* feat(deploy): move dev application CD through Terraform
GitHub creates the immutable Elastic Beanstalk version; HCP Terraform is the only UpdateEnvironment caller via a guarded version_label run.
* fix: add permissions block for dependency-review workflow
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* fix(terraform): stop pinning the generated dev instance SG
---------
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* feat(terraform): add safe backend environment adoption
Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.
* ci(deploy): pause dev and staging deployments
Prevent application releases from racing Terraform adoption while retaining production deployment and validation.
* ci(deploy): require manual environment dispatch
* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`
The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.
CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding
* chore(deps): add `terraform` to renovate dependency coverage
* ci(deploy): drop unprovisioned prod dispatch path
* chore(renovate): add Renovate frontend overlay config
* chore: remove dependabot.yml config
* fix: add `github-actions` to `enabledManagers`
With the removal of this repositories `dependabot.yml`, a lack of `github-actions` within the config would leave a coverage gap on `actions/checkout`, `actions/setup-dotnet`, `actions/setup-node`, etc.
* fix(renovate): annotate pinned actions
---------
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>
* refactor(api): enforce service and data-service boundaries
* refactor(api): complete feature service boundaries
* refactor(identity): enforce service and data boundaries
* refactor(vendors): enforce service and data boundaries
* refactor(workorders): enforce service and data boundaries
* refactor(backend): enforce architecture and optimize dispatch
* style(backend): format changed architecture files
* fix(architecture): address backend review follow-ups
* fix(backend): sanitize exception disclosure in changed API endpoints
Replace raw exception-message disclosure (ex.Message) returned to API
callers with a stable sanitized public message plus correlated structured
internal logging, across the endpoints changed in this PR.
- Add SanitizedErrors helper: logs the original exception at Error with a
generated correlation id and returns a stable public message referencing
it so support can trace without exposing internals.
- Inject ILogger<T> into the 14 changed controllers and route every
ex.Message/dbex.Message disclosure through the helper, preserving status
codes, response shapes, and business data (e.g. OpenWorkOrders).
- Leave FluentValidation (vex.Errors) and existing fixed-message catches
untouched; out-of-scope controllers (Account/Contact/Employee/Asset/
PMSchedule) are unchanged.
- Add focused tests proving internal exception text is not returned and
that Error logging carrying the original exception is invoked.
* fix(architecture): abstract job run state access
* style: format board update service
* test: use collection assertion idiom
Add the callable PR labeler workflow. README badges skipped: no root
README.md exists in this repo (only BACKEND_ARCHITECTURE.md). Dependabot
unchanged.
Part of INFRA-47 (INFRA-56, INFRA-57).
* Add dependency-review caller workflow
Add a pull_request-triggered caller that invokes the org-level
callable-dependency-review workflow to scan dependency changes and
fail on high-severity advisories.
* chore: retrigger checks
* chore: retrigger dep review (post-fix)