openclaw/CHANGELOG/2026.1.14-1.md
Hannes Rudolph 2227743f74
refactor: split release changelogs and synchronize docs mirrors (#145464)
* refactor: split release changelogs and synchronize docs mirrors

* fix: complete split changelog instructions and validation wiring

* fix: complete release changelog mirror integration

Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver.

* test: align docs agent Git ownership fixtures

Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-11 21:19:18 -07:00

3.8 KiB

2026.1.14-1

Highlights

  • Web search: web_search/web_fetch tools (Brave API) + first-time setup in onboarding/configure.
  • Browser control: Chrome extension relay takeover mode + remote browser control support.
  • Plugins: channel plugins (gateway HTTP hooks) + Zalo plugin + onboarding install flow. (#854) - thanks @longmaba.
  • Security: expanded openclaw security audit (+ --fix), detect-secrets CI scan, and a SECURITY.md reporting policy.

Changes

  • Docs: clarify per-agent auth stores, sandboxed skill binaries, and elevated semantics.
  • Docs: add FAQ entries for missing provider auth after adding agents and Gemini thinking signature errors.
  • Agents: add optional auth-profile copy prompt on agents add and improve auth error messaging.
  • Security: expand openclaw security audit checks (model hygiene, config includes, plugin allowlists, exposure matrix) and extend --fix to tighten more sensitive state paths.
  • Security: add SECURITY.md reporting policy.
  • Channels: add Matrix plugin (external) with docs + onboarding hooks.
  • Plugins: add Zalo channel plugin with gateway HTTP hooks and onboarding install prompt. (#854) - thanks @longmaba.
  • Onboarding: add a security checkpoint prompt (docs link + sandboxing hint); require --accept-risk for --non-interactive.
  • Docs: expand gateway security hardening guidance and incident response checklist.
  • Docs: document DM history limits for channel DMs. (#883) - thanks @pkrmf.
  • Security: add detect-secrets CI scan and baseline guidance. (#227) - thanks @Hyaxia.
  • Tools: add web_search/web_fetch (Brave API), auto-enable web_fetch for sandboxed sessions, and remove the brave-search skill.
  • CLI/Docs: add a web tools configure section for storing Brave API keys and update onboarding tips.
  • Browser: add Chrome extension relay takeover mode (toolbar button), plus openclaw browser extension install/path and remote browser control (standalone server + token auth).

Fixes

  • Sessions: refactor session store updates to lock + mutate per-entry, add chat.inject, and harden subagent cleanup flow. (#944) - thanks @tyler6204.
  • Browser: add tests for snapshot labels/efficient query params and labeled image responses.
  • Google: downgrade unsigned thinking blocks before send to avoid missing signature errors.
  • Doctor: avoid re-adding WhatsApp config when only legacy ack reactions are set. (#927, fixes #900) - thanks @grp06.
  • Agents: scrub tuple items schemas for Gemini tool calls. (#926, fixes #746) - thanks @grp06.
  • Agents: harden Antigravity Claude history/tool-call sanitization. (#968) - thanks @rdev.
  • Agents: stabilize sub-agent announce status from runtime outcomes and normalize Result/Notes. (#835) - thanks @roshanasingh4.
  • Embedded runner: suppress raw API error payloads from replies. (#924) - thanks @grp06.
  • Auth: normalize Claude Code CLI profile mode to oauth and auto-migrate config. (#855) - thanks @sebslight.
  • Daemon: clear persisted launchd disabled state before bootstrap (fixes daemon install after uninstall). (#849) - thanks @ndraiman.
  • Logging: tolerate EIO from console writes to avoid gateway crashes. (#925, fixes #878) - thanks @grp06.
  • Sandbox: restore docker.binds config validation for custom bind mounts. (#873) - thanks @akonyer.
  • Sandbox: preserve configured PATH for docker exec so custom tools remain available. (#873) - thanks @akonyer.
  • Slack: respect channels.slack.requireMention default when resolving channel mention gating. (#850) - thanks @evalexpr.
  • Telegram: aggregate split inbound messages into one prompt (reduces "one reply per fragment") (#57018). Thanks @hydro13.
  • Auto-reply: treat trailing NO_REPLY tokens as silent replies.
  • Config: prevent partial config writes from clobbering unrelated settings (base hash guard + merge patch for connection saves).