* refactor(scripts): deslop scripts/lib
Consolidate script lifecycle, scenario, planner, report, release and
packaging helpers while retaining CLI and publication contracts.
Keep config-boundary source caches within one scan so repeated in-process
checks observe edits. Carry extracted helpers through selective fixtures
and iOS scope routing. Leave PR tooling and its library import closure intact.
* fix(scripts): retain sanitizer fast path after helper cleanup
* fix(scripts): model watchdog shell consumer in dead-code checks
Honor the release operator decision that a moving Codex npm latest must
not invalidate a release whose pinned harness passed release validation.
Remove the SHA-specific 2026.8.2 exception. Stale pins and unavailable
latest lookups warn in check logs, plan JSON, candidate evidence, and
plugin and parent release job summaries. Keep the declared dependencies
and exact tested pin unchanged.
Malformed or missing required runtime dependency metadata still errors.
Version floors, registry publication checks, package/install failures,
trusted publishing, and required validation lanes remain blocking.
Also read the candidate package count from the planners' canonical all field.
Proof: the live npm check passes for frozen 2026.9.1 metadata with Codex
0.152.1 pinned and npm latest 0.153.0. Three boundary regressions fail on
the original helper. Focused npm/candidate tests pass (161), sibling
ClawHub/workflow tests pass (432), and final aggregate warning tests pass
(9). Changed checks, workflow sanity, and independent review pass.
* fix(plugins): keep OpenCode Go bundled
* fix(plugins): mark OpenCode Go dist bundled
* fix(docs): show OpenCode Go as bundled
* fix(release): defer bundled plugin publication
* feat(tooling): enforce noUncheckedIndexedAccess in the scripts lane
Burns down all 153 scripts-lane errors (bench aggregation, release
checks, i18n inventories, argv indexing) and flips the flag in
tsconfig.scripts.json. Direct-Node-executed release harness scripts use
local narrowing instead of workspace imports, which do not resolve
under plain node execution. Benchmark measured loops untouched.
* fix(scripts): import expect helpers via relative package sources
tsconfig path aliases resolve from cwd under tsx, so release wrapper
scripts running against old release target cwds could not resolve
@openclaw/normalization-core (not a linked root dependency). Relative
package-source imports match the established pattern on the adjacent
lines and are cwd-independent; old-target planning verified directly.
* feat(tooling): add tsgo typecheck lane for scripts/**
* fix(scripts): burn down scripts type debt surfaced by the new lane
Typing-only except bugs the lane surfaced: gh-read timeout race,
Discord Headers spread dropping entries, undefined allowedHeadBranches
match, plugin-boundary matchAll crash. Deletes retired config keys from
fixtures/benches (prompt snapshots regenerated, config dump only) and
the orphaned non-runnable sync-moonshot-docs script. Adds full-surface
.d.mts declarations for existing .mjs boundaries.
Prevents opted-in plugin runtime dependencies from being published with stale
registry pins. The same freshness assertion now guards both npm and ClawHub
release paths, including the managed Codex runtime.
Prepared head SHA: d5d0ecba4b423503475d8861192a48d55b7ef873
Reviewed-by: @fuller-stack-dev
Closes#99951
Extract shared normalization/coercion helpers into private @openclaw/normalization-core workspace package while preserving existing plugin SDK helper subpaths.\n\nAlso keeps direct normalization-core imports internal, wires UI/build/loader resolution, and replaces the slow PR network CodeQL lane with a fast added-line boundary scan while retaining full CodeQL for scheduled/manual runs.\n\nVerification: local moved tests, plugin SDK boundary tests, extension loader tests, agents-support shard, UI build/test, build artifacts, lint, workflow guards, autoreview, and GitHub CI passed on PR head 963d893715.