# Caterium v17.6.0 Stability & Security ## Rollback v17.5.31 is frozen separately as `Caterium-v17.5.31-ROLLBACK.zip` and remains the rollback point. ## Verification completed - Stored DOM-XSS regression payload: no script execution in the completed browser QA pass. - Shared safe DOM insertion helper replaces fragile insertBefore call sites used by dynamic navigation/settings UI. - Four client-offer templates checked: Light, Editorial Grid, Midnight Glass, Emerald Gold. - Catalog PDF checked separately. - Final PDF preflight: 0 open/structure errors across all 5 generated PDF files; every page re-rendered successfully. - PDF pages use consistent A4 geometry; no page clipping/overlap was found in the visual contact-sheet review. - PDFs remain image-based by design in this release; the preflight warning about image-only/scanned-like content is expected. - 390px mobile viewport was rechecked after the second-pass containment fix; the document-level horizontal overflow was removed. - Chat navigation remains a single sidebar/bottom-nav item and order chat remains inline in the order. - Current catalog: 113 photos; legacy compatibility: 60 photos. - Production `caterium-create-employee` Edge Function source is versioned in the archive; service-role credentials remain environment-only. - Blocking `offer-gallery-data.js` was removed; only the two gallery JPGs actually used by the offer remain. ## Automated gates - `npm test` = syntax checks + static security checks + release checks. - Playwright E2E specifications are included under `tests/` for CI/local environments with Playwright installed. - The current execution environment blocks direct Chromium navigation by administrator policy, so the final packaging pass relies on the already completed browser QA artifacts plus the repeatable static/release gates and PDF render/preflight loop. ## Release score loop First full pass: **7.0/10**. Main residual issues were mobile horizontal overflow, remaining fragile DOM insertion points, and insufficient release gating. Second pass: **9.0/10** after mobile containment, additional safe DOM insertion replacements, PDF render/preflight QA, production Edge Function source recovery, startup payload trimming, and release/security gates. The remaining point is architectural debt: the application is still a large historical monolith and the PDF is image-based rather than selectable/vector text.