Commit Graph

  • 9130fd2b06 ci: harden workflow action input handling Peter Steinberger 2026-02-19 15:27:41 +01:00
  • efca61e3ac test: share cron tool mock harness Peter Steinberger 2026-02-19 14:26:59 +00:00
  • eb9861b20a test: share memory manager bootstrap helper Peter Steinberger 2026-02-19 14:25:08 +00:00
  • 2581b67cdb refactor: share exec approval request helper Peter Steinberger 2026-02-19 14:23:21 +00:00
  • 3179097a1f refactor: dedupe redact snapshot restore prelude Peter Steinberger 2026-02-19 14:18:28 +00:00
  • ffd4e85873 refactor: share allow-from merge and sender-id checks Peter Steinberger 2026-02-19 14:14:02 +00:00
  • ba538c98c7 refactor: share plain object guard across config and utils Peter Steinberger 2026-02-19 14:10:58 +00:00
  • 397f243ded refactor: dedupe gateway session guards and agent test fixtures Peter Steinberger 2026-02-19 14:08:50 +00:00
  • a99fd8f2dd refactor: reuse daemon action response type in lifecycle core Peter Steinberger 2026-02-19 14:03:47 +00:00
  • 672b1c5084 refactor: dedupe slack monitor mrkdwn and modal event base Peter Steinberger 2026-02-19 14:02:55 +00:00
  • cb6b835a49 test: dedupe heartbeat and action-runner fixtures Peter Steinberger 2026-02-19 13:59:27 +00:00
  • 26c9b37f5b fix(security): enforce strict IPv4 SSRF literal handling Peter Steinberger 2026-02-19 15:24:03 +01:00
  • 77c748304b refactor(plugins): extract safety and provenance helpers Peter Steinberger 2026-02-19 15:24:02 +01:00
  • 775816035e fix(security): enforce trusted sender auth for discord moderation Peter Steinberger 2026-02-19 15:18:00 +01:00
  • baa335f258 fix(security): harden SSRF IPv4 literal parsing Peter Steinberger 2026-02-19 15:14:22 +01:00
  • 3561442a9f fix(plugins): harden discovery trust checks Peter Steinberger 2026-02-19 15:13:34 +01:00
  • 5dc50b8a3f fix(security): harden npm plugin and hook install integrity flow Peter Steinberger 2026-02-19 15:10:57 +01:00
  • 2777d8ad93 refactor(security): unify gateway scope authorization flows Peter Steinberger 2026-02-19 15:06:28 +01:00
  • f4b288b8f7 refactor(feishu): dedupe mention regex escaping Peter Steinberger 2026-02-19 15:04:40 +01:00
  • b54ba3391b fix: credit contributor in changelog (#20916) (thanks @orlyjamie) Peter Steinberger 2026-02-19 14:59:30 +01:00
  • 29118995ad refactor(lobster): remove lobsterPath overrides Peter Steinberger 2026-02-19 14:58:01 +01:00
  • f8b61bb4ed refactor(acp): split session tests and share rate limiter Peter Steinberger 2026-02-19 14:55:00 +01:00
  • 19348050be style: normalize acp translator import ordering Peter Steinberger 2026-02-19 13:54:40 +00:00
  • 7a89049d1d refactor: dedupe pending pairing request flow and add reuse tests Peter Steinberger 2026-02-19 13:54:35 +00:00
  • d900d5efbd style: normalize ws message handler import ordering Peter Steinberger 2026-02-19 13:51:47 +00:00
  • 79ab4927c1 test: dedupe extracted-size budget assertions in archive tests Peter Steinberger 2026-02-19 13:51:38 +00:00
  • 7426848913 test(feishu): add mention regex injection regressions Peter Steinberger 2026-02-19 14:51:27 +01:00
  • 7e67ab75cc fix(feishu): escape regex metacharacters in stripBotMention Jamie 2026-02-19 23:41:36 +11:00
  • e01011e3e4 fix(acp): harden session lifecycle against flooding Peter Steinberger 2026-02-19 14:50:02 +01:00
  • 4ddc4dfd76 test: dedupe fetch cleanup-throw signal harness Peter Steinberger 2026-02-19 13:50:01 +00:00
  • 0bda0202fd fix(security): require explicit approval for device access upgrades Peter Steinberger 2026-02-19 14:49:03 +01:00
  • 182ffdf557 test: dedupe zai env test setup and cover blank legacy key Peter Steinberger 2026-02-19 13:48:17 +00:00
  • d9046f0d2a chore(deps): update dependencies to latest Peter Steinberger 2026-02-19 14:46:10 +01:00
  • 177654f526 refactor: dedupe APNs push send flow and add wake default test Peter Steinberger 2026-02-19 13:45:34 +00:00
  • 722a898f20 refactor: dedupe openclaw root traversal and add coverage Peter Steinberger 2026-02-19 13:43:24 +00:00
  • cf6edc6d57 docs(changelog): credit allsmog for Lobster security report Peter Steinberger 2026-02-19 14:42:53 +01:00
  • 758ea3c5a1 style: apply oxfmt import ordering for check Peter Steinberger 2026-02-19 14:38:49 +01:00
  • 08a7967936 fix(security): fail closed on gateway bind fallback and tighten canvas IP fallback Peter Steinberger 2026-02-19 14:36:39 +01:00
  • a40c10d3e2 fix: harden agent gateway authorization scopes Peter Steinberger 2026-02-19 14:37:56 +01:00
  • 165c18819e refactor(security): simplify safe-bin validation structure Peter Steinberger 2026-02-19 14:29:58 +01:00
  • 74c51aeb1e style: format gateway server methods Peter Steinberger 2026-02-19 13:32:52 +00:00
  • 7c9130f3c5 docs: require SECURITY.md before GHSA reviews Peter Steinberger 2026-02-19 14:32:15 +01:00
  • 268b0dc921 style: fix formatting drift in security allowlist checks Peter Steinberger 2026-02-19 13:30:52 +00:00
  • ff74d89e86 fix: harden gateway control-plane restart protections Peter Steinberger 2026-02-19 14:29:44 +01:00
  • 14b4c7fd56 refactor: dedupe provider usage auth/fetch logic and expand coverage Peter Steinberger 2026-02-19 13:27:40 +00:00
  • 2d485cd47a refactor(security): extract safe-bin policy and dedupe tests Peter Steinberger 2026-02-19 14:23:19 +01:00
  • 0e85380e56 style: format files and fix safe-bins e2e typing Peter Steinberger 2026-02-19 14:26:04 +01:00
  • e3e0ffd801 feat(security): audit gateway HTTP no-auth exposure Peter Steinberger 2026-02-19 14:25:45 +01:00
  • 808a60d3bd docs: clarify intentional network-visible canvas model in security policy Peter Steinberger 2026-02-19 14:25:34 +01:00
  • fec48a5006 refactor(exec): split host flows and harden safe-bin trust Peter Steinberger 2026-02-19 14:21:07 +01:00
  • b45bb6801c fix(doctor): skip embedding provider check when QMD backend is active (openclaw#17295) thanks @miloudbelarebia Thorfinn 2026-02-19 14:21:27 +01:00
  • bafdbb6f11 fix(security): eliminate safeBins file-existence oracle Peter Steinberger 2026-02-19 14:14:46 +01:00
  • 1316e57403 fix: enforce inbound attachment root policy across pipelines Peter Steinberger 2026-02-19 14:15:34 +01:00
  • cfe8457a0f fix(security): harden safeBins stdin-only enforcement Peter Steinberger 2026-02-19 14:07:43 +01:00
  • 3c127b6eac test: dedupe provider usage tests and expand coverage Peter Steinberger 2026-02-19 13:07:51 +00:00
  • ec232a9e2d refactor(security): harden temp-path handling for inbound media Peter Steinberger 2026-02-19 14:06:11 +01:00
  • 9f9cd5cbb2 refactor(browser): unify navigation guard path and error typing Peter Steinberger 2026-02-19 14:04:08 +01:00
  • badafdc7b3 refactor: dedupe provider usage fetch logic and tests Peter Steinberger 2026-02-19 12:50:55 +00:00
  • 6195660b1a fix(browser): unify SSRF guard path for navigation Peter Steinberger 2026-02-19 13:43:48 +01:00
  • 3c419b7bd3 docs(security): document webhook hardening and changelog Peter Steinberger 2026-02-19 13:31:04 +01:00
  • aa267812d3 test(security): add webhook hardening regressions Peter Steinberger 2026-02-19 13:30:59 +01:00
  • a23e0d5140 fix(security): harden feishu and zalo webhook ingress Peter Steinberger 2026-02-19 13:30:51 +01:00
  • e0aaf2d399 fix(security): block prototype-polluting keys in deepMerge (#20853) David Rudduck 2026-02-19 21:47:48 +10:00
  • 043b2f5e7a changelog: add unreleased fixes from recent PRs (#20897) Vincent Koc 2026-02-19 03:44:15 -08:00
  • 466a1e1cdb fix(clawdock): include docker-compose.extra.yml in helper commands (#17094) zerone0x 2026-02-19 19:40:47 +08:00
  • 3feb7fc3a3 fix(matrix): detect mentions in formatted_body matrix.to links (#16941) zerone0x 2026-02-19 19:40:21 +08:00
  • 825cc70796 test: dedupe gateway auth and sessions patch coverage (#20087) habakan 2026-02-19 20:35:58 +09:00
  • db73402235 Security: add explicit opt-in for deprecated plugin runtime exec (#20874) Mariano 2026-02-19 11:30:36 +00:00
  • e955582c8f security: add baseline security headers to gateway HTTP responses (#10526) Abdel Fane 2026-02-19 03:28:24 -08:00
  • 57102cbec9 Security: use crypto.randomBytes for temp file names (#20654) mahanandhi 2026-02-19 03:19:29 -08:00
  • fb35635c10 Security: use execFileSync instead of execSync with shell strings (#20655) mahanandhi 2026-02-19 03:19:09 -08:00
  • ee6d0bd321 fix(security): escape backticks in exec-approval command previews (#20854) David Rudduck 2026-02-19 21:17:06 +10:00
  • f1e1ad73ad fix(security): SHA-256 hash before timingSafeEqual to prevent length leak (#20856) David Rudduck 2026-02-19 21:16:35 +10:00
  • baf4a799a9 fix(security): use YAML core schema to prevent type coercion (#20857) David Rudduck 2026-02-19 21:15:36 +10:00
  • 9edec67a18 fix(security): block plaintext WebSocket connections to non-loopback addresses (#20803) Jay Caldwell 2026-02-19 05:13:08 -06:00
  • f7a7a28c56 fix: enforce hooks token separation from gateway auth (#20813) Coy Geek 2026-02-19 02:48:08 -08:00
  • 267bb3c81c changelog: backfill PR release-note entries (#20839) Vincent Koc 2026-02-19 02:43:57 -08:00
  • 3904d7ca06 deps: migrate request to @cypress/request (#20836) Vincent Koc 2026-02-19 02:41:13 -08:00
  • de656e3194 fix(otel): complete diagnostics-otel OpenTelemetry v2 API migration (#12897) Vincent Koc 2026-02-19 02:36:47 -08:00
  • 1faa7a87a0 lobster: parse windows cmd shim paths with rooted tokens (#20833) Vincent Koc 2026-02-19 02:34:08 -08:00
  • 942ed89277 deps: update overrides for minimatch and fast-xml-parser (#20832) Vincent Koc 2026-02-19 02:31:20 -08:00
  • a14dcafbaa Format: fix import ordering in two files (#20829) Vincent Koc 2026-02-19 02:18:27 -08:00
  • da341bfbe1 test(daemon): dedupe service path cases and bootstrap failures Peter Steinberger 2026-02-19 10:16:21 +00:00
  • e8e343aeee test(ci): fix launchd and diagnostics-otel test harnesses Peter Steinberger 2026-02-19 10:08:06 +00:00
  • 45db2aa0cd Security: disable plugin runtime command execution primitive (#20828) Mariano 2026-02-19 10:17:29 +00:00
  • 771af40913 chore(ci): fix main check blockers and stabilize tests Peter Steinberger 2026-02-19 10:15:25 +00:00
  • 53aecf7a8e test(bluebubbles): merge typing start stop method checks Peter Steinberger 2026-02-19 10:09:27 +00:00
  • 49d0def6d1 fix(security): harden imessage remote scp/ssh handling Peter Steinberger 2026-02-19 11:07:56 +01:00
  • cdb00fe242 fix(feishu): isolate temp download writes in mkdtemp dirs Peter Steinberger 2026-02-19 11:04:12 +01:00
  • 1b46f7d0ba refactor(daemon): simplify gateway service backend delegates Peter Steinberger 2026-02-19 10:03:17 +00:00
  • 70900feaa7 refactor(daemon): share service arg types across backends Peter Steinberger 2026-02-19 10:03:09 +00:00
  • be7462af1e Gateway: clarify launchctl domain bootstrap error (#13795) Vincent Koc 2026-02-19 02:03:23 -08:00
  • 88f698974a fix(otel): sanitize OTLP endpoint URL resolution (#13791) Vincent Koc 2026-02-19 02:02:57 -08:00
  • a7c0aa94d9 refactor(security): share safe temp media path builder (#20810) Mariano 2026-02-19 09:59:21 +00:00
  • ee1d6427b5 fix(security): enforce symlink-safe skill packaging Peter Steinberger 2026-02-19 10:54:45 +01:00
  • c275932aa4 fix(security): OC-22 prevent Zip Slip and symlink following in skill packaging aether-ai-agent 2026-02-19 20:32:23 +11:00
  • c06ad38a71 test(voice-call): merge provider credential source cases Peter Steinberger 2026-02-19 09:55:43 +00:00
  • 981d266480 security(gateway): block webchat session mutators (#20800) Vincent Koc 2026-02-19 01:54:02 -08:00
  • 32ba62dc69 test(bluebubbles): merge setGroupIcon credential checks Peter Steinberger 2026-02-19 09:51:35 +00:00
  • fa726792ce refactor(agents): dedupe pi subscribe e2e stream fixtures Peter Steinberger 2026-02-19 09:49:46 +00:00