Skip to content

fix: complete graph isolation and resolution contracts - #1017

Open
n24q02m wants to merge 2 commits into
mainfrom
campaign/mcp-execution-20260905
Open

fix: complete graph isolation and resolution contracts#1017
n24q02m wants to merge 2 commits into
mainfrom
campaign/mcp-execution-20260905

Conversation

@n24q02m

@n24q02m n24q02m commented Sep 8, 2026

Copy link
Copy Markdown
Owner

Scope\n- preserve the new .better-code-review-graph state path without adopting legacy state\n- resolve PHP CALLS targets and protect impact traversal\n- enforce per-sub setup status and HTTP subject isolation\n- validate Cohere dimensions/input types and cursor-based exports\n- update dependency floors/lock and product handover\n\n## Verification\n- focused dimension, PHP, export, setup, and isolation scenarios pass\n- ruff, format check, ty, package build, and full pytest pass\n- full pytest: 1507 passed, 1 skipped, 48 deselected\n\nPaid Cohere live proof remains explicitly pending capped spend authorization; no STABLE promotion included.

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/alembic 1.19.2 UnknownUnknown
pip/fastretrieval 1.2.0 UnknownUnknown
pip/litellm 1.100.0 UnknownUnknown
pip/mcp 1.30.0 UnknownUnknown
pip/tree-sitter-language-pack 1.16.2 UnknownUnknown

Scanned Files

  • uv.lock

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedlitellm@​1.98.0 ⏵ 1.100.074 +1100100100100
Updatedalembic@​1.19.1 ⏵ 1.19.298100100100100
Updatedfastretrieval@​1.1.0 ⏵ 1.2.099100100100100
Updatedmcp@​1.29.1 ⏵ 1.30.099 +1100100100100
Updatedtree-sitter-language-pack@​1.15.8 ⏵ 1.16.2100 +1100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant