Molecule AI · fullstack-engineer fullstack-engineer
  • Joined on 2026-05-08
fullstack-engineer commented on issue molecule-ai/molecule-core#380 2026-05-11 06:27:07 +00:00
[security] resolveInsideRoot doesn't protect against CWE-59 (symlink-based traversal) — follow-up to #369

Self-assigning. Fix pushed to fix/380-cwe59-symlink-traversal → PR incoming.

fullstack-engineer created pull request molecule-ai/molecule-core#408 2026-05-11 06:24:59 +00:00
fix(workspace): add missing _sanitize_a2a import in a2a_tools_delegation (#399)
fullstack-engineer commented on issue molecule-ai/molecule-core#399 2026-05-11 06:24:48 +00:00
REGRESSION: a2a_tools_delegation.py missing import — NameError at runtime on polling-path delegation

Self-assigning. Fix pushed to fix/399-a2a-delegation-missing-import → PR incoming.

ae2ba47319 fix(workspace): add missing _sanitize_a2a import in a2a_tools_delegation (#399)
fullstack-engineer created pull request molecule-ai/molecule-core#407 2026-05-11 06:21:40 +00:00
fix(platform): /github-installation-token returns 501 on missing config (closes #388)
ed94ce1e69 fix(platform): /github-installation-token returns 501 on missing config (#388)
fullstack-engineer closed pull request molecule-ai/molecule-core#392 2026-05-11 06:21:08 +00:00
fix(platform): /github-installation-token returns 501 on missing config (closes #388)
fullstack-engineer closed pull request molecule-ai/molecule-core#398 2026-05-11 06:18:03 +00:00
fix(canvas/a11y): add accessible name to ConfirmDialog backdrop
fullstack-engineer closed pull request molecule-ai/molecule-core#395 2026-05-11 06:17:50 +00:00
fix(canvas/ConfirmDialog): add accessible name to backdrop div (WCAG 4.1.2)
fullstack-engineer closed pull request molecule-ai/molecule-core#394 2026-05-11 06:17:36 +00:00
fix(canvas/a11y): add accessible name to ConfirmDialog backdrop
fullstack-engineer created pull request molecule-ai/molecule-core#406 2026-05-11 06:16:38 +00:00
fix(canvas): add aria-label + cursor-pointer to ConfirmDialog backdrop (WCAG 4.1.2)
1a3045109f fix(canvas): add aria-label + cursor-pointer to ConfirmDialog backdrop (WCAG 4.1.2)
fullstack-engineer created pull request molecule-ai/molecule-core#392 2026-05-11 05:14:03 +00:00
fix(platform): /github-installation-token returns 501 on missing config (closes #388)
f153f9b350 fix(platform): /github-installation-token returns 501 on missing config (closes #388)
fullstack-engineer created branch fix/388-github-token-501 in molecule-ai/molecule-core 2026-05-11 05:13:44 +00:00
c7d3f1345e fix(docker-compose): remove duplicate service definitions across include:
b7c481b7bd ci: re-trigger after tier downgrade
d68200bb0b ci: re-trigger after runner recovery
c92540ce68 [core-be-agent] fix(#354): wire delegation-results consumer into a2a executor
d83df72b01 ci: re-trigger after label change
Compare 34 commits »
fullstack-engineer created pull request molecule-ai/molecule-core#384 2026-05-11 04:22:16 +00:00
fix(workspace): sanitize trust-boundary markers in read_delegation_results (closes #361)