v2.3.1
v2.3.1 (current) — Security audit hardening
A full security/privacy review found the codebase solid (no XSS, no privacy
leaks, minimal permissions). These are the hardening fixes it produced:
notifLogno longer grows unbounded. The background dedup log (one
timestamped key per fired notification) is now pruned of entries older than
90 days on each daily run. Refund + price-alert + wishlist-jump checks were
consolidated into a singlerunDailyJobs()that prunes afterwards.- Defense-in-depth on tag colors. The one spot that interpolated a tag
color into an HTMLstyleattribute (dashboard game cards) now passes it
through a render-time#hexvalidator (safeHexColor), so it can't become a
CSS-injection vector even if a future write-path forgets to validate. All
other color usages already went through CSSOMsetProperty(injection-proof). AGENTS.mdgitignored. A per-machine Codex mirror of CLAUDE.md (with a
machine-specific path) is no longer flagged as untracked repo noise.
No functional behavior changes. All 34 tests pass; ESLint clean.
Download gog-enhancer-webstore.zip below and load it as an unpacked extension, or wait for the Chrome Web Store listing.