Commit graph

8 commits

Author SHA1 Message Date
renovate[bot]
6a5c7d074d
chore(deps): update dependency vitest to v5 (#82)
* chore(deps): update dependency vitest to v5

* chore(deps): bump @vitest/coverage-v8 to v5

Keep coverage-v8 on the same major as vitest so npm can resolve peers and regenerate the lockfile.

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-09-25 20:19:36 +00:00
renovate[bot]
321c5a1389
chore(deps): update npm minor and patch (#78)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-17 15:22:58 +00:00
renovate[bot]
5ba5bea1f3
chore(deps): update npm minor and patch (#73)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-08-31 15:50:18 +00:00
renovate[bot]
54f59d593a
fix(deps): update npm minor and patch (#68) 2026-08-25 16:12:59 +00:00
dependabot[bot]
57d4f9a212
chore(deps-dev): bump typescript from 5.6.3 to 6.0.3 (#23)
Some checks failed
deploy / deploy (push) Has been cancelled
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.6.3 to 6.0.3.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/compare/v5.6.3...v6.0.3)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-06 23:54:04 +00:00
dependabot[bot]
dbdea98f69
chore(deps-dev): bump vitest and @vitest/coverage-v8 from 3.x to 4.1.10 (#13)
* chore(deps-dev): bump vitest from 3.2.7 to 4.1.10

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 3.2.7 to 4.1.10.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.10
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix: bump @vitest/coverage-v8 alongside vitest to 4.1.10

The vitest 4.x bump had a peer dependency conflict with @vitest/coverage-v8
still pinned at 3.x. Bump it in lockstep to resolve npm install errors.

Refs #13

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
2026-07-06 23:43:30 +00:00
Adam Moussa
0b1fe539d2
chore(deps): patch vitest/vite advisories and add dependabot (#6)
Some checks are pending
deploy / deploy (push) Waiting to run
Upgrade vitest to 3.2.7 across the monorepo, override vite to 6.4.3 for
the high-severity fs.deny advisory, and add weekly grouped Dependabot for
npm workspaces and GitHub Actions.
2026-07-06 16:54:50 -04:00
Adam Moussa
0d1fefb326
Phase 0b slice: monorepo scaffold + @sh-mcp/shared core + integration packages (#2)
Some checks are pending
deploy / deploy (push) Waiting to run
* Phase 0b slice: monorepo scaffold + shared core + integration packages

The 0a-INDEPENDENT code slice (one-shot via af-0b-package-slice workflow: Haiku
scaffold + Sonnet packages, Sonnet fix-to-green). Nothing deploys; no CDK/servers.

- Monorepo scaffold: npm workspaces, strict TS (NodeNext), vitest (80% gate),
  eslint 9 flat config, prettier; ci.yaml/deploy.yaml callers (Node 24, enable-qemu).
- @sh-mcp/shared: transport-agnostic core — Scope/AuthContext/ToolDef, ToolRegistry,
  redact()+maskValue() (PII), OpenAPI 3.1 generator. AUTH STUBBED behind an AuthProvider
  interface (TODO auth-layer-0a); JWT/aud/client_id/JWKS/deny-list deferred per design.md §2.
- 9 integration packages (qbo, google-maps, internal-data, payments, knowledge-base,
  gmail, calendar, tasks, reminders): tools against shared, external deps mocked behind
  injected client interfaces; finance handlers call redact().

Verified green: tsc -b clean, vitest 245/245, eslint 0 errors. Auth mechanism intentionally
deferred until the 0a spike resolves it (G16/§0.4).

* Complete Cognito auth provider + Phase 1 build brief

Finish the WIP CognitoAuthProvider (client_id allow-list as audience
boundary, finance TTL ceiling, deny-list, scope-prefix stripping) with
its test suite, and check in docs/build-plan-phase-1.md so the Phase 1
work has its governing brief in-tree (design.md §2.5).

* ci: disable cdk synth for Phase 0b (no CDK app yet)

The reusable ci-typescript-cdk workflow defaults run-cdk-synth: true, but
the Phase 0b package scaffold has no cdk.json or stacks, so cdk synth fails
with '--app is required'. Disable it here; Phase 1 re-enables it with the
server CDK stubs.
2026-06-26 12:42:17 -04:00