Commit graph

121 commits

Author SHA1 Message Date
Adam Moussa
3a8de4e88b
feat(ci): deploy the marketing site through the org static caller (PLAT-225) (#69)
* feat(ci): deploy the marketing site through the org static caller (PLAT-225)

Prod still ships on merge to main. Exec roles leave this workspace, and the deploy reads the bucket and distribution from SSM.

* fix(ci): run the static check after the legacy ci job

Both jobs call ci-static, which cancels the other in-progress run on the same ref, so ci-complete never saw both succeed.

* fix(ci): address review feedback

* fix(ci): address review feedback

* fix(ci): address review feedback

* fix(ci): address review feedback
2026-09-25 15:18:40 +00:00
Adam Moussa
f194d65ee5
fix(careers): return 301s for retired job URLs (DEV-297) (#68)
Some checks failed
Deploy / deploy (push) Has been cancelled
* fix(careers): return 301s for retired job URLs

Send the old careers paths to the Paychex portal from the viewer-request function so clients get a permanent redirect instead of the HTML stub.

* fix(careers): match retired job redirects case-insensitively

CloudFront does not normalize URI case, so a mixed-case old job link skipped the 301 and missed the lowercase S3 stub.
2026-09-24 21:31:30 +00:00
Adam Moussa
ff66171782
feat(careers): render openings from the Paychex job feed (#67)
Some checks are pending
Deploy / deploy (push) Waiting to run
Load listings at build time so Learn more goes to each Paychex posting, and rebuild on weekday mornings so new roles appear without a code change.
2026-09-24 21:17:17 +00:00
Adam Moussa
1f0af545d4
chore(ci): remove unused Mergify stub (#66)
Some checks failed
Deploy / deploy (push) Has been cancelled
2026-09-22 18:41:26 +00:00
Adam Moussa
16bb7ab89f
fix(deps): apply js-yaml 4.3.2 override for gray-matter (#64)
Some checks failed
Deploy / deploy (push) Has been cancelled
The override was already in package.json, but the lockfile still nested js-yaml 3.15.0 under gray-matter. Drop that copy so the tree uses 4.3.2 and Renovate cannot propose js-yaml 5 until Eleventy supports it.
2026-09-21 17:12:20 +00:00
renovate[bot]
e5e56e0122
chore(deps): update terraform aws to ~> 6.65 (#62)
Some checks are pending
Deploy / deploy (push) Waiting to run
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 16:05:40 +00:00
renovate[bot]
140f17d482
chore(deps): update aws-actions/configure-aws-credentials action to v6.3.0 (#61)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-21 16:05:04 +00:00
renovate[bot]
079af59da0
chore(deps): update terraform aws to ~> 6.64 (#60)
Some checks failed
Deploy / deploy (push) Has been cancelled
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 17:26:12 +00:00
renovate[bot]
e8854e5804
chore(deps): update sea-haven-industries/.github action to v1.0.11 (#59)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-16 16:45:57 +00:00
renovate[bot]
167eb1bcbf
chore(deps): update terraform aws to ~> 6.63 (#58)
Some checks failed
Deploy / deploy (push) Has been cancelled
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-09 18:43:07 +00:00
renovate[bot]
b82ed4deec
chore(deps): update aws-actions/configure-aws-credentials action to v6.2.4 (#57)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-09 18:42:45 +00:00
Adam Moussa
e80bdb9be5
feat(iam): import hcptf roles into app Terraform (PLAT-146) (#56)
Some checks failed
Deploy / deploy (push) Has been cancelled
* feat(iam): import hcptf roles into app Terraform (PLAT-146)

Move the existing hcptf pair into this repo so app Terraform owns prod IAM after the substrate handoff.

* fix(iam): add apply-role IAM list permissions (PLAT-146)

IamReadOnly omitted ListRoleTags needed to refresh imported roles after detaching the substrate guardrail.
2026-09-02 21:47:10 +00:00
renovate[bot]
84eeee84da
chore(deps): update github actions (#54)
Some checks are pending
Deploy / deploy (push) Waiting to run
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2026-09-01 16:46:58 +00:00
renovate[bot]
54a09e205c
chore(deps): update dependency js-yaml to ^4.3.2 (#53)
* chore(deps): update dependency js-yaml to ^4.3.2

* chore(deps): add js-yaml@4.3.2 to package lock

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-09-01 16:46:45 +00:00
Adam Moussa
b6bfe91283
fix(ci): run merge-queue checks only on merge_group (#55)
Some checks are pending
Deploy / deploy (push) Waiting to run
The gh-readonly-queue push trigger raced merge_group and cancelled the required ci / ci check, which GitHub treats as a queue failure.
2026-09-01 16:30:37 +00:00
367e9cfda5
ci: clean up merge_group trigger in CI workflow 2026-09-01 12:09:29 -04:00
Adam Moussa
24480bd1db
chore(deps): remove dependabot version updates (#52)
Some checks failed
Deploy / deploy (push) Has been cancelled
Renovate is the version-update bot on this Interactive repo. GitHub Dependabot alerts stay.
2026-08-25 11:51:11 -04:00
renovate[bot]
b6f349535d
chore(deps): update dependency js-yaml to ^4.3.0 [security] (#50)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-08-24 23:33:09 +00:00
Adam Moussa
1203c95b0a
chore(ci): remove pr policy workflow caller (#49)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-08-24 15:12:44 -04:00
Adam Moussa
ea31b5ae99
chore(ci): switch auto-merge from seahaven-bot to Mergify (#48)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-08-24 13:53:11 -04:00
Adam Moussa
f01e528874
ci: enable squash auto-merge on ready PRs (PLAT-108) (#46)
Some checks failed
Deploy / deploy (push) Has been cancelled
* ci: enable squash auto-merge on ready PRs

* fix(ci): serialize auto-merge enable and ignore already-enabled

* fix(ci): emit ci / ci on the merge-queue branch
2026-08-21 23:45:11 +00:00
Adam Moussa
14476f5801
ci: add merge_group trigger for required ci / ci (#45)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-08-21 17:41:45 -04:00
Adam Moussa
dc28a1bbca
fix(iam): drop lambda boundary from github deploy role (PLAT-52) (#44)
Some checks are pending
Deploy / deploy (push) Waiting to run
* fix(iam): drop lambda boundary from github deploy role (PLAT-52)

* fix(iam): skip boundary delete on github deploy role (PLAT-52)
2026-08-20 16:05:23 -04:00
dependabot[bot]
cf7e407386
chore(deps): bump the minor-and-patch group with 4 updates (#43)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 4 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 13:28:31 -04:00
Adam Moussa
7480aee3c8
fix(infra): serve pretty URLs via CloudFront directory index (PLAT-105) (#42)
Some checks failed
Deploy / deploy (push) Has been cancelled
S3 OAC has no directory index, so /sustainability/ 404s while
/sustainability/index.html is live. Rewrite directory URIs on viewer-request.
2026-08-15 05:26:23 +00:00
Adam Moussa
edc4f3f6b9
feat(site): add public sustainability page (DEV-209) (#41)
Some checks are pending
Deploy / deploy (push) Waiting to run
* feat(content): add sustainability page

* feat(nav): add sustainability to primary nav

Five links plus the CTA button no longer fit above the existing 768px
breakpoint; between 769px and ~855px the Get a Quote button wrapped to
two lines inside the 72px bar. Move the nav collapse to its own 900px
media query so the hamburger takes over before the bar runs out of room.
2026-08-14 20:12:29 -04:00
Adam Moussa
70aae64464
chore(infra): restrict Vercel to preview deployments (#40)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-08-14 13:32:44 -04:00
dependabot[bot]
f24af4e790
chore(deps): bump the minor-and-patch group with 4 updates (#39)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 4 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.5 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](9c1ecf9428...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-11 13:59:07 -04:00
Adam Moussa
37c6f80eba
feat(infra): associate shared prod CloudFront WAF (PLAT-92) (#38)
Some checks failed
Deploy / deploy (push) Has been cancelled
* feat(infra): associate shared prod CloudFront WAF with site distribution

Read /seahaven/waf/app-web-acl-arn and set web_acl_id so the marketing
site sits behind the same-account M-17 WebACL.

* chore: empty commit to trigger CI

* fix(infra): mark CloudFront WebACL output nonsensitive

SSM String parameters are sensitive by default, which broke the HCP
speculative plan when exporting the WebACL ARN.
2026-08-07 17:21:46 -04:00
Adam Moussa
7812ec102d
feat(infra): add HCP Terraform for prod static hosting (PLAT-91) (#37)
Some checks are pending
Deploy / deploy (push) Waiting to run
* feat(infra): add HCP Terraform for prod static hosting

Greenfield S3+CloudFront+ACM+OIDC content-deploy role under /tf-managed/,
with OOB mgmt DNS helper for ACM validation and apex alias cutover.

* chore(security): suppress pre-existing js-yaml npm audit

* feat(ci): retarget content deploy to seahaven-prod origin

Point OIDC, S3 sync, and CloudFront invalidation at the HCP-managed
prod hosting stack so GHA remains the content publish path after cutover.
2026-08-07 15:09:54 -04:00
dependabot[bot]
a5b9716c31
chore(deps): bump the minor-and-patch group with 3 updates (#35)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 3 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 18:39:20 -04:00
dependabot[bot]
901dd20027
chore(deps): bump brace-expansion from 1.1.16 to 1.1.18 (#36)
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.16 to 1.1.18.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.16...v1.1.18)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 18:26:55 -04:00
Adam Moussa
f341cf4340
ci: add org PR policy caller (#34)
Some checks are pending
Deploy / deploy (push) Waiting to run
Refs: PLAT-62
2026-08-04 11:56:33 -04:00
Adam Moussa
916c50686a
Merge pull request #33 from Sea-Haven-Industries/ci/pin-reusables-v1.0.2
Some checks failed
Deploy / deploy (push) Has been cancelled
ci(deps): pin org reusable workflows to v1.0.2
2026-07-28 18:11:55 -04:00
Adam Moussa
507a7a1251 style(ci): normalize workflow block spacing 2026-07-28 18:06:30 -04:00
Adam Moussa
69fdc92623 ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:56:30 -04:00
dependabot[bot]
d7848bedbc
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#32)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group with 1 update: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.2 to 6.2.3
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 15:29:34 -04:00
Adam Moussa
1b71f5f56e
chore(security): resolve open npm audit and code scanning alerts (#31)
Some checks are pending
Deploy / deploy (push) Waiting to run
* build(deps): resolve npm audit advisories via in-range bumps

npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs
10.27.2, and brace-expansion 1.1.16 to clear four high DoS
advisories. Eleventy build verified passing at 3.1.6.

The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has
no in-range fix: the patch exists only in 5.0.8, and
@11ty/recursive-copy pins an older minimatch. Exposure is
build-time only (glob patterns from our own config, never
untrusted input), so it is suppressed with justification in
.security-review/suppressions.json rather than forcing the
eleventy downgrade npm audit fix --force proposes. Remove the
npmaudit-* suppressions when recursive-copy ships a minimatch
>=10.0.3 bump.

* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.

* ci(dependency-review): allow adjudicated brace-expansion GHSA

Re-pins the callable to 07ce007 (adds the allow-ghsas input, org
PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check
flags on the bumped-but-still-in-range brace-expansion 1.1.16.
The advisory has no in-range fix and is an accepted risk with
written justification in .security-review/suppressions.json;
remove the allowance together with those suppressions when
@11ty/recursive-copy ships a minimatch >=10.0.3 bump.
2026-07-27 17:41:00 +00:00
dependabot[bot]
761faceed7
Bump actions/setup-node from 6 to 7 (#30)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 13:25:35 -04:00
Adam Moussa
e9b121ecfa
chore(security): suppress historical elementor gitleaks FP (INFRA-181) (#29)
Some checks failed
Deploy / deploy (push) Has been cancelled
Adds a scoped suppression for gitleaks-generic-api-key-2464, a high-entropy
false positive in a removed Elementor/WordPress minified vendor bundle that
survives only in git history. Not a live secret. With INFRA-143's two
reCAPTCHA suppressions, the pre-push scanner now passes cleanly on this repo
(0 confirmed high, 3 suppressed) with no --no-verify needed.
2026-07-08 16:53:55 -04:00
Adam Moussa
7fd529ba98
ci: expand dependabot coverage (INFRA-130) (#28)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-08 16:41:16 -04:00
Adam Moussa
68ac0be0d4
INFRA-143: suppress reCAPTCHA site-key gitleaks FP + clear js-yaml DoS advisory (#27)
* chore(security): suppress gitleaks FP on public reCAPTCHA site key (INFRA-143)

The SITE_KEY in assets/js/form.js is a Google reCAPTCHA v3 site key, public
by design (shipped to the browser, passed to grecaptcha.execute). It is not a
secret and is not rotated. Add a scoped repo-local gitleaks suppression with
justification for the current (line 7) and historical (line 5) hits so the
pre-push scanner stops blocking on it.

* fix(deps): pin gray-matter js-yaml to 3.15.0 to clear DoS advisory (INFRA-143)

gray-matter (transitive via @11ty/eleventy) pulled js-yaml 3.14.2, flagged by
GHSA-h67p-54hq-rp68 (quadratic-complexity DoS in merge-key handling, moderate).
Add a scoped nested npm override pinning gray-matter's js-yaml to ^3.15.0, the
fixed 3.x release, leaving Eleventy's direct js-yaml 4.x untouched. npm audit
now reports 0 vulnerabilities and the Eleventy build passes.
2026-07-08 16:21:21 -04:00
dependabot[bot]
e78fe4f730
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#26)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group with 1 update: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.2
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](254c19bd24...517a711dbc)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 13:54:15 -04:00
Adam Moussa
3d8a9cb459
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 18:28:22 -04:00
Adam Moussa
753e54c70c
chore(ci): SHA-pin mutable-tag third-party actions (INFRA-118) (#24) 2026-07-06 18:27:59 -04:00
Adam Moussa
c1b463639b
chore(ci): add org dependency-review caller (INFRA-125) (#23)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:41:00 -04:00
dependabot[bot]
76365ceeeb
Bump actions/checkout from 6 to 7 (#22)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 12:29:43 -04:00
Adam Moussa
c31819ab01
Merge pull request #21 from Sea-Haven-Industries/feature/frontend-polish
Some checks failed
Deploy / deploy (push) Has been cancelled
Frontend polish: self-host fonts, lazy reCAPTCHA, structured data, CSS cleanup
2026-06-12 17:28:31 -04:00
01daf05bbc docs: changelog for frontend polish 2026-06-12 17:26:34 -04:00
87d5dd5d0a perf: self-host fonts + lazy-load reCAPTCHA
Self-host DM Serif Display (regular+italic) and Inter (variable) as
latin-subset woff2 (~84KB), with @font-face + font-display:swap and
preloads. Removes render-blocking Google Fonts (2 third-party origins,
extra DNS/preconnect). reCAPTCHA api.js is no longer eager-loaded in
<head>; form.js injects it on first form focus/submit, keeping ~50KB+
of third-party JS off initial load on form pages. CloudFront CSP
font-src updated to allow 'self' (additive; gstatic kept for transition).
2026-06-12 17:26:14 -04:00