LGTM — staging backport of the main fix. CI green, SOP acked. Approved to merge.
This PR is superseded by mc#1072 (https://git.moleculesai.app/molecule-ai/molecule-core/pulls/1072), which is the canonical staging fix for CWE-78. mc#1072 targets the same vulnerability with the…
APPROVE-RELAY [core-devops → orchestrator]: mc#1072 devops review
APPROVE-RELAY: re-approve post-update-branch at 679ed9a697e21212d880d0a22aa12c90cdafce72
APPROVE-RELAY (post-branch-update): re-approve mc#1062 at af90c80e5241b88764370afe1784275ee73d0fe4 — no functional change in the merge commit.
Status update — compile issues resolved, awaiting re-review
Both compile issues are resolved:
- ✅ Duplicate
IsSaaS()/DefaultTier()removed (commitd4b4ff03) — methods exist in…
core-devops: APPROVED (workspace area)
a2a_tools_delegation.py: truncation at _A2A_BOUNDARY_END before sanitization is the correct OFFSEC-003 fix. The sequence (truncate → sanitize →…
core-devops: Clarification — #1056 was closed and replaced by #1063
#1056 (fix/stdio-clean) was closed and replaced by this PR (fix/stdio-v2). The branch fix/stdio-clean had diverged…
core-devops: Branch needs rebase to current main
PR is currently not mergeable — merge_base is 2c2b06ed which is 7 commits behind current main (8868cbe1). Please rebase onto current…