Closed as duplicate of #159 / PR #160
Fresh whole-repository PR inventory proved this issue duplicates the already-existing Blob pre-read resource boundary owned by #159 and Draft PR #160.
PR #160 exact head 14652dd74e6f3000b7e963a7549f84970f7354df already implements the same root-cause fix: check authoritative Blob.size before readBlobBytes(blob), retain the post-read assertion as defense in depth, and preserve accepted conversion semantics. Its exact-head hosted evidence is already GREEN in CI 31434603128, Security Scan 31434602378, and SAST 31434603038, with exact 100% owned production coverage plus browser/package/Office evidence.
The duplicate Draft PR #180 created from this issue has also been closed without merging or transferring evidence. #160 remains the canonical active implementation lane while #118 keeps protected main frozen as the 0.6.0 release candidate.
Closed as duplicate of #159 / PR #160
Fresh whole-repository PR inventory proved this issue duplicates the already-existing Blob pre-read resource boundary owned by #159 and Draft PR #160.
PR #160 exact head
14652dd74e6f3000b7e963a7549f84970f7354dfalready implements the same root-cause fix: check authoritativeBlob.sizebeforereadBlobBytes(blob), retain the post-read assertion as defense in depth, and preserve accepted conversion semantics. Its exact-head hosted evidence is already GREEN in CI31434603128, Security Scan31434602378, and SAST31434603038, with exact 100% owned production coverage plus browser/package/Office evidence.The duplicate Draft PR #180 created from this issue has also been closed without merging or transferring evidence. #160 remains the canonical active implementation lane while #118 keeps protected main frozen as the 0.6.0 release candidate.