Skip to content

fix(provider-types): update tool response metadata fixture - #11101

Closed
jbg wants to merge 1 commit into
mainfrom
jbg/security-tool-response-meta
Closed

fix(provider-types): update tool response metadata fixture#11101
jbg wants to merge 1 commit into
mainfrom
jbg/security-tool-response-meta

Conversation

@jbg

@jbg jbg commented Aug 10, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • update the legitimate tool-response sanitization fixture for the locked rmcp 3.0.0 API
  • restore compilation and execution of the regression coverage added by fix(conversation): sanitize nested tool responses #10609
  • preserve coverage for text/image annotations, structured content, and result metadata

Security context

This is a follow-up to the merged remediation for:

The production sanitizer is already on main; this corrects the metadata constructor in its legitimate-content regression fixture so the covered issues can be verified on current main after merge.

Verification

  • bin/cargo fmt --check
  • bin/cargo test -p goose-provider-types tool_response (29 passed)
  • bin/cargo build -p goose-provider-types
  • bin/cargo clippy -p goose-provider-types --all-targets -- -D warnings

This finding was discovered by Project Loupe.

@filipkujawa

Copy link
Copy Markdown
Collaborator

Closing as duplicate - same fix landed via #11107.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants