History-preserving absorb: the branch's content lands in this merge
commit and is restored to the previous main tree in the next commit.
The branch ref is deleted after this merge; its history stays reachable
through the second parent.
Clears all 23 open advisories (13 high, 10 moderate) on the default
branch.
next 16.2.10 -> 16.2.11 (18 of the 23 alerts), with eslint-config-next
kept in lockstep.
Bump the exact-pinned overrides that held two packages at vulnerable
versions: js-yaml 4.2.0 -> 4.3.0, postcss 8.5.16 -> 8.5.18.
Add two overrides that no upstream bump could reach:
- sharp 0.35.0, because next 16.2.11 declares ^0.34.5 and caret on a 0.x
version excludes the patched 0.35.0
- brace-expansion 1.1.16 and 5.0.7, scoped per major branch, since
minimatch@3 pulls 1.x and minimatch@10 pulls 5.x independently
Verified by absence: the lockfile no longer contains next 16.2.10,
sharp 0.34.5, postcss 8.5.16, js-yaml 4.2.0, brace-expansion 1.1.14 or
5.0.6. Checking only that patched versions are present would pass while a
vulnerable copy survived under a different parent.
- Downgrade eslint ^10 → ^9 (eslint-config-next@16 requires eslint >=9)
- Rewrite eslint.config.mjs to use native flat config API (defineConfig +
eslint-config-next/core-web-vitals direct import) instead of FlatCompat
bridge which triggers a circular-structure JSON crash with eslint-config-next@16
- Remove @eslint/eslintrc devDep (no longer needed with native flat config)
* refactor: clean up source files and split viewer into modules
Source-level cleanup with no behavior changes:
- Drop unused React default imports (React 19 auto JSX runtime)
- Hoist CHART_COLORS and add MAX_DOTS_DAYS / MAX_LEGEND_LINES named constants
- Use date-fns addDays/subDays in route helpers (no more setDate mutation)
- Drop dead current:0 field from progress state
- Use format() for export filename (local tz, not UTC)
- Replace key={idx} with composite domain keys in table rows
- Fix border-3 (non-existent in Tailwind v4) -> border-[3px] in spinner
- Fix html lang from "vi" to "en" to match UI language
- Sync description text to "Excel or CSV" across metadata and header
Restructure:
- Rename ExchangeRateViewer.js -> exchange-rate-viewer.js (kebab-case)
- Extract icons, storage helpers, and constants into sibling modules
* chore: fix lint script and align dependabot commit format
- Switch pnpm lint to "eslint src" (Next 16 removed "next lint")
- Add conventional commit-message prefix/scope to dependabot config
* docs: align README with current build and export reality
- Mention CSV alongside Excel in feature description
- Drop npm/yarn/bun commands (project locks to pnpm 11.1.1)
- Add Node 24+ / pnpm 11+ requirement note
- Fix edit-page path: src/app/page.js
Replace all inline styles with Tailwind classes, add SVG icons to
action buttons, right-align numeric table cells with tabular-nums,
add sticky table headers, highlight active date preset, improve
empty state with illustration, fix SSR hydration mismatch for
localStorage settings, and make buttons mobile-responsive.
Toggle "Show Chart" displays line chart above the table.
Supports single-bank and comparison mode visualizations.
Also modularized components: extracted tables, status indicators,
and chart into separate files for maintainability.
Toggle fetches both banks simultaneously, merges by date+currency,
and displays side-by-side in a unified table. Bank selector disabled
in compare mode. Export handles comparison data format.
API now accepts currency param (USD, EUR, JPY, ALL, etc.).
Returns array of rates per date instead of single object.
Frontend adds currency dropdown with 12 common currencies plus "All".
- Fetch dates in parallel chunks of 5 instead of sequentially
- Simplify page.js to server component, move default dates into viewer
- Replace showTable with hasFetched for clearer semantics
- Normalize date display to yyyy-MM-dd for both banks
- Remove unused Geist_Mono font import (~50KB savings)
- Change lang to "vi" for Vietnamese bank data context
- Clean up empty blocks and redundant variables in API route
- Add card layout, loading spinner, error/empty states for better UX
- Full dark mode support for date picker, tables, and inputs via CSS vars
- Extract reusable RateTable component, remove duplicate table markup
- Fix CSV injection vulnerability with escapeCsv sanitizer
- Fix URL.createObjectURL memory leak
- Replace JS hover handlers with CSS hover for better performance
- Add aria-live region for screen reader announcements
- Fix metadata from default "Create Next App" to proper title
- Differentiate table stripe/hover colors in light mode
Introduces a new index.html file providing a web interface to fetch and export USD exchange rates from BIDV for a selected date range. The README is updated with feature descriptions and relevant API endpoints.
* build(deps): remove unused frameworks and clear all advisories
The v0 scaffold declared @remix-run/react, @sveltejs/kit, svelte, vue and
vue-router, none of which are imported anywhere in the app. Removing them
drops react-router, react-router-dom, turbo-stream, cookie, vite and their
trees, clearing 13 advisories outright.
Replace xlsx with write-excel-file. The npm release of xlsx is abandoned at
0.18.5, so its prototype pollution and ReDoS advisories have no registry fix,
and SheetJS only ships newer builds from its own CDN as a tarball with no
integrity hash, which pnpm rejects. write-excel-file is maintained, carries no
advisories, and pulls in only fflate. The export writes the same eight columns
in the same order to a sheet named "Exchange Rates", with every value still
written as a string. It also cuts the route's first-load JS from 264 kB to
163 kB.
Add pnpm overrides forcing the lowest release that closes every advisory
affecting the previously resolved version of each remaining transitive dep.
postcss is pinned exactly because pnpm's minimumReleaseAge policy rejects
releases younger than 24h during CI installs.
* ci: add typecheck and build workflow
The repository had no workflows. Type errors are skipped during builds via
next.config.mjs, so check them here where a regression fails the run.
Installs use --frozen-lockfile so dependency overrides cannot silently stop
applying.