Commit graph

101 commits

Author SHA1 Message Date
Adam Moussa
f01e528874
ci: enable squash auto-merge on ready PRs (PLAT-108) (#46)
Some checks failed
Deploy / deploy (push) Has been cancelled
* ci: enable squash auto-merge on ready PRs

* fix(ci): serialize auto-merge enable and ignore already-enabled

* fix(ci): emit ci / ci on the merge-queue branch
2026-08-21 23:45:11 +00:00
Adam Moussa
14476f5801
ci: add merge_group trigger for required ci / ci (#45)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-08-21 17:41:45 -04:00
Adam Moussa
dc28a1bbca
fix(iam): drop lambda boundary from github deploy role (PLAT-52) (#44)
Some checks are pending
Deploy / deploy (push) Waiting to run
* fix(iam): drop lambda boundary from github deploy role (PLAT-52)

* fix(iam): skip boundary delete on github deploy role (PLAT-52)
2026-08-20 16:05:23 -04:00
dependabot[bot]
cf7e407386
chore(deps): bump the minor-and-patch group with 4 updates (#43)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 4 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.6 to 1.0.7
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](7ac3528750...e5691d8a7f)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 13:28:31 -04:00
Adam Moussa
7480aee3c8
fix(infra): serve pretty URLs via CloudFront directory index (PLAT-105) (#42)
Some checks failed
Deploy / deploy (push) Has been cancelled
S3 OAC has no directory index, so /sustainability/ 404s while
/sustainability/index.html is live. Rewrite directory URIs on viewer-request.
2026-08-15 05:26:23 +00:00
Adam Moussa
edc4f3f6b9
feat(site): add public sustainability page (DEV-209) (#41)
Some checks are pending
Deploy / deploy (push) Waiting to run
* feat(content): add sustainability page

* feat(nav): add sustainability to primary nav

Five links plus the CTA button no longer fit above the existing 768px
breakpoint; between 769px and ~855px the Get a Quote button wrapped to
two lines inside the 72px bar. Move the nav collapse to its own 900px
media query so the hamburger takes over before the bar runs out of room.
2026-08-14 20:12:29 -04:00
Adam Moussa
70aae64464
chore(infra): restrict Vercel to preview deployments (#40)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-08-14 13:32:44 -04:00
dependabot[bot]
f24af4e790
chore(deps): bump the minor-and-patch group with 4 updates (#39)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 4 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.3 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](3f74677422...7ac3528750)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml` from 1.0.5 to 1.0.6
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](9c1ecf9428...7ac3528750)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml
  dependency-version: 1.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-11 13:59:07 -04:00
Adam Moussa
37c6f80eba
feat(infra): associate shared prod CloudFront WAF (PLAT-92) (#38)
Some checks failed
Deploy / deploy (push) Has been cancelled
* feat(infra): associate shared prod CloudFront WAF with site distribution

Read /seahaven/waf/app-web-acl-arn and set web_acl_id so the marketing
site sits behind the same-account M-17 WebACL.

* chore: empty commit to trigger CI

* fix(infra): mark CloudFront WebACL output nonsensitive

SSM String parameters are sensitive by default, which broke the HCP
speculative plan when exporting the WebACL ARN.
2026-08-07 17:21:46 -04:00
Adam Moussa
7812ec102d
feat(infra): add HCP Terraform for prod static hosting (PLAT-91) (#37)
Some checks are pending
Deploy / deploy (push) Waiting to run
* feat(infra): add HCP Terraform for prod static hosting

Greenfield S3+CloudFront+ACM+OIDC content-deploy role under /tf-managed/,
with OOB mgmt DNS helper for ACM validation and apex alias cutover.

* chore(security): suppress pre-existing js-yaml npm audit

* feat(ci): retarget content deploy to seahaven-prod origin

Point OIDC, S3 sync, and CloudFront invalidation at the HCP-managed
prod hosting stack so GHA remains the content publish path after cutover.
2026-08-07 15:09:54 -04:00
dependabot[bot]
a5b9716c31
chore(deps): bump the minor-and-patch group with 3 updates (#35)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps the minor-and-patch group with 3 updates: [Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml](https://github.com/sea-haven-industries/.github), [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/ci-static.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 18:39:20 -04:00
dependabot[bot]
901dd20027
chore(deps): bump brace-expansion from 1.1.16 to 1.1.18 (#36)
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.16 to 1.1.18.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.16...v1.1.18)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 18:26:55 -04:00
Adam Moussa
f341cf4340
ci: add org PR policy caller (#34)
Some checks are pending
Deploy / deploy (push) Waiting to run
Refs: PLAT-62
2026-08-04 11:56:33 -04:00
Adam Moussa
916c50686a
Merge pull request #33 from Sea-Haven-Industries/ci/pin-reusables-v1.0.2
Some checks failed
Deploy / deploy (push) Has been cancelled
ci(deps): pin org reusable workflows to v1.0.2
2026-07-28 18:11:55 -04:00
Adam Moussa
507a7a1251 style(ci): normalize workflow block spacing 2026-07-28 18:06:30 -04:00
Adam Moussa
69fdc92623 ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:56:30 -04:00
dependabot[bot]
d7848bedbc
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#32)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group with 1 update: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.2 to 6.2.3
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](517a711dbc...e6de054238)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 15:29:34 -04:00
Adam Moussa
1b71f5f56e
chore(security): resolve open npm audit and code scanning alerts (#31)
Some checks are pending
Deploy / deploy (push) Waiting to run
* build(deps): resolve npm audit advisories via in-range bumps

npm audit fix bumps js-yaml 4.3.0, linkify-it 5.0.2, liquidjs
10.27.2, and brace-expansion 1.1.16 to clear four high DoS
advisories. Eleventy build verified passing at 3.1.6.

The remaining brace-expansion advisory (GHSA-mh99-v99m-4gvg) has
no in-range fix: the patch exists only in 5.0.8, and
@11ty/recursive-copy pins an older minimatch. Exposure is
build-time only (glob patterns from our own config, never
untrusted input), so it is suppressed with justification in
.security-review/suppressions.json rather than forcing the
eleventy downgrade npm audit fix --force proposes. Remove the
npmaudit-* suppressions when recursive-copy ships a minimatch
>=10.0.3 bump.

* ci: add least-privilege permissions blocks to workflow callers
Resolves code scanning alert #3 (actions/missing-workflow-permissions). Callable workflow only needs contents: read; the dependency-review callable already declares it internally, this caps the caller token to match.

* ci(dependency-review): allow adjudicated brace-expansion GHSA

Re-pins the callable to 07ce007 (adds the allow-ghsas input, org
PR #89) and allows GHSA-mh99-v99m-4gvg, which the review check
flags on the bumped-but-still-in-range brace-expansion 1.1.16.
The advisory has no in-range fix and is an accepted risk with
written justification in .security-review/suppressions.json;
remove the allowance together with those suppressions when
@11ty/recursive-copy ships a minimatch >=10.0.3 bump.
2026-07-27 17:41:00 +00:00
dependabot[bot]
761faceed7
Bump actions/setup-node from 6 to 7 (#30)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 13:25:35 -04:00
Adam Moussa
e9b121ecfa
chore(security): suppress historical elementor gitleaks FP (INFRA-181) (#29)
Some checks failed
Deploy / deploy (push) Has been cancelled
Adds a scoped suppression for gitleaks-generic-api-key-2464, a high-entropy
false positive in a removed Elementor/WordPress minified vendor bundle that
survives only in git history. Not a live secret. With INFRA-143's two
reCAPTCHA suppressions, the pre-push scanner now passes cleanly on this repo
(0 confirmed high, 3 suppressed) with no --no-verify needed.
2026-07-08 16:53:55 -04:00
Adam Moussa
7fd529ba98
ci: expand dependabot coverage (INFRA-130) (#28)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-08 16:41:16 -04:00
Adam Moussa
68ac0be0d4
INFRA-143: suppress reCAPTCHA site-key gitleaks FP + clear js-yaml DoS advisory (#27)
* chore(security): suppress gitleaks FP on public reCAPTCHA site key (INFRA-143)

The SITE_KEY in assets/js/form.js is a Google reCAPTCHA v3 site key, public
by design (shipped to the browser, passed to grecaptcha.execute). It is not a
secret and is not rotated. Add a scoped repo-local gitleaks suppression with
justification for the current (line 7) and historical (line 5) hits so the
pre-push scanner stops blocking on it.

* fix(deps): pin gray-matter js-yaml to 3.15.0 to clear DoS advisory (INFRA-143)

gray-matter (transitive via @11ty/eleventy) pulled js-yaml 3.14.2, flagged by
GHSA-h67p-54hq-rp68 (quadratic-complexity DoS in merge-key handling, moderate).
Add a scoped nested npm override pinning gray-matter's js-yaml to ^3.15.0, the
fixed 3.x release, leaving Eleventy's direct js-yaml 4.x untouched. npm audit
now reports 0 vulnerabilities and the Eleventy build passes.
2026-07-08 16:21:21 -04:00
dependabot[bot]
e78fe4f730
Bump aws-actions/configure-aws-credentials in the minor-and-patch group (#26)
Some checks are pending
Deploy / deploy (push) Waiting to run
Bumps the minor-and-patch group with 1 update: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials).


Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.2
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](254c19bd24...517a711dbc)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 13:54:15 -04:00
Adam Moussa
3d8a9cb459
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#25)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 18:28:22 -04:00
Adam Moussa
753e54c70c
chore(ci): SHA-pin mutable-tag third-party actions (INFRA-118) (#24) 2026-07-06 18:27:59 -04:00
Adam Moussa
c1b463639b
chore(ci): add org dependency-review caller (INFRA-125) (#23)
Some checks are pending
Deploy / deploy (push) Waiting to run
2026-07-06 17:41:00 -04:00
dependabot[bot]
76365ceeeb
Bump actions/checkout from 6 to 7 (#22)
Some checks failed
Deploy / deploy (push) Has been cancelled
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 12:29:43 -04:00
Adam Moussa
c31819ab01
Merge pull request #21 from Sea-Haven-Industries/feature/frontend-polish
Some checks failed
Deploy / deploy (push) Has been cancelled
Frontend polish: self-host fonts, lazy reCAPTCHA, structured data, CSS cleanup
2026-06-12 17:28:31 -04:00
01daf05bbc docs: changelog for frontend polish 2026-06-12 17:26:34 -04:00
87d5dd5d0a perf: self-host fonts + lazy-load reCAPTCHA
Self-host DM Serif Display (regular+italic) and Inter (variable) as
latin-subset woff2 (~84KB), with @font-face + font-display:swap and
preloads. Removes render-blocking Google Fonts (2 third-party origins,
extra DNS/preconnect). reCAPTCHA api.js is no longer eager-loaded in
<head>; form.js injects it on first form focus/submit, keeping ~50KB+
of third-party JS off initial load on form pages. CloudFront CSP
font-src updated to allow 'self' (additive; gstatic kept for transition).
2026-06-12 17:26:14 -04:00
381f6b6dce feat(seo): BreadcrumbList on interior pages + richer LocalBusiness
Add a breadcrumb-ld partial (rendered from breadcrumbName/breadcrumbParent
front-matter) emitting BreadcrumbList JSON-LD on all 11 interior pages
(3-level on the job pages). Enrich homepage LocalBusiness with geo,
areaServed (US), and hasMap. NOTE: geo coords are approximate (Ronkonkoma
ZIP) — set precisely from the Google Business Profile; openingHours and
sameAs omitted pending real hours + non-placeholder social URLs.
2026-06-12 17:23:11 -04:00
999249c0fe refactor(css): drop dead classes + nav !important hacks
Remove unused .display-xl/.body-lg/.body-sm. Replace the 4 !important
nav-hover overrides with specificity-correct hover rules in home.css
(transparent homepage nav) so the cascade resolves without !important.
No visual change.
2026-06-12 17:23:11 -04:00
Adam Moussa
5ee640074c
Migrate to thin Eleventy build + a11y/SEO/perf/CI hardening (#20)
* chore(build): add Eleventy scaffold

Thin Eleventy build (v3.1.6, pinned) — passthrough-copies assets/,
robots.txt, sitemap.xml; outputs flat HTML to _site/. _data/site.json
holds site-wide constants; _data/images.json maps image keys to
src+width+height for the {% image %} shortcode (CLS fix). Output stays
flat HTML served from the same S3 bucket + CloudFront.

* refactor(templates): base layout, partials, shared JS, CSS extraction

- _includes/base.njk + nav/mobile-menu/footer partials reproduce the
  shared chrome once (was hand-duplicated across 13 pages). Adds a
  skip-link and <main> landmark (WCAG 2.4.1), aria-expanded/role=dialog
  hooks on the menu, and a {% year %} shortcode replacing document.write.
- assets/js/nav.js: extracted sticky-nav + accessible mobile-menu dialog
  (focus trap, Escape, focus return) + rAF-throttled hero parallax.
- assets/js/form.js: Basin AJAX submit with an accessible status region.
- assets/css/*.css: per-page inline <style> extracted into page CSS files
  (home/about/services/careers/jobs/contact/social/legal/404); skip-link
  + :focus-visible added to main.css.
- index.njk: homepage converted as the reference page.

* fix(css): make hero-bg url root-relative after extraction

Inline CSS used a document-relative url('assets/...') that resolves
correctly from / but breaks once moved into /assets/css/home.css.
Rewrite to /assets/images/.

* refactor(pages): convert 12 pages to Eleventy templates

Convert about, services, careers (listing + 3 jobs), contact, social-
accountability, privacy-policy, terms-of-service, eula, and 404 from
standalone HTML to .njk against base.njk. Each page now carries only
front-matter (title/description/SEO) + its <main> content; shared head/
nav/footer/scripts come from the layout. JobPosting + LocalBusiness
JSON-LD preserved. Images use the {% image %} shortcode (width/height).
Contact gets an accessible #form-status region. form.js generalized to
wire BOTH the contact form and the .apply-form job application forms
(was contact-only), preserving each submit button's own label.

* fix(a11y): footer contrast to WCAG AA + scope services .form-group

Raise footer text colors (footer-bottom/col/brand/social/contact) and
darken --text-muted so muted text clears 4.5:1 on the dark footer and
warm-gray surfaces. Scope services' flex .form-group override to
.contact-form .form-group so it can't leak to the global rule.

* perf(seo): og-cover image, webp logos, hero preload

Add a real 1200x630 og-cover.jpg (was a 153x49 favicon) wired site-wide
via base.njk og:image/twitter:image. Convert nav/footer logos to webp
(nav 58KB->22KB); PNGs kept as passthrough so old URLs still resolve.
Preload the LCP hero image on the homepage (fetchpriority=high). All
<img> carry width/height via the image shortcode (CLS).

* ci(deploy): build-then-sync, cache headers, safe concurrency

Rename main.yml -> deploy.yaml (org convention). Build with Eleventy
(npm ci && npm run build) and sync _site/ instead of the repo root, so
only built output ships (no source/templates/node_modules). Split
Cache-Control (1-day assets, no-cache HTML) and keep /* invalidation
since filenames are not yet fingerprinted. concurrency cancel-in-progress
false so a deploy is never cut mid sync. ci.yaml validates _site/ via
ci-static build mode.

* docs: README for the Eleventy build and structure

* fix(security): wire services form, guard build, harden deploy

Fable build-review findings:
- BLOCK: services puts .contact-form on the <form> itself (contact uses a
  wrapper div), so form.js selector '.contact-form form' never matched it
  — the services lead form submitted natively with an empty reCAPTCHA
  token. Selector now also matches form.contact-form.
- Guard the build before the --delete S3 sync: require index/contact/404
  and >=40 files, so a silently-empty build can never wipe the live bucket.
- npm ci --ignore-scripts on deploy (build verified to pass) to shrink the
  supply-chain window on the OIDC-credentialed runner.
- Escape quotes in the image shortcode alt text.
2026-06-12 17:02:06 -04:00
Adam Moussa
f3955e8279
Add Scheduling Coordinator careers posting (#19)
Some checks failed
Deploy Static Site to S3 / deploy (push) Has been cancelled
* Add Scheduling Coordinator careers posting

Publish the Scheduling Coordinator listing covering preventive
maintenance scheduling across U.S. industrial facilities. Includes
the full job description, $70k-$80k pay band, benefits, and an
application form wired to the existing Basin endpoint with reCAPTCHA.

* Add scheduling-coordinator to sitemap and validThrough to all JobPostings

- Add /careers/scheduling-coordinator/ to sitemap.xml so it is
  discoverable by search engines and Google Jobs
- Add validThrough (2026-12-31) to all three JobPosting JSON-LD blocks
  to clear Search Console warnings and prevent stale jobs lingering
- Fix indentation nit on the traveling-maintenance sitemap entry

* Add CI caller for static-site reusable workflow

Calls the org ci-static.yaml reusable on pull_request, emitting the
ci / ci status context required by the main-branch ruleset.

Depends on Sea-Haven-Industries/.github#56 (ci-static.yaml) being merged
to .github@main; until then this run startup-fails.

* Set least-privilege permissions on CI caller

Add explicit 'permissions: contents: read' to the ci.yaml caller,
resolving CodeQL actions/missing-workflow-permissions (medium). The
ci-static reusable only needs read access for checkout + read-only checks.
(Also serves as the re-trigger push now that ci-static.yaml is on main.)
2026-06-12 16:09:48 -04:00
Adam Moussa
705cf9ca82
Repo hygiene: PR labeler + README badges (INFRA-56/57) (#18)
Some checks are pending
Deploy Static Site to S3 / deploy (push) Waiting to run
- Add callable-labeler.yaml caller workflow (.github/workflows/labeler.yml)
- Add minimal README badges (HTML, JavaScript, CI status via main.yml)

Part of INFRA-47 (INFRA-56, INFRA-57).
2026-06-11 14:14:36 -04:00
Adam Moussa
7b54066da0
Update Dependabot: remove assignees, group minor/patch updates (#14) 2026-05-08 14:24:12 -04:00
Adam Moussa
5990a4a126
Remove wrapper workflow — using required workflow via org ruleset (#13) 2026-05-06 19:59:08 -04:00
dependabot[bot]
2411455203
Bump aws-actions/configure-aws-credentials from 2 to 6 (#10)
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 2 to 6.
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](https://github.com/aws-actions/configure-aws-credentials/compare/v2...v6)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-06 18:44:44 -04:00
dependabot[bot]
514da26443
Bump actions/checkout from 4 to 6 (#9)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-06 18:44:33 -04:00
Adam Moussa
e9f8f1a3d3
Add Claude Code review workflow (#12) 2026-05-06 18:11:49 -04:00
Adam Moussa
14249f260f
Merge pull request #11 from Sea-Haven-Industries/feature/dependabot-auto-assign
Auto-assign Dependabot PRs
2026-05-02 17:28:25 -04:00
Adam Moussa
a9c55a921f Auto-assign Dependabot PRs to amoussa1229 2026-05-02 17:26:38 -04:00
Adam Moussa
1933bf9bf7
Merge pull request #8 from Sea-Haven-Industries/feature/add-dependabot-config
Add Dependabot version update configuration
2026-05-02 17:16:00 -04:00
Adam Moussa
2d55878de6 Add Dependabot version update configuration 2026-05-02 17:14:39 -04:00
Adam Moussa
c06e568469
Merge pull request #7 from Sea-Haven-Industries/feature/careers-ui-improvements
Improve careers pages UI/UX
2026-04-30 18:53:34 -04:00
Adam Moussa
e291276f3b Improve careers pages UI/UX for readability, marketing, and conversion
- Add "Apply Now" CTA button to sticky sidebar on both job pages
- Add "Why Work Here" benefit cards section to careers landing
- Make salary visually prominent on job cards (own line, display font)
- Move "Why This Role Stands Out" above requirements on traveling maintenance page
- Add "Back to All Positions" link in hero on both job pages
- Add quick-scan summary callout at top of each job description
- Make entire job card clickable with hover lift effect
- Add team photo as careers hero background
- Consolidate fragmented requirement lists on traveling maintenance page
- Add JSON-LD JobPosting structured data for Google job search SEO
2026-04-30 16:10:12 -04:00
Adam Moussa
028a23b1cd Update README changelog with dynamic copyright year entry 2026-04-30 12:25:06 -04:00
Adam Moussa
43780265f4
Merge pull request #6 from Sea-Haven-Industries/feature/copyright-year-script
Auto-update copyright year in footer
2026-04-30 12:22:41 -04:00
Adam Moussa
a7d347b7d7 Update hardcoded copyright year in footer with document.write(new Date()... on all page footers 2026-04-30 12:21:09 -04:00
Adam Moussa
84c69da929
Merge pull request #5 from Sea-Haven-Industries/feature/careers-restructure
Restructure careers pages and update job postings
2026-04-30 12:11:21 -04:00