Jesse Merhi
a3de2360b4
docs: clarify ClawHub vulnerability disclosure policy ( #2567 )
2026-06-09 17:38:56 +10:00
Patrick Erichsen
893f341bdb
feat: add security audits page ( #2207 )
...
* feat: add security audits page
* fix: remove stale nav icon export
2026-05-13 15:37:16 -07:00
c51cfe2459
Add publisher notes and unify ClawScan review pages ( #2111 )
...
* feat: store clawscan notes on artifact versions
* feat: include clawscan notes in evaluation
* feat: unify ClawScan report layout for plugins and skills
* feat: render clawscan notes in publish and security UI
* chore: document local moderation seed fixtures
* fix: remove appeal surfaces
* fix: remove owner-requested rescans
* feat: add publisher note rescan flow
* fix: resolve main rebase fallout
* fix: address review feedback - breadcrumbs, tab guard, merge target, test matcher
Agent-Logs-Url: https://github.com/openclaw/clawhub/sessions/7bfbe5cf-0b8e-44f9-bf0a-e6235f7f3f1d
Co-authored-by: BunsDev <68980965+BunsDev@users.noreply.github.com >
* fix: address pr ci fallout
* fix: resolve ci after main rebase
* fix: make package VT AI verdicts advisory
* fix: restore skill sidebar actions
* fix: resolve clawscan ui and ci checks
* fix: align security settings access and pending audits
* fix: restore skill version tabs
* fix: show publisher names in sidebars
* fix: align plugin install command styling
* fix: clarify virustotal audit copy
* fix: polish security summaries
* test: align security UI expectations
* docs: document clawscan note workflow
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com >
Co-authored-by: BunsDev <68980965+BunsDev@users.noreply.github.com >
2026-05-11 14:14:12 -07:00
Peter Steinberger
3173ecd629
fix: treat VirusTotal AI verdicts as advisory
2026-05-11 08:43:57 +01:00
Peter Steinberger
5d0264daa7
fix: split ClawScan review from suspicious
2026-05-11 01:28:42 +01:00
Peter Steinberger
3d934a5f28
fix: reduce ClawScan false positives
2026-05-10 16:29:02 +01:00
Peter Steinberger
c2c01300a7
fix: make static suspicious findings advisory
2026-05-10 09:57:58 +01:00
Peter Steinberger
3b80e3f67d
fix: reduce ClawScan false positives
2026-05-10 06:50:54 +01:00
Peter Steinberger
003d243ccc
fix: allow staff security rescans
2026-05-10 05:23:41 +01:00
Peter Steinberger
3a6ab49dc3
fix: include package env metadata in ClawScan
2026-05-10 02:50:25 +01:00
Peter Steinberger
0b56c68643
feat: add moderation hold recovery
...
Add admin-only moderation hold recovery with audit logs, docs, and safe skill restoration that preserves independently hidden scanner/manual moderation reasons.\n\nTests:\n- bunx vitest run convex/users.test.ts convex/skills.moderationHold.test.ts --testNamePattern "liftModerationHold|reserveHandleInternal|moderation holds"\n- bunx tsc --noEmit && bunx tsc -p packages/schema/tsconfig.json --noEmit && bunx tsc -p packages/clawhub/tsconfig.json --noEmit\n- bun run ci:static\n- bunx convex codegen\n\nCo-authored-by: Justin Sparks <openclaw@openclaw-secure.local >
2026-05-09 08:40:40 -04:00
Deepak Jain
cb018bf64c
docs: document trademark takedown reports ( #1860 )
...
Fixes #1591
2026-05-09 07:33:47 -04:00
Patrick Erichsen
86898837fb
docs: split ClawHub public docs from specs ( #2095 )
...
* docs: split clawhub docs source
* docs: make clawhub docs product-facing
* docs: refine public clawhub docs routes
2026-05-07 18:54:47 -07:00
Patrick Erichsen
0749f16499
feat: split moderator commands into private cli
2026-05-06 19:05:07 -07:00
Patrick Erichsen
03328f7523
chore: remove stale maintenance helpers
2026-05-06 17:32:24 -07:00
Patrick Erichsen
9fe7532e27
feat: add report status backfill
2026-05-06 17:01:48 -07:00
Patrick Erichsen
cab18339e6
docs: align moderation wording with moderator role
2026-05-06 16:42:15 -07:00
Patrick Erichsen
c4d1fcdbc6
feat: add skill artifact moderation cases
2026-05-06 15:22:54 -07:00
Vincent Koc
ca0d0bd1bd
docs(security): clarify clawpack scan scope
2026-05-02 13:47:05 -07:00
Vincent Koc
28da510571
feat(packages): resolve package appeals
2026-05-02 10:50:57 -07:00
Vincent Koc
6e5578ee6d
feat(packages): submit package appeals
2026-05-02 10:47:26 -07:00
Vincent Koc
68017740e7
feat(packages): show moderation status
2026-05-02 10:44:37 -07:00
Vincent Koc
ff68eeb5d1
feat(packages): triage package reports
2026-05-02 10:40:13 -07:00
Vincent Koc
276760d703
feat(packages): report packages for review
2026-05-02 10:35:28 -07:00
Peter Steinberger
bc06c472e4
fix(packages): authenticate repository lookups
2026-04-28 02:20:35 +01:00
Peter Steinberger
3fb3150ee2
fix: allow package downloads while VT scan is pending
2026-03-28 02:54:10 +00:00
Peter Steinberger
dda6d55fbf
fix: unblock package vt scan fallback stalls
2026-03-27 02:06:03 +00:00
Peter Steinberger
c1363ec8d0
feat: add acceptable usage about page
2026-03-23 17:37:17 -07:00
Peter Steinberger
7e09196f92
feat: backfill static plugin scans
2026-03-23 15:58:02 -07:00
Val Alexander
deb592d4ce
docs: update repository guidelines and improve formatting across multiple files
...
- Enhanced AGENTS.md with clearer project structure and development commands.
- Updated CHANGELOG.md to reflect recent fixes and additions.
- Improved formatting in CONTRIBUTING.md for better readability.
- Adjusted package.json and configuration files for consistent command structure.
- Refined README.md and VISION.md for clarity and organization.
- Standardized code formatting in various TypeScript files for consistency.
These changes aim to enhance documentation clarity and maintainability across the repository.
2026-03-18 21:56:01 -05:00
Peter Steinberger
0ab23862a9
feat: harden skill moderation and canonicalization
2026-03-13 21:35:39 +00:00
Peter Steinberger
e31a8e9d32
fix: add structured moderation snapshots ( #333 ) (thanks @ArthurzKV)
2026-03-08 03:13:13 +00:00
Peter Steinberger
3e45d67e0d
fix: delete and hide comments from banned users
2026-02-26 05:52:09 +01:00
Peter Steinberger
df346aeea9
feat: require 14-day GitHub age for publish and comments
2026-02-26 05:35:44 +01:00
Peter Steinberger
e04d16bdae
feat: add ai comment scam backfill and auto-ban flow
2026-02-26 02:16:31 +01:00
Peter Steinberger
cb66d8d6f3
feat: add abuse-resistant comment reporting
2026-02-26 01:28:22 +01:00
Peter Steinberger
3326a5c838
refactor: simplify GitHub age gate cache
2026-02-14 20:53:05 +01:00
Matt Krokosz
f05dd556db
fix: gate publish by immutable GitHub account ID
2026-02-14 20:25:15 +01:00
Peter Steinberger
a4b850ec33
feat: improve moderation/admin UX + language-aware quality gate
...
- API: owner-visible responses for hidden/soft-deleted skills\n- Admin: add unban user mutations + docs\n- Quality: Intl.Segmenter tokenization + CJK signal to reduce false rejects\n- Jobs: skill-stat-events interval 15m -> 5m\n- Tests: add coverage for owner-visible states + non-Latin docs\n- Changelog: add Unreleased entry
2026-02-14 13:54:03 +01:00
Peter Steinberger
65a14dcef3
feat: make account deletion irreversible and migrate lint to oxlint
2026-02-14 02:15:01 +01:00
Peter Steinberger
d12d6e3926
feat: add non-suspicious skills filter toggle
2026-02-13 19:05:46 +01:00
7dcada9122
fix: handle GitHub API rate limits in account age check ( #246 )
...
* fix: handle GitHub API rate limits in account age check
The GitHub account lookup uses unauthenticated requests (60 req/hr
per IP). Since this runs server-side in Convex, all users share the
same IP and quickly exhaust the rate limit, causing "GitHub account
lookup failed" errors during skill publish.
- Detect 403/429 responses and surface a clear rate-limit message
- Support optional GITHUB_TOKEN env var for authenticated requests
(5,000 req/hr)
Fixes #155
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
* fix: stabilize GitHub account gate tests and docs
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-02-13 01:21:30 +01:00
Peter Steinberger
81b53f0b20
feat: add ban reasons to moderation
2026-02-10 13:11:47 +01:00
Peter Steinberger
405c74a4ef
feat: require report reasons
2026-02-02 00:57:45 -08:00
Peter Steinberger
7b2bdbd08f
feat: harden moderation and upload safety
2026-02-02 00:17:34 -08:00