-
GO-30-CSP W2+W3: migrate all inline on* handlers to delegated dispatch
-
Audit Run 34 cold spots: JMAP tracing, connection-string, calendar bug, cred cleanup
-
Frontend cold spots R4: escapeHandlerArg sweep + gate rule, email preview to Rust
-
Frontend cold spots R1: isAllDay flag, time-summary rollup to Rust, extract injected CSS
-
Frontend XSS: seal the unsafe attribute escaper (CHRONIC-XSS)
-
UX/security: encode attacker-controlled values for HTML attributes, guard URL schemes
-
CSS dedup + UI mode separation + ยง3 launch-readiness fixes
-
UX audit sweep: Tier 1-4 + Tier 6 + design-system charter
-
Mobile UX rework: touch-native interactions, segmented events, iOS fixes
-
Daily notes, implicit contacts, UX polish, calendar views, search