dependabot[bot]
96b9587fe1
build(deps): bump @notionhq/client in the minor-and-patch group ( #32 )
...
Bumps the minor-and-patch group with 1 update: [@notionhq/client](https://github.com/makenotion/notion-sdk-js ).
Updates `@notionhq/client` from 5.20.0 to 5.21.0
- [Release notes](https://github.com/makenotion/notion-sdk-js/releases )
- [Commits](https://github.com/makenotion/notion-sdk-js/compare/v5.20.0...v5.21.0 )
---
updated-dependencies:
- dependency-name: "@notionhq/client"
dependency-version: 5.21.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-12 12:32:30 +00:00
dependabot[bot]
ae899b9d6f
build(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 ( #26 )
...
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder ) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-builder/compare/v1.1.5...v1.2.0 )
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 22:27:58 +00:00
dependabot[bot]
8394d6c21c
build(deps): bump the minor-and-patch group with 5 updates ( #24 )
...
Bumps the minor-and-patch group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib ) | `2.252.0` | `2.253.1` |
| [@aws-sdk/client-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-dynamodb ) | `3.1041.0` | `3.1045.0` |
| [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb ) | `3.1041.0` | `3.1045.0` |
| [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk ) | `2.1120.0` | `2.1121.0` |
| [esbuild](https://github.com/evanw/esbuild ) | `0.25.12` | `0.28.0` |
Updates `aws-cdk-lib` from 2.252.0 to 2.253.1
- [Release notes](https://github.com/aws/aws-cdk/releases )
- [Changelog](https://github.com/aws/aws-cdk/blob/v2.253.1/CHANGELOG.v2.alpha.md )
- [Commits](https://github.com/aws/aws-cdk/commits/v2.253.1/packages/aws-cdk-lib )
Updates `@aws-sdk/client-dynamodb` from 3.1041.0 to 3.1045.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases )
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-dynamodb/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1045.0/clients/client-dynamodb )
Updates `@aws-sdk/lib-dynamodb` from 3.1041.0 to 3.1045.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases )
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1045.0/lib/lib-dynamodb )
Updates `aws-cdk` from 2.1120.0 to 2.1121.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases )
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1121.0/packages/aws-cdk )
Updates `esbuild` from 0.25.12 to 0.28.0
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.25.12...v0.28.0 )
---
updated-dependencies:
- dependency-name: aws-cdk-lib
dependency-version: 2.253.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/client-dynamodb"
dependency-version: 3.1045.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/lib-dynamodb"
dependency-version: 3.1045.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: minor-and-patch
- dependency-name: aws-cdk
dependency-version: 2.1121.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: minor-and-patch
- dependency-name: esbuild
dependency-version: 0.28.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 22:27:48 +00:00
dependabot[bot]
54d5aa8a20
build(deps): bump fast-xml-builder in /services/socket-mode ( #23 )
...
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder ) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-builder/compare/v1.1.5...v1.2.0 )
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-08 22:27:09 +00:00
Adam Moussa
50da33712b
Set explicit arm64 platform on Docker image build ( #30 )
...
fromAsset() builds for the host architecture by default. On x86_64
GitHub Actions runners, this produces an x86 image even with QEMU
installed — the Fargate ARM64 task then fails with exec format error.
2026-05-08 17:58:28 -04:00
Adam Moussa
94a837c08c
Enable QEMU for arm64 Docker builds ( #29 )
...
Fargate task runs ARM64 but GHA runner is x86_64 — without QEMU
the Docker image gets built for the wrong architecture, causing
exec format error at container startup.
2026-05-08 17:48:19 -04:00
Adam Moussa
78ecba68ae
Add GitHub Actions deploy workflow ( #28 )
...
* Add GitHub Actions deploy workflow (OIDC)
* Add permissions block for OIDC token exchange
* Add concurrency control to prevent parallel deploys
2026-05-08 17:08:12 -04:00
Adam Moussa
bcd01d9918
Add CI workflow ( #27 )
2026-05-08 15:52:56 -04:00
Adam Moussa
a75dbfd359
Update Dependabot: remove assignees, group minor/patch updates ( #22 )
2026-05-08 14:22:03 -04:00
Adam Moussa
11b5ccbf7f
Remove wrapper workflow — using required workflow via org ruleset ( #21 )
2026-05-06 19:58:56 -04:00
Adam Moussa
77e7dcfe46
Upgrade to TypeScript ~6.0.3 ( #19 )
...
* Upgrade to TypeScript 6.0.3 and @types/node 25.6.0
TS 6 requires explicit node type resolution — added "types": ["node"]
to tsconfig.json to resolve path and __dirname globals.
* Pin typescript to ~6.0.3 and @types/node to ^22
TS doesn't follow semver — use tilde to avoid surprise minor-release
breakage. Keep @types/node on v22 to match Lambda NODEJS_22_X runtime.
* Regenerate lockfile with npm 11.14.0
Fixes corrupted peer:true flags on direct dependencies caused by
npm <11.6.3 bug (npm/cli#8690 ).
* Trigger CI
* Trigger CI
* Trigger CI
* Add id-token: write permission for claude-code-action
* Trigger CI
2026-05-06 19:56:57 -04:00
Adam Moussa
a2477f4c57
Add id-token: write permission for claude-code-action ( #20 )
2026-05-06 19:47:30 -04:00
dependabot[bot]
95115dcf38
build(deps): bump @notionhq/client from 2.3.0 to 5.20.0 ( #15 )
...
Bumps [@notionhq/client](https://github.com/makenotion/notion-sdk-js ) from 2.3.0 to 5.20.0.
- [Release notes](https://github.com/makenotion/notion-sdk-js/releases )
- [Commits](https://github.com/makenotion/notion-sdk-js/compare/v2.3.0...v5.20.0 )
---
updated-dependencies:
- dependency-name: "@notionhq/client"
dependency-version: 5.20.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-06 18:37:05 -04:00
dependabot[bot]
1fd51c9f18
build(deps): bump aws-cdk-lib from 2.248.0 to 2.252.0 ( #11 )
...
Bumps [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib ) from 2.248.0 to 2.252.0.
- [Release notes](https://github.com/aws/aws-cdk/releases )
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md )
- [Commits](https://github.com/aws/aws-cdk/commits/v2.252.0/packages/aws-cdk-lib )
---
updated-dependencies:
- dependency-name: aws-cdk-lib
dependency-version: 2.252.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-05-06 18:22:53 -04:00
dependabot[bot]
ab80e6c251
build(deps-dev): bump aws-cdk from 2.1118.0 to 2.1120.0 ( #12 )
...
Bumps [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk ) from 2.1118.0 to 2.1120.0.
- [Release notes](https://github.com/aws/aws-cdk-cli/releases )
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1120.0/packages/aws-cdk )
---
updated-dependencies:
- dependency-name: aws-cdk
dependency-version: 2.1120.0
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
2026-05-06 18:22:49 -04:00
Adam Moussa
f011108971
Add Claude Code review workflow ( #18 )
2026-05-06 18:12:07 -04:00
Adam Moussa
52d26e89c0
Merge pull request #16 from Sea-Haven-Industries/feature/dependabot-auto-assign
...
Auto-assign Dependabot PRs
2026-05-02 17:28:09 -04:00
Adam Moussa
9bdfceca28
Auto-assign Dependabot PRs to amoussa1229
2026-05-02 17:26:17 -04:00
Adam Moussa
1f243e2ab1
Merge pull request #14 from Sea-Haven-Industries/dependabot/npm_and_yarn/aws-sdk/lib-dynamodb-3.1041.0
...
build(deps-dev): bump @aws-sdk/lib-dynamodb from 3.1030.0 to 3.1041.0
2026-05-02 17:23:36 -04:00
dependabot[bot]
9115495f3a
build(deps-dev): bump @aws-sdk/lib-dynamodb from 3.1030.0 to 3.1041.0
...
Bumps [@aws-sdk/lib-dynamodb](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-dynamodb ) from 3.1030.0 to 3.1041.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases )
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-dynamodb/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1041.0/lib/lib-dynamodb )
---
updated-dependencies:
- dependency-name: "@aws-sdk/lib-dynamodb"
dependency-version: 3.1041.0
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-02 21:17:42 +00:00
Adam Moussa
d4c1973004
Merge pull request #10 from Sea-Haven-Industries/feature/add-dependabot-config
...
Add Dependabot version update configuration
2026-05-02 17:15:44 -04:00
Adam Moussa
d43b7974b4
Add Dependabot version update configuration
2026-05-02 17:14:23 -04:00
Adam Moussa
423c68584f
Merge pull request #9 from Sea-Haven-Industries/feature/alex-rollout
...
feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions
2026-04-30 18:57:23 -04:00
Adam Moussa
e7b421e4cf
fix: flat DM replies, clean up debug logging
...
DMs now reply flat in conversation instead of threading. Channel
@mentions still thread. Removed verbose debug logging from socket-mode
service, kept minimal operational logs. Added .DS_Store to gitignore.
2026-04-30 18:37:08 -04:00
Adam Moussa
5a9d588ebe
fix: add package-lock.json for socket-mode Docker build
2026-04-30 16:44:55 -04:00
Adam Moussa
006dbf7c6b
feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions
...
- Rename bot to Alex with friendly/professional persona (Bedrock Agent instruction rewrite)
- Replace HTTP webhook Lambda with ECS Fargate Socket Mode service (persistent WebSocket)
- Add payment/invoice lookup via PaymentsDashboard table (vendor, invoice, check search)
- Switch from manual SiteAssignments to auto-populated verified-sites table
- Add channel support via app_mention events (threaded replies)
- Add App Home tab with Block Kit capabilities view
- Add unanswered questions logging to seahaven-unanswered-questions DynamoDB table
- Fix pre-existing compliance: add arm64 + 60-day log retention to all Lambdas
- Remove webhook Lambda and seed-sites script (both obsolete)
2026-04-30 16:38:54 -04:00
Adam Moussa
3a3e2dc14f
Merge pull request #8 from Sea-Haven-Industries/dependabot/npm_and_yarn/multi-b112b4ff1d
...
build(deps): bump fast-xml-parser and @aws-sdk/xml-builder
2026-04-30 12:55:39 -04:00
dependabot[bot]
36e202d7fe
build(deps): bump fast-xml-parser and @aws-sdk/xml-builder
...
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser ) and [@aws-sdk/xml-builder](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/xml-builder ). These dependencies needed to be updated together.
Updates `fast-xml-parser` from 5.5.8 to 5.7.2
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases )
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.8...v5.7.2 )
Updates `@aws-sdk/xml-builder` from 3.972.17 to 3.972.21
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases )
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/xml-builder/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/xml-builder )
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.7.2
dependency-type: indirect
- dependency-name: "@aws-sdk/xml-builder"
dependency-version: 3.972.21
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-04-28 18:26:26 +00:00
Adam Moussa
26598e8fff
Update README with QBO OAuth flow, VPC, and static IP details
2026-04-13 20:26:06 -04:00
Adam Moussa
d1b91ae661
Read OAuth client credentials from Secrets Manager at runtime
...
Removes CloudFormation dynamic references for clientId/clientSecret
env vars. Credentials are now fetched from Secrets Manager at runtime
so secret updates don't require a redeploy.
2026-04-13 20:22:21 -04:00
Adam Moussa
9463a07e50
Use Intuit discovery document for OAuth endpoints
...
Fetch authorization, token, and revocation endpoints from Intuit's
.well-known/openid_configuration at runtime instead of hardcoding.
Cached per Lambda instance for performance.
2026-04-13 19:59:23 -04:00
Adam Moussa
066ff59d22
Place QBO Lambdas in VPC for static outbound IP
...
Puts qbo-lookup and qbo-oauth Lambdas in seahaven-vpc private subnets
so all outbound traffic routes through NAT Gateway (52.202.83.13).
Required for Intuit app listing IP allowlist.
2026-04-13 19:51:00 -04:00
Adam Moussa
266fe833fd
Fix Intuit security compliance issues
...
- CSRF: store OAuth state in Secure/HttpOnly cookie, validate on callback
- Cache-Control: add no-cache, no-store headers to all responses
- Sensitive info: callback errors now 302 redirect instead of returning HTML
- Logging: remove realmId and sanitize error logs to prevent QBO data leaks
2026-04-13 19:49:29 -04:00
Adam Moussa
acfe8185a9
Add QBO OAuth endpoints for QuickBooks app listing
...
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.
2026-04-13 19:31:13 -04:00
Adam Moussa
fb026dfd72
Add Amazon site assignments lookup via DynamoDB
...
- Create SiteAssignments DynamoDB table with state GSI for site code and
state-based queries
- Add lookup_site function to wo-po-lookup action group lambda
- Add seed script (scripts/seed-sites.ts) to load site CSV into DynamoDB
- Upload site list markdown to KB S3 bucket for semantic search
- Update agent instruction to include site lookup capability
- Update README with site assignment docs and maintenance notes
2026-04-13 19:11:39 -04:00
Adam Moussa
8cb762d055
Fix agent identity: clarify that we ARE Sea Haven, not an external vendor
...
The bot was suggesting Sea Haven as a vendor to contact because it didn't
understand it belongs to Sea Haven. Updated system prompt to make clear
that Sea Haven is our company and "local vendor" means a subcontractor.
2026-04-13 18:50:35 -04:00
Adam Moussa
8b6e65bd20
Improve Slack formatting for WO/PO lookups
...
- Add markdown-to-Slack mrkdwn conversion in processor (** → *, ## → bold)
- Restructure lambda output with cleaner sections and date formatting
- Update agent instruction to present data concisely
2026-04-13 18:34:47 -04:00
Adam Moussa
24ebe8bdcc
Add WO/PO direct lookup action group for reliable ID-based queries
...
Vector search couldn't match exact work order/PO numbers, so queries
always came back empty. This adds a dedicated lambda that queries
DynamoDB directly by ID, wired as a Bedrock Agent action group.
2026-04-13 17:59:47 -04:00
Adam Moussa
5943b775eb
Update agent alias description to force version bump on deploy
2026-04-13 17:15:11 -04:00
Adam Moussa
510834533b
Add work order and purchase order lookups to Bedrock agent instructions
...
The agent's system prompt and KB description didn't mention WO/PO data,
so it refused queries even though the data was already in the knowledge base.
2026-04-13 17:05:26 -04:00
Adam Moussa
8c71d8267c
docs: update README for PO and work order KB syncs
...
ref #4 — documents the new po-sync and workorder-sync Lambdas,
EventBridge schedules, DynamoDB data sources, and manual trigger
instructions.
2026-04-13 15:42:27 -04:00
Adam Moussa
1dc275dee4
Merge pull request #7 from Sea-Haven-Industries/feature/workorder-kb-sync
...
feat: work orders → Bedrock KB sync
2026-04-13 15:38:20 -04:00
Adam Moussa
40216430c6
Merge master after PO sync PR merge
2026-04-13 15:38:13 -04:00
Adam Moussa
50d5c3cc81
Merge pull request #6 from Sea-Haven-Industries/feature/po-kb-sync
...
Tested: 9,279 POs synced, 0 failures, KB ingestion clean
2026-04-13 15:37:29 -04:00
Adam Moussa
641494530b
fix: concurrent uploads and overwrite-in-place sync strategy
...
- Upload S3 files 10x concurrently instead of sequentially
- Replace clear-then-write with overwrite-in-place + delete stale
to avoid S3 404s during concurrent KB ingestion jobs
2026-04-13 15:36:16 -04:00
Adam Moussa
adbe19aa16
fix: concurrent uploads, overwrite-in-place, 15min timeout
...
- Bump Lambda timeout from 5min to 15min (9k+ POs need more time)
- Upload S3 files 25x concurrently instead of sequentially
- Replace clear-then-write with overwrite-in-place + delete stale
to avoid S3 404s during concurrent KB ingestion jobs
2026-04-13 15:36:07 -04:00
Adam Moussa
7240147736
feat: daily work orders DynamoDB → Bedrock KB sync
...
Add a new Lambda and CDK construct that scans the WorkOrders and
WorkOrderComments DynamoDB tables (owned by workorder-ingest),
converts each work order + comment history to markdown, uploads
to S3 under the work-orders/ prefix, and triggers a Bedrock
Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
2026-04-13 14:35:47 -04:00
Adam Moussa
615970eba2
feat: daily purchase-orders DynamoDB → Bedrock KB sync
...
Add a new Lambda and CDK construct that scans the purchase-orders
DynamoDB table (owned by po-ingest), converts each PO to markdown,
uploads to S3 under the purchase-orders/ prefix, and triggers a
Bedrock Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
2026-04-13 14:33:53 -04:00
2dba68c14d
Merge feature/notion-kb-sync into master
...
Daily Notion → Bedrock KB sync: EventBridge cron triggers notion-sync
Lambda which exports Office Operations pages to S3 and kicks off KB
ingestion. Runs at 02:00 UTC. Refs #4
2026-04-13 00:01:44 -04:00
f254776ba6
docs: update README for Notion KB sync
...
Documents the notion-sync Lambda, daily EventBridge schedule, Notion
secret setup, and updated project structure.
Refs #4
2026-04-13 00:00:39 -04:00