot coverage
2026-07-08 16:35:46 -04:00
328ca575ec
ci: expand dependabot coverage (INFRA-130) 2026-07-08 16:31:26 -04:00
Adam Moussa
c5bbd238e2
Merge pull request #193 from Sea-Haven-Industries/feature/combine-vite-plugin-react-updates 2026-07-04 16:23:23 -04:00
amoussa1229
58a485c462 chore: re-trigger CI 2026-07-04 18:22:38 +00:00
dependabot[bot]
59a4c1d2fa
build(deps): bump the infra group in /infra with 3 updates (#186) 2026-07-04 14:11:31 -04:00
dependabot[bot]
d3761942e7
build(deps): update boto3 requirement in /lambdas/library-ingest (#187) 2026-07-04 14:11:07 -04:00
dependabot[bot]
0e342a2892
build(deps): bump the mobile-npm group in /mobile with 6 updates (#190) 2026-07-04 14:10:44 -04:00