run seed on merge to upsert - #49
Conversation
|
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
|
Caution Review failedThe pull request is closed. WalkthroughThis pull request introduces a new step in the GitHub Actions workflow for database migrations to seed the database using Changes
Sequence Diagram(s)sequenceDiagram
participant CI as GitHub Actions
participant Runner as Workflow Runner
participant DB as Database
CI->>Runner: Trigger migrate job
Runner->>Runner: Generate Prisma Client
Runner->>Runner: Run database seed (new step)
Runner->>DB: Execute `bunx prisma db seed`
DB-->>Runner: Return seed results
sequenceDiagram
participant Script as Seed Script
participant DB as Database
Note over Script: Directly seed data without cleanup
Script->>DB: Seed policies
Script->>DB: Seed frameworks
Script->>DB: Seed policy frameworks
DB-->>Script: Confirm data insertion
Poem
📜 Recent review detailsConfiguration used: CodeRabbit UI 📒 Files selected for processing (2)
🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
…H-49, GH-52, GH-75, GH-102, GH-272) (#3573) * fix(api): derive soa organizationId from session, not request body Every SOA handler now overwrites dto.organizationId with the trusted @organizationId() session value before calling the service, closing the cross-tenant read/tamper/destroy gap in save-answer, auto-fill, create-document, ensure-setup, approve, decline, and submit-for-approval. Refs GH-36 * fix(api): scope task automations to task and organization automationId lookups are now verified against the task in the URL and the caller's organization via a shared verifyAutomationAccess helper, so an automationId from another org's task 404s on read, update, delete, runs, versions, and publish instead of leaking or mutating it. Refs GH-46 * fix(api): harden public trust-portal access endpoints reclaimAccess no longer returns the access link/token in the response body and returns an identical generic message whether or not a grant exists, removing the unauthenticated token disclosure and the email-enumeration oracle; the link is only emailed to the requester. findPublishedTrustByRouteId no longer auto-creates a published Trust row or flips drafts to published: public endpoints only resolve rows that are already published and 404 otherwise, so an unauthenticated caller can no longer force-publish an organization's trust portal. Refs GH-42, GH-272 * fix(app): require session and org match in task-automation actions Every exported server action now resolves the caller's session and active organization and fails closed when unauthenticated. Actions that take orgId must match the session's active org; S3 keys must be prefixed with the active org; automationId-only actions verify ownership through the automation's task before proxying to the enterprise API. Refs GH-52 * fix(app): require auth and run ownership before minting trigger tokens healAndSetAccessToken and createAccessToken now require a session with an active organization and only mint a Trigger.dev run-read token when the run id is recorded against that organization (onboarding job, knowledge base document, or remediation batch). Refs GH-102 * ci(device-agent): restrict release workflow to protected branches The device-agent release pipeline runs branch-controlled build scripts with Apple and SSL.com code-signing secrets in scope, so push triggers are now limited to main and release (manual staging builds remain via workflow_dispatch), and the secret-bearing jobs are gated behind the staging/production GitHub environments. Refs GH-49, GH-75
Summary by CodeRabbit