Yiğit ERDOĞAN
8bf424cff1
fix: keep logged package publish metadata on a single line ( #3447 )
...
The resolve step echoes the publish command with shlex.quote, which is shell
quoting rather than output escaping: it wraps a value holding a line break in
single quotes and leaves the break itself intact. A caller-supplied changelog,
categories or topics value carrying a newline therefore opened a second line
in the step log, and the runner parses each stdout line, so that second line
reached it as a workflow command.
Escape the parts that are not printable in the echo. The re-runnable .sh file
keeps plain shell quoting, because there the quoting is what makes the script
correct.
2026-08-11 10:52:24 -07:00
Martin Cleary
d9157142e9
fix: synchronize ClawSweeper dispatch identity ( #3449 )
2026-08-11 01:00:36 +01:00
Gio Della-Libera
348851eeb9
feat(claws): align package layers with schema v1 ( #3328 )
...
Adds conventional harness profiles, package-root BOOTSTRAP.md, strict OpenClaw validation, portable path hardening, and an official upstream contract pin.
2026-08-09 07:46:06 -07:00
Sergio Peschiera and Patrick Erichsen
6d935f0595
feat: forward package catalog metadata in publish workflow ( #3074 )
...
* feat: forward package catalog metadata in publish workflow
* docs: make package publish metadata example event-safe
* fix: preserve package metadata clearing
---------
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com >
2026-08-05 21:03:32 -07:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
c943f578f1
chore(deps): bump the github-actions group across 1 directory with 4 updates ( #3291 )
...
Bumps the github-actions group with 4 updates in the / directory: [actions/setup-node](https://github.com/actions/setup-node ), [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/analyze](https://github.com/github/codeql-action ) and [actions/stale](https://github.com/actions/stale ).
Updates `actions/setup-node` from 6.4.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v6.4.0...v7 )
Updates `github/codeql-action/init` from 4.37.1 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/7188fc363630916deb702c7fdcf4e481b751f97a...f205ea1c3313d32999d8d6a48b4f6530d4437b38 )
Updates `github/codeql-action/analyze` from 4.37.1 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/7188fc363630916deb702c7fdcf4e481b751f97a...f205ea1c3313d32999d8d6a48b4f6530d4437b38 )
Updates `actions/stale` from 10 to 11
- [Release notes](https://github.com/actions/stale/releases )
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/stale/compare/v10...v11 )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/stale
dependency-version: '11'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/init
dependency-version: 4.37.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 19:26:38 -07:00
Vincent Koc
e590103d70
fix(ci): authenticate skill updater pull requests ( #3404 )
...
Punchcard-Session: amber-orchard-valley-s4
2026-08-05 10:24:35 +08:00
Vincent Koc
00dd3c3055
fix: prevent worker artifact directory collisions ( #3392 )
...
* fix(workers): share verified artifact materialization
* fix(ci): restore prepublication batch limit
2026-08-04 14:21:00 +08:00
Patrick Erichsen
a16ff751bb
feat: notify plugin owners only for hard compatibility errors ( #3365 )
...
* chore: update plugin inspector to 0.3.20
* feat: gate plugin compatibility emails on hard errors
2026-07-31 17:37:52 -07:00
Vincent Koc
44cee65cac
fix(deploy): preserve active rollout modes ( #3357 )
2026-08-01 01:36:35 +08:00
Vincent Koc
1a3ee6e015
fix(publish): wait for definitive package publication
2026-08-01 01:00:02 +08:00
Patrick Erichsen
6afd21e1a2
feat: refresh beta plugin compatibility nightly ( #3325 )
...
* feat: reconcile nightly plugin validation state
* feat: refresh beta plugin validation nightly
* fix: scope nightly scan notification findings
2026-07-30 15:46:11 -07:00
Patrick Erichsen
5a1d9c9472
fix: preserve canonical skills.sh supplement hashes ( #3308 )
2026-07-30 04:49:52 -07:00
Vincent Koc
23af0934e4
chore: remove kitchen sink repair tooling ( #3307 )
2026-07-30 19:16:58 +08:00
Vincent Koc
d890dfefe8
fix: guard kitchen sink latest repair ( #3306 )
2026-07-30 18:59:17 +08:00
Patrick Erichsen
5b969f9835
feat: publish verified skills.sh catalog ( #3300 )
...
* feat: publish verified skills.sh mirrors
* feat: automate skills.sh catalog synchronization
2026-07-30 01:19:56 -07:00
Gio Della-Libera
79ef4af17f
feat(claws): publish CLAW.md prompts ( #3262 )
...
* feat(claws): publish CLAW.md prompts
* docs(claws): link prompt bridge PR
* fix(claws): align prompt package validation
* test(claws): repin OpenClaw prompt contract
* test(claws): repin updated OpenClaw contract
* test(claws): pin merged OpenClaw prompt contract
2026-07-28 21:42:27 -07:00
Sebastien Tardif
fadecfcd2f
fix(ci): accept npm 12 pack --json object shape in release ( #3276 )
...
npm 12 returns a package-keyed object from `npm pack --json` instead of
an array. The CLI packages.ts path already dual-parses; the release
workflow still assumed an array and would fail packing the CLI tarball
on npm 12 runners.
Refs: openclaw/clawhub#3275
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca >
2026-07-27 14:23:49 -05:00
Patrick Erichsen
f92495fc80
feat: add canonical Trending snapshot API ( #3265 )
...
* feat: materialize canonical trending snapshots
* feat: expose canonical trending api
* test: prove canonical trending in permanent Test
* test: seed canonical trending Test corpus
* test: retain trending sources on cleanup failure
2026-07-25 12:48:02 -05:00
Patrick Erichsen
79cdd938c4
feat: claim skills.sh listings through GitHub Skill Sync ( #3230 )
...
* feat: add verified mirrored skill adoption state
* feat: add mirrored skill adoption preview
* feat: route skills.sh claims through GitHub sync
* ci: allow guarded CLAW-560 Test deploy
* fix: canonicalize claimed GitHub source repos
* fix: use public GitHub auth for skill sync
* fix: authenticate public GitHub source reads
2026-07-25 10:32:09 -05:00
Patrick Erichsen
cb9c6d8381
feat: add external skills.sh detail and install flow ( #3231 )
...
* feat: integrate external skills.sh listings
* test: record permanent Test external flow
* fix: distinguish GitHub alias source fingerprints
* fix: match controlled skills.sh source URL
* test: disambiguate external detail heading
* fix: use folder hash for controlled skills.sh fixture
* test: prepare controlled external fixture for proof
* fix: preserve OpenClaw external trust state
2026-07-25 05:17:04 -05:00
Patrick Erichsen
65ea02f4ca
feat: add canonical mixed skill search ( #3264 )
...
* feat: add canonical mixed skill search
* test: add permanent Test search proof
2026-07-25 02:06:41 -05:00
Patrick Erichsen
5fbd52e137
feat: add skills.sh trending rank overlay ( #3256 )
...
* feat: add skills.sh trending rank overlay
* test: prove trending overlay in permanent Test
* fix: preflight trending hydration bound
* fix: exclude known quarantines from trending hydration
* fix: preserve authoritative trending quarantine state
* fix: read legacy leaderboard captures for trending
* fix: bound trending drift to one mirror batch
* fix: preserve trending hydration overflow
* fix: keep trending replays hydration-free
2026-07-25 01:23:58 -05:00
Gio Della-Libera and Patrick Erichsen
5a3b050751
Add gated Claw hosted feed and lifecycle proof ( #3092 )
...
* feat(claws): publish hosted feed with OpenClaw proof
* test(claws): prove package-local profile feed flow
* fix(claws): encode scoped package artifact routes
* fix(claws): enforce feed rollback and binding
* test(claws): pin hosted OpenClaw contract proof
* test(claws): add Convex feed runtime smoke
* chore(schema): refresh experimental feed declarations
---------
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com >
2026-07-24 19:29:12 -05:00
Patrick Erichsen
62a697ef1e
feat: add permanent Test ranking metrics import ( #3259 )
...
* feat: add Test ranking metrics import
* fix: harden ranking metric table replacement
* fix: reserve Test for ranking imports
* fix: bind ranking rollback to imported state
* fix: persist rollback guard before import
* fix: quiesce ranking metric writes during imports
* fix: bind ranking imports to target identities
* fix: lock ranking target identities during imports
2026-07-24 16:00:27 -05:00
Patrick Erichsen
17f8118d7c
fix: restore rollout automation checks ( #3253 )
2026-07-24 15:39:16 -05:00
Patrick Erichsen
ead9d9409c
chore(deps): migrate to Carapace v0.2.0
2026-07-24 15:27:21 -05:00
Patrick Erichsen
0f84533e9c
feat: add permanent skills.sh mirror storage ( #3227 )
...
* feat: add staged skills.sh mirror storage
* ci: allow guarded CLAW-563 Test deploy
* ci: expose guarded Test deploy diagnostics
* ci: defer branch guard to deploy step
* ci: deploy CLAW-563 PR head to Test
* ci: admit CLAW-563 PR Test job
* fix: make mirror source recovery durable
* ci: trigger labeled mirror load
* feat: activate mirror search queries
* fix: tighten mirror source typing
* fix: bypass protected Test mirror proof
* feat: attribute skill metrics by source
* feat: present stars as bookmarks
* style: format mirror proof changes
* fix: bypass protected mirror readback
* fix: resume mirror past missing scanner pages
* fix: fetch skills.sh mirror audits from api
* fix: validate structural skills.sh identities
* fix: resolve ambiguous skills.sh mirror identities
* feat: stabilize skills.sh mirror ingestion
* fix: account mirror identity conflicts in proof
* fix: quarantine invalid skills.sh detail ids
* fix: resume skills.sh mirror proof
* fix: preserve skills.sh mirror provenance
* fix: recover exact skills.sh mirror runs
* fix: recover stale skills.sh mirror runs
* fix: normalize skills.sh mirror topic facets
* feat: prove complete skills.sh leaderboard mirror
* fix: canonicalize skills.sh source page hashes
* test: enable skills.sh rollout in mirror tests
* ci: skip unrelated Test deploy pull requests
* fix: preserve Vercel preview marker in Test deploy
* fix: tighten Test deploy and metric reconciliation
* fix: bound mirror detail proof pages
* fix: delegate controlled mirror rate limits
* fix: preserve mirror reconciliation progress
* fix: release mirror retry responses
* fix: preserve stale mirror replay state
* fix: authenticate mirror source starts
* fix: delegate mirror identity rate limits
* ci: trigger mirror proof when labeled
* ci: couple mirror deploy and proof opt-in
* fix: admit permanent Vercel Test runtime
* fix: pass Test target to Vercel runtime
* test: align bookmark sync browser labels
* fix: preserve skills.sh source accounting
* fix: preflight active mirror runs
* fix: bind mirror snapshot accounting
* fix: reject truncated replay hashes
* fix: preserve live mirror overlay metadata
2026-07-24 14:32:00 -05:00
Patrick Erichsen
fe8eff20ee
feat: keep external skill rollouts production-dark ( #3236 )
...
* feat: add fail-closed skill rollout gates
* fix: preserve scan queue pagination semantics
2026-07-23 08:36:41 -07:00
Patrick Erichsen
904038cbb4
fix(security): prevent ClawScan timeout worker leaks ( #3223 )
2026-07-22 12:33:49 -07:00
Patrick Erichsen
a9c8efdd93
fix(security): extend prepublication ClawScan timeout ( #3190 )
2026-07-20 11:39:57 -07:00
Patrick Erichsen
57d1e1530b
fix: isolate ClawScan worker shard concurrency ( #3188 )
2026-07-20 11:17:46 -07:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
8aa76c1a72
chore(deps): bump the github-actions group with 2 updates ( #3184 )
...
Bumps the github-actions group with 2 updates: [actions/checkout](https://github.com/actions/checkout ) and [actions/setup-python](https://github.com/actions/setup-python ).
Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases )
- [Commits](https://github.com/actions/checkout/compare/v7...v7.0.1 )
Updates `actions/setup-python` from 6 to 7
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: actions/setup-python
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-20 10:55:30 -07:00
Patrick Erichsen
af3d01c6ad
feat: verify organization GitHub profiles ( #3169 )
2026-07-17 18:02:30 -07:00
Patrick Erichsen
c92776da8b
fix: increase prepublication worker throughput ( #3162 )
2026-07-17 14:25:45 -07:00
Patrick Erichsen
f9e58d4f0c
fix(security): remove VirusTotal from ClawScan workers ( #3156 )
2026-07-17 10:55:54 -07:00
Patrick Erichsen
173fca15fa
ci: cut local-auth e2e critical path ( #3140 )
2026-07-17 10:24:00 -07:00
Patrick Erichsen
aba593104c
chore: pin clawscan 0.1.5 ( #3144 )
2026-07-17 01:29:26 -07:00
Patrick Erichsen
0da4aa718b
fix: restore prepublication ClawScan authentication ( #3142 )
...
* fix: preserve prepublication judge errors
* fix: pass codex credential to prepublication scans
* fix: keep node tests out of vitest
2026-07-16 23:38:09 -07:00
Patrick Erichsen
67e6413cf5
fix: preserve empty prepublication inputs ( #3139 )
2026-07-16 22:14:21 -07:00
Patrick Erichsen
709a4b1dc5
ci: guard catalog feed schema version changes ( #3138 )
2026-07-16 22:11:37 -07:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
872a982014
chore(deps): bump the github-actions group across 1 directory with 4 updates ( #3082 )
...
Bumps the github-actions group with 4 updates in the / directory: [actions/checkout](https://github.com/actions/checkout ), [actions/setup-node](https://github.com/actions/setup-node ), [github/codeql-action/init](https://github.com/github/codeql-action ) and [github/codeql-action/analyze](https://github.com/github/codeql-action ).
Updates `actions/checkout` from 4.2.2 to 7.0.0
- [Release notes](https://github.com/actions/checkout/releases )
- [Commits](https://github.com/actions/checkout/compare/v4.2.2...v7 )
Updates `actions/setup-node` from 6 to 7
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v6...v7 )
Updates `github/codeql-action/init` from 4.36.2 to 4.37.1
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...7188fc363630916deb702c7fdcf4e481b751f97a )
Updates `github/codeql-action/analyze` from 4.36.2 to 4.37.1
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...7188fc363630916deb702c7fdcf4e481b751f97a )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/setup-node
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
- dependency-name: github/codeql-action/init
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-16 20:52:48 -07:00
Patrick Erichsen
352b901c77
fix: install prepublication judge runtime ( #3132 )
2026-07-16 20:36:41 -07:00
Patrick Erichsen
f5ce8d702f
fix: support exact prepublication recovery claims ( #3131 )
2026-07-16 20:32:37 -07:00
Patrick Erichsen
728aba7b9d
fix: prevent prepublication scan starvation ( #3130 )
2026-07-16 20:21:16 -07:00
Patrick Erichsen
1ab6ab1e84
ci: give local-auth shards larger runners ( #3119 )
2026-07-16 16:59:35 -07:00
Patrick Erichsen
bcf33f04ee
refactor(security): remove legacy scan implementation ( #3124 )
2026-07-16 16:49:36 -07:00
Patrick Erichsen
812bc21560
fix(security): reuse cached VirusTotal evidence ( #3118 )
...
* fix(security): reuse cached VirusTotal evidence
* fix(security): requeue failed scan backlog
* fix(security): harden failed scan recovery
2026-07-16 13:27:03 -07:00
Patrick Erichsen
b23d10d989
feat: gate public publishes without breaking old CLIs
...
Closes CLAW-526.\n\nSummary:\n- create pending skill versions and plugin releases that remain hidden until TruffleHog and ClawScan pass\n- preserve older CLI response compatibility while newer CLI output explains pending security checks\n- run prepublication worker promotion/blocking for skills and plugins\n- add local-auth coverage for clean skill/plugin publish and secret-positive skill rejection\n\nValidation on PR head d2482434:\n- local: bunx tsc -p packages/schema/tsconfig.json --noEmit\n- local: bunx tsc -p packages/clawhub/tsconfig.json --noEmit\n- local: bunx vitest run convex/lib/skillPublish.test.ts convex/publishAttempts.test.ts convex/skills.versions.public.test.ts convex/packages.public.test.ts packages/schema/src/schemas.test.ts scripts/security/run-prepublication-worker.test.ts scripts/security/prepublication-worker-workflow.test.ts\n- local: bun run ci:static\n- local: bun run ci:types-build && bun run ci:packages\n- GitHub: pr-gates, static, unit, packages, types-build, e2e-http, old-cli-publish, playwright-smoke, secret scanning, CodeQL, and Vercel preview passed\n\nKnown CI note:\n- unrelated local-auth shards continued to rotate failures under the already-diagnosed local Convex starvation issue; ignored per maintainer instruction.
2026-07-16 11:38:40 -07:00
Patrick Erichsen
8e614ba8d2
fix(security): require ClawScan artifact inspection ( #3099 )
2026-07-15 22:31:20 -07:00
Patrick Erichsen
49abba7747
feat: add security scan comparison modes ( #3095 )
2026-07-15 17:23:28 -07:00