-
Frontend cold spots R4: escapeHandlerArg sweep + gate rule, email preview to Rust
-
Security: single-source escaping into js/escape.js, cover the compose window; bump ammonia
-
Frontend XSS: seal the unsafe attribute escaper (CHRONIC-XSS)
-
Add "What's New" after-update dialog and standardize empty states
-
Audit remediation: observability, adversarial fixes, JS tests, doc comments