Replace pnpm-lock.yaml with package-lock.json. The seven security overrides
move to package.json#overrides, including the two version-scoped
brace-expansion entries, which npm resolves per major branch the same way
pnpm did.
pnpm-workspace.yaml's allowBuilds becomes package.json#allowScripts: npm 11
gates dependency install scripts the same way, so sharp and unrs-resolver stay
explicitly approved rather than silently enabled.
History-preserving absorb: the branch's content lands in this merge
commit and is restored to the previous main tree in the next commit.
The branch ref is deleted after this merge; its history stays reachable
through the second parent.
History-preserving absorb: the branch's content lands in this merge
commit and is restored to the previous main tree in the next commit.
The branch ref is deleted after this merge; its history stays reachable
through the second parent.
History-preserving absorb: the branch's content lands in this merge
commit and is restored to the previous main tree in the next commit.
The branch ref is deleted after this merge; its history stays reachable
through the second parent.
History-preserving absorb: the branch's content lands in this merge
commit and is restored to the previous main tree in the next commit.
The branch ref is deleted after this merge; its history stays reachable
through the second parent.
History-preserving absorb: the branch's content lands in this merge
commit and is restored to the previous main tree in the next commit.
The branch ref is deleted after this merge; its history stays reachable
through the second parent.
Clears all 23 open advisories (13 high, 10 moderate) on the default
branch.
next 16.2.10 -> 16.2.11 (18 of the 23 alerts), with eslint-config-next
kept in lockstep.
Bump the exact-pinned overrides that held two packages at vulnerable
versions: js-yaml 4.2.0 -> 4.3.0, postcss 8.5.16 -> 8.5.18.
Add two overrides that no upstream bump could reach:
- sharp 0.35.0, because next 16.2.11 declares ^0.34.5 and caret on a 0.x
version excludes the patched 0.35.0
- brace-expansion 1.1.16 and 5.0.7, scoped per major branch, since
minimatch@3 pulls 1.x and minimatch@10 pulls 5.x independently
Verified by absence: the lockfile no longer contains next 16.2.10,
sharp 0.34.5, postcss 8.5.16, js-yaml 4.2.0, brace-expansion 1.1.14 or
5.0.6. Checking only that patched versions are present would pass while a
vulnerable copy survived under a different parent.
- Downgrade eslint ^10 → ^9 (eslint-config-next@16 requires eslint >=9)
- Rewrite eslint.config.mjs to use native flat config API (defineConfig +
eslint-config-next/core-web-vitals direct import) instead of FlatCompat
bridge which triggers a circular-structure JSON crash with eslint-config-next@16
- Remove @eslint/eslintrc devDep (no longer needed with native flat config)
* refactor: clean up source files and split viewer into modules
Source-level cleanup with no behavior changes:
- Drop unused React default imports (React 19 auto JSX runtime)
- Hoist CHART_COLORS and add MAX_DOTS_DAYS / MAX_LEGEND_LINES named constants
- Use date-fns addDays/subDays in route helpers (no more setDate mutation)
- Drop dead current:0 field from progress state
- Use format() for export filename (local tz, not UTC)
- Replace key={idx} with composite domain keys in table rows
- Fix border-3 (non-existent in Tailwind v4) -> border-[3px] in spinner
- Fix html lang from "vi" to "en" to match UI language
- Sync description text to "Excel or CSV" across metadata and header
Restructure:
- Rename ExchangeRateViewer.js -> exchange-rate-viewer.js (kebab-case)
- Extract icons, storage helpers, and constants into sibling modules
* chore: fix lint script and align dependabot commit format
- Switch pnpm lint to "eslint src" (Next 16 removed "next lint")
- Add conventional commit-message prefix/scope to dependabot config
* docs: align README with current build and export reality
- Mention CSV alongside Excel in feature description
- Drop npm/yarn/bun commands (project locks to pnpm 11.1.1)
- Add Node 24+ / pnpm 11+ requirement note
- Fix edit-page path: src/app/page.js
Source-level cleanup with no behavior changes:
- Drop unused React default imports (React 19 auto JSX runtime)
- Hoist CHART_COLORS and add MAX_DOTS_DAYS / MAX_LEGEND_LINES named constants
- Use date-fns addDays/subDays in route helpers (no more setDate mutation)
- Drop dead current:0 field from progress state
- Use format() for export filename (local tz, not UTC)
- Replace key={idx} with composite domain keys in table rows
- Fix border-3 (non-existent in Tailwind v4) -> border-[3px] in spinner
- Fix html lang from "vi" to "en" to match UI language
- Sync description text to "Excel or CSV" across metadata and header
Restructure:
- Rename ExchangeRateViewer.js -> exchange-rate-viewer.js (kebab-case)
- Extract icons, storage helpers, and constants into sibling modules
Replace all inline styles with Tailwind classes, add SVG icons to
action buttons, right-align numeric table cells with tabular-nums,
add sticky table headers, highlight active date preset, improve
empty state with illustration, fix SSR hydration mismatch for
localStorage settings, and make buttons mobile-responsive.
Toggle "Show Chart" displays line chart above the table.
Supports single-bank and comparison mode visualizations.
Also modularized components: extracted tables, status indicators,
and chart into separate files for maintainability.
Toggle fetches both banks simultaneously, merges by date+currency,
and displays side-by-side in a unified table. Bank selector disabled
in compare mode. Export handles comparison data format.