The org PR template pre-filled Summary / Validation / Tests / Notes here while
PRs in this repository use Summary / Changes and value / Ticket. A repo template
now overrides the org one, and the review framework gains the description
contract plus a note on the divergence from the org pr-policy workflow, which
is not wired in.
README: the CI badge tracked the retired dev branch; branches come from main,
not dev; the fix/ prefix replaces bug/; staging exists alongside dev; and PRs
now merge through the merge queue.
Cleanup: four PR description drafts under tmp/ were tracked; they are removed
and /tmp/ is ignored.
governance and Build and test are the required checks on main. A merge queue
only counts checks that ran on the merge_group event, so the workflow now
triggers on it. The governance gate reads the merge group's own base SHA
because github.event.before is empty there.
The org window (before 6am on Monday) has produced only one security PR in
this repository since the overlay landed, so the overlay now opens every
weekday morning. The github-actions manager is enabled so the digest-pinned
actions in the workflows follow the org's pinning and grouping rules. A regex
manager tracks the actionlint release installed by the governance job; it is
held for dashboard approval because the SHA256 pin next to it has to be
updated by hand.
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD
Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.
* ci: run Frontend checks and Terraform CI on PRs to main and dev
Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.
* refactor(terraform): keep live/dev and live/staging as HCP roots
Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.
* style: prettier terraform-validate.mjs
* fix(terraform): pin githubdeploy assume-role policy in import checker
Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
* fix(terraform): ignore origin response_completion_timeout in the release plan guard (SH-300)
AWS returns 0 when the timeout is unset. The provider writes null on
origin_path updates, so the first real CD plan failed closed.
* fix(ci): drop duplicate verify from the content CD workflow (SH-300)
Frontend checks already runs verify on PRs and pushes. Removing the
validate job also requires dropping needs: validate so dispatch can run.
* fix(terraform): equate origin timeout 0 and null only (SH-300)
Numeric timeout changes still fail closed. Rename the filter so it is
not read as an after_unknown allowlist.
* feat(terraform): ship dev content CD through Terraform (SH-300)
GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.
* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
* ci(terraform-isolation): re-evaluate the gate on label changes
* test(terraform-isolation): lock the ci.yaml label-event contract
* fix(terraform-isolation): do not treat terraform markdown as a mixed change
* fix(ci): do not skip Frontend checks on isolation label events
* ci(terraform-isolation): run label retriggers in a dedicated workflow
* fix: apply eslint formatting
* fix: apply additional missed eslint formatting
Governance now runs the import-plan checker tests, Terraform fmt and
validate for terraform/live/dev, the isolation gate tests, and the CDK
build, tests, and synth in both modes. A new terraform-isolation
workflow fails PRs that change terraform/** together with application
code; the terraform-isolation-override label is the reviewed exception.
Renovate gains the terraform manager.
Remove the push-to-dev trigger and the org cd-cdk.yaml caller so CI no
longer runs cdk deploy during the adoption. The workflow assumes the
pinned dev role and runs the simple scripts/deploy-web.sh against a
pinned bucket and distribution, which keeps content deploys working
after CloudFormation relinquishes the stack outputs. Staging is
untouched.
* chore(governance): make React/TS conventions mandatory via executable gates
Add AGENTS.md, QUALITY_GATES.md, ARCHITECTURE_AND_CODE_QUALITY.md, and
REVIEW_AND_PR_FRAMEWORK.md as the binding conventions and PR review
contract for humans and all coding/review agents.
Add a single 'npm run verify' command (format + lint + build + test +
governance) and 'npm run governance', which runs a dependency-free godfile
ratchet (whole-repo, baseline in scripts/governance-baseline.json) and a
changed-file maintainability gate (complexity<=20, function<=150, params<=4,
depth<=4) via ESLint. Legacy is handled by ratchets, not relaxation: 5
godfiles over 500 lines are grandfathered debt; maintainability thresholds
apply to changed TS/TSX (72 legacy violations across ~51 files otherwise).
Add a repo-owned 'governance' CI job that runs 'npm run verify' so every
gate is guaranteed from this repository, independent of the org reusable
workflow.
* fix(governance): make frontend ratchets fail closed
Self-contained CDK app (S3 + CloudFront + OIDC deploy role) deployed via the org reusable cd-cdk.yaml. Frontend served on dev.seahaven.com with the *.seahaven.com cert and a Route 53 apex alias; the SPA calls the dev backend directly at https://api.dev.seahaven.com/api.
Replace the inline 5-job ci.yml with a thin caller of the org reusable
workflow ci-typescript-frontend.yaml. The standards gate, changed-line
guard, format/lint/build, unit tests, and Playwright browser smoke now
live centrally in Sea-Haven-Industries/.github and are maintained once.
Renames ci.yml -> ci.yaml (kebab-case .yaml convention) and triggers on
pull_request and push to main and dev, so this branch keeps CI coverage.
The reusable workflow runs as a single `ci` job, so this caller emits the
`ci / ci` status context. Branch-protection rulesets for main and dev must
have their required checks switched from the old job names (Metadata and
standards, Code quality, Build, Unit tests, Browser smoke) to `ci / ci`.
Assign all files to the internal-dev team so every pull request needs an
approving review from an internal-dev member, giving internal engineering
oversight of changes. The org main-branch-protection ruleset enforces this
via required code-owner review; the internal-dev team has write access, so
it is an eligible code owner.
* chore: add eslint, prettier, husky and commitlint tooling
* ci: add GitHub Actions workflow for lint and build
* build: migrate from CRA to Vite with TypeScript config
* docs: add architecture plan and design system documentation
* fix: scope ESLint to new components and hooks directories
* feat: add HTTP client, query cache and shared utilities
* feat: add theme system and global application styles
* feat: add shared UI, layout and domain badge components
* feat: add auth domain, provider and login page
* feat: add app shell, file-based routing and bootstrap
* feat: add protected layout and dashboard module
* feat: add accounts CRUD module
* feat: add assets CRUD module
* feat: add contacts CRUD module
* feat: add employees CRUD module
* feat: add locations CRUD module
* feat: add calendar events module
* feat: add follow-ups CRUD module
* feat: add PM schedules CRUD module
* feat: add work orders module with dispatch modals
* feat: add vendors CRUD and portal token panel
* feat: add vendor purchase orders module
* feat: add uplifts queue module
* feat: add settings for dropdowns and task templates
* feat: add vendor portal routes and signature capture
* test: add Vitest setup and Playwright login e2e spec
* chore: remove legacy CRA pages, Redux store and JS hooks
* chore: update gitignore and env example for Vite
* docs: translate pt-BR docs and Cursor rules to English
* fix(ci): fix login e2e session mock and prettier formatting
* fix(build): use mjs router script for Node 20 CI compatibility
* chore: remove migration scripts and unused generouted router
* fix(auth): restore JWT and align CRUD with backend routes
* fix(api): add no-content helpers and align paths with backend
* fix(accounts): align detail and mutation payloads with backend
* fix(contacts): resolve detail via GetContacts and map address DTOs
* fix(work-orders): align routes, delete body, and create payload
* fix(vendors): delete vendors via REST route
* fix(pm-schedules): handle empty save and delete responses
* fix(employees): add fallbacks for detail and dropdown calls
* chore(calendar): disable routes until backend exists
* chore(env): switch tracked env vars to Vite prefixes
* fix(api): align frontend contracts with backend review findings
Correct Work Order getById query param, asset site options via Location API,
Employee JobTitleId payload, and remove stale API paths.
* fix(employees,pm-schedules): align forms with backend API contracts
Align PM Schedule form and save payload with PMSchedule_DTO fields.
Bind employee Job Title select to jobTitleId for create/update payloads.
Add regression tests for both flows.
* fix(pm-schedules): gate edit/delete for Dev API contract
Production Dev API exposes only GetList and Save.
Hide unsupported edit/delete UI and block the edit route.
Add regression tests for disabled actions.
* docs(env): document VITE_API_URL must include /api suffix
* refactor(api): extract shared API prefix URL resolution
* feat(build): fail build on misconfigured absolute VITE_API_URL
* test(api): cover API URL contract and prefix resolution
* feat(auth): disable login submit until email and password are valid
* test(auth): align login tests with disabled submit behavior
* Feat/ab/menu-and-header (#17)
* chore(deps): add lucide-react for layout icon migration
* feat(auth): add getPrimaryUserRole helper for header display
* style(theme): add sidebar active tokens and nav group typography
* refactor(menu): migrate nav icons to lucide and trim menu groups
* feat(layout): redesign sidebar, topbar, and admin shell viewport
* chore(menu): hide Reports and Documents from sidebar
---------
Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
* ci: add frontend PR quality baseline (#18)
* chore(deps): add lucide-react for layout icon migration
* feat(auth): add getPrimaryUserRole helper for header display
* style(theme): add sidebar active tokens and nav group typography
* refactor(menu): migrate nav icons to lucide and trim menu groups
* feat(layout): redesign sidebar, topbar, and admin shell viewport
* chore(menu): hide Reports and Documents from sidebar
* ci: add PR quality baseline checks
* ci: avoid self-matching standards guard
* ci: split frontend quality gates
---------
Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
---------
Co-authored-by: Arthur Bassi <arthur.winiarski.ranger@outlook.com>
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>