Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
2a65d49
refactor: remove stale duplicate entry points
sgarcese Aug 21, 2026
8f5f48a
docs: point curl examples at the /mcp route
sgarcese Aug 21, 2026
27c3eef
perf: persist event loop across Lambda invocations
sgarcese Aug 21, 2026
a978f5d
refactor: add shared plugin base classes (BaseOpenDataPlugin, BasePlu…
sgarcese Aug 21, 2026
132f4ed
refactor(ckan): migrate onto shared plugin base classes
sgarcese Aug 21, 2026
a341adb
fix(ckan): validate identifiers and metric expressions in aggregate_data
sgarcese Aug 21, 2026
9669b8e
refactor(socrata): migrate onto shared plugin base classes
sgarcese Aug 21, 2026
562577a
refactor(arcgis): migrate onto shared plugin base classes and align w…
sgarcese Aug 21, 2026
b75cb9c
fix(arcgis): restrict feature-service URLs to trusted hosts
sgarcese Aug 21, 2026
90b32f1
refactor: modernize plugin template, defer config loading, tidy Plugi…
sgarcese Aug 21, 2026
997265f
fix(ckan): restore valid aggregate_data inputs over-rejected by harde…
sgarcese Aug 22, 2026
ac8bd9f
fix(core): validate field identifiers inside build_where_clause
sgarcese Aug 22, 2026
21a9441
fix(arcgis): address code-review regressions in migration and SSRF guard
sgarcese Aug 22, 2026
cb301bc
fix(socrata): enforce required 'query' argument for search_datasets
sgarcese Aug 22, 2026
789db71
ci: Python 3.11/3.12 matrix, terraform validate job, Dependabot config
sgarcese Aug 22, 2026
cc7e549
fix(core): make validate_url a staticmethod for cross-version pydanti…
sgarcese Aug 22, 2026
926515d
docs: document the decoupled plugin base layer and ArcGIS plugin
sgarcese Aug 22, 2026
301374b
ci: remove "Sync develop with main" workflow (#21)
sgarcese Sep 13, 2026
6650d5e
feat(opendatasoft): add Opendatasoft Explore v2.1 provider plugin
sgarcese Aug 22, 2026
3543fcc
docs(opendatasoft): document the Opendatasoft plugin and config example
sgarcese Aug 22, 2026
cdf85d4
fix(opendatasoft): return a single row for global aggregates
sgarcese Aug 22, 2026
5ad59c4
fix(opendatasoft): address adversarial code-review findings
sgarcese Aug 22, 2026
0c06af5
feat(core): guardrails for untrusted portal content flowing into the LLM
sgarcese Aug 27, 2026
c98d03d
fix(socrata): follow redirects on the SODA client (#19)
sgarcese Sep 13, 2026
89d660d
fix(core): scope credential headers across redirects; follow redirect…
sgarcese Sep 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 34 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
version: 2
updates:
# Python dependencies (pyproject.toml / uv.lock, requirements*.txt)
- package-ecosystem: "pip"
directory: "/"
schedule:
interval: "weekly"
groups:
python-minor-patch:
update-types:
- "minor"
- "patch"

# Go client
- package-ecosystem: "gomod"
directory: "/client"
schedule:
interval: "weekly"

# GitHub Actions pins
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"

# Terraform providers/modules
- package-ecosystem: "terraform"
directory: "/terraform/aws"
schedule:
interval: "weekly"
- package-ecosystem: "terraform"
directory: "/terraform/bootstrap"
schedule:
interval: "weekly"
40 changes: 37 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,15 +58,19 @@ jobs:
test-suite:
name: Test suite
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
python-version: ["3.11", "3.12"]

steps:
- name: Checkout code
uses: actions/checkout@v4

- name: Set up Python 3.11
- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
with:
python-version: "3.11"
python-version: ${{ matrix.python-version }}

- name: Install uv
uses: astral-sh/setup-uv@v4
Expand All @@ -75,7 +79,7 @@ jobs:
cache-dependency-glob: "uv.lock"

- name: Install dependencies
run: uv sync --all-extras
run: uv sync --all-extras --python ${{ matrix.python-version }}

- name: Run Python tests with coverage
run: |
Expand All @@ -94,3 +98,33 @@ jobs:
- name: Run Go tests
working-directory: ./client
run: go test ./...

terraform-validate:
name: Terraform validate
runs-on: ubuntu-latest

steps:
- name: Checkout code
uses: actions/checkout@v4

- name: Set up Terraform
uses: hashicorp/setup-terraform@v3
with:
terraform_version: "1.9.x"

- name: Check Terraform formatting
run: terraform fmt -check -recursive terraform/

- name: Validate terraform/aws
working-directory: ./terraform/aws
run: |
# Placeholder for the Lambda artifact referenced by filebase64sha256()
touch lambda-deployment.zip
terraform init -backend=false -input=false
terraform validate

- name: Validate terraform/bootstrap
working-directory: ./terraform/bootstrap
run: |
terraform init -backend=false -input=false
terraform validate
33 changes: 0 additions & 33 deletions .github/workflows/sync-develop.yml

This file was deleted.

5 changes: 5 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -233,3 +233,8 @@ examples/
terraform/aws/secrets.*.tfvars
.env.staging
.env.prod

# Claude Code local files
CLAUDE.md
CLAUDE.local.md
.claude/
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ See [Getting Started](docs/GETTING_STARTED.md) for full setup.
| [Architecture](docs/ARCHITECTURE.md) | System design and plugins |
| [Deployment](docs/DEPLOYMENT.md) | AWS, Terraform, monitoring |
| [Testing](docs/TESTING.md) | Local testing (Terminal, Claude, MCP Inspector) |
| [Security](docs/SECURITY.md) | Threat model, prompt-injection guardrails |


---
Expand Down
12 changes: 12 additions & 0 deletions config-example.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,18 @@ plugins:
city_name: "Your City"
timeout: 120
# token: "${ARCGIS_TOKEN}" # Optional: Bearer token for private items
# trusted_service_hosts: # Extra hosts trusted for Feature Service queries
# - "gis.yourcity.gov" # (needed when Hub references self-hosted services)

# Built-in: Opendatasoft (for Opendatasoft Explore v2.1 portals)
# Examples: data.longbeach.gov, public.opendatasoft.com
opendatasoft:
enabled: false # Set to true to use
base_url: "https://data.longbeach.gov" # Portal API base URL
portal_url: "https://data.longbeach.gov" # Public portal URL
city_name: "Long Beach" # City/organization name
timeout: 30 # HTTP timeout in seconds
# api_key: "${ODS_API_KEY}" # Optional: only needed for private datasets

# yamllint disable rule:comments-indentation
# Custom: Add your own plugins here
Expand Down
Loading