mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 09:39:25 +00:00
* refactor: split release changelogs and synchronize docs mirrors * fix: complete split changelog instructions and validation wiring * fix: complete release changelog mirror integration Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver. * test: align docs agent Git ownership fixtures Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions. --------- Co-authored-by: Peter Steinberger <steipete@gmail.com>
3.8 KiB
3.8 KiB
2026.1.14-1
Highlights
- Web search:
web_search/web_fetchtools (Brave API) + first-time setup in onboarding/configure. - Browser control: Chrome extension relay takeover mode + remote browser control support.
- Plugins: channel plugins (gateway HTTP hooks) + Zalo plugin + onboarding install flow. (#854) - thanks @longmaba.
- Security: expanded
openclaw security audit(+--fix), detect-secrets CI scan, and aSECURITY.mdreporting policy.
Changes
- Docs: clarify per-agent auth stores, sandboxed skill binaries, and elevated semantics.
- Docs: add FAQ entries for missing provider auth after adding agents and Gemini thinking signature errors.
- Agents: add optional auth-profile copy prompt on
agents addand improve auth error messaging. - Security: expand
openclaw security auditchecks (model hygiene, config includes, plugin allowlists, exposure matrix) and extend--fixto tighten more sensitive state paths. - Security: add
SECURITY.mdreporting policy. - Channels: add Matrix plugin (external) with docs + onboarding hooks.
- Plugins: add Zalo channel plugin with gateway HTTP hooks and onboarding install prompt. (#854) - thanks @longmaba.
- Onboarding: add a security checkpoint prompt (docs link + sandboxing hint); require
--accept-riskfor--non-interactive. - Docs: expand gateway security hardening guidance and incident response checklist.
- Docs: document DM history limits for channel DMs. (#883) - thanks @pkrmf.
- Security: add detect-secrets CI scan and baseline guidance. (#227) - thanks @Hyaxia.
- Tools: add
web_search/web_fetch(Brave API), auto-enableweb_fetchfor sandboxed sessions, and remove thebrave-searchskill. - CLI/Docs: add a web tools configure section for storing Brave API keys and update onboarding tips.
- Browser: add Chrome extension relay takeover mode (toolbar button), plus
openclaw browser extension install/pathand remote browser control (standalone server + token auth).
Fixes
- Sessions: refactor session store updates to lock + mutate per-entry, add chat.inject, and harden subagent cleanup flow. (#944) - thanks @tyler6204.
- Browser: add tests for snapshot labels/efficient query params and labeled image responses.
- Google: downgrade unsigned thinking blocks before send to avoid missing signature errors.
- Doctor: avoid re-adding WhatsApp config when only legacy ack reactions are set. (#927, fixes #900) - thanks @grp06.
- Agents: scrub tuple
itemsschemas for Gemini tool calls. (#926, fixes #746) - thanks @grp06. - Agents: harden Antigravity Claude history/tool-call sanitization. (#968) - thanks @rdev.
- Agents: stabilize sub-agent announce status from runtime outcomes and normalize Result/Notes. (#835) - thanks @roshanasingh4.
- Embedded runner: suppress raw API error payloads from replies. (#924) - thanks @grp06.
- Auth: normalize Claude Code CLI profile mode to oauth and auto-migrate config. (#855) - thanks @sebslight.
- Daemon: clear persisted launchd disabled state before bootstrap (fixes
daemon installafter uninstall). (#849) - thanks @ndraiman. - Logging: tolerate
EIOfrom console writes to avoid gateway crashes. (#925, fixes #878) - thanks @grp06. - Sandbox: restore
docker.bindsconfig validation for custom bind mounts. (#873) - thanks @akonyer. - Sandbox: preserve configured PATH for
docker execso custom tools remain available. (#873) - thanks @akonyer. - Slack: respect
channels.slack.requireMentiondefault when resolving channel mention gating. (#850) - thanks @evalexpr. - Telegram: aggregate split inbound messages into one prompt (reduces "one reply per fragment") (#57018). Thanks @hydro13.
- Auto-reply: treat trailing
NO_REPLYtokens as silent replies. - Config: prevent partial config writes from clobbering unrelated settings (base hash guard + merge patch for connection saves).