- http.Server with ReadHeaderTimeout/IdleTimeout (no read/write timeouts: /stream/ is long-lived)
- shared outbound clients: providerHTTPClient (5m), apiHTTPClient (30s), imgcache client (30s)
- imgcache: download outside the lock, per-item helper, cache URL uses the file name not the fs path
- writeFileAtomic (temp + fsync + rename) for settings/xepg/pms/urls/authentication JSON
- one package-level logMu for WebScreenLog and notifications; ring buffer keeps the newest lines
- notifications evict the oldest instead of random map entries
- xepg XMLTV file removal rebuilt after the loop; data.go range-mutation removed
- API handler returns after error body; WS request/response fresh per command
- checked type assertions in data/backup/provider/screen
- SIGINT/SIGTERM handled in main via src.Shutdown(); fatal paths exit 1
- Delete BinaryUpdate, internal/up2date, GitHub/Update structs and the
xteveAutoUpdate / update.url settings (UI rows, en.json, defaults).
Settings-schema migrations kept and moved to src/migrate.go.
- Drop kardianos/osext dependency.
- xteve.go version 0200 -> 0201 to match changelog; Drone now fails on drift.
- go.mod go 1.27.1; Dockerfile and Drone golang images pinned to 1.27.1.
- Fix four go vet unreachable-code warnings.
- .gitignore: .gocache/, agent.md, skill.md. .dockerignore: build context
no longer includes caches, ts/, tasks/ or markdown except the changelog.
- Drone: publish :latest only from master; other branches publish a
branch-named tag so a feature push cannot replace the deployed image.
- Add tasks/improvement-plan.md and tasks/todo.md.
- Regenerate src/webUI.go.