* feat(infra): add HCP Terraform for prod static hosting
Greenfield S3+CloudFront+ACM+OIDC content-deploy role under /tf-managed/,
with OOB mgmt DNS helper for ACM validation and apex alias cutover.
* chore(security): suppress pre-existing js-yaml npm audit
* feat(ci): retarget content deploy to seahaven-prod origin
Point OIDC, S3 sync, and CloudFront invalidation at the HCP-managed
prod hosting stack so GHA remains the content publish path after cutover.
* build(deps): resolve npm audit advisories via in-range bumps
npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs
10.27.2, and brace-expansion 1.1.16 to clear four high DoS
advisories. Eleventy build verified passing at 3.1.6.
The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has
no in-range fix: the patch exists only in 5.0.8, and
@11ty/recursive-copy pins an older minimatch. Exposure is
build-time only (glob patterns from our own config, never
untrusted input), so it is suppressed with justification in
.security-review/suppressions.json rather than forcing the
eleventy downgrade npm audit fix --force proposes. Remove the
npmaudit-* suppressions when recursive-copy ships a minimatch
>=10.0.3 bump.
* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.
* ci(dependency-review): allow adjudicated brace-expansion GHSA
Re-pins the callable to 07ce007 (adds the allow-ghsas input, org
PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check
flags on the bumped-but-still-in-range brace-expansion 1.1.16.
The advisory has no in-range fix and is an accepted risk with
written justification in .security-review/suppressions.json;
remove the allowance together with those suppressions when
@11ty/recursive-copy ships a minimatch >=10.0.3 bump.
Adds a scoped suppression for gitleaks-generic-api-key-2464, a high-entropy
false positive in a removed Elementor/WordPress minified vendor bundle that
survives only in git history. Not a live secret. With INFRA-143's two
reCAPTCHA suppressions, the pre-push scanner now passes cleanly on this repo
(0 confirmed high, 3 suppressed) with no --no-verify needed.
* chore(security): suppress gitleaks FP on public reCAPTCHA site key (INFRA-143)
The SITE_KEY in assets/js/form.js is a Google reCAPTCHA v3 site key, public
by design (shipped to the browser, passed to grecaptcha.execute). It is not a
secret and is not rotated. Add a scoped repo-local gitleaks suppression with
justification for the current (line 7) and historical (line 5) hits so the
pre-push scanner stops blocking on it.
* fix(deps): pin gray-matter js-yaml to 3.15.0 to clear DoS advisory (INFRA-143)
gray-matter (transitive via @11ty/eleventy) pulled js-yaml 3.14.2, flagged by
GHSA-h67p-54hq-rp68 (quadratic-complexity DoS in merge-key handling, moderate).
Add a scoped nested npm override pinning gray-matter's js-yaml to ^3.15.0, the
fixed 3.x release, leaving Eleventy's direct js-yaml 4.x untouched. npm audit
now reports 0 vulnerabilities and the Eleventy build passes.
Self-host DM Serif Display (regular+italic) and Inter (variable) as
latin-subset woff2 (~84KB), with @font-face + font-display:swap and
preloads. Removes render-blocking Google Fonts (2 third-party origins,
extra DNS/preconnect). reCAPTCHA api.js is no longer eager-loaded in
<head>; form.js injects it on first form focus/submit, keeping ~50KB+
of third-party JS off initial load on form pages. CloudFront CSP
font-src updated to allow 'self' (additive; gstatic kept for transition).
Add a breadcrumb-ld partial (rendered from breadcrumbName/breadcrumbParent
front-matter) emitting BreadcrumbList JSON-LD on all 11 interior pages
(3-level on the job pages). Enrich homepage LocalBusiness with geo,
areaServed (US), and hasMap. NOTE: geo coords are approximate (Ronkonkoma
ZIP) — set precisely from the Google Business Profile; openingHours and
sameAs omitted pending real hours + non-placeholder social URLs.
Remove unused .display-xl/.body-lg/.body-sm. Replace the 4 !important
nav-hover overrides with specificity-correct hover rules in home.css
(transparent homepage nav) so the cascade resolves without !important.
No visual change.
* chore(build): add Eleventy scaffold
Thin Eleventy build (v3.1.6, pinned) — passthrough-copies assets/,
robots.txt, sitemap.xml; outputs flat HTML to _site/. _data/site.json
holds site-wide constants; _data/images.json maps image keys to
src+width+height for the {% image %} shortcode (CLS fix). Output stays
flat HTML served from the same S3 bucket + CloudFront.
* refactor(templates): base layout, partials, shared JS, CSS extraction
- _includes/base.njk + nav/mobile-menu/footer partials reproduce the
shared chrome once (was hand-duplicated across 13 pages). Adds a
skip-link and <main> landmark (WCAG 2.4.1), aria-expanded/role=dialog
hooks on the menu, and a {% year %} shortcode replacing document.write.
- assets/js/nav.js: extracted sticky-nav + accessible mobile-menu dialog
(focus trap, Escape, focus return) + rAF-throttled hero parallax.
- assets/js/form.js: Basin AJAX submit with an accessible status region.
- assets/css/*.css: per-page inline <style> extracted into page CSS files
(home/about/services/careers/jobs/contact/social/legal/404); skip-link
+ :focus-visible added to main.css.
- index.njk: homepage converted as the reference page.
* fix(css): make hero-bg url root-relative after extraction
Inline CSS used a document-relative url('assets/...') that resolves
correctly from / but breaks once moved into /assets/css/home.css.
Rewrite to /assets/images/.
* refactor(pages): convert 12 pages to Eleventy templates
Convert about, services, careers (listing + 3 jobs), contact, social-
accountability, privacy-policy, terms-of-service, eula, and 404 from
standalone HTML to .njk against base.njk. Each page now carries only
front-matter (title/description/SEO) + its <main> content; shared head/
nav/footer/scripts come from the layout. JobPosting + LocalBusiness
JSON-LD preserved. Images use the {% image %} shortcode (width/height).
Contact gets an accessible #form-status region. form.js generalized to
wire BOTH the contact form and the .apply-form job application forms
(was contact-only), preserving each submit button's own label.
* fix(a11y): footer contrast to WCAG AA + scope services .form-group
Raise footer text colors (footer-bottom/col/brand/social/contact) and
darken --text-muted so muted text clears 4.5:1 on the dark footer and
warm-gray surfaces. Scope services' flex .form-group override to
.contact-form .form-group so it can't leak to the global rule.
* perf(seo): og-cover image, webp logos, hero preload
Add a real 1200x630 og-cover.jpg (was a 153x49 favicon) wired site-wide
via base.njk og:image/twitter:image. Convert nav/footer logos to webp
(nav 58KB->22KB); PNGs kept as passthrough so old URLs still resolve.
Preload the LCP hero image on the homepage (fetchpriority=high). All
<img> carry width/height via the image shortcode (CLS).
* ci(deploy): build-then-sync, cache headers, safe concurrency
Rename main.yml -> deploy.yaml (org convention). Build with Eleventy
(npm ci && npm run build) and sync _site/ instead of the repo root, so
only built output ships (no source/templates/node_modules). Split
Cache-Control (1-day assets, no-cache HTML) and keep /* invalidation
since filenames are not yet fingerprinted. concurrency cancel-in-progress
false so a deploy is never cut mid sync. ci.yaml validates _site/ via
ci-static build mode.
* docs: README for the Eleventy build and structure
* fix(security): wire services form, guard build, harden deploy
Fable build-review findings:
- BLOCK: services puts .contact-form on the <form> itself (contact uses a
wrapper div), so form.js selector '.contact-form form' never matched it
— the services lead form submitted natively with an empty reCAPTCHA
token. Selector now also matches form.contact-form.
- Guard the build before the --delete S3 sync: require index/contact/404
and >=40 files, so a silently-empty build can never wipe the live bucket.
- npm ci --ignore-scripts on deploy (build verified to pass) to shrink the
supply-chain window on the OIDC-credentialed runner.
- Escape quotes in the image shortcode alt text.
* Add Scheduling Coordinator careers posting
Publish the Scheduling Coordinator listing covering preventive
maintenance scheduling across U.S. industrial facilities. Includes
the full job description, $70k-$80k pay band, benefits, and an
application form wired to the existing Basin endpoint with reCAPTCHA.
* Add scheduling-coordinator to sitemap and validThrough to all JobPostings
- Add /careers/scheduling-coordinator/ to sitemap.xml so it is
discoverable by search engines and Google Jobs
- Add validThrough (2026-12-31) to all three JobPosting JSON-LD blocks
to clear Search Console warnings and prevent stale jobs lingering
- Fix indentation nit on the traveling-maintenance sitemap entry
* Add CI caller for static-site reusable workflow
Calls the org ci-static.yaml reusable on pull_request, emitting the
ci / ci status context required by the main-branch ruleset.
Depends on Sea-Haven-Industries/.github#56 (ci-static.yaml) being merged
to .github@main; until then this run startup-fails.
* Set least-privilege permissions on CI caller
Add explicit 'permissions: contents: read' to the ci.yaml caller,
resolving CodeQL actions/missing-workflow-permissions (medium). The
ci-static reusable only needs read access for checkout + read-only checks.
(Also serves as the re-trigger push now that ci-static.yaml is on main.)
- Add callable-labeler.yaml caller workflow (.github/workflows/labeler.yml)
- Add minimal README badges (HTML, JavaScript, CI status via main.yml)
Part of INFRA-47 (INFRA-56, INFRA-57).
- Add "Apply Now" CTA button to sticky sidebar on both job pages
- Add "Why Work Here" benefit cards section to careers landing
- Make salary visually prominent on job cards (own line, display font)
- Move "Why This Role Stands Out" above requirements on traveling maintenance page
- Add "Back to All Positions" link in hero on both job pages
- Add quick-scan summary callout at top of each job description
- Make entire job card clickable with hover lift effect
- Add team photo as careers hero background
- Consolidate fragmented requirement lists on traveling maintenance page
- Add JSON-LD JobPosting structured data for Google job search SEO
Move ~2,600 lines of duplicated CSS (reset, tokens, typography, nav,
footer, buttons, mobile menu, page hero, CTA, form base styles, and
shared responsive breakpoints) into /assets/css/main.css. Each page
now only contains page-specific styles inline.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Add custom 404.html page with branded design
- Preload Google Fonts stylesheet on all 9 pages for faster rendering
- Add LocalBusiness JSON-LD structured data on homepage for SEO
- Hide reCAPTCHA v3 floating badge on form pages and add required
Google attribution text in footer
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>