Commit graph

85 commits

Author SHA1 Message Date
dependabot[bot]
d7848bedbc
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#32)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group with 1 update: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.2 to 6.2.3
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 15:29:34 -04:00
Adam Moussa
1b71f5f56e
chore(security): resolve open npm audit and code scanning alerts (#31)
Some checks are pending
Deploy / deploy (push) Waiting to run
* build(deps): resolve npm audit advisories via in-range bumps

npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs
10.27.2, and brace-expansion 1.1.16 to clear four high DoS
advisories. Eleventy build verified passing at 3.1.6.

The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has
no in-range fix: the patch exists only in 5.0.8, and
@11ty/recursive-copy pins an older minimatch. Exposure is
build-time only (glob patterns from our own config, never
untrusted input), so it is suppressed with justification in
.security-review/suppressions.json rather than forcing the
eleventy downgrade npm audit fix --force proposes. Remove the
npmaudit-* suppressions when recursive-copy ships a minimatch
>=10.0.3 bump.

* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.

* ci(dependency-review): allow adjudicated brace-expansion GHSA

Re-pins the callable to 07ce007 (adds the allow-ghsas input, org
PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check
flags on the bumped-but-still-in-range brace-expansion 1.1.16.
The advisory has no in-range fix and is an accepted risk with
written justification in .security-review/suppressions.json;
remove the allowance together with those suppressions when
@11ty/recursive-copy ships a minimatch >=10.0.3 bump.
2026-07-27 17:41:00 +00:00
dependabot[bot]
761faceed7
Bump actions/setup-node from 6 to 7 (#30)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 13:25:35 -04:00
Adam Moussa
e9b121ecfa
chore(security): suppress historical elementor gitleaks FP (INFRA-181) (#29)
Some checks failed
Deploy / deploy (push) Has been cancelled
Adds a scoped suppression for gitleaks-generic-api-key-2464, a high-entropy
false positive in a removed Elementor/WordPress minified vendor bundle that
survives only in git history. Not a live secret. With INFRA-143's two
reCAPTCHA suppressions, the pre-push scanner now passes cleanly on this repo
(0 confirmed high, 3 suppressed) with no --no-verify needed.
2026-07-08 16:53:55 -04:00
Adam Moussa
7fd529ba98
ci: expand dependabot coverage (INFRA-130) (#28)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-08 16:41:16 -04:00
Adam Moussa
68ac0be0d4
INFRA-143: suppress reCAPTCHA site-key gitleaks FP + clear js-yaml DoS advisory (#27)
* chore(security): suppress gitleaks FP on public reCAPTCHA site key (INFRA-143)

The SITE_KEY in assets/js/form.js is a Google reCAPTCHA v3 site key, public
by design (shipped to the browser, passed to grecaptcha.execute). It is not a
secret and is not rotated. Add a scoped repo-local gitleaks suppression with
justification for the current (line 7) and historical (line 5) hits so the
pre-push scanner stops blocking on it.

* fix(deps): pin gray-matter js-yaml to 3.15.0 to clear DoS advisory (INFRA-143)

gray-matter (transitive via @11ty/eleventy) pulled js-yaml 3.14.2, flagged by
GHSA-h67p-54hq-rp68 (quadratic-complexity DoS in merge-key handling, moderate).
Add a scoped nested npm override pinning gray-matter's js-yaml to ^3.15.0, the
fixed 3.x release, leaving Eleventy's direct js-yaml 4.x untouched. npm audit
now reports 0 vulnerabilities and the Eleventy build passes.
2026-07-08 16:21:21 -04:00
dependabot[bot]
e78fe4f730
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#26)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group with 1 update: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.2
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](254c19bd24...517a711dbc)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 13:54:15 -04:00
Adam Moussa
3d8a9cb459
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 18:28:22 -04:00
Adam Moussa
753e54c70c
chore(ci): SHA-pin mutable-tag third-party actions (INFRA-118) (#24) 2026-07-06 18:27:59 -04:00
Adam Moussa
c1b463639b
chore(ci): add org dependency-review caller (INFRA-125) (#23)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:41:00 -04:00
dependabot[bot]
76365ceeeb
Bump actions/checkout from 6 to 7 (#22)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 12:29:43 -04:00
Adam Moussa
c31819ab01
Merge pull request #21 from Sea-Haven-Industries/feature/frontend-polish
Some checks failed
Deploy / deploy (push) Has been cancelled
Frontend polish: self-host fonts, lazy reCAPTCHA, structured data, CSS cleanup
2026-06-12 17:28:31 -04:00
01daf05bbc docs: changelog for frontend polish 2026-06-12 17:26:34 -04:00
87d5dd5d0a perf: self-host fonts + lazy-load reCAPTCHA
Self-host DM Serif Display (regular+italic) and Inter (variable) as
latin-subset woff2 (~84KB), with @font-face + font-display:swap and
preloads. Removes render-blocking Google Fonts (2 third-party origins,
extra DNS/preconnect). reCAPTCHA api.js is no longer eager-loaded in
<head>; form.js injects it on first form focus/submit, keeping ~50KB+
of third-party JS off initial load on form pages. CloudFront CSP
font-src updated to allow 'self' (additive; gstatic kept for transition).
2026-06-12 17:26:14 -04:00
381f6b6dce feat(seo): BreadcrumbList on interior pages + richer LocalBusiness
Add a breadcrumb-ld partial (rendered from breadcrumbName/breadcrumbParent
front-matter) emitting BreadcrumbList JSON-LD on all 11 interior pages
(3-level on the job pages). Enrich homepage LocalBusiness with geo,
areaServed (US), and hasMap. NOTE: geo coords are approximate (Ronkonkoma
ZIP) — set precisely from the Google Business Profile; openingHours and
sameAs omitted pending real hours + non-placeholder social URLs.
2026-06-12 17:23:11 -04:00
999249c0fe refactor(css): drop dead classes + nav !important hacks
Remove unused .display-xl/.body-lg/.body-sm. Replace the 4 !important
nav-hover overrides with specificity-correct hover rules in home.css
(transparent homepage nav) so the cascade resolves without !important.
No visual change.
2026-06-12 17:23:11 -04:00
Adam Moussa
5ee640074c
Migrate to thin Eleventy build + a11y/SEO/perf/CI hardening (#20)
* chore(build): add Eleventy scaffold

Thin Eleventy build (v3.1.6, pinned) — passthrough-copies assets/,
robots.txt, sitemap.xml; outputs flat HTML to _site/. _data/site.json
holds site-wide constants; _data/images.json maps image keys to
src+width+height for the {% image %} shortcode (CLS fix). Output stays
flat HTML served from the same S3 bucket + CloudFront.

* refactor(templates): base layout, partials, shared JS, CSS extraction

- _includes/base.njk + nav/mobile-menu/footer partials reproduce the
  shared chrome once (was hand-duplicated across 13 pages). Adds a
  skip-link and <main> landmark (WCAG 2.4.1), aria-expanded/role=dialog
  hooks on the menu, and a {% year %} shortcode replacing document.write.
- assets/js/nav.js: extracted sticky-nav + accessible mobile-menu dialog
  (focus trap, Escape, focus return) + rAF-throttled hero parallax.
- assets/js/form.js: Basin AJAX submit with an accessible status region.
- assets/css/*.css: per-page inline <style> extracted into page CSS files
  (home/about/services/careers/jobs/contact/social/legal/404); skip-link
  + :focus-visible added to main.css.
- index.njk: homepage converted as the reference page.

* fix(css): make hero-bg url root-relative after extraction

Inline CSS used a document-relative url('assets/...') that resolves
correctly from / but breaks once moved into /assets/css/home.css.
Rewrite to /assets/images/.

* refactor(pages): convert 12 pages to Eleventy templates

Convert about, services, careers (listing + 3 jobs), contact, social-
accountability, privacy-policy, terms-of-service, eula, and 404 from
standalone HTML to .njk against base.njk. Each page now carries only
front-matter (title/description/SEO) + its <main> content; shared head/
nav/footer/scripts come from the layout. JobPosting + LocalBusiness
JSON-LD preserved. Images use the {% image %} shortcode (width/height).
Contact gets an accessible #form-status region. form.js generalized to
wire BOTH the contact form and the .apply-form job application forms
(was contact-only), preserving each submit button's own label.

* fix(a11y): footer contrast to WCAG AA + scope services .form-group

Raise footer text colors (footer-bottom/col/brand/social/contact) and
darken --text-muted so muted text clears 4.5:1 on the dark footer and
warm-gray surfaces. Scope services' flex .form-group override to
.contact-form .form-group so it can't leak to the global rule.

* perf(seo): og-cover image, webp logos, hero preload

Add a real 1200x630 og-cover.jpg (was a 153x49 favicon) wired site-wide
via base.njk og:image/twitter:image. Convert nav/footer logos to webp
(nav 58KB->22KB); PNGs kept as passthrough so old URLs still resolve.
Preload the LCP hero image on the homepage (fetchpriority=high). All
<img> carry width/height via the image shortcode (CLS).

* ci(deploy): build-then-sync, cache headers, safe concurrency

Rename main.yml -> deploy.yaml (org convention). Build with Eleventy
(npm ci && npm run build) and sync _site/ instead of the repo root, so
only built output ships (no source/templates/node_modules). Split
Cache-Control (1-day assets, no-cache HTML) and keep /* invalidation
since filenames are not yet fingerprinted. concurrency cancel-in-progress
false so a deploy is never cut mid sync. ci.yaml validates _site/ via
ci-static build mode.

* docs: README for the Eleventy build and structure

* fix(security): wire services form, guard build, harden deploy

Fable build-review findings:
- BLOCK: services puts .contact-form on the <form> itself (contact uses a
  wrapper div), so form.js selector '.contact-form form' never matched it
  — the services lead form submitted natively with an empty reCAPTCHA
  token. Selector now also matches form.contact-form.
- Guard the build before the --delete S3 sync: require index/contact/404
  and >=40 files, so a silently-empty build can never wipe the live bucket.
- npm ci --ignore-scripts on deploy (build verified to pass) to shrink the
  supply-chain window on the OIDC-credentialed runner.
- Escape quotes in the image shortcode alt text.
2026-06-12 17:02:06 -04:00
Adam Moussa
f3955e8279
Add Scheduling Coordinator careers posting (#19)
Some checks failed
Deploy Static Site to S3 / deploy (push) Has been cancelled
* Add Scheduling Coordinator careers posting

Publish the Scheduling Coordinator listing covering preventive
maintenance scheduling across U.S. industrial facilities. Includes
the full job description, $70k-$80k pay band, benefits, and an
application form wired to the existing Basin endpoint with reCAPTCHA.

* Add scheduling-coordinator to sitemap and validThrough to all JobPostings

- Add /careers/scheduling-coordinator/ to sitemap.xml so it is
  discoverable by search engines and Google Jobs
- Add validThrough (2026-12-31) to all three JobPosting JSON-LD blocks
  to clear Search Console warnings and prevent stale jobs lingering
- Fix indentation nit on the traveling-maintenance sitemap entry

* Add CI caller for static-site reusable workflow

Calls the org ci-static.yaml reusable on pull_request, emitting the
ci / ci status context required by the main-branch ruleset.

Depends on Sea-Haven-Industries/.github#56 (ci-static.yaml) being merged
to .github@main; until then this run startup-fails.

* Set least-privilege permissions on CI caller

Add explicit 'permissions: contents: read' to the ci.yaml caller,
resolving CodeQL actions/missing-workflow-permissions (medium). The
ci-static reusable only needs read access for checkout + read-only checks.
(Also serves as the re-trigger push now that ci-static.yaml is on main.)
2026-06-12 16:09:48 -04:00
Adam Moussa
705cf9ca82
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#18)
Some checks are pending
Deploy Static Site to S3 / deploy (push) Waiting to run
- Add callable-labeler.yaml caller workflow (.github/workflows/labeler.yml)
- Add minimal README badges (HTML, JavaScript, CI status via main.yml)

Part of INFRA-47 (INFRA-56, INFRA-57).
2026-06-11 14:14:36 -04:00
Adam Moussa
7b54066da0
Update Dependabot: remove assignees, group minor/patch updates (#14) 2026-05-08 14:24:12 -04:00
Adam Moussa
5990a4a126
Remove wrapper workflow — using required workflow via org ruleset (#13) 2026-05-06 19:59:08 -04:00
dependabot[bot]
2411455203
Bump aws-actions/configure-aws-credentials from 2 to 6 (#10)
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 2 to 6.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws-actions/configure-aws-credentials/compare/v2...v6)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-06 18:44:44 -04:00
dependabot[bot]
514da26443
Bump actions/checkout from 4 to 6 (#9)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-06 18:44:33 -04:00
Adam Moussa
e9f8f1a3d3
Add Claude Code review workflow (#12) 2026-05-06 18:11:49 -04:00
Adam Moussa
14249f260f
Merge pull request #11 from Sea-Haven-Industries/feature/dependabot-auto-assign
Auto-assign Dependabot PRs
2026-05-02 17:28:25 -04:00
Adam Moussa
a9c55a921f Auto-assign Dependabot PRs to amoussa1229 2026-05-02 17:26:38 -04:00
Adam Moussa
1933bf9bf7
Merge pull request #8 from Sea-Haven-Industries/feature/add-dependabot-config
Add Dependabot version update configuration
2026-05-02 17:16:00 -04:00
Adam Moussa
2d55878de6 Add Dependabot version update configuration 2026-05-02 17:14:39 -04:00
Adam Moussa
c06e568469
Merge pull request #7 from Sea-Haven-Industries/feature/careers-ui-improvements
Improve careers pages UI/UX
2026-04-30 18:53:34 -04:00
Adam Moussa
e291276f3b Improve careers pages UI/UX for readability, marketing, and conversion
- Add "Apply Now" CTA button to sticky sidebar on both job pages
- Add "Why Work Here" benefit cards section to careers landing
- Make salary visually prominent on job cards (own line, display font)
- Move "Why This Role Stands Out" above requirements on traveling maintenance page
- Add "Back to All Positions" link in hero on both job pages
- Add quick-scan summary callout at top of each job description
- Make entire job card clickable with hover lift effect
- Add team photo as careers hero background
- Consolidate fragmented requirement lists on traveling maintenance page
- Add JSON-LD JobPosting structured data for Google job search SEO
2026-04-30 16:10:12 -04:00
Adam Moussa
028a23b1cd Update README changelog with dynamic copyright year entry 2026-04-30 12:25:06 -04:00
Adam Moussa
43780265f4
Merge pull request #6 from Sea-Haven-Industries/feature/copyright-year-script
Auto-update copyright year in footer
2026-04-30 12:22:41 -04:00
Adam Moussa
a7d347b7d7 Update hardcoded copyright year in footer with document.write(new Date()... on all page footers 2026-04-30 12:21:09 -04:00
Adam Moussa
84c69da929
Merge pull request #5 from Sea-Haven-Industries/feature/careers-restructure
Restructure careers pages and update job postings
2026-04-30 12:11:21 -04:00
Adam Moussa
79a03f01fa Update README changelog with April 2026 careers restructure 2026-04-30 12:00:02 -04:00
Adam Moussa
522cacc7af Update sitemap and README for new careers URL structure 2026-04-30 11:59:25 -04:00
Adam Moussa
1906f10891 Update sitewide nav and footer links from /career/ to /careers/ 2026-04-30 11:59:10 -04:00
Adam Moussa
4f5a6de08f Restructure career/jobs directories into unified careers/
Move career/index.html to careers/index.html, jobs/dispatcher/ to
careers/dispatcher/, and add new careers/traveling-maintenance-assistant/.
2026-04-30 11:58:52 -04:00
Adam Moussa
cc20e9d556 Update workflow trigger from static to main 2026-04-28 14:29:03 -04:00
Adam Moussa
12e0c1efa1 Add EULA page for QuickBooks app listing
Direct-URL-only page (noindex/nofollow, not in sitemap or nav)
for Intuit app store compliance.
2026-04-13 19:18:23 -04:00
Adam Moussa
8bfb13073a
Merge pull request #4 from Sea-Haven-Industries/redesign
Full site redesign: WordPress to clean static HTML
2026-04-07 15:13:11 -04:00
Adam Moussa
0345c1ed18 Extract shared CSS into central main.css stylesheet
Move ~2,600 lines of duplicated CSS (reset, tokens, typography, nav,
footer, buttons, mobile menu, page hero, CTA, form base styles, and
shared responsive breakpoints) into /assets/css/main.css. Each page
now only contains page-specific styles inline.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 15:11:10 -04:00
Adam Moussa
a208794404 Add 404 page, font preloading, JSON-LD schema, and reCAPTCHA badge fix
- Add custom 404.html page with branded design
- Preload Google Fonts stylesheet on all 9 pages for faster rendering
- Add LocalBusiness JSON-LD structured data on homepage for SEO
- Hide reCAPTCHA v3 floating badge on form pages and add required
  Google attribution text in footer

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 14:49:39 -04:00
Adam Moussa
3a9bcc59ce Update README to reflect full static site redesign
Rewrite README with current stack, page index, and April 2026
redesign changelog entries covering the WP-to-static migration.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 14:42:46 -04:00
Adam Moussa
4dd626a3fb Add clean asset images and remove last wp-includes file
Move all site images to /assets/images/ with clean names and delete
the remaining wp-includes block library CSS.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 14:41:24 -04:00
Adam Moussa
49af440bc2 Add original blue wave favicon at 32px and 192px sizes
Restore the original WP site favicon (blue wave icon) in clean paths
for browser tabs and Apple touch icon support.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 14:41:09 -04:00
Adam Moussa
7883a4bfe5 Update homepage with reCAPTCHA v3 and correct favicon
Add Basin reCAPTCHA v3 integration and replace full-logo favicon with
original blue wave icon at 32px and 192px sizes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 14:41:01 -04:00
Adam Moussa
9a6fdff2f8 Rewrite all interior pages as clean static HTML
Strip all WordPress/Elementor markup from 8 interior pages and rebuild
with clean semantic HTML, inline CSS design system, always-white nav,
Basin form backends with AJAX submission, and canonical/OG meta tags.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 14:40:55 -04:00
Adam Moussa
087fe91033 Remove all remaining WordPress/Elementor files
Delete ~8MB of dead WP assets: Elementor CSS, Font Awesome webfonts,
theme files, Simple Job Board plugin, orphaned image uploads, and
wp-includes block library CSS.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-07 14:39:47 -04:00
ca12e05f47 Redesign homepage with custom HTML/CSS template
Replaces Elementor-generated markup with a clean, custom-built template.
Key changes: editorial typography (DM Serif Display + Inter), dark frosted
nav, full-bleed photo service cards, warm off-white color scheme, and
vector SVG logo converted from source EPS via Ghostscript + Inkscape.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-05 16:19:57 -04:00