-
GO-30-CSP W2+W3: migrate all inline on* handlers to delegated dispatch
-
Remove Rhai plugin runtime; native CSV import (Security axis)
-
Frontend XSS: seal the unsafe attribute escaper (CHRONIC-XSS)
-
UX/security: encode attacker-controlled values for HTML attributes, guard URL schemes
-
CSS dedup + UI mode separation + ยง3 launch-readiness fixes
-
Audit Run 14: tests, security hardening, JSDoc, date_utils extraction
-
Mobile UX improvements, monthly review, maintainability splits
-
Initial commit