-
GO-30-CSP W2+W3: migrate all inline on* handlers to delegated dispatch
-
Frontend cold spots R4: escapeHandlerArg sweep + gate rule, email preview to Rust
-
Frontend XSS: seal the unsafe attribute escaper (CHRONIC-XSS)
-
UX/security: encode attacker-controlled values for HTML attributes, guard URL schemes
-
CSS dedup + UI mode separation + ยง3 launch-readiness fixes
-
UX audit sweep: Tier 1-4 + Tier 6 + design-system charter
-
Email features: signatures, drafts, labels, notifications
-
Audit Run 14: tests, security hardening, JSDoc, date_utils extraction
-
v0.3.1: Time tracking, file attachments, external sync, email attachments