diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..a6a86e8 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,24 @@ +# Audit COMP-007: keep dependencies and CI actions current. Updates arrive as PRs through the normal flow (CI + review); +# `develop` is the production branch, so nothing here deploys on its own. +version: 2 +updates: + - package-ecosystem: npm + directory: / + target-branch: develop + schedule: + interval: weekly + day: monday + open-pull-requests-limit: 5 + groups: + minor-and-patch: + update-types: [minor, patch] + commit-message: + prefix: "chore(deps)" + - package-ecosystem: github-actions + directory: / + target-branch: develop + schedule: + interval: weekly + day: monday + commit-message: + prefix: "chore(ci)" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 65f899c..425d86f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,9 +19,9 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 with: node-version-file: .nvmrc cache: npm diff --git a/eslint.config.mjs b/eslint.config.mjs index 5248082..5cbe259 100644 --- a/eslint.config.mjs +++ b/eslint.config.mjs @@ -15,6 +15,25 @@ const eslintConfig = defineConfig([ // Plain service worker script served as-is "public/sw.js", ]), + // ADR-026: pages, components and libs reach the database only through src/server (the tenant layer). Type-only imports are fine. + { + files: ["src/app/**/*.{ts,tsx}", "src/components/**/*.{ts,tsx}", "src/lib/**/*.{ts,tsx}"], + ignores: ["**/*.test.{ts,tsx}"], + rules: { + "@typescript-eslint/no-restricted-imports": [ + "error", + { + patterns: [ + { + group: ["@/db", "@/db/*"], + allowTypeImports: true, + message: "Do not import the database outside src/server: go through getTenant() / createTenant() (ADR-026).", + }, + ], + }, + ], + }, + }, ]); export default eslintConfig; diff --git a/src/app/(app)/cadastros/panels.tsx b/src/app/(app)/cadastros/panels.tsx index 75ab16f..62f279b 100644 --- a/src/app/(app)/cadastros/panels.tsx +++ b/src/app/(app)/cadastros/panels.tsx @@ -4,8 +4,7 @@ import { Badge } from "@/components/ui/badge"; import { ActionButton } from "./entity-dialog"; import { setOrganizationArchived, setProjectArchived } from "./actions"; import { OrganizationDialog, ProjectDialog, TagDialog } from "./entity-dialogs"; -import { getDb } from "@/db"; -import { authRolesByUser } from "@/server/auth/member-roles"; +import { workspaceAuthRoles } from "@/server/workspace-auth-roles"; import { InviteMembersButton } from "./invite-members-button"; import { MemberAccessDialog } from "./member-access-dialog"; import { PendingInvitations } from "./pending-invitations"; @@ -157,7 +156,7 @@ export async function MembersPanel({ tenant, workspaceId, currentUserId }: { ten const [members, assignable, authRoles] = await Promise.all([ tenant.projectMembers.overview(), tenant.projectMembers.assignableProjects(), - authRolesByUser(getDb(), workspaceId), + workspaceAuthRoles(workspaceId), ]); return (