Skip to content

Preserve Places attribution metadata and refresh project trust guidance - #96

Merged
cablate merged 1 commit into
mainfrom
codex/maps-compliance-deps-demo
Sep 16, 2026
Merged

cablate merged 1 commit into
mainfrom
codex/maps-compliance-deps-demo

Conversation

@cablate

@cablate cablate commented Sep 16, 2026

Copy link
Copy Markdown
Owner

Summary

  • Preserve place, review, photo, and AI-summary source/disclosure metadata through maps_place_details; remove the legacy newest-review merge because it lacks individual review source links.
  • Add focused attribution/storage guidance to the Agent Skill, plus a reproducible no-MCP CLI walkthrough and refreshed backlog.
  • Refresh the lockfile to protobufjs 7.6.6 (GHSA-xq3m-2v4x-88gg patched at 7.5.5) without changing the Google Places/gax major lines.

Verification

  • npm ci, npm ls protobufjs, npm run build, npm run test:unit (30 passed), npm test (no-key smoke), npm run lint (0 errors), npm run format:check, Skill validation, archive check, and npm pack dry-run passed locally.
  • Production audit now reports 0 critical, with 16 other advisories still requiring separate triage. The protobufjs advisory requires attacker-controlled schema/descriptor input; we found no such MCP/CLI/HTTP path, but the lockfile update removes the vulnerable version from repository builds.
  • Real Places metadata field availability and Node 18 compatibility remain for hosted CI with the repository API key. This patch preserves metadata and instructions; downstream apps still own their rendered attribution, terms/privacy, and policy compliance.

@cablate
cablate merged commit ff13fe4 into main Sep 16, 2026
2 checks passed
@cablate
cablate deleted the codex/maps-compliance-deps-demo branch September 16, 2026 14:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant